TL;DR for the DPO
Three things. First: a risk written into an assessment and never closed becomes proof that you knew, and IMY used it as an aggravating factor. Second: Article 32 applies identically to controllers and processors, and IMY refused to spend time separating the two roles. Third: the fine was calculated on the group's turnover, not the company's, because holding 85% of the shares plus an agreement for the rest is enough to form a single economic unit.
What happened
Sportadmin provides sports clubs and other organisations with a web tool for member management, invoicing and websites, plus an app used by club officials, members and parents. On 16 January 2025 the company discovered an intrusion and notified IMY the next day. Log analysis showed the attacker got in through an SQL injection against a variable present on one of the web pages, which lacked protection against that type of attack, and that attempts had started on the morning of 14 January. On 14 March 2025 all the exfiltrated data appeared on the darknet.
The data included full names, contact details, sex, personal identity numbers, the relationship between guardian and member, nationality, the sport and the club. And, among special categories, allergies and disabilities. Because sports clubs mainly run activities for children and young people, that is the group most represented in the records.
The variable of 28 June 2022
The defect goes back to a change to the login procedure for club websites, made on 28 June 2022. That change introduced a variable on a web page and, because it reused a variable the company regarded as safe, nobody applied the SQL injection protection method the company did in fact have. In early 2023 Sportadmin introduced a reinforced protection method, but it did not know that variable was unprotected, so the method was never applied to it.
Two further factors widened the damage: the SQL account had higher privileges than necessary for compatibility reasons with the older system, and the Windows account running the SQL service had more than the company knew. The SQL server also allowed external programs to be executed, for example PowerShell scripts.
The point that changes how you write risk assessments
Sportadmin is not a company without processes. It ran broad reviews in 2021, in 2022 and around the turn of 2023 into 2024, and in those reviews it consistently identified a heightened risk of intrusion through SQL injection, caused by the presence of older code. In May and June 2024 it had also assessed introducing a Web Application Firewall, then set it aside because it required too much manual handling and carried high implementation costs.
How IMY turned the argument around
The company offered those reviews in its defence: look how much work we do on security. IMY read them the other way round. If for years you identified that exact risk, and for years you deferred the measures needed to cover it - measures you then delivered within days of the incident - you were not unlucky: you were grossly negligent. Gross negligence entered the calculation as an aggravating factor.
It is worth pausing here, because it is counterintuitive and it has practical consequences. A risk register is not a neutral document to show an inspector. It is a dated statement of what you knew. If there is no measure with a date and an outcome next to the risk, that document works against you.
Controller or processor: Article 32 does not care
IMY notes that Sportadmin acts mainly as a processor and only to a limited extent as a controller, and then says something useful: since the Article 32 obligation falls identically on controllers and processors, it will not set about establishing which role applied to each activity. Whoever designs and supplies the service is the one with the actual ability to implement the measures, and that is enough.
The 72-hour cascade
There is an operational aspect worth attention. The incident concerned a supplier, but each sports club was a controller for its own members and therefore had its own notification to make. Sportadmin shut down all services about an hour after discovery, then made over 2,000 phone calls to the clubs to help them notify, and around 1,700 of them filed within 72 hours of the incident.
What did not reduce the fine, and what did
IMY ruled out self-reporting and cooperation with the authority as mitigating factors, because they are what is expected of anyone. It also ruled out the technical measures adopted after the incident, with a blunt reason: for the most part they were what should have been done beforehand. The only mitigating factor recognised was the active coordinating role towards the sports clubs, enabling them to meet their own obligations on time.
The turnover used as the basis was not the company's
Sportadmin argued it was an autonomous unit: its own board, its own offices, its own technical environment, and a parent holding 85% of the shares without exercising decisive influence. IMY answered by reconstructing the links: the 85% acquired on 9 January 2024 with an agreement for the remaining 15% in the third quarter of 2027, the company referred to throughout the parent's annual report under the group name, two directors out of five holding positions in both companies, four sitting in group management, the group's chief legal officer acting as counsel in the investigation, and documented code-change procedures supplied by the group.
Conclusion: a single economic unit within the meaning of Articles 101 and 102 TFEU, the basis of calculation being the group's 2024 turnover of roughly SEK 685,700,000. Two per cent of that is SEK 13,714,000, lower than the static maximum, so the applicable cap remains EUR 10 million. The final fine is SEK 6,000,000, with high severity and group turnover on one side and the coordination mitigation on the other.
What to do now, in practice
1) Take your clients' risk assessments from the last three years and look for risks that repeat identically year after year: those are the most dangerous, not because they are the most severe but because they prove you knew. Each one needs a measure with a date and an outcome. 2) Ask software suppliers how code review is organised: if it is not mandatory and the risk criteria are subjective, you have just found the defect. 3) Check the privileges of service and database accounts: here they multiplied the damage. 4) If a client uses a platform shared with other organisations, put in writing now who tells whom and within what time: in the Swedish case 1,700 controllers each had their own 72-hour deadline. 5) Remember that a processor answers for Article 32 just as a controller does, and that if it belongs to a group the fine may be calculated on the group's turnover.
The decision can be appealed within three weeks to the Administrative Court in Stockholm, so the amount is not final.
Official source:IMY - Decision after supervision under the GDPR, Sportadmin i Skandinavien AB, ref. IMY-2025-7801 (26 January 2026)Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free