Sweden
Sweden Data Privacy Laws: GDPR, the Swedish Data Protection Act, and IMY (2026)
Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 31 primary sources cited on this page. How we verify our legal content

Sweden enforces the EU General Data Protection Regulation (GDPR, Regulation 2016/679) directly as EU law and supplements it with the Swedish Data Protection Act (Dataskyddslagen, 2018:218), which sets the child consent age at 13, elevates protection for Swedish personal identity numbers, and governs criminal data processing. IMY enforces both frameworks.
Sweden has one of the oldest data protection traditions in the world. The original Swedish Data Act (Datalagen) dates to 1973, placing the country decades ahead of most nations in recognizing the legal significance of personal data. Today, Sweden operates a layered framework: the EU General Data Protection Regulation applies directly as EU law, the Swedish Data Protection Act (2018:218) fills in national-level gaps, and the Integritetsskyddsmyndigheten (IMY) enforces the whole structure.
This guide covers the full scope of Sweden's data privacy regime: the constitutional basis and its tensions with GDPR, the laws that govern processing, the authority that enforces them, the fines that have been levied, and the compliance obligations every organization in Sweden must meet in 2026.
For the broader European context, see our EU Data Privacy Laws guide. Sweden's approach to recording and wiretapping is covered separately in Sweden Recording Laws.
Quick Answer: Sweden's Data Privacy Framework at a Glance
Sweden's data privacy framework rests on three pillars.
First, the EU General Data Protection Regulation (GDPR, Regulation 2016/679) applies directly as EU law with no need for domestic transposition. It has been in force since May 25, 2018.
Second, the Swedish Data Protection Act (Dataskyddslagen, Lag 2018:218 med kompletterande bestammelser till EU:s dataskyddsforordning) supplements the GDPR on matters where member states have discretion, including children's consent age, the elevated protection of Swedish personal identity numbers, and criminal data processing by non-public bodies.
Third, the Integritetsskyddsmyndigheten (IMY, formerly Datainspektionen until 2021) is the independent supervisory authority that investigates complaints, conducts audits, issues guidance, and imposes administrative fines.
Organizations established in Sweden or processing personal data of individuals in Sweden must comply with all three layers.
The GDPR: Sweden's Core Legal Instrument
The GDPR is a directly applicable EU regulation. It did not need to be enacted into Swedish law. Every provision of the GDPR has applied in Sweden since May 25, 2018, with the same legal force as a Swedish statute.
The GDPR establishes the foundational principles of data protection: lawfulness, fairness and transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality; and accountability. These principles bind every organization that processes personal data about individuals in Sweden, whether or not that organization is based in Sweden.
The GDPR's territorial reach is deliberately broad. A company established outside the EU must comply with the GDPR when it offers goods or services to individuals in Sweden, or when it monitors the behavior of individuals in Sweden. This extraterritorial reach means that even non-European companies serving Swedish users must understand Swedish data protection requirements.
The Swedish Data Protection Act (Dataskyddslagen, 2018:218)
The Swedish Data Protection Act entered into force on May 25, 2018, the same day as the GDPR. It does not replace the GDPR; it fills in areas where the GDPR expressly permits or requires national legislation.
One notable extension is that the Swedish Act's supplementary provisions apply not only to processing within EU law's scope, but also to processing outside the scope of Union law and to activities covered by Title V, Chapter 2 of the Treaty on European Union, which is the common foreign and security policy. This means the GDPR framework governs Swedish data processing more broadly than it might in other member states.
The extension has limits. Chapter 1, Section 3 of the Act carves out the Armed Forces, the National Defence Radio Establishment (FRA) and the Security Service, and from January 1, 2027 it will also carve out Sweden's foreign intelligence service.
Law enforcement processing runs on a separate track entirely. Police and prosecution data processing is governed by the Criminal Data Act (brottsdatalagen, 2018:1177), which implements Directive (EU) 2016/680, not by the GDPR or the Data Protection Act.
The Act's key national provisions include:
Age of consent for children. Sweden set the minimum consent age for information society services at 13 years, one of the lowest allowed under GDPR Article 8 (which permits ages between 13 and 16). This threshold applies to children living in Sweden regardless of where the data controller is established.
Personal identity numbers (personnummer). Every Swedish resident holds a personnummer, a universal identifier embedded in healthcare, banking, taxation, and official records. The Data Protection Act gives personnummer elevated protection beyond ordinary personal data. Processing personnummer without consent is only permitted when it is "clearly justified" by the purpose, the need for secure identification, or another significant reason. This effective near-special-category status prevents routine collection.
Criminal data. The Act regulates how personal data relating to criminal convictions and offenses may be processed by private entities, beyond what GDPR Article 10 alone requires.
Extended scope. The Act applies its provisions to processing outside the scope of Union law and to common foreign and security policy activities, giving IMY supervision over a wider range of processing than in many peer countries. Defence, signals intelligence and Security Service processing are excluded, and law enforcement processing falls under the Criminal Data Act instead.
The Data Protection Ordinance (2018:219)
The Data Protection Ordinance supplements the Act with procedural rules. It specifies which public authorities may process criminal records data and sets procedural requirements for IMY's supervisory powers.
The Camera Surveillance Act (Kamerabevakningslagen, 2018:1200)
Sweden maintains a separate law governing video surveillance. Lag (2025:220), in force April 1, 2025, removed the permit requirement, but only for bodies carrying out a task of general interest. Private businesses outside that category never needed a permit and continue to rely on the GDPR.
What replaced the permit is a statutory balancing test in the Camera Surveillance Act itself, not a GDPR legitimate interest assessment. Section 8 allows surveillance only where the interest in watching outweighs the individual's interest in not being watched. Section 9 requires that assessment before surveillance starts, again on any material change, and it must be documented and kept for at least five years after the surveillance ends.
Section 10 adds a standing register of ongoing surveillance. It records the address of each monitored place, the type of place, the purpose, whether sound or other special technology is captured, and when the last assessment was made. The register must be produced to IMY on request.
The Electronic Communications Act (2022:482)
This law implements the EU ePrivacy Directive, governing cookies, traffic data, and the confidentiality of electronic communications. The Swedish Post and Telecom Authority (PTS) oversees ePrivacy compliance until 1 January 2027, when the electronic-communications remit passes to Digitaliseringsmyndigheten under Forordning (2026:1769). Organizations must obtain informed consent before placing non-essential cookies on users' devices.
Constitutional Basis and the Public Access Principle (Offentlighetsprincipen)
Sweden has a unique constitutional feature that directly shapes its data protection landscape: the principle of public access to official documents, known as offentlighetsprincipen. Enshrined in the Freedom of the Press Act (Tryckfrihetsforordningen) and the Fundamental Law on Freedom of Expression (Yttrandefrihetsgrundlagen), this principle is one of the cornerstones of Swedish democracy.
Under offentlighetsprincipen, official government documents are presumptively public. Any person may request and obtain official documents from Swedish public authorities without having to justify the request. The principle dates to 1766 and is regarded as a fundamental democratic safeguard.
The GDPR collides directly with this tradition. Public authorities must publish and provide personal data contained in official documents, yet the GDPR restricts disclosure of personal data. Swedish law resolves this tension by excluding offentlighetsprincipen from GDPR's reach: where the constitutional principle applies, GDPR does not override it.
The Media Exemption and Its Exploitation
A related constitutional provision creates broader exemptions for media. Under the Data Protection Act, the GDPR and its supplementary provisions do not apply to the extent that they would conflict with freedom of the press or freedom of expression protections.
In practice, Swedish online publishers can obtain a "publication certificate" (utgivningsbevis) by registering a responsible editor. Once granted, the service is treated as constitutionally protected media, potentially exempting it from GDPR requirements altogether.
This system has been widely exploited. Websites have used publication certificates to share personal data such as addresses, incomes, tax records, and criminal histories in ways that the GDPR would normally prohibit.
Courts Begin to Push Back
The legal landscape shifted significantly in 2024 and 2025. Multiple Swedish administrative courts ruled in March and April 2024 that each case requires an individual proportionality assessment between privacy rights under GDPR and constitutional press freedom protections. A blanket exemption is not sufficient.
On February 25, 2025, the Swedish Supreme Court decided two landmark cases on bulk requests for criminal judgments, one from a news agency and one from a company supplying background checks (cases 3457-24 and 3169-24). The Court held that the arrangement the legislature intended, under which the GDPR would not apply at all within the constitutionally protected area, cannot be reconciled with the GDPR.
The Court then read the Swedish secrecy rules so that the GDPR can be taken into account, found that secrecy applied, and released the documents subject to a proviso limiting further dissemination and searchability. It adjusted that proviso so the news agency could continue publishing edited news text. A broader balancing between freedom of expression and data protection, the Court said, would require legislation.
Case C-199/24 before the EU Court of Justice is further testing the limits of Sweden's constitutional exemptions against EU law. The outcome will have significant implications for how Sweden balances press freedom and data protection.
Government Constitutional Amendment Proposal
On November 20, 2024, the Swedish government proposed a significant constitutional amendment: limiting freedom of information protection where published content constitutes an "improper breach of privacy." The proposal specifically targets search services that publish personal data such as addresses, incomes, and criminal records.
If enacted, the change would allow GDPR to apply more broadly to these services. The proposed effective date is January 1, 2027. The consultation period closed in March 2025 and the proposal is under legislative consideration.
The Integritetsskyddsmyndigheten (IMY): Sweden's Supervisory Authority
IMY is Sweden's independent national supervisory authority for data protection. Before January 2021, it was named Datainspektionen (the Data Inspection Board). The renaming reflected a broadened mandate and public profile.

IMY is responsible for:
- Supervising compliance with the GDPR, the Data Protection Act, and all related data protection legislation.
- Investigating complaints from individuals about potential GDPR violations.
- Conducting proactive audits and inspections of organizations.
- Issuing administrative fines and corrective orders.
- Providing guidance, recommendations, and templates to organizations and the public.
- Participating in the European Data Protection Board (EDPB) as Sweden's member.
- Operating a regulatory sandbox for organizations testing innovative data processing activities.
- Acting as Sweden's lead supervisory authority for cross-border cases involving companies with their EU main establishment in Sweden, including Spotify.
IMY's 2026 Supervisory Priorities
For 2026, IMY has designated three priority areas:
Law enforcement tools. IMY will examine the tools law enforcement agencies use, viewed from a data protection perspective, including newer ones such as secret coercive measures and the collection of biometric data.
Children and young people. IMY will work to raise awareness of how children and young people can protect their personal data, both among young people themselves and among the adults who handle it, including guardians and schools.
AI in the public sector. IMY will scrutinize the use of artificial intelligence by public authorities, particularly systems involving sensitive personal data and situations where individuals cannot opt out of AI-based processing.
IMY also established a dedicated guidance unit effective January 1, 2026, to provide more accessible and timely support to organizations navigating data protection compliance.
Record Breach Notifications in 2025
IMY received 12,276 personal data breach notifications in 2025, the highest annual total since GDPR took effect. This represents an 89 percent increase compared to 2024. IMY linked the surge in part to major darknet data leaks affecting Swedish service providers, many of which exposed children's personal data following blackmail attempts against the organizations. Total cases handled by IMY increased 56 percent in 2025 due to the combined surge in breach reports and individual complaints.
Legal Bases and Consent Requirements
Every processing activity requires a valid legal basis under GDPR Article 6. The six available bases are:
Consent. The data subject has given freely given, specific, informed, and unambiguous consent. Consent cannot be bundled, pre-ticked, or coerced. There must be no imbalance of power between the data subject and the controller.
Contract. Processing is necessary for the performance of a contract to which the data subject is a party, or to take pre-contractual steps at the data subject's request.
Legal obligation. Processing is necessary to comply with a legal obligation to which the controller is subject.
Vital interests. Processing is necessary to protect the vital interests of the data subject or another person.
Public task. Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority. Swedish public authorities rely on this basis frequently, but may not use the legitimate interest basis.
Legitimate interests. Processing is necessary for the legitimate interests pursued by the controller or a third party, provided those interests are not overridden by the data subject's interests or fundamental rights. Public authorities may not rely on this basis. IMY confirmed in a 2025 decision that a documented legitimate interest assessment is required, and that the responsibility for demonstrating compliance rests entirely with the controller.
Sweden added a national provision in 2025. Chapter 2, Section 5 of the Data Protection Act, inserted by Lag (2025:187) and in force since April 1, 2025, permits private parties to process personal data in order to supply information requested by the Economic Crime Authority, the Coast Guard, the Police Authority, the Tax Agency, the Security Service, Customs or the Prosecution Authority for preventing, detecting, investigating or prosecuting crime.
Special Categories of Personal Data
Processing special categories of data, including health data, genetic data, biometric data used for unique identification, racial or ethnic origin, political opinions, religious beliefs, and trade union membership, requires both a lawful basis under Article 6 and a specific exception under GDPR Article 9. The general rule is that processing special categories is prohibited; lawful processing requires both elements.
Data Subject Rights
The GDPR grants individuals a comprehensive suite of rights that Swedish organizations must honor.
Sweden added a procedural right of its own in 2025. Under Chapter 6, Section 8 of the Data Protection Act, inserted by Lag (2025:256) and in force since May 1, 2025, if IMY has not decided within three months of a complaint whether to open supervision, the complainant may ask in writing for an answer. IMY must then give that answer within two weeks, or refuse the request by separate decision. A refusal can be appealed to the administrative courts, and the court may order IMY to answer promptly.
Right of access. Individuals may request confirmation of whether their personal data is processed, and a copy of the data. The Spotify enforcement case arose partly from Spotify's failure to clearly explain how accessed data was used.
Right to rectification. Individuals may have inaccurate data corrected and incomplete data completed.
Right to erasure (right to be forgotten). Individuals may request deletion of their data in defined circumstances, including where data is no longer necessary for the purpose for which it was collected. Google's fine arose from systematic failures to honor right-to-delisting requests; IMY originally imposed SEK 75 million in March 2020, reduced on appeal to SEK 50 million in November 2021 and final in December 2022, when the Supreme Administrative Court refused leave to appeal.
Right to restriction. Individuals may restrict processing while a dispute about accuracy or lawfulness is pending.
Right to data portability. Where processing is based on consent or contract and carried out by automated means, individuals may receive their data in a structured, commonly used, machine-readable format.
Right to object. Individuals may object to processing based on legitimate interests or carried out for direct marketing. H&M's SEK 350,000 fine in 2023 arose from continued direct marketing despite objections from data subjects.
Rights related to automated decision-making. Individuals have the right not to be subject to solely automated decisions, including profiling, that produce legal or similarly significant effects.
Breach Notification Requirements

Sweden follows the GDPR's breach notification framework.
Notifying IMY: The 72-Hour Rule
Controllers must notify IMY within 72 hours of becoming aware of a personal data breach, provided the breach is likely to result in a risk to the rights and freedoms of individuals. Notification is not required where the breach is unlikely to cause any risk.
Notifications are submitted through IMY's electronic reporting system. If not all information is available within 72 hours, controllers may submit an initial notification and provide supplementary details within four weeks.
Notifying Affected Individuals
When a breach is likely to result in a high risk to individuals' rights and freedoms, the controller must also notify the affected data subjects without undue delay. The notification must explain the nature of the breach, likely consequences, and measures taken or proposed.
Processor Obligations
When a breach occurs at a data processor, the processor must notify its controller without undue delay. The legal obligation to report to IMY remains with the controller.
Consequences of Late or Failed Notification
Failure to report a breach constitutes an independent GDPR violation, potentially resulting in fines of up to EUR 10 million or 2 percent of global annual turnover. IMY has specifically enforced the notification obligation in multiple cases.
Data Protection Officers (DPOs)
Sweden follows the GDPR's DPO requirements without imposing additional national obligations beyond what the GDPR requires.
Appointment of a DPO is mandatory for:
- All public authorities and bodies.
- Organizations whose core activities require regular and systematic monitoring of individuals on a large scale.
- Organizations whose core activities involve large-scale processing of special categories of personal data.
Appointed DPOs must be reported to IMY. Swedish law imposes a confidentiality obligation on DPOs regarding information obtained while carrying out their duties. IMY maintains a notification form and publishes DPO guidance. The DPO must be provided with the resources necessary to fulfill their tasks and must be able to operate independently.
Data Protection Impact Assessments (DPIAs)
A DPIA is mandatory before beginning any processing likely to result in a high risk to individuals' rights and freedoms. IMY has published a detailed list of processing types that require a DPIA, along with two-part guidance and a three-part template.
IMY's criteria indicating a DPIA is needed include:
- Automated decision-making with legal or similarly significant effects.
- Large-scale processing of sensitive personal data or data of a very personal nature.
- Combining data from two or more sources in ways data subjects would not reasonably expect.
- Processing data about vulnerable individuals, including employees, children, and patients.
- Using new technologies or organizational solutions.
- Processing data to prevent individuals from accessing a service or entering into a contract.
The Skelleftea school facial recognition case, Sweden's first GDPR fine, was partly grounded in the school's failure to conduct a DPIA before deploying biometric attendance tracking.
Cross-Border Data Transfers

Sweden does not impose transfer restrictions beyond what the GDPR requires. Transfers within the European Economic Area (EEA) proceed without restriction.
For transfers to countries outside the EEA without an EU adequacy decision, organizations must use appropriate safeguards:
- Standard Contractual Clauses (SCCs) adopted by the European Commission.
- Binding Corporate Rules (BCRs) approved by a competent supervisory authority.
- Codes of conduct or certification mechanisms with binding commitments from the recipient.
IMY has demonstrated that it takes transfer compliance seriously. The 2023 fines against Tele2 (SEK 12 million) and CDON (SEK 300,000) for using Google Analytics were among the first penalties issued anywhere in the EU for inadequate safeguards on EU-US transfers following the Schrems II ruling.
The 2024 Meta pixel fines against Apoteket, Apohem, and Avanza Bank rest on a different theory and should not be read as transfer cases. IMY decided Apoteket and Apohem under GDPR Article 32(1), and Avanza under Articles 5(1)(f) and 32(1), for failing to implement appropriate technical and organizational measures, and the recipient was Meta Platforms Ireland Limited, an EEA entity. The Apoteket decision records that the supervision was limited to Article 32, and it never reaches Chapter V, third countries, or standard contractual clauses.
Sweden as Lead Supervisory Authority
Under GDPR's one-stop-shop mechanism, a company with its main EU establishment in Sweden is supervised primarily by IMY as lead supervisory authority. Spotify AB, headquartered in Stockholm, is the most prominent example. IMY's 2023 fine of SEK 58 million against Spotify arose from IMY's role as lead supervisor for that cross-border case.
EU AI Act Overlay
The EU AI Act (Regulation 2024/1689) entered into force in August 2024. It applies in Sweden as EU law and intersects significantly with GDPR obligations.
The compliance calendar changed in 2026. Regulation (EU) 2026/1744 of July 8, 2026, the Digital Omnibus on AI, amended Article 113 of the AI Act and moved the high-risk obligations in Chapter III, Sections 1 to 3 back to December 2, 2027 for Annex III systems and August 2, 2028 for Annex I systems.
The Act's general date of application, August 2, 2026, was not changed. The Article 50 transparency duties, including chatbot disclosure, deepfake labelling and marking of synthetic content, therefore apply now. Providers of systems generating synthetic content that were already on the market before August 2, 2026 have until December 2, 2026 to meet the Article 50(2) marking requirement, under the new Article 111(4).
Key Interaction Points
High-risk AI systems under the AI Act must comply with both the AI Act's requirements and the GDPR. Where an AI system processes personal data, the two regimes apply simultaneously. Controllers using high-risk AI systems that process personal data must satisfy both GDPR legal basis requirements and AI Act conformity obligations.
IMY and other data protection authorities across the EU have signaled that GDPR enforcement will extend to AI systems that process personal data unlawfully, creating overlapping regulatory exposure.
Sweden's National AI Governance Framework
The Swedish government published its official inquiry report SOU 2025:101, which proposes a national AI law and ordinance to supplement the EU AI Act. The proposed framework:
- Designates the Swedish Post and Telecom Authority (PTS) as the primary coordinating authority and single national contact point for AI Act supervision.
- Identifies eleven market surveillance authorities responsible for AI oversight across different sectors.
- Establishes a national AI regulatory sandbox.
- Addresses secrecy and confidentiality issues specific to Swedish law.
SOU 2025:101 proposed that the complementing law and ordinance enter into force on August 2, 2026. That date has passed and nothing has been enacted. As of September 2026 the Swedish statute register carries no complementing AI Act legislation and no national competent authority designated in law, only Lag (2026:806) and Forordning (2026:815) on police facial recognition. The inquiry itself flagged the risk, recommending that the government designate market surveillance and notifying authorities at least temporarily while the proposal was still under preparation.
The PTS designation is also less settled than it looks. Forordning (2026:1769), issued September 3, 2026, creates a new agency, Digitaliseringsmyndigheten, which takes over the electronic communications remit from January 1, 2027.
IMY has designated "AI in the public sector" as a 2026 supervisory priority, signaling that public bodies deploying AI systems involving personal data will face direct scrutiny. In January 2025, IMY and the Swedish Agency for Digital Government (Digg) jointly issued guidelines to support the use of generative AI in public administration while maintaining data protection compliance.
Facial Recognition: From Enforcement to Legislation
Sweden's evolving approach to facial recognition illustrates the AI Act's real-world tensions.
In 2019, IMY issued Sweden's first-ever GDPR fine, SEK 200,000, against a school in Skelleftea for using facial recognition to track student attendance. In 2021, IMY fined the Swedish Police Authority SEK 2.5 million for unlawfully processing biometric data using the Clearview AI application, without conducting a required DPIA. That penalty did not survive appeal: the Administrative Court of Appeal in Stockholm set it aside on November 7, 2022, and the Supreme Administrative Court refused leave to appeal on November 17, 2023.
In a sharp policy reversal, the Riksdag then authorized the practice. Proposition 2025/26:150 passed as bet. 2025/26:JuU28, rskr. 2025/26:288, and became Lag (2026:806) on the use of AI systems for real-time facial recognition for law enforcement purposes, issued May 28, 2026 and in force since July 1, 2026, alongside Forordning (2026:815). The law applies to the Police Authority and the Security Service.
Section 4 sets five narrow grounds. Real-time facial recognition may be used only where it is absolutely necessary to locate or identify a specific person who is a suspected victim of kidnapping, human trafficking or sexual exploitation; who is missing and suspected of being the victim of a crime; where there is an overhanging risk that the person will commit a serious offence endangering another person's life or physical safety; who is reasonably suspected of an offence listed in Annex II to the AI Act that carries four years or more on the penalty scale, in order to investigate or prosecute it; or who has been convicted of such an offence, in order to enforce the sentence.
Authorization runs on two tracks. A prosecutor decides on use for preventing, hindering or detecting criminal activity or enforcing a sentence (Section 6). A court decides, on the prosecutor's application, on use for investigating or prosecuting an offence (Section 7). A permit may not run longer than one month.
Where there is danger in delay, police may start without a permit, but they must document the reasons and file an application under Section 6 or Section 7 without undue delay and at the latest within 24 hours of starting (Sections 13 and 14). The 24-hour clock runs on filing the application, not on obtaining the permit. If the application is refused, the use must stop immediately and the data must be deleted. Every use must be reported to IMY under Section 2 of Forordning (2026:815).
The EU AI Act classifies real-time remote biometric identification in public spaces as high-risk and, with limited exceptions for law enforcement, as prohibited. Sweden's law sits at the outer edge of what the AI Act permits for law enforcement use. IMY and civil liberties organizations have raised concerns about proportionality and potential for mission creep.
Notable IMY Enforcement Actions
IMY has significantly increased its enforcement activity over the GDPR's lifetime. The following cases represent the most significant actions.
Skelleftea School: SEK 200,000 (2019). Sweden's first GDPR fine. A school trialed facial recognition to track student attendance over three weeks for 22 students. IMY found violations of data minimization (Article 5), unlawful processing of biometric data (Article 9), and failure to conduct a DPIA (Articles 35-36). The case established Sweden's willingness to fine public bodies and set precedent for biometric data enforcement.
Google: SEK 50 Million final (2020 to 2022). IMY imposed SEK 75 million in March 2020 following a 2017 audit and a 2018 follow-up audit revealing ongoing non-compliance with right-to-delisting requests. The Stockholm Administrative Court reduced the fine to SEK 52 million in November 2020. The Gothenburg Court of Appeal reduced it further to SEK 50 million in November 2021. The Swedish Supreme Administrative Court denied leave to appeal in December 2022, making SEK 50 million the final figure. At the time of the original decision it was one of the largest GDPR penalties issued by any Nordic data protection authority.
Swedish Police: SEK 2.5 Million (2021, set aside on appeal). IMY fined the Swedish Police Authority for unlawfully processing biometric data using the Clearview AI facial recognition application. The police failed to conduct a DPIA and violated the Criminal Data Act. IMY also ordered mandatory employee training. The fine did not stand. The Administrative Court of Appeal in Stockholm quashed IMY's penalty decision on November 7, 2022 (case 7678-21), and the Supreme Administrative Court refused leave to appeal on November 17, 2023 (case 6943-22).
Klarna: SEK 7.5 Million (2022). IMY found that Klarna Bank failed to provide adequate information on the legal basis and purpose for processing personal data in one of its services, gave misleading information about data recipients when sharing data with credit information companies, and provided incomplete information about data subjects' rights. The Administrative Court in Stockholm cut the fine to SEK 6 million on April 14, 2023, but the Administrative Court of Appeal in Stockholm restored the full SEK 7.5 million on March 11, 2024 (case 2829-23).
Spotify: SEK 58 Million (2023). In a decision of June 12, 2023, acting as lead supervisory authority for this cross-border case, IMY found that Spotify provided personal data when individuals exercised their access rights, but failed to clearly explain how that data was used. Descriptions of data categories, retention periods, and third-country transfers were insufficient. Approximately EUR 5 million. The Administrative Court in Stockholm cut the fine to SEK 40 million, but the Administrative Court of Appeal in Stockholm restored the full SEK 58 million on June 3, 2025 (case 4512-24).
Trygg-Hansa: SEK 35 Million (2023). Insurance company Trygg-Hansa received a fine of approximately EUR 3 million after IMY found that customer data for 650,000 customers was accessible without proper authentication from October 2018 to February 2021, due to a misconfigured web application.
Google Analytics: Tele2 SEK 12 Million, CDON SEK 300,000 (2023). Following 101 complaints triggered by the Schrems II decision, IMY imposed the first EU penalties for use of Google Analytics without adequate safeguards for US data transfers. These were landmark cases signaling regulatory expectations for analytics tools used across European businesses.
H&M: SEK 350,000 (2023). IMY fined the fashion retailer for continuing to use personal data for direct marketing after receiving objections from data subjects, in violation of GDPR Article 21.
Apoteket: SEK 37 Million (2024). In a decision of August 29, 2024 (IMY-2022-3270), IMY found that pharmacy chain Apoteket used Meta's tracking pixel on its website without implementing adequate technical and organizational measures to protect customers' personal data, including potentially sensitive health-related browsing data. The finding was a breach of GDPR Article 32(1) covering January 19, 2020 to April 25, 2022, and the effect was that personal data reached Meta Platforms Ireland Limited unintentionally.
Apohem: SEK 8 Million (2024). Online pharmacy Apohem received a related Article 32(1) fine on the same date for the same Meta pixel failure. This one is not final. The Administrative Court in Stockholm dismissed Apohem's appeal on May 15, 2026 (case 18096-24), and the company has appealed to the Administrative Court of Appeal.
Avanza Bank: SEK 15 Million (2024). Avanza Bank unintentionally transferred personal data of between 500,000 and one million customers to Meta through a tracking pixel deployed between November 2019 and June 2021.
Sportadmin: SEK 6 Million (2026). In a decision dated January 26, 2026 (IMY-2025-7801, announced by press release on January 28), IMY fined Sportadmin following a January 2025 cyberattack that exposed personal data of more than 2.1 million individuals. The leaked data included names, contact details, personal identity numbers, and sports club affiliations, much of it belonging to children. IMY found that Sportadmin had known about security weaknesses for an extended period but failed to address them adequately. The company lacked real-time intrusion detection and adequate procedures for identifying security gaps. The case is notable for the roles involved. IMY found that Sportadmin acts mainly as a processor and to a limited extent as a controller, and declined to allocate the roles activity by activity, because the Article 32(1) duty to take appropriate security measures binds processors and controllers alike.
Penalty Structure
The following table summarizes the administrative fine framework applicable in Sweden.
| Violation Category | Maximum: Companies | Maximum: Public Authorities |
|---|---|---|
| Less serious infringements (Art. 83(4)) | EUR 10M or 2% global annual turnover | SEK 5 million |
| Serious infringements (Art. 83(5-6)) | EUR 20M or 4% global annual turnover | SEK 10 million |
| Non-compliance with IMY orders | EUR 20M or 4% global annual turnover | SEK 10 million |
IMY determines fine amounts based on the nature, gravity, and duration of the infringement; whether it was intentional or negligent; actions taken to mitigate harm to data subjects; the degree of controller responsibility given implemented measures; any prior infringements; the personal data categories affected; and how the infringement came to IMY's attention.
Beyond monetary fines, IMY may issue warnings for planned processing likely to violate the GDPR, reprimands for ongoing violations, and orders to bring processing into compliance or cease specific activities. Sweden has chosen to make public authorities subject to fines, unlike some member states that exempt government bodies entirely.
Recent Developments (2024 to 2026)
Cookie banner enforcement (April 2025). On April 28, 2025, IMY reprimanded media company Aller Media AB for breaching GDPR Article 6(1)(f) by processing a complainant's personal data without a demonstrated lawful basis. The case came out of the EDPB Cookie Banner Taskforce complaints. Banner design featured in the complaint, but IMY did not hold that the relative prominence of an "accept all" button, on its own, invalidates consent. Equal prominence remains EDPB guidance rather than the ratio of this decision.
Camera surveillance deregulation (April 1, 2025). Lag (2025:220) removed the permit requirement for bodies carrying out a task of general interest. They now rely on a documented statutory balancing assessment that must be kept for five years, plus a register of ongoing surveillance that must be produced to IMY on request.
IMY guidance unit (January 1, 2026). A dedicated guidance unit was established within IMY to provide more accessible support to organizations.
AI in public administration guidance (January 2025). IMY and the Swedish Agency for Digital Government (Digg) jointly published guidelines supporting the use of generative AI in public administration within a GDPR-compliant framework.
Proposed constitutional amendment (November 2024). The Swedish government proposed limiting freedom of information protection where published content constitutes an improper breach of privacy, targeting search services that publish personal data under publication certificates. Targeted effective date: January 1, 2027.
SOU 2025:101 national AI law proposal (not enacted). The government's official inquiry of October 8, 2025 recommends PTS as the coordinating AI supervisory authority, with market surveillance bodies across sectors, a national AI sandbox, and new provisions on secrecy. It proposed entry into force on August 2, 2026, but as of September 2026 no complementing Swedish AI legislation has been enacted.
Police live facial recognition law in force (July 1, 2026). Lag (2026:806) and Forordning (2026:815), enacted from Prop. 2025/26:150, authorize the Police Authority and the Security Service to use real-time facial recognition on five narrow statutory grounds. A prosecutor authorizes preventive and enforcement use, a court authorizes investigative and prosecutorial use, and every use must be reported to IMY.
Swedish Supreme Court decisions on criminal judgments (February 25, 2025). In cases 3457-24 and 3169-24 the Supreme Court held that treating the GDPR as wholly inapplicable within the constitutionally protected area cannot be reconciled with the GDPR. It found that secrecy applied to bulk requests for criminal judgments and released the documents subject to a proviso limiting further dissemination and searchability.
Business Compliance: What Organizations in Sweden Must Do
Organizations processing personal data of individuals in Sweden should address the following areas.
Establish a documented lawful basis. Before collecting or processing personal data, identify which of the six GDPR legal bases applies. Document this in your Records of Processing Activities (RoPA). For processing based on legitimate interests, carry out and document a legitimate interest assessment. IMY's 2025 enforcement confirms the controller cannot delegate this responsibility.
Handle personnummer with care. Do not collect Swedish personal identity numbers as a matter of routine. Processing requires either explicit consent or clear justification based on purpose, identification necessity, or another significant reason. Treat personnummer as you would sensitive data.
Appoint a DPO if required. Public authorities and organizations engaged in large-scale systematic monitoring or large-scale processing of sensitive data must appoint a Data Protection Officer and notify IMY.
Implement 72-hour breach notification processes. Build internal incident detection, assessment, and reporting workflows so you can notify IMY within 72 hours of becoming aware of a qualifying breach. Establish clear processor notification obligations in your contracts.
Conduct DPIAs for high-risk processing. Apply IMY's criteria checklist before beginning any processing that might trigger a DPIA requirement. Document the assessment and consult IMY beforehand if residual risk remains high.
Provide transparent privacy information. Write clear, accessible privacy notices that explain what data you collect, why you collect it, how long you keep it, who receives it (including cross-border recipients), and what rights individuals have. The Spotify and Klarna fines both turned on insufficient transparency, not unlawful processing.
Audit tracking pixels and analytics tools. Review every third-party script on your site, and treat these as two separate exposures. The Google Analytics fines turned on transfers outside the EEA, so verify that appropriate SCCs or other safeguards are in place. The Meta pixel fines turned on Article 32 security, so check what each script actually transmits and whether anyone has reviewed the configuration, even where the recipient sits inside the EEA. Consent mechanisms must be valid in either case.
Use honest cookie consent mechanisms. Avoid dark patterns. Present "accept" and "reject" options with equal prominence and equal ease of use, as EDPB guidance recommends. IMY's April 2025 Aller Media reprimand shows the practical exposure: where a banner buries the option to object, the controller can end up unable to demonstrate any lawful basis at all.
Prepare for AI Act obligations. If you develop or deploy AI systems that process personal data, assess whether the system qualifies as high-risk under the EU AI Act. After Regulation (EU) 2026/1744, high-risk obligations apply from December 2, 2027 for Annex III systems and August 2, 2028 for Annex I systems. The Article 50 transparency duties already apply as of August 2, 2026, with a grace period to December 2, 2026 for marking synthetic content generated by systems placed on the market before that date. IMY will scrutinize AI systems in the public sector; private-sector deployers should track guidance from IMY and from whichever AI supervisory authorities Sweden eventually designates.
Train staff. Ensure all employees who handle personal data understand the legal requirements, your organization's data protection policies, and how to recognize and escalate potential data breaches.
This article is for informational purposes only and does not constitute legal advice. Data privacy laws are subject to change. Consult a qualified attorney licensed in Sweden for guidance on specific compliance obligations.
Frequently Asked Questions
What is the main data protection law in Sweden?
Sweden's data protection framework combines the EU General Data Protection Regulation (GDPR), which applies directly as EU law, with the Swedish Data Protection Act (Dataskyddslagen, 2018:218) and the Data Protection Ordinance (2018:219). The GDPR provides the core framework. The Swedish Act adds national rules on children's consent age (13), the elevated protection of personal identity numbers (personnummer), and criminal data processing. The Swedish Authority for Privacy Protection (IMY) enforces both.
What is the offentlighetsprincipen and how does it interact with GDPR?
The offentlighetsprincipen (public access principle) is a constitutional principle dating to 1766 that makes official government documents presumptively public. It is enshrined in Sweden's Freedom of the Press Act and Fundamental Law on Freedom of Expression. Where the principle applies, GDPR has historically not overridden it. However, Swedish courts and the Supreme Court ruled in 2024 and 2025 that a blanket exemption from GDPR is incompatible with EU law, and individual proportionality assessments are now required. The government has also proposed a constitutional amendment to limit freedom of information protections for search services that publish personal data.
What is IMY and what does it do?
IMY (Integritetsskyddsmyndigheten), or the Swedish Authority for Privacy Protection, is Sweden's independent data protection supervisory authority. It was called Datainspektionen until 2021. IMY investigates complaints, conducts audits, issues guidance, operates a regulatory sandbox, imposes fines for GDPR violations, and participates in the European Data Protection Board. IMY acts as lead supervisory authority for cross-border GDPR cases involving companies with their EU main establishment in Sweden, such as Spotify. In 2024, IMY imposed SEK 60.6 million in total fines.
How much can organizations be fined for GDPR violations in Sweden?
Private companies face fines of up to EUR 20 million or 4 percent of global annual turnover (whichever is higher) for serious GDPR violations, and up to EUR 10 million or 2 percent of turnover for less serious infringements. Swedish public authorities face lower caps: SEK 5 million for less serious violations and SEK 10 million for serious ones. IMY's largest fine now standing is SEK 58 million against Spotify (12 June 2023), cut to SEK 40 million by the Administrative Court and restored in full by Kammarratten i Stockholm on 3 June 2025. The largest sum IMY ever imposed was SEK 75 million against Google in 2020, reduced to SEK 50 million on appeal in 2021 and final in December 2022 when the Supreme Administrative Court refused leave to appeal. Sweden allows fines against public authorities, unlike some other EU member states.
How quickly must data breaches be reported in Sweden?
Data controllers must notify IMY of a personal data breach within 72 hours of becoming aware of it. If not all information is available, an initial notification can be submitted with supplementary details provided within four weeks. If the breach poses a high risk to affected individuals, the controller must also notify those individuals without undue delay. Notification responsibilities stay with the controller even when the breach occurs at a data processor. IMY received 12,276 breach notifications in 2025, an 89 percent increase over 2024.
Are there special rules for processing Swedish personal identity numbers (personnummer)?
Yes. The Swedish Data Protection Act gives personnummer elevated protection beyond ordinary personal data. Organizations may process personnummer without consent only when it is clearly justified by the purpose, the need for secure identification, or another significant reason. This threshold effectively prevents routine collection of personnummer and requires specific justification for each use case. The personnummer's use as a universal identifier across healthcare, banking, and taxation makes it a high-sensitivity data element under Swedish law.
How does the EU AI Act apply in Sweden?
The EU AI Act (Regulation 2024/1689) applies in Sweden as EU law from August 2024. Regulation (EU) 2026/1744, the Digital Omnibus on AI of July 8, 2026, moved the obligations for high-risk AI systems to December 2, 2027 for Annex III systems and August 2, 2028 for Annex I systems, while leaving the Article 50 transparency duties in place from August 2, 2026. Sweden's national inquiry (SOU 2025:101) proposed designating the Swedish Post and Telecom Authority (PTS) as the coordinating national AI supervisory authority, with market surveillance bodies across different sectors, but no complementing Swedish AI legislation had been enacted as of September 2026. IMY has designated AI in the public sector as a 2026 supervisory priority, signaling heightened scrutiny for public bodies deploying AI systems that process personal data.
Updates
Second-round corrections: the largest-fine statement now reflects the SEK 58 million Spotify fine restored on appeal in June 2025; the Avanza legal basis, the Trygg-Hansa euro figure and the 2027 ePrivacy supervision handover are stated precisely.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Full expansion: added constitutional basis and offentlighetsprincipen section, EU AI Act overlay, IMY 2026 enforcement priorities, Sportadmin SEK 6M fine (Jan 2026), proposed live facial recognition legislation (Prop 2025/26:150), 2025 record breach notification statistics, SOU 2025:101 national AI law proposal, and government constitutional amendment proposal.
Reviewed and approved by an editor
Sources and References
- Swedish Authority for Privacy Protection (IMY) - Official Website(imy.se).gov
- Act containing supplementary provisions to the EU General Data Protection Regulation (SFS 2018:218) - Government of Sweden(government.se).gov
- Lag (2018:218) med kompletterande bestammelser till EU:s dataskyddsforordning - Sveriges riksdag(riksdagen.se).gov
- The Constitution of Sweden and personal privacy - Government.se(government.se).gov
- IMY - Fines and Warnings Overview(imy.se).gov
- IMY - Administrative Fine Against Sportadmin (January 2026)(imy.se).gov
- IMY - Administrative Fines Against Apoteket and Apohem for Meta Pixel (2024)(imy.se).gov
- IMY - Personal Data Breach Notification(imy.se).gov
- IMY - Lawful Grounds for Personal Data Processing(imy.se).gov
- IMY - Camera Surveillance for Organisations(imy.se).gov
- IMY - Google, the right to have search results removed (SEK 75 million 2020, reduced to SEK 50 million, final December 2022)(imy.se).gov
- IMY - Spotify AB, right of access (SEK 58 million, 12 June 2023; restored on appeal 3 June 2025)(imy.se).gov
- IMY - Klarna Bank AB, inadequate information (SEK 7.5 million, 28 March 2022; restored on appeal 11 March 2024)(imy.se).gov
- IMY - Trygg-Hansa (SEK 35 million, 28 August 2023)(imy.se).gov
- IMY - Gymnasienamnden i Skelleftea kommun, facial recognition in school (SEK 200,000, 20 August 2019)(imy.se).gov
- IMY - Polismyndigheten, Clearview AI (SEK 2.5 million, 10 February 2021; penalty set aside on appeal 2022, final 2023)(imy.se).gov
- Lag (2026:806) om anvandning av AI-system for ansiktsigenkanning i realtid for brottsbekampande andamal - Regeringskansliets rattsdatabaser (in force 1 July 2026)(rkrattsbaser.gov.se).gov
- Lag (2026:806) amendment register - Prop. 2025/26:150, bet. 2025/26:JuU28, rskr. 2025/26:288, Ikraft 2026-07-01(rkrattsbaser.gov.se).gov
- EU AI Act - European Commission Digital Strategy(digital-strategy.ec.europa.eu).gov
- SOU 2025:101 Anpassningar till AI-forordningen - Sveriges riksdag (8 October 2025, not enacted)(riksdagen.se).gov
- Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus on AI), amending Regulation (EU) 2024/1689 - EUR-Lex, OJ L, 2026/1744, 24.7.2026(eur-lex.europa.eu).gov
- Forordning (2026:815) om anvandning av AI-system for ansiktsigenkanning i realtid for brottsbekampande andamal - Regeringskansliets rattsdatabaser(rkrattsbaser.gov.se).gov
- Kamerabevakningslag (2018:1200), consolidated text incl. Lag (2025:220) - Regeringskansliets rattsdatabaser(rkrattsbaser.gov.se).gov
- Lag (2018:218) amendment register incl. Lag (2025:187) and Lag (2025:256) - Regeringskansliets rattsdatabaser(rkrattsbaser.gov.se).gov
- IMY decision IMY-2022-3270, Apoteket AB, 29 August 2024 (GDPR Article 32(1), SEK 37 million)(imy.se).gov
- IMY - Apohem, Meta pixel (SEK 8 million, 29 August 2024; under appeal to the Administrative Court of Appeal)(imy.se).gov
- IMY decision IMY-2025-7801, Sportadmin i Skandinavien AB, 26 January 2026 (GDPR Article 32(1), SEK 6 million)(imy.se).gov
- IMY - Aller Media AB, cookie banner reprimand under GDPR Article 6(1)(f), 28 April 2025(imy.se).gov
- IMY's priorities for 2026: AI, children and law enforcement tools (23 February 2026)(imy.se).gov
- Sveriges Domstolar - Supreme Court decisions of 25 February 2025 on the GDPR and secrecy for personal data in criminal judgments (cases 3457-24 and 3169-24)(domstol.se).gov
- Forordning (2026:1769) med instruktion for Digitaliseringsmyndigheten (issued 3 September 2026, in force 1 January 2027)(rkrattsbaser.gov.se).gov