The Swedish Data Protection Authority imposed a SEK 1.8 million fine on an HR systems provider
This decision shows that, where health and employment data are processed, security cannot be assessed solely by reference to safeguards formally put in place. The full text of the decision in our Judykatura database records that the authority also expects verification that security components are current and the ability to detect an attack promptly.
This article is available free of charge in full. Subscribe to our newsletter to receive new case notes and a discount code for your first subscription.
⚖️ Key theses (click to expand)
Thesis 1 — High data protection level
Extensive processing of data relating to approximately 2,200,000 individuals, including numerous data points about each person, health data, children’s data, identification numbers and data subject to special protection, involved a high risk to the rights and freedoms of natural persons. The risk of unauthorised disclosure or access could have serious consequences for data subjects; therefore, the processing required a high level of security.
Thesis 2 — Version control is fundamental
When new software that has not first been tested in a test environment is installed on an internet-facing server, it was particularly important to verify that the correct version of the security component was installed. That verification was a fundamental security measure, especially where vulnerabilities in the outdated version were known.
Thesis 3 — Supplier trust is insufficient
The processor was responsible for ensuring adequate protection of personal data in its services. Failing to verify the version of a component because the product came from a well-known supplier resulted in the installation of a version with a critical vulnerability, which was subsequently exploited by the attacker, and did not ensure measures appropriate to the risk of unauthorised access or disclosure.
Thesis 4 — Real-time monitoring is necessary
Monitoring systems directed mainly at system performance and availability were insufficient to detect the initial intrusion attempts, the attacker’s movement within the systems, server encryption or data transfer. Given the high risk, automated real-time monitoring capable of identifying suspicious activity and intrusions or attempted intrusions was a fundamental security measure.
Thesis 5 — Fine for negligent security
The infringement of Article 32(1) GDPR resulted from a failure to implement sufficient technical and organisational measures. The Swedish Data Protection Authority found the company negligent and the infringement serious because it enabled unauthorised access to a large volume of sensitive and specially protected data, part of which was published on the Darknet.
In its decision of 22 September 2026, the Swedish Data Protection Authority, Integritetsskyddsmyndigheten (IMY), imposed an administrative fine of SEK 1,800,000 on a provider of digital systems supporting personnel and workplace-environment management for an infringement of Article 32(1) GDPR. The authority found that the company had failed to ensure measures appropriate to the high risk associated with the processing.
What was the case about?
The company provided web-based services used, among other things, to manage sickness absence, rehabilitation, workplace incidents and workplace-environment matters. In August 2025, it suffered a ransomware attack. The attacker exploited a vulnerability in a component supporting a firewall solution, gained access to the technical environment, escalated privileges, moved between servers, encrypted them and extracted data.
The incident affected approximately 2,200,000 individuals. The systems processed, among other data, identification and contact data, employment and absence data, as well as health data, rehabilitation documentation, information concerning pupil incidents and, to a certain extent, data subject to special protection. Part of the disclosed information was subsequently published on the Darknet.
Why did the processing require a high level of security?
IMY combined the scale of processing with the nature of the data. The services covered the data of approximately 2,200,000 individuals and contained approximately 20 categories of information for each of them. The authority attached particular importance to health data, children’s data, identification numbers and data subject to special protection.
The authority stated that “unauthorised disclosure or unauthorised access to personal data could have serious consequences for the data subjects” (editorial translation). Consequently, a high level of security was required, ensuring the resilience of the services and the effectiveness of the technical and organisational measures.
Can a controller rely on the version supplied by the manufacturer?
Not in the circumstances of this case. Approximately one week before the incident, the company installed a component supplied by a well-known manufacturer. The supplied version was, however, outdated and contained a known critical vulnerability. Information about that vulnerability had been available on the manufacturer’s website more than a year before the installation.
The company explained that it had had no reason to suspect that it had received an outdated version of an expensive product from a reputable supplier. IMY nevertheless found that the operator of the technical environment bore responsibility for ensuring adequate protection of the personal data processed.
The authority held that “a fundamental security measure was to verify that the correct version of the component had been installed” (editorial translation). Three factors reinforced the importance of that verification: the component was installed on an internet-facing server, it had not previously been tested in a test environment, and the vulnerability in the outdated version was known.
Can performance monitoring detect an intrusion?
IMY answered in the negative. The attack began on 20 August 2025, whereas technical alerts concerning service malfunctions were triggered on 23 August. For three days, the attacker was able to move through the technical environment before the incident was detected.
The monitoring in use was primarily directed at system performance and availability. It did not warn of the initial intrusion attempts, the attacker’s activity, server encryption or data transfer. The authority found that, given such a high risk, automated real-time threat monitoring capable of identifying suspicious activity, intrusions and attempted intrusions was a fundamental measure.
IMY stressed that the earlier implementation of such measures would have given the company a better opportunity to detect the incident earlier and limit its scope.
Why did the authority impose a fine?
IMY assessed the infringement as negligent and of high severity. Relevant factors included the scale of the incident, the nature of the data, the inclusion of specially protected data and the fact that the attacker accessed the data and published part of them on the Darknet.
The authority did not consider either the encryption of attachments and free-text fields or the remedial measures implemented after the attack sufficiently mitigating. It noted that encryption did not demonstrate that the data had been protected from unauthorised access during the incident. It did, however, take into account to a limited extent the information measures undertaken by the company towards the numerous controllers after the event.
The principal practical conclusion is twofold. First, in systems processing health and employment data, verifying the currency and security of installed components cannot be replaced by trust in a supplier. Secondly, monitoring intended solely to ensure business continuity does not by itself satisfy the requirement to detect threats to data confidentiality.
This material was prepared partly with the use of a general-purpose AI model and, despite due care, may contain errors. The information provided does not constitute legal advice — it reflects solely the Author's view.
The rest of this analysis, all theses and the full text of the ruling are available with an AKTUALNOŚCI PLUS subscription.
Find out how EU supervisory authorities, administrative and civil courts and the CJEU reason their decisions — and keep your organisation aligned with current case law.