EnglishSV
Sweden flag

Sweden

Sweden Data Privacy Laws: GDPR, the Swedish Data Protection Act, and IMY (2026)

Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 31 primary sources cited on this page. How we verify our legal content

Sweden Data Privacy Laws: GDPR, the Swedish Data Protection Act, and IMY (2026)

Frequently Asked Questions

What is the main data protection law in Sweden?

Sweden's data protection framework combines the EU General Data Protection Regulation (GDPR), which applies directly as EU law, with the Swedish Data Protection Act (Dataskyddslagen, 2018:218) and the Data Protection Ordinance (2018:219). The GDPR provides the core framework. The Swedish Act adds national rules on children's consent age (13), the elevated protection of personal identity numbers (personnummer), and criminal data processing. The Swedish Authority for Privacy Protection (IMY) enforces both.

What is the offentlighetsprincipen and how does it interact with GDPR?

The offentlighetsprincipen (public access principle) is a constitutional principle dating to 1766 that makes official government documents presumptively public. It is enshrined in Sweden's Freedom of the Press Act and Fundamental Law on Freedom of Expression. Where the principle applies, GDPR has historically not overridden it. However, Swedish courts and the Supreme Court ruled in 2024 and 2025 that a blanket exemption from GDPR is incompatible with EU law, and individual proportionality assessments are now required. The government has also proposed a constitutional amendment to limit freedom of information protections for search services that publish personal data.

What is IMY and what does it do?

IMY (Integritetsskyddsmyndigheten), or the Swedish Authority for Privacy Protection, is Sweden's independent data protection supervisory authority. It was called Datainspektionen until 2021. IMY investigates complaints, conducts audits, issues guidance, operates a regulatory sandbox, imposes fines for GDPR violations, and participates in the European Data Protection Board. IMY acts as lead supervisory authority for cross-border GDPR cases involving companies with their EU main establishment in Sweden, such as Spotify. In 2024, IMY imposed SEK 60.6 million in total fines.

How much can organizations be fined for GDPR violations in Sweden?

Private companies face fines of up to EUR 20 million or 4 percent of global annual turnover (whichever is higher) for serious GDPR violations, and up to EUR 10 million or 2 percent of turnover for less serious infringements. Swedish public authorities face lower caps: SEK 5 million for less serious violations and SEK 10 million for serious ones. IMY's largest fine now standing is SEK 58 million against Spotify (12 June 2023), cut to SEK 40 million by the Administrative Court and restored in full by Kammarratten i Stockholm on 3 June 2025. The largest sum IMY ever imposed was SEK 75 million against Google in 2020, reduced to SEK 50 million on appeal in 2021 and final in December 2022 when the Supreme Administrative Court refused leave to appeal. Sweden allows fines against public authorities, unlike some other EU member states.

How quickly must data breaches be reported in Sweden?

Data controllers must notify IMY of a personal data breach within 72 hours of becoming aware of it. If not all information is available, an initial notification can be submitted with supplementary details provided within four weeks. If the breach poses a high risk to affected individuals, the controller must also notify those individuals without undue delay. Notification responsibilities stay with the controller even when the breach occurs at a data processor. IMY received 12,276 breach notifications in 2025, an 89 percent increase over 2024.

Are there special rules for processing Swedish personal identity numbers (personnummer)?

Yes. The Swedish Data Protection Act gives personnummer elevated protection beyond ordinary personal data. Organizations may process personnummer without consent only when it is clearly justified by the purpose, the need for secure identification, or another significant reason. This threshold effectively prevents routine collection of personnummer and requires specific justification for each use case. The personnummer's use as a universal identifier across healthcare, banking, and taxation makes it a high-sensitivity data element under Swedish law.

How does the EU AI Act apply in Sweden?

The EU AI Act (Regulation 2024/1689) applies in Sweden as EU law from August 2024. Regulation (EU) 2026/1744, the Digital Omnibus on AI of July 8, 2026, moved the obligations for high-risk AI systems to December 2, 2027 for Annex III systems and August 2, 2028 for Annex I systems, while leaving the Article 50 transparency duties in place from August 2, 2026. Sweden's national inquiry (SOU 2025:101) proposed designating the Swedish Post and Telecom Authority (PTS) as the coordinating national AI supervisory authority, with market surveillance bodies across different sectors, but no complementing Swedish AI legislation had been enacted as of September 2026. IMY has designated AI in the public sector as a 2026 supervisory priority, signaling heightened scrutiny for public bodies deploying AI systems that process personal data.

Updates

Second-round corrections: the largest-fine statement now reflects the SEK 58 million Spotify fine restored on appeal in June 2025; the Avanza legal basis, the Trygg-Hansa euro figure and the 2027 ePrivacy supervision handover are stated precisely.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Full expansion: added constitutional basis and offentlighetsprincipen section, EU AI Act overlay, IMY 2026 enforcement priorities, Sportadmin SEK 6M fine (Jan 2026), proposed live facial recognition legislation (Prop 2025/26:150), 2025 record breach notification statistics, SOU 2025:101 national AI law proposal, and government constitutional amendment proposal.

Reviewed and approved by an editor

Sources and References

  1. Swedish Authority for Privacy Protection (IMY) - Official Website(imy.se).gov
  2. Act containing supplementary provisions to the EU General Data Protection Regulation (SFS 2018:218) - Government of Sweden(government.se).gov
  3. Lag (2018:218) med kompletterande bestammelser till EU:s dataskyddsforordning - Sveriges riksdag(riksdagen.se).gov
  4. The Constitution of Sweden and personal privacy - Government.se(government.se).gov
  5. IMY - Fines and Warnings Overview(imy.se).gov
  6. IMY - Administrative Fine Against Sportadmin (January 2026)(imy.se).gov
  7. IMY - Administrative Fines Against Apoteket and Apohem for Meta Pixel (2024)(imy.se).gov
  8. IMY - Personal Data Breach Notification(imy.se).gov
  9. IMY - Lawful Grounds for Personal Data Processing(imy.se).gov
  10. IMY - Camera Surveillance for Organisations(imy.se).gov
  11. IMY - Google, the right to have search results removed (SEK 75 million 2020, reduced to SEK 50 million, final December 2022)(imy.se).gov
  12. IMY - Spotify AB, right of access (SEK 58 million, 12 June 2023; restored on appeal 3 June 2025)(imy.se).gov
  13. IMY - Klarna Bank AB, inadequate information (SEK 7.5 million, 28 March 2022; restored on appeal 11 March 2024)(imy.se).gov
  14. IMY - Trygg-Hansa (SEK 35 million, 28 August 2023)(imy.se).gov
  15. IMY - Gymnasienamnden i Skelleftea kommun, facial recognition in school (SEK 200,000, 20 August 2019)(imy.se).gov
  16. IMY - Polismyndigheten, Clearview AI (SEK 2.5 million, 10 February 2021; penalty set aside on appeal 2022, final 2023)(imy.se).gov
  17. Lag (2026:806) om anvandning av AI-system for ansiktsigenkanning i realtid for brottsbekampande andamal - Regeringskansliets rattsdatabaser (in force 1 July 2026)(rkrattsbaser.gov.se).gov
  18. Lag (2026:806) amendment register - Prop. 2025/26:150, bet. 2025/26:JuU28, rskr. 2025/26:288, Ikraft 2026-07-01(rkrattsbaser.gov.se).gov
  19. EU AI Act - European Commission Digital Strategy(digital-strategy.ec.europa.eu).gov
  20. SOU 2025:101 Anpassningar till AI-forordningen - Sveriges riksdag (8 October 2025, not enacted)(riksdagen.se).gov
  21. Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus on AI), amending Regulation (EU) 2024/1689 - EUR-Lex, OJ L, 2026/1744, 24.7.2026(eur-lex.europa.eu).gov
  22. Forordning (2026:815) om anvandning av AI-system for ansiktsigenkanning i realtid for brottsbekampande andamal - Regeringskansliets rattsdatabaser(rkrattsbaser.gov.se).gov
  23. Kamerabevakningslag (2018:1200), consolidated text incl. Lag (2025:220) - Regeringskansliets rattsdatabaser(rkrattsbaser.gov.se).gov
  24. Lag (2018:218) amendment register incl. Lag (2025:187) and Lag (2025:256) - Regeringskansliets rattsdatabaser(rkrattsbaser.gov.se).gov
  25. IMY decision IMY-2022-3270, Apoteket AB, 29 August 2024 (GDPR Article 32(1), SEK 37 million)(imy.se).gov
  26. IMY - Apohem, Meta pixel (SEK 8 million, 29 August 2024; under appeal to the Administrative Court of Appeal)(imy.se).gov
  27. IMY decision IMY-2025-7801, Sportadmin i Skandinavien AB, 26 January 2026 (GDPR Article 32(1), SEK 6 million)(imy.se).gov
  28. IMY - Aller Media AB, cookie banner reprimand under GDPR Article 6(1)(f), 28 April 2025(imy.se).gov
  29. IMY's priorities for 2026: AI, children and law enforcement tools (23 February 2026)(imy.se).gov
  30. Sveriges Domstolar - Supreme Court decisions of 25 February 2025 on the GDPR and secrecy for personal data in criminal judgments (cases 3457-24 and 3169-24)(domstol.se).gov
  31. Forordning (2026:1769) med instruktion for Digitaliseringsmyndigheten (issued 3 September 2026, in force 1 January 2027)(rkrattsbaser.gov.se).gov
Share: