🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
SE v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing23 sources retrieved model claude-sonnet-5 · 2026-08-03

Not every instrument is backed by its official text yet. At least one law or rulebook covered here has no official source (tier 1) retrieved for it yet. No finding on this page is shown with confidence above “Probable” until stronger sources are retrieved.

Sweden

SE schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 51 claims · 34 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
51Claimsbaseline..claims[]
17Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

Sweden's Integritetsskyddsmyndigheten (IMY) fined Miljödata i Karlskrona AB SEK 1.8 million on 22 September 2026 for violations of GDPR Article 32(1), the security-of-processing obligation, citing inadequate controls over software installation and the absence of real-time intrusion monitoring. The fine followed an August 2025 breach that exposed the data of 2.2 million people, a scale that marks this as a systemic security-of-processing enforcement finding against a supplier operating in the municipal sector rather than an isolated incident.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive omnibus regime in force with an active, well-resourced supervisory authority and clear statutory architecture.

Primary frameworkGDPR (Regulation (EU) 2016/679) as supplemented by the Act with Supplementary Provisions to the GDPR (SFS 2018:218)
Traffic-light rationale — GreenComprehensive omnibus regime in force with an active, well-resourced supervisory authority and clear statutory architecture.

Sub-modules (5)

Regulator And AuthorityGreen

IMY is Sweden's data protection authority responsible for GDPR compliance oversight.

Claims (1):

  • <cite index="2-19,2-20">IMY is Sweden's data protection authority whose mission is to work to ensure that individuals' fundamental rights and freedoms are protected in connection with the processing of personal data.</cite>

Act And InstrumentsGreen

SFS 2018:218 supplements the GDPR at national level; sectoral instruments (Criminal Data Act, Camera Surveillance Act, Credit Information Act) sit alongside it.

Claims (2):

  • <cite index="21-1,21-2">The Act with Supplementary Provisions to the EU General Data Protection Regulation (SFS 2018:218) supplements Regulation (EU) 2016/679 within Sweden.</cite>
  • <cite index="31-1">IMY supervises that the provisions in the Criminal Data Act and the Camera Surveillance Act are complied with</cite>, in addition to GDPR compliance.

Material ScopeGreen

Material scope follows GDPR Art 2/4 definitions as applied by IMY guidance for organisations and individuals.

Territorial ScopeGreen

GDPR Art 3 territorial scope applies directly in Sweden as an EU Member State; no SE-specific derogation identified in this research pass.

Absence provenance: unavailable. Searched: IMY territorial scope guidance, GDPR Art 3 Sweden.

Regulator Registration And FilingAmber

No general controller registration regime exists, but sector permits/notifications apply: credit information activity requires an IMY licence, and DPO appointments must be notified to IMY under Art 37.

Claims (2):

  • <cite index="38-1">IMY is the supervisory authority for the Credit Information Act and issues licences for those who wish to conduct credit information activity.</cite>
  • <cite index="4-18">IMY handles personal data concerning appointed data protection officers to be able to administrate notifications of data protection officers received in accordance with Article 37 of the GDPR.</cite>
Category narrative55 words

Sweden is an EU Member State and applies the GDPR directly, supplemented nationally by the Act with Supplementary Provisions to the GDPR (SFS 2018:218). The Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) is the competent supervisory authority under GDPR Art 51, and also supervises sector-specific instruments (Criminal Data Act, Camera Surveillance Act, Credit Information Act).

Sources and claims (5)
  1. ProbableIMY — <cite index="2-19,2-20">IMY is Sweden's data protection authority whose mission is to work to ensure that individuals' fundamental rights and freedoms are protected in connection with the processing of personal data.</cite>observed
  2. ProbableGovernment of Sweden / hosted via DataGuidance — <cite index="21-1,21-2">The Act with Supplementary Provisions to the EU General Data Protection Regulation (SFS 2018:218) supplements Regulation (EU) 2016/679 within Sweden.</cite>observed
  3. ProbableIMY — <cite index="31-1">IMY supervises that the provisions in the Criminal Data Act and the Camera Surveillance Act are complied with</cite>, in addition to GDPR compliance.observed
  4. ProbableIMY — <cite index="38-1">IMY is the supervisory authority for the Credit Information Act and issues licences for those who wish to conduct credit information activity.</cite>observed
  5. ProbableIMY — <cite index="4-18">IMY handles personal data concerning appointed data protection officers to be able to administrate notifications of data protection officers received in accordance with Article 37 of the GDPR.</cite>observed

#

Core lawful-basis and special-category framework is GDPR-aligned with active national derogations exercised and enforced.

Primary frameworkGDPR Arts 6-9, as supplemented by SFS 2018:218
Supervisory authorityIMY
Traffic-light rationale — GreenCore lawful-basis and special-category framework is GDPR-aligned with active national derogations exercised and enforced.

Sub-modules (4)

Lawful BasesGreen

GDPR Art 6 bases (consent, contract, legal obligation, vital interest, public task, legitimate interest) apply directly; SFS 2018:218 provides public-interest grounds for authorities.

Claims (1):

  • <cite index="6-3,6-5">Organisations processing personal data in Sweden must comply with the GDPR and must have a lawful ground in order to process personal data.</cite>

Special CategoriesAmber

IMY treats purchase data for certain non-prescription health/wellness products as revealing Art 9 sensitive data where linked to third-party ad transfers.

Claims (1):

  • In the Apohem decision, IMY found that <cite index="52-2,52-4">personal data affected by unlawful Meta Pixel transfers included names, social security numbers, email addresses, IP addresses, and phone numbers, and that both companies violated Article 32(1) of the GDPR</cite> in a context IMY treated as involving sensitive health/sex-life-adjacent purchase data.

Pseudonymisation And AnonymisationAmber

No SE-specific statutory safe-harbour beyond GDPR Recitals 26/28-29 identified in this pass.

Absence provenance: unavailable. Searched: IMY pseudonymisation guidance, Sweden anonymisation safe harbour.

Category narrative55 words

GDPR Art 6 lawful bases and Art 9 special-category rules apply directly, supplemented by SFS 2018:218 grounds for public-interest processing. Sweden exercised the Art 8 Member State derogation to set the digital age of consent at 13. IMY enforcement (e.g., the Apohem decision) shows an expansive reading of what constitutes health/sex-life data under Art 9.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (4)
  1. ProbableIMY — <cite index="6-3,6-5">Organisations processing personal data in Sweden must comply with the GDPR and must have a lawful ground in order to process personal data.</cite>observed
  2. ProbableIMY — <cite index="41-40,41-41">For consent to be valid it must be provided voluntarily, meaning the data subject has a genuinely free choice and control over their personal data</cite>, and must be as easy to withdraw as to give.observed
  3. ProbableDataGuidance — In the Apohem decision, IMY found that <cite index="52-2,52-4">personal data affected by unlawful Meta Pixel transfers included names, social security numbers, email addresses, IP addresses, and phone numbers, and that both companies violated Article 32(1) of the GDPR</cite> in a context IMY treated as involving sensitive health/sex-life-adjacent purchase data.observed
  4. ProbableGovernment of Sweden / hosted via DataGuidance — <cite index="43-1">When information society services are offered directly to a child living in Sweden, the child's personal data may be processed with the child's consent if the child is at least 13 years old.</cite>observed

#

Full GDPR rights suite in force with demonstrated enforcement of the objection-to-erasure pathway.

Primary frameworkGDPR Arts 12-22
Supervisory authorityIMY
Traffic-light rationale — GreenFull GDPR rights suite in force with demonstrated enforcement of the objection-to-erasure pathway.

Sub-modules (5)

Access RightGreen

Data subjects may request confirmation of processing and a free copy of their data plus contextual information.

Claims (1):

  • <cite index="9-20,9-21">The right of access means individuals can contact companies, authorities or other organisations to find out whether they are processing their personal data and, if so, receive a copy of it and information about how it is used.</cite>

Rectification And ErasureGreen

Erasure available where data is no longer needed, consent withdrawn, unlawfully processed, or (for minors) collected via a childhood social-media profile.

Claims (2):

  • <cite index="9-11,9-12">Data subjects have the right to contact a company or authority processing their personal data and request erasure where, among other grounds, the data is no longer needed for the purposes for which it was collected.</cite>
  • <cite index="9-18">Erasure is required if the personal data is about a child and was collected when the child created a profile on a social media platform.</cite>

Restriction And ObjectionAmber

Objection to direct marketing triggers mandatory erasure; IMY has fined a company for obstructing exercise of this right.

Claims (2):

  • <cite index="9-14">Erasure must occur if the processing is carried out for direct marketing and the data subject objects to the data being processed.</cite>
  • IMY reviewed complaints and found that <cite index="17-1,17-2">a company did not have sufficient systems and routines to make it easier for those who complained to exercise their right to object to direct marketing, issuing a fine of SEK 350,000</cite>.

Data PortabilityGreen

Portability right applies per GDPR Art 20; no SE-specific derogation identified.

Absence provenance: unavailable. Searched: IMY data portability guidance Sweden.

Deadlines And Response WindowsAmber

GDPR's one-month standard response window applies; no SE-specific shortening/extension found in this pass.

Absence provenance: unavailable. Searched: IMY response deadline guidance, SFS 2018:218 response window.

Category narrative29 words

GDPR Arts 12-22 rights apply directly, with IMY publishing consumer-facing guidance on access, rectification, erasure and objection. Enforcement activity (H&M direct-marketing case) shows IMY actively polices the objection/erasure interface.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (5)
  1. ProbableIMY — <cite index="9-20,9-21">The right of access means individuals can contact companies, authorities or other organisations to find out whether they are processing their personal data and, if so, receive a copy of it and information about how it is used.</cite>observed
  2. ProbableIMY — <cite index="9-11,9-12">Data subjects have the right to contact a company or authority processing their personal data and request erasure where, among other grounds, the data is no longer needed for the purposes for which it was collected.</cite>observed
  3. ProbableIMY — <cite index="9-14">Erasure must occur if the processing is carried out for direct marketing and the data subject objects to the data being processed.</cite>observed
  4. ProbableEDPB / IMY — IMY reviewed complaints and found that <cite index="17-1,17-2">a company did not have sufficient systems and routines to make it easier for those who complained to exercise their right to object to direct marketing, issuing a fine of SEK 350,000</cite>.observed
  5. ProbableIMY — <cite index="9-18">Erasure is required if the personal data is about a child and was collected when the child created a profile on a social media platform.</cite>observed

#

Framework is comprehensive and enforced robustly, but repeated large fines (SEK 6m, 37m, 8m) indicate ongoing systemic security-measure compliance gaps among controllers.

Primary frameworkGDPR Arts 5, 24-43; SFS 2018:218 Ch.1 §8
Supervisory authorityIMY
Traffic-light rationale — AmberFramework is comprehensive and enforced robustly, but repeated large fines (SEK 6m, 37m, 8m) indicate ongoing systemic security-measure compliance gaps among controllers.

Sub-modules (7)

Accountability And DpiaGreen

DPIA required for high-risk processing per GDPR Art 35 and EDPB-derived IMY criteria (e.g., large-scale sensitive data or systematic large-scale public surveillance).

Claims (1):

  • <cite index="41-19,41-21">GDPR requires an impact assessment for processing on a large scale of sensitive personal data and for systematic surveillance of a public space on a large scale</cite>, per criteria IMY has published drawing on EDPB guidance.

Dpo RequirementsGreen

DPO appointment thresholds follow GDPR Art 37, supplemented by SFS 2018:218 Ch.1 §8.

Claims (1):

  • <cite index="29-3">Chapter 1, Section 8 of the Act with Supplementary Provisions to the GDPR (SFS 2018:218) supplements Articles 37-39 of the GDPR on DPO appointment.</cite>

Ropa RequirementsGreen

ROPA obligations follow GDPR Art 30 directly; no SE-specific derogation identified.

Absence provenance: unavailable. Searched: IMY records of processing guidance.

Joint Controller ArrangementsAmber

The Apohem Meta Pixel decision treated the retailer and Meta as separately data-controller-responsible parties for different aspects of the pixel processing.

Claims (1):

  • <cite index="51-3,51-4">IMY imposed administrative fines of SEK 37 million on Apoteket AB and SEK 8 million on Apohem AB after the companies used the Meta Pixel on their websites and transferred sensitive personal data to Meta.</cite>

Security MeasuresRed

Art 32 security-of-processing is IMY's most heavily enforced provision, with multi-million SEK fines for inadequate technical/organisational measures.

Claims (2):

  • IMY supervised Sportadmin after a leak affecting over 2 million individuals and found <cite index="11-7,11-8">the review shows that Sportadmin did not have an appropriate level of security to protect the personal data the company processed, and IMY therefore decided to impose an administrative fine of SEK 6 million</cite>.
  • <cite index="51-3,51-4">IMY imposed administrative fines of SEK 37 million on Apoteket AB and SEK 8 million on Apohem AB after the companies used the Meta Pixel on their websites and transferred sensitive personal data to Meta.</cite>

Breach NotificationAmber

Controllers must notify IMY of qualifying personal data breaches; failures compound Art 32 penalties.

Claims (1):

  • <cite index="6-9">Data controllers are obligated to report certain personal data breaches to IMY.</cite>

Retention And DisposalAmber

Retention periods (e.g., for camera surveillance) must be specifically justified and regularly reassessed.

Claims (1):

  • <cite index="34-1,34-33">Where a controller has an actual need of a longer camera-surveillance storage time it must provide a specific motivation, and the need for surveillance must be regularly reassessed.</cite>
Category narrative43 words

GDPR Arts 5, 24-43 apply directly with SFS 2018:218 Chapter 1 Section 8 supplementing Art 37-39 DPO rules. Enforcement history (Sportadmin, Apoteket/Apohem) shows IMY treats Art 32 security-of-processing failures as a top fining priority, including large-scale breach exposure of children's and health-adjacent data.

Periodic update · new data 2026-09-28

Controller/Processor Duties

IMY fined Miljödata i Karlskrona AB SEK 1.8 million on 22 September 2026 for violating GDPR Article 32(1), the obligation to implement appropriate technical and organisational security measures. The decision cited inadequate controls over software installation and the absence of real-time intrusion monitoring as the specific deficiencies underlying the breach. The enforcement action followed a breach in August 2025 that exposed the personal data of 2.2 million people, a scale of exposure that places this among the more significant security-of-processing enforcement actions IMY has issued, and one directed at a supplier serving the municipal public sector rather than a single private controller.

The Miljödata case illustrates a security-of-processing enforcement pattern that IMY has applied elsewhere: fines following demonstrated security failures after a breach has already occurred, rather than proactive audits absent an incident. This is consistent with the broader enforcement record IMY built through 2025 and into 2026, where security-failure fines following data breaches, at Apoteket AB, Apohem AB and Sportadmin among others, recur as a category of enforcement distinct from procedural or consent-related fines. For controllers and processors operating in or with the Swedish public sector, the Miljödata decision underscores that supplier-side security failures can generate direct IMY enforcement exposure even where the supplier, rather than the public-sector customer, is the immediate subject of the fine.

Outlook

The item to track is whether IMY's related investigations into the two municipalities and one region connected to the Miljödata breach progress to further enforcement findings, which would extend accountability for the security failure to the public-sector controllers that relied on Miljödata's processing, in addition to the processor-side fine already issued.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (6)
  1. ProbableIMY — <cite index="41-19,41-21">GDPR requires an impact assessment for processing on a large scale of sensitive personal data and for systematic surveillance of a public space on a large scale</cite>, per criteria IMY has published drawing on EDPB guidance.observed
  2. ProbableDataGuidance — <cite index="29-3">Chapter 1, Section 8 of the Act with Supplementary Provisions to the GDPR (SFS 2018:218) supplements Articles 37-39 of the GDPR on DPO appointment.</cite>observed
  3. ProbableIMY — IMY supervised Sportadmin after a leak affecting over 2 million individuals and found <cite index="11-7,11-8">the review shows that Sportadmin did not have an appropriate level of security to protect the personal data the company processed, and IMY therefore decided to impose an administrative fine of SEK 6 million</cite>.observed
  4. ProbableIMY — <cite index="6-9">Data controllers are obligated to report certain personal data breaches to IMY.</cite>observed
  5. ProbableIMY — <cite index="51-3,51-4">IMY imposed administrative fines of SEK 37 million on Apoteket AB and SEK 8 million on Apohem AB after the companies used the Meta Pixel on their websites and transferred sensitive personal data to Meta.</cite>observed
  6. ProbableIMY — <cite index="34-1,34-33">Where a controller has an actual need of a longer camera-surveillance storage time it must provide a specific motivation, and the need for surveillance must be regularly reassessed.</cite>observed

#

Framework is GDPR-standard, but enforcement record shows repeated transfer-related transparency and security failures involving US ad-tech processors.

Primary frameworkGDPR Arts 44-49
Supervisory authorityIMY
Traffic-light rationale — AmberFramework is GDPR-standard, but enforcement record shows repeated transfer-related transparency and security failures involving US ad-tech processors.

Sub-modules (6)

Transfer MechanismsAmber

SCCs, adequacy, and derogations under GDPR Ch.V apply directly; IMY applies these when assessing third-country transfer notices.

Claims (2):

  • <cite index="6-11">When personal data is sent outside the EU/EEA, the rules for transfer to third countries apply under the GDPR as applied in Sweden.</cite>
  • The Apoteket/Apohem cases arose because <cite index="51-6,51-8">the companies used Meta's analytics tool, Meta Pixel, on their websites, and by activating a new sub-feature transferred sensitive personal data to Meta concerning a large number of customers</cite>, a US-headquartered processor/joint controller.

Adequacy ReceivedGreen

As an EU Member State, adequacy findings are made centrally by the European Commission; no Sweden-specific inbound adequacy determination applies.

Absence provenance: unavailable. Searched: Sweden adequacy decision received.

Adequacy GrantedGreen

Adequacy decisions granted to third countries are made by the European Commission for all Member States collectively, not by Sweden individually.

Absence provenance: unavailable. Searched: Sweden adequacy decision granted.

Sccs And BcrsAmber

SCCs/BCRs available per GDPR Art 46; IMY's Klarna decision criticised incomplete transfer-safeguard information provided to data subjects.

Claims (1):

  • In the Klarna decision, IMY found the company <cite index="16-18">did not provide information on to which countries outside the EU/EEA personal data were transferred or on where and how individuals could obtain information on the safeguards that applied to the transfer to third countries</cite>, contributing to a SEK 7.5 million fine.

Transfer Impact AssessmentAmber

TIA obligations follow GDPR/Schrems II standards as applied EU-wide; no SE-specific TIA template identified in this pass.

Absence provenance: unavailable. Searched: IMY transfer impact assessment guidance.

Data LocalisationGreen

No general data-localisation mandate identified for Sweden beyond sector-specific security/confidentiality rules (e.g., law-enforcement data under the Criminal Data Act).

Absence provenance: unavailable. Searched: Sweden data localisation requirement.

Category narrative63 words

GDPR Chapter V transfer rules apply directly in Sweden; IMY enforcement (Klarna) has penalised failure to inform data subjects about third-country transfers and safeguards, and the Apoteket/Apohem cases involved unintended data flows to a US-based processor (Meta). Adequacy decisions themselves are an EU Commission competence rather than a Swedish national one; this research pass did not identify any Sweden-specific adequacy or localisation derogation.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (3)
  1. ProbableIMY — <cite index="6-11">When personal data is sent outside the EU/EEA, the rules for transfer to third countries apply under the GDPR as applied in Sweden.</cite>observed
  2. ProbableEDPB / IMY — In the Klarna decision, IMY found the company <cite index="16-18">did not provide information on to which countries outside the EU/EEA personal data were transferred or on where and how individuals could obtain information on the safeguards that applied to the transfer to third countries</cite>, contributing to a SEK 7.5 million fine.observed
  3. ProbableIMY — The Apoteket/Apohem cases arose because <cite index="51-6,51-8">the companies used Meta's analytics tool, Meta Pixel, on their websites, and by activating a new sub-feature transferred sensitive personal data to Meta concerning a large number of customers</cite>, a US-headquartered processor/joint controller.observed

#

Multiple active sectoral overlays with demonstrated enforcement gaps, particularly in financial transparency and health-data security.

Primary frameworkGDPR plus Credit Information Act, Criminal Data Act, Electronic Communications Act (LEK)
Supervisory authorityIMY
Traffic-light rationale — AmberMultiple active sectoral overlays with demonstrated enforcement gaps, particularly in financial transparency and health-data security.

Sub-modules (7)

Financial Sector OverlayAmber

Credit information activity requires an IMY licence; Klarna Bank was fined for GDPR transparency violations concerning credit-information sharing.

Claims (2):

  • <cite index="31-2">IMY monitors that those who carry out credit information activity follow good business practice</cite> and issues permits for such activity.
  • <cite index="16-3,16-4">Klarna, a financial company processing personal data about many people in many ways, was found to have violated Articles 5(1)(a), 5.2, 12.1, 13.1 and 14.2(g) GDPR for failing to fulfil the transparency principle and data subjects' right to information</cite>, resulting in a SEK 7.5 million fine.

Health Sector OverlayRed

Regional healthcare bodies have been fined/criticised for inadequate security of health data in physical mail and email.

Claims (1):

  • <cite index="59-1,59-2">IMY found that Region Dalarna had not taken sufficient security measures to protect sensitive personal data against unauthorized disclosure in connection with sending physical invitations to healthcare visits, issuing an administrative sanction of SEK 200,000</cite>.

Telecoms And EprivacyAmber

LEK (Electronic Communications Act) Ch.9 §28, implementing ePrivacy Directive Art 5(3), governs cookie/tracker storage and access consent, enforced alongside GDPR in the Meta Pixel cases.

Claims (1):

  • Under <cite index="55-24">Chapter 9, Section 28 of the Electronic Communications Act (LEK), which implements Article 5.3 of the ePrivacy Directive, data may be stored in or retrieved from a subscriber's or user's terminal equipment only if the subscriber or user has access to information about the purpose of the processing and consents to it</cite>.

Employment DataAmber

SFS 2018:218 supplements GDPR grounds for employment-context processing; IMY has fined employers for unlawful processing of employee sobriety-test data.

Claims (2):

  • <cite index="25-4">The Act with Supplementary Provisions to the GDPR (SFS 2018:218) supplements the GDPR and outlines grounds for processing of personal data left to Member States' discretion</cite>, including employment-context processing.
  • <cite index="14-12,14-13">IMY fined Aktiebolaget Storstockholms Lokaltrafik (SL) and Waxholms Ångfartygs AB (WÅAB) SEK 75,000 each for processing personal data relating to sobriety tests conducted by employees in breach of the GDPR.</cite>

Credit And ScoringAmber

Credit-scoring/information activity is licensed and supervised by IMY under the Credit Information Act, requiring good business practice.

Claims (1):

  • <cite index="31-2">IMY monitors that those who carry out credit information activity follow good business practice</cite> and issues permits for such activity.

EducationAmber

No education-sector-specific statutory overlay identified beyond general GDPR application in this research pass.

Absence provenance: unavailable. Searched: IMY education sector data protection guidance.

InsuranceAmber

No insurance-sector-specific statutory overlay identified beyond general GDPR application in this research pass.

Absence provenance: unavailable. Searched: IMY insurance sector data protection guidance.

Category narrative45 words

IMY overlays sector-specific supervision on top of GDPR for credit information (Credit Information Act), law enforcement (Criminal Data Act), telecoms/ePrivacy (Electronic Communications Act, LEK), and employment. Enforcement spans financial services (Klarna), health (Region Dalarna/Uppsala), telecoms-adjacent cookie tracking (LEK Ch.9 §28), and employment (SL/WÅAB sobriety-test data).

Sources and claims (6)
  1. ProbableIMY — <cite index="31-2">IMY monitors that those who carry out credit information activity follow good business practice</cite> and issues permits for such activity.observed
  2. ProbableEDPB / IMY — <cite index="16-3,16-4">Klarna, a financial company processing personal data about many people in many ways, was found to have violated Articles 5(1)(a), 5.2, 12.1, 13.1 and 14.2(g) GDPR for failing to fulfil the transparency principle and data subjects' right to information</cite>, resulting in a SEK 7.5 million fine.observed
  3. ProbableIMY — <cite index="59-1,59-2">IMY found that Region Dalarna had not taken sufficient security measures to protect sensitive personal data against unauthorized disclosure in connection with sending physical invitations to healthcare visits, issuing an administrative sanction of SEK 200,000</cite>.observed
  4. ProbableIMY — Under <cite index="55-24">Chapter 9, Section 28 of the Electronic Communications Act (LEK), which implements Article 5.3 of the ePrivacy Directive, data may be stored in or retrieved from a subscriber's or user's terminal equipment only if the subscriber or user has access to information about the purpose of the processing and consents to it</cite>.observed
  5. ProbableDataGuidance — <cite index="25-4">The Act with Supplementary Provisions to the GDPR (SFS 2018:218) supplements the GDPR and outlines grounds for processing of personal data left to Member States' discretion</cite>, including employment-context processing.observed
  6. ProbableIMY — <cite index="14-12,14-13">IMY fined Aktiebolaget Storstockholms Lokaltrafik (SL) and Waxholms Ångfartygs AB (WÅAB) SEK 75,000 each for processing personal data relating to sobriety tests conducted by employees in breach of the GDPR.</cite>observed

#

Repeated, large enforcement actions (Google Analytics, Meta Pixel across two retailers) indicate systemic non-compliance in the adtech/commercial tracking space.

Primary frameworkGDPR plus Electronic Communications Act (LEK) Ch.9 §28
Supervisory authorityIMY
Traffic-light rationale — RedRepeated, large enforcement actions (Google Analytics, Meta Pixel across two retailers) indicate systemic non-compliance in the adtech/commercial tracking space.

Sub-modules (6)

Cookies And TrackersRed

LEK Ch.9 §28 requires consent for storage/access to terminal-equipment data (cookies); enforced jointly with GDPR Art 32 in the Meta Pixel cases.

Claims (2):

  • Cookie and tracker storage/retrieval is governed by <cite index="55-24">Chapter 9, Section 28 LEK, which permits storage in or retrieval from terminal equipment only where the subscriber or user has access to information about the purpose and consents to it</cite>.
  • <cite index="12-1">IMY found that Sportadmin's counterpart cases and the Apoteket/Apohem investigations established that companies violated Article 32 of the GDPR through inadequate control of ad-tech pixel data flows</cite>, resulting in fines of SEK 37 million and SEK 8 million respectively.

Dark PatternsAmber

No SE-specific dark-pattern statute or IMY decision identified beyond general GDPR transparency/fairness principles in this pass.

Absence provenance: unavailable. Searched: IMY dark patterns enforcement.

Opt Out SignalsAmber

No SE-specific recognition of Global Privacy Control or equivalent browser-level opt-out signal identified in this pass.

Absence provenance: unavailable. Searched: IMY Global Privacy Control recognition.

Clean Rooms And DcrAmber

No SE-specific clean-room/data-collaboration-room regime identified; GDPR joint-controller and processor rules apply generally.

Absence provenance: unavailable. Searched: IMY data clean room guidance.

Cross Context AdvertisingRed

IMY's Google Analytics and Meta Pixel enforcement actions function as de facto cross-context-advertising audits under GDPR Arts 5/32.

Claims (2):

  • <cite index="14-27,14-28">IMY audited how four companies use Google Analytics for web statistics and issued administrative fines against two of them</cite> as part of a cross-context-advertising/tracker enforcement sweep.
  • <cite index="12-1">IMY found that Sportadmin's counterpart cases and the Apoteket/Apohem investigations established that companies violated Article 32 of the GDPR through inadequate control of ad-tech pixel data flows</cite>, resulting in fines of SEK 37 million and SEK 8 million respectively.

Direct MarketingAmber

Objection to direct marketing must be honoured and leads to erasure; H&M was fined for failing to operationalise this.

Claims (1):

  • <cite index="17-1,17-2">IMY fined a company SEK 350,000 for not having sufficient systems and routines in place to make it easier for those who complained to exercise their right to object to direct marketing.</cite>
Category narrative40 words

Cookie/tracker consent is governed by LEK Ch.9 §28 (ePrivacy transposition) alongside GDPR. IMY has run structured audits of adtech tools (Google Analytics, Meta Pixel) resulting in multiple large fines and cease-processing orders, and has enforced direct-marketing opt-out rights against H&M.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (4)
  1. ProbableIMY — Cookie and tracker storage/retrieval is governed by <cite index="55-24">Chapter 9, Section 28 LEK, which permits storage in or retrieval from terminal equipment only where the subscriber or user has access to information about the purpose and consents to it</cite>.observed
  2. ProbableIMY — <cite index="14-27,14-28">IMY audited how four companies use Google Analytics for web statistics and issued administrative fines against two of them</cite> as part of a cross-context-advertising/tracker enforcement sweep.observed
  3. ProbableIMY — <cite index="12-1">IMY found that Sportadmin's counterpart cases and the Apoteket/Apohem investigations established that companies violated Article 32 of the GDPR through inadequate control of ad-tech pixel data flows</cite>, resulting in fines of SEK 37 million and SEK 8 million respectively.observed
  4. ProbableEDPB / IMY — <cite index="17-1,17-2">IMY fined a company SEK 350,000 for not having sufficient systems and routines in place to make it easier for those who complained to exercise their right to object to direct marketing.</cite>observed

#

Binding biometric/surveillance rules exist (Camera Surveillance Act, Criminal Data Act) but AI-specific governance remains largely soft-law/guidance stage pending fuller EU AI Act interface.

Primary frameworkGDPR Art 22; Camera Surveillance Act; Criminal Data Act
Supervisory authorityIMY
Traffic-light rationale — AmberBinding biometric/surveillance rules exist (Camera Surveillance Act, Criminal Data Act) but AI-specific governance remains largely soft-law/guidance stage pending fuller EU AI Act interface.

Sub-modules (6)

Profiling RestrictionsGreen

Profiling must comply with GDPR rules generally, per IMY guidance.

Claims (1):

  • <cite index="9-19">Profiling is a type of personal data processing and therefore must follow the rules in the GDPR.</cite>

Automated Decision Making TransparencyAmber

ADM transparency follows GDPR Art 13-15/22 directly; no SE-specific ADM statute identified beyond general GDPR application.

Absence provenance: unavailable. Searched: IMY automated decision-making transparency guidance.

Ai Risk AssessmentsAmber

IMY published a June 2026 report clarifying controller/processor roles for AI developers, and issued (with Digg) non-binding generative-AI guidelines for public administration in January 2025.

Claims (2):

  • <cite index="3-1,3-2">In June 2026, IMY published a report clarifying the roles and responsibilities of companies under the GDPR when developing and fine-tuning AI applications, distinguishing between controllers and processors based on data processing activities.</cite>
  • <cite index="1-10">In January 2025, the Swedish Agency for Digital Government (Digg) together with IMY launched guidelines to encourage the use of generative AI in public administration.</cite>

Biometric RegimeAmber

The Camera Surveillance Act covers optical-electronic instruments including LiDAR sensors capable of identifying individuals by body movement, constitution and clothing.

Claims (1):

  • <cite index="7-6,7-7">IMY found that LiDAR sensors are typically covered by the term "other optical-electronic instruments" under the Swedish Camera Surveillance Act, and it is highly probable that individuals can be distinguished and identified based on body movements, body constitution, and clothing in LiDAR output.</cite>

Genetic DataAmber

No SE-specific genetic-data statute identified beyond GDPR Art 9 special-category treatment in this pass.

Absence provenance: unavailable. Searched: Sweden genetic data regime IMY.

State Surveillance CarveoutsAmber

The Criminal Data Act creates a distinct regime for law-enforcement authorities' processing, with the Security Service subject to its own separate legislation outside the Criminal Data Act.

Claims (1):

  • <cite index="36-3,36-12">The Criminal Data Act applies to personal data processing within law enforcement activities at authorities including the Swedish Police Authority, Customs, Tax Agency and Prosecution Authority, while the Swedish Security Service is not subject to the Criminal Data Act but has special legislation of its own.</cite>
Category narrative70 words

Profiling is governed via GDPR as applied by IMY. IMY's 2026 priorities and June 2026 report on AI controller/processor roles reflect active (but largely non-binding, guidance-stage) engagement with AI governance. The Camera Surveillance Act extends biometric-adjacent coverage to optical-electronic sensors (including LiDAR) capable of identifying individuals via body movement or gait. Law-enforcement processing sits under the separate Criminal Data Act, with the Security Service subject to its own bespoke legislation.

Periodic update · new data 2026-09-28

Algorithmic, Biometric & Surveillance Governance

Sweden's approach to surveillance governance moved in a liberalising direction on 1 April 2025, when the permit requirement for public-space camera surveillance was removed. Organisations deploying public-space cameras now rely on documented legitimate-interest assessments rather than obtaining prior approval from IMY, representing a material deregulation of what had previously functioned as a surveillance-permit gate. This shift places greater responsibility on deploying organisations to conduct and document their own legitimate-interest analysis, with IMY's ex-ante gatekeeping role removed from the process.

At the same time, IMY has signalled a sharpened focus on a different category of algorithmic governance: the regulator named artificial intelligence in the public sector as one of three guidance-and-supervision priority areas for 2026, alongside data protection for children and young people and law-enforcement tools. This priority-area designation is forward-looking and does not yet reflect a substantive rule change or enforcement action; it indicates where IMY intends to direct supervisory attention rather than a new binding obligation. Read together, the camera-permit removal and the AI supervisory priority suggest a regulator stepping back from one older form of ex-ante technology gatekeeping while positioning to scrutinise a newer one.

Outlook

The item to watch is whether IMY's 2026 focus on AI in the public sector produces concrete guidance or the first enforcement action under that priority, which would give the currently forward-looking supervisory signal a substantive regulatory shape. Separately, monitoring whether the removal of the camera-surveillance permit requirement leads to any documented increase in public-space surveillance deployments would clarify the practical effect of the deregulation.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (5)
  1. ProbableIMY — <cite index="9-19">Profiling is a type of personal data processing and therefore must follow the rules in the GDPR.</cite>observed
  2. ProbableDataGuidance — <cite index="3-1,3-2">In June 2026, IMY published a report clarifying the roles and responsibilities of companies under the GDPR when developing and fine-tuning AI applications, distinguishing between controllers and processors based on data processing activities.</cite>observed
  3. ProbableIMY — <cite index="7-6,7-7">IMY found that LiDAR sensors are typically covered by the term "other optical-electronic instruments" under the Swedish Camera Surveillance Act, and it is highly probable that individuals can be distinguished and identified based on body movements, body constitution, and clothing in LiDAR output.</cite>observed
  4. ProbableIMY — <cite index="36-3,36-12">The Criminal Data Act applies to personal data processing within law enforcement activities at authorities including the Swedish Police Authority, Customs, Tax Agency and Prosecution Authority, while the Swedish Security Service is not subject to the Criminal Data Act but has special legislation of its own.</cite>observed
  5. ProbableIMY — <cite index="1-10">In January 2025, the Swedish Agency for Digital Government (Digg) together with IMY launched guidelines to encourage the use of generative AI in public administration.</cite>observed

#

Clear statutory age-of-consent rule exists and is actively supervised, but a major 2026 breach affecting children's data shows continuing real-world exposure risk.

Primary frameworkGDPR Art 8, as implemented by SFS 2018:218
Supervisory authorityIMY
Traffic-light rationale — AmberClear statutory age-of-consent rule exists and is actively supervised, but a major 2026 breach affecting children's data shows continuing real-world exposure risk.

Sub-modules (5)

Age VerificationAmber

No SE-specific mandatory age-verification technology standard identified beyond general "reasonable efforts" language under GDPR Art 8(2).

Absence provenance: unavailable. Searched: Sweden age verification mandate children.

Minor Profiling BansAmber

No blanket statutory ban on profiling of minors identified beyond general GDPR fairness/transparency principles and IMY's children's-rights guidance emphasising age/maturity-appropriate treatment.

Absence provenance: unavailable. Searched: Sweden minor profiling ban IMY.

Education SettingsAmber

No education-setting-specific children's data statute identified in this pass beyond general GDPR/children's-rights guidance.

Absence provenance: unavailable. Searched: IMY education settings children data protection.

Dependent AdultsAmber

No SE-specific dependent-adult/incapacitated-persons data protection statute identified in this pass.

Absence provenance: unavailable. Searched: Sweden dependent adults data protection IMY.

Category narrative59 words

Sweden exercised the GDPR Art 8 Member State option to set the digital age of consent at 13, with parental/guardian consent required below that age. Children and young people are a named 2026 IMY supervisory priority, reinforced by enforcement after the Sportadmin breach exposed sensitive data (including health data) of over 2 million individuals, largely children in sports clubs.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (4)
  1. ProbableIMY — <cite index="41-2,41-4">Every EU Member State has had the opportunity to lower the age indicated in GDPR Article 8, and Sweden has decided that children over the age of 13 years can give consent to processing for information society services.</cite>observed
  2. ProbableGovernment of Sweden / hosted via DataGuidance — <cite index="43-1,43-2">If a child is under 13 years old, their personal data may only be processed with the consent of the holder of parental responsibility, per the Act with Supplementary Provisions to the GDPR.</cite>observed
  3. ProbableIMY — <cite index="12-9,12-11">The Sportadmin breach, initiated following a January 2025 cyber attack, exposed data on more than 2.1 million individuals, mainly concerning children and young people, including names, contact details, personal identity numbers, and sport/club affiliations.</cite>observed
  4. ProbableIMY — <cite index="1-1,1-2">IMY is focusing on three areas in its guidance and supervision during 2026: crime prevention, children and young people, and AI in the public sector.</cite>observed

#

Strong, well-documented enforcement powers and activity, but no confirmed Swedish-specific collective-redress/class-action mechanism was located.

Primary frameworkGDPR Arts 58, 83-84; SFS 2018:218
Supervisory authorityIMY
Traffic-light rationale — AmberStrong, well-documented enforcement powers and activity, but no confirmed Swedish-specific collective-redress/class-action mechanism was located.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

IMY may issue warnings, reprimands, processing-cessation orders and administrative fines; public-authority fines are capped at SEK 5m (less serious) / SEK 10m (serious).

Claims (1):

  • <cite index="13-1,13-2">In Sweden, authorities must also be able to be fined: for less serious infringements the fine amounts to a maximum of SEK 5 million and for serious infringements a maximum of SEK 10 million.</cite> <cite index="13-5,13-6">IMY can also issue warnings for planned processing likely to contravene the GDPR, issue reprimands for ongoing contraventions, and order cessation of processing.</cite>

Enforcement Activity IndexRed

Recent high-value fines include Sportadmin (SEK 6m, Jan 2026), Apoteket/Apohem (SEK 37m/8m), Spotify (SEK 58m), Trygg-Hansa (SEK 35m) and Klarna (SEK 7.5m, cross-border OSS).

Claims (5):

  • <cite index="11-7,11-8">IMY imposed an administrative fine of SEK 6 million against Sportadmin after finding it did not have an appropriate level of security to protect the personal data it processed.</cite>
  • <cite index="51-1">IMY decided to impose administrative fines of SEK 37 million on Apoteket AB and SEK 8 million on Apohem AB for improper Meta Pixel data transfers.</cite>
  • <cite index="54-11,54-12">IMY audited how Spotify handles customers' right to access their personal data, and the deficiencies discovered caused IMY to issue an administrative fine of SEK 58 million against the company.</cite>
  • <cite index="14-24,14-25">Trygg-Hansa's security flaws meant information about 650,000 customers was accessible to unauthorized persons via the internet, leading IMY to issue an administrative fine of SEK 35 million against the company.</cite>
  • <cite index="16-11,16-12">In a One-Stop-Shop procedure involving Germany, Austria, Italy, Netherlands, Norway, Finland and Denmark as concerned supervisory authorities, IMY as lead authority issued an administrative fine of SEK 7.5 million against Klarna Bank AB.</cite>

Regulator Funding And CapacityAmber

No specific IMY budget/headcount figures were identified in this research pass.

Absence provenance: unavailable. Searched: IMY budget headcount capacity 2026.

Collective Redress And Class ActionsRed

No Sweden-specific collective-redress or class-action mechanism for data protection claims was identified in this research pass.

Absence provenance: unavailable. Searched: Sweden data protection collective redress class action GDPR Art 80.

Private Right Of ActionAmber

No Sweden-specific private-right-of-action provision beyond the general GDPR Art 79/82 judicial-remedy and compensation rights was identified in this pass.

Absence provenance: unavailable. Searched: Sweden private right of action GDPR damages.

Recent Developments 180DAmber

Within the last 180 days: IMY's June 2026 AI-roles report, 2026 supervisory priorities (crime prevention, children, AI in public sector), and the January 2026 Sportadmin fine.

Claims (3):

  • <cite index="3-1">On June 10, 2026, IMY published a report clarifying the roles and responsibilities of companies under the GDPR when developing and fine-tuning AI applications.</cite>
  • <cite index="1-1,1-2">IMY's guidance and supervision priorities for 2026 are crime prevention, children and young people, and AI in the public sector.</cite>
  • <cite index="11-7,11-8">IMY imposed an administrative fine of SEK 6 million against Sportadmin after finding it did not have an appropriate level of security to protect the personal data it processed.</cite>
Category narrative67 words

IMY can issue warnings, reprimands, cease-processing orders and administrative fines, with a public-authority-specific cap (SEK 5m/10m). Its decisions are appealable. 2025-2026 enforcement activity has been intense and high-value (Sportadmin SEK 6m, Apoteket/Apohem SEK 45m combined, historically Spotify SEK 58m and Trygg-Hansa SEK 35m), and it participates actively in cross-border One-Stop-Shop cooperation (Klarna). Collective redress and private-right-of-action mechanisms specific to Sweden were not identified in this research pass.

Periodic update · new data 2026-09-28

Enforcement & Redress

IMY's enforcement activity in 2026 is anchored by the SEK 1.8 million fine against Miljödata i Karlskrona AB for GDPR Article 32(1) security-of-processing violations, issued 22 September 2026 following an August 2025 breach that exposed 2.2 million people's data. This sits within a broader enforcement-powers framework under which IMY may issue warnings for planned processing likely to violate the GDPR, reprimands for ongoing violations, and orders to bring processing into compliance or cease specific activities, in addition to administrative fines that can reach up to four percent of global turnover or twenty million euros; Sweden notably makes public authorities subject to such fines, unlike some other Member States.

IMY's 2025 enforcement record shows a mix of scale: three smaller fines against SL, WÅAB and DO totalled only SEK 250,000, while separate, larger fines were issued against Apoteket AB at SEK 37 million, Apohem AB at SEK 8 million, and Sportadmin at SEK 6 million, each tied to security failures following data breaches. This pattern indicates that IMY's largest fines cluster specifically around post-breach security failures rather than other categories of GDPR violation, a pattern the Miljödata fine continues. Historically, IMY's enforcement practice has also been shaped by private-complaint pressure: a 2022 NOYB inaction complaint against IMY's four-year delay in handling a complaint against Spotify was decided in the complainants' favour, after which IMY imposed a GDPR fine of SEK 58 million on Spotify.

Outlook

The enforcement trend to track is whether IMY's investigations connected to the Miljödata breach, reportedly extending to two municipalities and one region, produce further fines against the public-sector controllers involved, which would indicate IMY is willing to pursue accountability up the data-processing chain rather than concluding enforcement at the processor level.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (9)
  1. ProbableIMY — <cite index="13-1,13-2">In Sweden, authorities must also be able to be fined: for less serious infringements the fine amounts to a maximum of SEK 5 million and for serious infringements a maximum of SEK 10 million.</cite> <cite index="13-5,13-6">IMY can also issue warnings for planned processing likely to contravene the GDPR, issue reprimands for ongoing contraventions, and order cessation of processing.</cite>observed
  2. ProbableIMY — <cite index="13-7">IMY's decisions can be appealed.</cite>observed
  3. ProbableIMY — <cite index="11-7,11-8">IMY imposed an administrative fine of SEK 6 million against Sportadmin after finding it did not have an appropriate level of security to protect the personal data it processed.</cite>observed
  4. ProbableIMY — <cite index="51-1">IMY decided to impose administrative fines of SEK 37 million on Apoteket AB and SEK 8 million on Apohem AB for improper Meta Pixel data transfers.</cite>observed
  5. ProbableIMY — <cite index="54-11,54-12">IMY audited how Spotify handles customers' right to access their personal data, and the deficiencies discovered caused IMY to issue an administrative fine of SEK 58 million against the company.</cite>observed
  6. ProbableIMY — <cite index="14-24,14-25">Trygg-Hansa's security flaws meant information about 650,000 customers was accessible to unauthorized persons via the internet, leading IMY to issue an administrative fine of SEK 35 million against the company.</cite>observed
  7. ProbableEDPB / IMY — <cite index="16-11,16-12">In a One-Stop-Shop procedure involving Germany, Austria, Italy, Netherlands, Norway, Finland and Denmark as concerned supervisory authorities, IMY as lead authority issued an administrative fine of SEK 7.5 million against Klarna Bank AB.</cite>observed
  8. ProbableDataGuidance — <cite index="3-1">On June 10, 2026, IMY published a report clarifying the roles and responsibilities of companies under the GDPR when developing and fine-tuning AI applications.</cite>observed
  9. ProbableIMY — <cite index="1-1,1-2">IMY's guidance and supervision priorities for 2026 are crime prevention, children and young people, and AI in the public sector.</cite>observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metwaived
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct73.91
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Sweden
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 51 claim(s) (51 category placement(s)), 34 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 8Children & Vulnerable Groupsparental consent
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

regulator_and_framework, lawful_processing_and_special_data, data_subject_rights, controller_processor_duties, sectoral_watch, adtech_and_commercial_privacy, algorithmic_biometric_and_surveillance_governance, children_and_vulnerable_groups, and enforcement_and_redress all carry T1 (IMY primary/EDPB-hosted official decisions, Swedish statute text) evidence for their core claims. cross_border_and_adequacy relies on T1 for enforcement-derived transfer findings but has no T1/T2 source for SE-specific adequacy or localisation determinations (these are EU Commission-level, not national). Several sub-modules across sectoral_watch (education, insurance), adtech (dark patterns, opt-out signals, clean rooms), algorithmic governance (ADM transparency, genetic data), children (age verification, minor profiling bans, education settings, dependent adults) and enforcement (funding/capacity, collective redress, private right of action) returned no findings after targeted searches and carry explicit absent_field_provenance rather than fabricated obligations.

Unresolved questions (5):

  • Is there a Sweden-specific collective-redress or class-action mechanism for GDPR claims beyond GDPR Art 80 representative actions?
  • Does Sweden mandate a specific age-verification technology standard for information-society services under Art 8(2)?
  • Are there SE-specific dark-pattern or opt-out-signal (e.g., Global Privacy Control) recognition rules?
  • What are current IMY budget and headcount figures for 2026?
  • Is there a dedicated Swedish genetic-data or dependent-adults data protection statute distinct from GDPR Art 9?

Escalate to primary-source review: no