SE — Country Profile

Sweden

17TOTAL
17OFFICIAL SOURCES
2TOPIC AREAS
Law / Act5
Executive Order1
National Strategy1
Standard / Framework1
Working Paper1
Court Case1
Other7
15 JAN 2026 · Law / Act

Cybersecurity Act (2025:1506) implementing NIS 2 Directive

On 15 January 2026, the Cybersecurity Act (2025:1506), transposing Directive (EU) 2022/2555 (NIS 2 Directive), enters into force. The Act applies to public and private operators that fall within its scope under Chapters 1 and 2, including operators in sectors listed in Annexes I and II to the NIS 2 Directive and meeting the applicable size or designation criteria. Operators in scope are subject to binding obligations to register with the competent supervisory authority, implement appropriate ...

Primary legal sourceNational StrategyOfficial source · riksdagen.se ↗
12 SEP 2025 · Working Paper

Data Protection Authority inquiry into personal data processing for training artificial intelligence models in custody matters

On 9 December 2025, the Data Protection Authority (IMY) released a report on personal data processing for training artificial intelligence models in custody matters. The project, conducted with the law firm Familjens Jurist within the IMY regulatory sandbox, evaluated the use of custody case data to predict high-conflict scenarios. The inquiry focused on whether further processing for AI training complies with General Data Protection Regulation (GDPR) principles, specifically purpose limitati...

Official materialNational StrategyOfficial source · imy.se ↗
30 AUG 2024 · Other

Swedish Data Protection Authority investigation into Apoteket and Apohem for transfer of personal data to Meta

On 30 August 2024, the Swedish Data Protection Authority (IMY) issued a ruling in its investigation into local pharmacies Apoteket and Apohem for unlawful transfer of personal information to Meta. In particular, the IMY found that the companies breached Article 32(1) of the GDPR for failing to adopt adequate measures to ensure an appropriate level of security for the personal information of their customers when using the Meta pixel analysis tool on their websites. The tool was used by the com...

Official materialNational StrategyOfficial source · imy.se ↗
24 JUN 2024 · Law / Act

Data Protection Authority investigation into Avanza Bank's use of Meta-pixel analysis tool compliance with GDPR

On 24 June 2024, the Data Protection Authority (IMY) announced its decision to impose an administrative sanction fee of SEK 15 million against Avanza Bank AB for violating articles 5.1(f) and 32.1 of the General Data Protection Regulation (GDPR) due to inadequate security measures while using the Meta-pixel analysis tool from 15 November 2019 to 2 June 2021. Article 5.1f of GDPR requires that personal data must be processed securely, employing appropriate technical and organisational measures...

Primary legal sourceNational StrategyOfficial source · imy.se ↗
14 MAY 2024 · Other

IMY Legal position IMYRS 2024:1 on complaints against search services with publication certificates

On 14 May 2024, the Swedish Data Protection Authority (IMY) issued Legal position IMYRS 2024:1 on complaints against search services with publication certificates. The Legal position is issued to provide an operational position and guidance on an issue where there is no other guidance by courts or the European Data Protection Board. With the new Legal position, IMY changes its previous position regarding the investigation of data protection complaints with publication certificates under Swedi...

Official materialNational StrategyOfficial source · imy.se ↗
15 MAR 2024 · Court Case

IMY investigation into its decisions in complaints against holders of voluntary issuance certificates following Court of Appeal ruling on GDPR precedence

On 15 March 2024, the Swedish Data Protection Authority (IMY) announced a review of its handling of complaints against holders of voluntary publication licenses under the EU Data Protection Regulation (GDPR). This decision was made following the ruling in Case 6027-23 of the Administrative Court of Appeal. The Court ruled that constitutional protection of publication certificates does not always take precedence over the GDPR. IMY has received several complaints regarding holders of publicatio...

Court recordNational StrategyOfficial source · imy.se ↗
27 FEB 2024 · Standard / Framework

IMY Guideline on Processing of Personal Information by AI in Accordance with GDPR

Official source record dated 27 February 2024 for Sweden concerning IMY Guideline on Processing of Personal Information by AI in Accordance with GDPR. See the linked imy.se source for the authoritative text, procedural context, and implementation details.

Official materialNational StrategyOfficial source · imy.se ↗
09 FEB 2024 · Law / Act

Privacy Authority regulatory sandbox on LiDAR use in public spaces under GDPR and surveillance law

On 9 February 2024, the Swedish Authority for Privacy Protection (IMY) concluded its second regulatory sandbox pilot, focused on the use of LiDAR sensors to measure public safety conditions in urban environments. Conducted in partnership with the Stockholm City Transport Office, IoT Sweden, and Kista Science City, the project explored the legal implications of processing data from LiDAR-based Internet of Things (IoT) systems intended to estimate the demographic composition of crowds in public...

Primary legal sourceNational StrategyOfficial source · imy.se ↗
12 JAN 2024 · Law / Act

Law 2024:954 on supplementary national provisions to Digital Services Act in Sweden designating competent authorities and coordinator

On 1 December 2024, Law 2024:954 on supplementary provisions to the Digital Services Act (DSA) entered into force in Sweden. The Law supplements the DSA by setting out national rules on competent authorities, supervisory measures, judicial review, and sanctions. Within that framework, the Law designates the Swedish Post and Telecom Authority (PTS) as Sweden’s Digital Services Coordinator and assigns supervisory and enforcement responsibilities, alongside additional competent authorities for s...

Primary legal sourceContent ModerationOfficial source · data.riksdagen.se ↗
19 OCT 2023 · Other

IMY investigation into H&M's direct marketing based on data subject requests

On 19 October 2023, the Swedish Agency for Privacy Protection (IMY) issued an administrative fine of SEK 350,000 in its investigation into H&M over its alleged failure to stop direct marketing based on data subject requests in violation of the General Data Protection Regulation (GDPR). The IMY investigation found that the company has failed to handle requests from individuals who do not want to receive marketing from the company. H&M failed to stop the direct marketing based on personal data ...

Official materialNational StrategyOfficial source · imy.se ↗
18 SEP 2023 · Executive Order

IMY Regulations on the processing of personal data relating to criminal offences

On 18 September 2023, the Swedish Authority for Privacy Protection (IMY) published a draft of new regulations on the processing of personal data relating to criminal offences. The regulations set out the conditions under which persons other than the authorities can process personal data referred to in article 10 of EU regulation 2016/679 of 27 April 2016, and apply to companies under the supervision of the Financial Supervisory Authority offering financial services and being obliged to comply...

Primary legal sourceNational StrategyOfficial source · imy.se ↗
30 AUG 2023 · Law / Act

IMY investigation into Trygg-Hansa for alleged GDPR breach

On 30 August 2023, the Swedish Authority for Privacy Protection (IMY) imposed a fine of SEK 35 million on the insurance company Trygg-Hansa. The IMY, following its investigation, found vulnerabilities that resulted in the exposure of customer insurance data on the internet. The IMY's investigation determined that customer information for 650’000 individuals was accessible from October 2018 to February 2021. The IMY's findings indicated that Trygg-Hansa had failed to implement adequate technic...

Primary legal sourceNational StrategyOfficial source · imy.se ↗
26 JUN 2023 · Other

IMY investigation into Bonnier for alleged misuse of personal data

On 26 June 2023, the Swedish Privacy Protection Agency (IMY) fined Bonnier, a Swedish media group, for purportedly misusing personal data to ad profile customers. The company has been sanctioned with an administrative fine of SEK 13 million for the acquisition and management of personal data with the intention of using it for marketing, without obtaining the consent of the individuals involved. The IMY asserts that the company gathered information from multiple sources, which was subsequently...

Official materialNational StrategyOfficial source · imy.se ↗
15 MAY 2023 · Other

IMY Supervisory Plan 2023

On 15 May 2023, the Swedish Privacy Protection Authority (IMY) published its annual Supervisory Plan. The plan sets forth the IMY's decisions regarding the reviews to be conducted throughout the year. This year, the planned inspections encompass the evaluation of camera surveillance in publicly accessible locations. Earlier this year, the European Data Protection Board (EDPB) launched a collaborative effort to investigate the role and position of data protection officers. As part of this init...

Official materialNational StrategyOfficial source · imy.se ↗
20 DEC 2022 · Other

IMY investigation of Google LLC concerning data processing and compliance with right to be forgotten

On 20 December 2022, the Swedish Supreme Administrative Court decided not to grant an appeal in the Google v Swedish Authority for Privacy Protection's (IMY) case concerning Google's practices in complying with the right to be forgotten under the GDPR, giving effect to the judgment issued on 30 November 2021 by the Gothenburg Court of Appeal, which ordered Google to pay a fine of SEK 50 million. The Court of Appeal found that Google's practice of informing webmasters about the removal of a UR...

Official materialNational StrategyOfficial source · imy.se ↗
13 SEP 2022 · Other

Swedish Authority for Privacy Protection investigation into Klarna Bank AB identity verifications methods

On 13 September 2022, the Swedish Authority for Privacy Protection (APP) announced that it had opened an investigation into Klarna Bank concerning the company's methods of verifying individuals' identities. In particular, the Data Protection Authority opened its investigation in response to individual complaints against Klarna Bank. According to the complaints, Klarna Bank has made unreasonable demands on how private individuals have had to identify themselves. Individuals also complained abo...

Official materialNational StrategyOfficial source · imy.se ↗
National Strategy

National approach to artificial intelligence (Nationell inriktning för artificiell intelligens)

AI law in Sweden: Published by the Swedish Government on 16 May 2018, the "National approach to artificial intelligence" (Nationell inriktning för artificiell intelligens) sets out Sweden's strategic direction for AI focusing on four pillars: education, research, innovation & use, and framework & infrastructure. The document identifies priorities such as skills development, public-sector uptake, data access, ethical principles and participation in international standard-setting to realise AI's economic and societal benefits while managing associated risks....

Official materialNational StrategyOfficial source · digital-strategy.ec.europa.eu ↗