Lime Technologies’ Sportadmin Fined 6 Million Kronor Over Massive Data Breach
Sweden-based IT company Lime Technologies AB, a provider of CRM and SaaS solutions including Sportadmin a club management service has been fined 6 million kronor (approx. €530,000) by the Swedish Authority for Privacy Protection (IMY) for inadequate IT security following a January 2025 data breach. The incident exposed personal information of over 2.1 million individuals, including children and young people, with leaked data encompassing personal identity numbers, club affiliations, and in some cases, sensitive protected information.
The IMY ruled that Sportadmin violated Article 32 of the GDPR, which mandates sufficient technical and organizational safeguards to protect personal data. The breach highlighted systemic failures in the company’s security measures, prompting regulatory action.
Lime Technologies, which operates across the Nordic region with offices in Sweden, Norway, Denmark, and Finland, develops cloud-based CRM systems such as Lime Go and Lime CRM. The fine arrives amid leadership changes, including the appointment of Tommas Davoust as CEO, effective January 1, 2026, succeeding Nils Olsson. The company also recently acquired a portal solution from E.ON in Germany, signaling expansion efforts.
The incident underscores growing regulatory scrutiny over data protection in the SaaS sector, particularly for platforms handling sensitive user information.
SportAdmin cybersecurity rating report: https://www.rankiteo.com/company/sportadmin
Lime Technologies cybersecurity rating report: https://www.rankiteo.com/company/lime-technologies
"id": "SPOLIM1769425652",
"linkid": "sportadmin, lime-technologies",
"type": "Breach",
"date": "1/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '2100000',
'industry': 'CRM, Club Management, Cloud Services',
'location': 'Sweden (Nordic region: Sweden, Norway, '
'Denmark, Finland)',
'name': 'Lime Technologies AB',
'type': 'IT Company / SaaS Provider'}],
'data_breach': {'number_of_records_exposed': '2100000',
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High (includes children and young '
'people)',
'type_of_data_compromised': ['Personal identity numbers',
'Club affiliations',
'Sensitive protected '
'information']},
'date_detected': '2025-01',
'description': 'Sweden-based IT company Lime Technologies AB, provider of CRM '
'and SaaS solutions including Sportadmin, was fined 6 million '
'kronor (approx. €530,000) by the Swedish Authority for '
'Privacy Protection (IMY) for inadequate IT security following '
'a January 2025 data breach. The incident exposed personal '
'information of over 2.1 million individuals, including '
'children and young people, with leaked data encompassing '
'personal identity numbers, club affiliations, and in some '
'cases, sensitive protected information.',
'impact': {'brand_reputation_impact': 'Yes',
'data_compromised': 'Personal identity numbers, club affiliations, '
'sensitive protected information',
'financial_loss': '6000000 SEK (approx. €530,000)',
'identity_theft_risk': 'High',
'legal_liabilities': 'GDPR violation (Article 32)',
'systems_affected': 'Sportadmin (club management service)'},
'investigation_status': 'Completed (regulatory action taken)',
'lessons_learned': 'Systemic failures in security measures highlight the need '
'for sufficient technical and organizational safeguards '
'under GDPR.',
'post_incident_analysis': {'root_causes': 'Inadequate IT security measures'},
'recommendations': 'Implement robust IT security measures, enhance '
'monitoring, and ensure compliance with GDPR Article 32.',
'references': [{'source': 'Swedish Authority for Privacy Protection (IMY)'}],
'regulatory_compliance': {'fines_imposed': '6000000 SEK (approx. €530,000)',
'regulations_violated': ['GDPR Article 32'],
'regulatory_notifications': 'Swedish Authority for '
'Privacy Protection '
'(IMY)'},
'title': 'Lime Technologies’ Sportadmin Data Breach and GDPR Violation',
'type': 'Data Breach',
'vulnerability_exploited': 'Inadequate IT security measures'}