All news
Enforcement January 26, 2026 8 min

Sweden: SEK 6 million for an SQL injection. The hardest part is not the fine, it is that the risk had been sitting in their own risk register since 2021

IMY used the company's own risk assessments as evidence of gross negligence. Documenting a risk and not closing it is worse than never having seen it

TL;DR for the DPO

Three things. First: a risk written into an assessment and never closed becomes proof that you knew, and IMY used it as an aggravating factor. Second: Article 32 applies identically to controllers and processors, and IMY refused to spend time separating the two roles. Third: the fine was calculated on the group's turnover, not the company's, because holding 85% of the shares plus an agreement for the rest is enough to form a single economic unit.

What happened

Sportadmin provides sports clubs and other organisations with a web tool for member management, invoicing and websites, plus an app used by club officials, members and parents. On 16 January 2025 the company discovered an intrusion and notified IMY the next day. Log analysis showed the attacker got in through an SQL injection against a variable present on one of the web pages, which lacked protection against that type of attack, and that attempts had started on the morning of 14 January. On 14 March 2025 all the exfiltrated data appeared on the darknet.

2,126,075
people affected, identifiable through their Swedish personal identity number

The data included full names, contact details, sex, personal identity numbers, the relationship between guardian and member, nationality, the sport and the club. And, among special categories, allergies and disabilities. Because sports clubs mainly run activities for children and young people, that is the group most represented in the records.

The variable of 28 June 2022

The defect goes back to a change to the login procedure for club websites, made on 28 June 2022. That change introduced a variable on a web page and, because it reused a variable the company regarded as safe, nobody applied the SQL injection protection method the company did in fact have. In early 2023 Sportadmin introduced a reinforced protection method, but it did not know that variable was unprotected, so the method was never applied to it.

Two further factors widened the damage: the SQL account had higher privileges than necessary for compatibility reasons with the older system, and the Windows account running the SQL service had more than the company knew. The SQL server also allowed external programs to be executed, for example PowerShell scripts.

The point that changes how you write risk assessments

Sportadmin is not a company without processes. It ran broad reviews in 2021, in 2022 and around the turn of 2023 into 2024, and in those reviews it consistently identified a heightened risk of intrusion through SQL injection, caused by the presence of older code. In May and June 2024 it had also assessed introducing a Web Application Firewall, then set it aside because it required too much manual handling and carried high implementation costs.

How IMY turned the argument around

The company offered those reviews in its defence: look how much work we do on security. IMY read them the other way round. If for years you identified that exact risk, and for years you deferred the measures needed to cover it - measures you then delivered within days of the incident - you were not unlucky: you were grossly negligent. Gross negligence entered the calculation as an aggravating factor.

It is worth pausing here, because it is counterintuitive and it has practical consequences. A risk register is not a neutral document to show an inspector. It is a dated statement of what you knew. If there is no measure with a date and an outcome next to the risk, that document works against you.

Controller or processor: Article 32 does not care

IMY notes that Sportadmin acts mainly as a processor and only to a limited extent as a controller, and then says something useful: since the Article 32 obligation falls identically on controllers and processors, it will not set about establishing which role applied to each activity. Whoever designs and supplies the service is the one with the actual ability to implement the measures, and that is enough.

The 72-hour cascade

There is an operational aspect worth attention. The incident concerned a supplier, but each sports club was a controller for its own members and therefore had its own notification to make. Sportadmin shut down all services about an hour after discovery, then made over 2,000 phone calls to the clubs to help them notify, and around 1,700 of them filed within 72 hours of the incident.

What did not reduce the fine, and what did

IMY ruled out self-reporting and cooperation with the authority as mitigating factors, because they are what is expected of anyone. It also ruled out the technical measures adopted after the incident, with a blunt reason: for the most part they were what should have been done beforehand. The only mitigating factor recognised was the active coordinating role towards the sports clubs, enabling them to meet their own obligations on time.

The turnover used as the basis was not the company's

Sportadmin argued it was an autonomous unit: its own board, its own offices, its own technical environment, and a parent holding 85% of the shares without exercising decisive influence. IMY answered by reconstructing the links: the 85% acquired on 9 January 2024 with an agreement for the remaining 15% in the third quarter of 2027, the company referred to throughout the parent's annual report under the group name, two directors out of five holding positions in both companies, four sitting in group management, the group's chief legal officer acting as counsel in the investigation, and documented code-change procedures supplied by the group.

685,700,000SEK
kronor: 2024 group turnover used as the basis of calculation

Conclusion: a single economic unit within the meaning of Articles 101 and 102 TFEU, the basis of calculation being the group's 2024 turnover of roughly SEK 685,700,000. Two per cent of that is SEK 13,714,000, lower than the static maximum, so the applicable cap remains EUR 10 million. The final fine is SEK 6,000,000, with high severity and group turnover on one side and the coordination mitigation on the other.

What to do now, in practice

1) Take your clients' risk assessments from the last three years and look for risks that repeat identically year after year: those are the most dangerous, not because they are the most severe but because they prove you knew. Each one needs a measure with a date and an outcome. 2) Ask software suppliers how code review is organised: if it is not mandatory and the risk criteria are subjective, you have just found the defect. 3) Check the privileges of service and database accounts: here they multiplied the damage. 4) If a client uses a platform shared with other organisations, put in writing now who tells whom and within what time: in the Swedish case 1,700 controllers each had their own 72-hour deadline. 5) Remember that a processor answers for Article 32 just as a controller does, and that if it belongs to a group the fine may be calculated on the group's turnover.

The decision can be appealed within three weeks to the Administrative Court in Stockholm, so the amount is not final.

Official source:IMY - Decision after supervision under the GDPR, Sportadmin i Skandinavien AB, ref. IMY-2025-7801 (26 January 2026)

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

Enforcement
26complaints, and no fine

You declare contract, then you reject the objections: Norway shows how the two mistakes travel together

SATS asked members for a photo kept in the membership system and used at the desk to check the identity of people coming in. Datatilsynet found the notice stated the wrong legal basis, failed to explain the right to object, and that objections were rejected without demonstrating compelling legitimate grounds. The deadline to fix it is 11 September 2026.

Aug 26, 2026New 6 min
Enforcement
825 mln €the second-largest fine ever

Eight hundred and twenty-five million for an algorithm that deactivated accounts with nobody looking

It is the second-largest fine ever imposed under the GDPR, behind only Meta's 1.2 billion. It is not about a data transfer or a security breach: it is about Article 22, the rule on automated decisions that almost nobody documents because it looks like a big-platform problem. It is in fact about anyone who lets software decide something that weighs on a person's life.

Aug 24, 2026New 5 min
Enforcement
64 mln złagainst 14 the year before

Poland quadrupled its fines in a year, and the three highest ever all date from 2025

For years Poland was treated as a low-enforcement market. That assumption no longer holds: in twelve months the total went from fourteen to over sixty-four million zloty, and the three largest fines in the country's history all carry the same year. If you look after a client with a branch, a supplier or a service centre in Poland, the risk calculation has changed.

Aug 24, 2026New 4 min