Swedish DPA fines Trygg-Hansa $3.2M for GDPR breaches

Trygg-Hansa

Sweden’s data protection authority (DPA) issued a penalty of 35 million Swedish krona (U.S. $3.2 million) against insurance company Trygg-Hansa for alleged security flaws that made customer insurance information accessible on the internet.

The issue occurred in November 2020 at Moderna Försäkringar, which Trygg-Hansa merged with in April 2022, the company said in a translated clarifying statement. Trygg-Hansa said the issue did not affect its customers.

The Swedish DPA said in a translated press release Wednesday its review, informed by a customer tip, found the data of 650,000 Moderna Försäkringar customers was left accessible from October 2018 to February 2021. The tipster “noticed that it was possible to access other policyholders’ documents, without any kind of login, by simply replacing a few numbers in the web link,” according to the regulator.

lock iconTHIS IS MEMBERS-ONLY CONTENT. To continue reading, choose one of the options below.