Swedish DPA Fines Processor for GDPR Security Failure

26th February 2026

The Swedish data protection agency IMY has imposed a SEK 6 million fine on software supplier SportAdmin following a data breach that exposed the data of 2 million individuals, many of whom are children. This follows an IMY investigation that revealed SportAdmin had failed to implement appropriate security measures, in violation of Article 32 of the GDPR. What’s unusual about this case is that SportAdmin were not acting as a Controller, but a Processor. 

The SportAdmin Data Breach

In January 2025, hackers accessed SportAdmin’s IT systems using an SQL injection attack. This involves inserting malicious SQL statements into an entry field, allowing attackers to tamper with or access all data held in the database server. Due to a security vulnerability, hackers were able to obtain the personal data of more than 2.1 million people, primarily children and young people involved in sports clubs. This data was then published on the dark web and included personal information such as contact details, addresses, information about guardians and family relationships, and even sensitive health data.

The IMY Investigation

The IMY conducted an investigation of SportAdmin following the data breach and found that technical and organisational failures led to the data breach. SportAdmin had long been aware of weaknesses in its IT system, and its efforts to address them were not effective. They had no procedures in place to detect deficiencies in their existing security measures, no real-time monitoring in place to identify hacking attempts, and insufficient code review routines. Additionally, users had excessive system permissions, increasing the impact of the data breach.

Following their investigation, the discovery of the multiple, avoidable failures that led to the data breach, and the amount of personal data leaked relating to children, the IMY issued a fine of SEK 6 million, which is approximately £491,000. 

The Role of Processors vs Controllers

A Controller is the party that makes decisions about processing activities and decides how and why data is processed. The Controller can be an individual or an organisation. A Processor is the party that acts under the instruction of the Controller and processes personal data on behalf of the Controller. Again, a Controller can be an individual or an organisation. In this case, SportAdmin were acting as the Processor, processing personal data on behalf of sports clubs in Sweden. While the overall responsibility of data protection lies with the Controller, the Processor still has responsibilities under the GDPR and other data protection laws. While SportAdmin were processing data on behalf of the Controllers, they took on this responsibility. 

Article 32 of the GDPR

Article 32 (1) states that “the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk”. Article 32 (2) goes on to say “In assessing the appropriate level of security account shall be taken in particular of the risks that are presented by processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data transmitted, stored or otherwise processed”. Source: EU GDPR

SportAdmin violated this by failing to ensure the appropriate technical and organisational measures were in place, and by failing to consider the increased risk involved with the volume and sensitivity of the data they were processing.

This case teaches us that while Processors may have more limited compliance responsibilities than a Controller, they are still responsible for complying with the GDPR and are not exempt from enforcement actions from data protection authorities. Processors need to demonstrate their adherence to Article 32 and the GDPR in general – just making promises in their agreement with a Controller will not suffice. 

Takeaways for Organisations and Processors

If you employ the services of a Processor to process data on behalf of your organisation, you should ask for proof of their adherence to the GDPR and other data protection laws. Special category data and the personal data of children require stronger protection, and security measures should reflect this. The responsibilities of both the Controller and the Processor should be clearly defined so that there is no question of accountability and responsibility.

If you are acting as a Processor, be proactive about adherence to legislation – don’t wait until there is a problem to take action. This can include using a DPIA to assess risk, implementing risk-appropriate safeguards, active system monitoring to detect any hacking attempts, ongoing testing of systems to check for any weaknesses, and frequent code reviews.

If you are concerned about data processing activities, whether done by your own organisation or outsourced to a third party, we are here to help. You can get in touch with Griffin House Consultancy for a friendly chat to discuss your needs – see the contact form below.

Author: Mike Martin LLM

Mike is an information governance specialist and one of the founding directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting, and auditing requirements.

Sources

GRC Report

Legislation.gov.uk

EDPB 

Morling Consulting

IMY

Let us ease your mind

If you have any queries, questions or requests then please get in touch. We’re always very happy to talk, you’ll find a friendly voice on the end of the line or simply fill out the form below.

    Your Contact Details