Changeflow GovPing Privacy Enforcement Administrative Fine for Data Collection Without...
Priority review Enforcement Amended Final

Administrative Fine for Data Collection Without Security

Favicon for www.imy.se IMY News (Sweden DPA)
Filed May 12th, 2025
Detected February 11th, 2026
Email

Summary

The Swedish Privacy Protection Authority (IMY) has issued an administrative fine of SEK 100,000 against the Equality Ombudsman (DO) for insufficient security measures during personal data collection via a web form. The incident led to the inadvertent disclosure of approximately 500 tips and complaints.

What changed

The Swedish Privacy Protection Authority (IMY) has imposed an administrative fine of SEK 100,000 on the Equality Ombudsman (DO) following a supervision of a personal data incident. The DO failed to implement sufficiently effective security measures for its web form used to collect tips and complaints, resulting in the inadvertent disclosure of personal data, potentially including sensitive information, to a data processor. Approximately 500 submissions were affected by this breach, which occurred over a year before being discovered and reported.

This enforcement action highlights the critical need for continuous and systematic work with data security to identify and rectify insufficient measures promptly. Regulated entities, particularly government agencies handling personal data, must ensure robust security protocols are in place and regularly reviewed to prevent data breaches and avoid potential fines. The DO has since closed the affected web form.

What to do next

  1. Review data collection web forms for adequate security measures.
  2. Ensure continuous and systematic monitoring of data security protocols.
  3. Verify that data processors have appropriate security agreements in place.

Penalties

SEK 100,000 administrative fine

Source document (simplified)

Svensk version Listen

Administrative fine against the Equality Ombudsman when personal data was collected via a web form

Published: 12 May 2025 The Swedish Privacy Protection Authority (IMY) has done a supervision of a personal data incident at the Equality Ombudsman (DO). IMY concludes that the DO did not take sufficiently effective security measures and issues an administrative fine of SEK 100,000. The reason for the supervision is a personal data breach that DO reported to the IMY in the fall of 2021. The incident concerned the DO's web form for collecting tips and complaints about discrimination. During the supervision, it emerged that the DO had taken a security measure intended to protect the personal data collected via the web form so that the data would not be included in usage analyses of the DO's website.

However, the security measure did not work as intended, which lead to some data, potentially sensitive personal data, being inadvertently disclosed to the personal data processor that the DO had hired to conduct the analyses. It is estimated that approximately 500 tips and complaints have been affected.

As soon as DO became aware of the incident, the authority closed the web form.

– The incident lasted for a year and shows the importance of working continuously and systematically with security in order to be able to discover insufficient security measures earlier, says Petter Flink, IT and information security specialist at IMY.

The decision in Swedish is published on the Swedish version of this site.

Latest update: 12 May 2025 Print Page labels Data protection, Tillsyn

More news on this topic

28 January 2026
- ### Administrative fines against two companies in the SL Group

3 July 2025
- ### The Hospital Board has failed in its security measures when handling e-mail

12 May 2025
- ### Administrative fines against Apoteket and Apohem for transferring personal data to Meta

3 July 2025
See more news

More news on this topic

28 January 2026
- ### Administrative fines against two companies in the SL Group

3 July 2025
- ### The Hospital Board has failed in its security measures when handling e-mail

12 May 2025
- ### Administrative fines against Apoteket and Apohem for transferring personal data to Meta

3 July 2025
See more news Latest update: 12 May 2025 Print Page labels Data protection, Tillsyn

Source

Analysis generated by AI. Source diff and links are from the original.

Classification

Agency
Various
Filed
May 12th, 2025
Instrument
Enforcement
Legal weight
Binding
Stage
Final
Change scope
Substantive

Who this affects

Applies to
Government agencies
Geographic scope
National (Sweden)

Taxonomy

Primary area
Data Privacy
Operational domain
Compliance
Topics
Data Security Enforcement Actions

Get Privacy Enforcement alerts

Weekly digest. AI-summarized, no noise.

Free. Unsubscribe anytime.

Get alerts for this source

We'll email you when IMY News (Sweden DPA) publishes new changes.

Free. Unsubscribe anytime.