Third-Party Risk

Sweden fined the supplier, not its customers. That should get your attention.

Published
Read time3 min read
Third-Party Risk

On 22 September 2026 Sweden's data protection authority, IMY, fined the IT supplier Miljödata SEK 1.8 million — around $183,000 — for breaching Article 32(1) of the GDPR. The sum is modest. The findings behind it are not, because they describe the two failures most organisations never think to ask a supplier about.

What happened

Miljödata provides work-environment and HR management systems used, according to reporting by Cybernews and teiss, by roughly 80% of Sweden's municipalities. In August 2025 it was breached. The compromised data spanned more than 200 regional and municipal bodies and included national identity numbers, addresses, confidential sickness absence records, workplace rehabilitation files and school disciplinary records involving minors.

Around 2.2 million people were affected. An extortion group demanded 1.5 Bitcoin on 25 August 2025; when Miljödata and public officials refused, the data was published on a leak site under the name Datacarry.

What the regulator actually faulted

IMY's decision turned on two specific shortcomings, and both are worth reading carefully:

  • No proper checks during the installation of new software. A change was made to a production system holding sensitive data about millions of people without the verification you would expect around it.
  • No automated, real-time monitoring capable of detecting breaches and suspicious activity. Not an absence of policy. An absence of the ability to notice.
Key points
Who was fined
The processor, not the municipalities whose residents' data was exposed.
The finding
Article 32(1) — inadequate technical and organisational measures.
Concentration risk
One supplier, roughly 80% of Swedish municipalities, 2.2 million people.

Three things this changes about supplier assurance

1. Processors are directly liable, and regulators are willing to say so. A common but mistaken reading of the GDPR treats the controller as the only party with real exposure. Article 32 applies to processors in their own right, and here the enforcement landed on the supplier. If you are a supplier holding customer data, your own security posture is now a balance sheet item, not just a sales objection to be handled.

2. Concentration risk is a governance question, not an IT one. When one supplier serves 80% of a sector, its control failures are systemic. None of those municipalities did anything unusual; they each bought a widely used, sector-standard product. The risk was in how many of them made the same reasonable decision.

3. "Can you detect it?" is now a due diligence question. Most supplier questionnaires ask whether the vendor has a security policy, holds a certification and encrypts data at rest. IMY's finding was about none of those. It was about whether anyone would notice an intrusion while it was happening. That is a different question, and it deserves to be asked directly: what monitoring runs, in real time, over the system holding our data, and who looks at the alerts?

What to do with your own supplier list

Start with the suppliers that hold your most sensitive data rather than the ones that spend the most. For each, you want evidence rather than assertion: what change control applies to the environment our data sits in, what detection covers it, how quickly they would tell us, and what their last incident looked like. A supplier that answers those four questions clearly is telling you something real. One that responds with a certificate number is telling you something too.

The practical obstacle is never knowing what to ask — it is the effort of asking hundreds of suppliers and reading what comes back. That is a solvable problem, and it is the one worth solving before a regulator makes the point for you.

See which of your suppliers could not detect a breach in the system holding your data.

Explore TPRM

Common questions

Yes. Article 32 places security obligations on processors as well as controllers, and IMY's decision against Miljödata is an example of a supervisory authority fining the supplier itself rather than the customers whose data it held.

Two things: it did not carry out proper checks when installing new software, and it had no automated real-time monitoring capable of detecting breaches and suspicious activity in its systems. The fine was SEK 1.8 million, roughly $183,000, under Article 32(1).

Add questions about detection and change control, not just policies and certifications. Ask what real-time monitoring covers the environment holding your data, who reviews the alerts, what change control applies to production, and how quickly the supplier commits to notifying you of a breach.

Sources

  1. Miljödata data breach exposes 2.2M people, draws GDPR fine — Cybernews, 22 September 2026
  2. Swedish regulator fines IT provider Miljödata over data breach affecting millions — teiss, 22 September 2026