{
 "jurisdiction_id": "SE",
 "jurisdiction": "Sweden",
 "url": "https://dataprotection.gi/jurisdictions/sweden/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 51,
  "sub_modules": 57,
  "source_register": 23
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "green",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/sweden/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Comprehensive omnibus regime in force with an active, well-resourced supervisory authority and clear statutory architecture.",
   "claims": [
    {
     "statement": "<cite index=\"2-19,2-20\">IMY is Sweden's data protection authority whose mission is to work to ensure that individuals' fundamental rights and freedoms are protected in connection with the processing of personal data.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IMY",
     "source_url": "https://www.imy.se/en/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"21-1,21-2\">The Act with Supplementary Provisions to the EU General Data Protection Regulation (SFS 2018:218) supplements Regulation (EU) 2016/679 within Sweden.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Government of Sweden / hosted via DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/swedish_code_of_statuses_2018218_pdf_1_1_0.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"31-1\">IMY supervises that the provisions in the Criminal Data Act and the Camera Surveillance Act are complied with</cite>, in addition to GDPR compliance.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IMY",
     "source_url": "https://www.imy.se/en/about-us/swedish-authority-for-privacy-protections-assignment/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"38-1\">IMY is the supervisory authority for the Credit Information Act and issues licences for those who wish to conduct credit information activity.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IMY",
     "source_url": "https://www.imy.se/en/about-us/contact-us/telephone-guidance2/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"4-18\">IMY handles personal data concerning appointed data protection officers to be able to administrate notifications of data protection officers received in accordance with Article 37 of the GDPR.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IMY",
     "source_url": "https://www.imy.se/en/about-us/swedish-authority-for-privacy-protections-assignment/",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "green",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/sweden/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Core lawful-basis and special-category framework is GDPR-aligned with active national derogations exercised and enforced.",
   "claims": [
    {
     "statement": "<cite index=\"6-3,6-5\">Organisations processing personal data in Sweden must comply with the GDPR and must have a lawful ground in order to process personal data.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IMY",
     "source_url": "https://www.imy.se/en/news/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"41-40,41-41\">For consent to be valid it must be provided voluntarily, meaning the data subject has a genuinely free choice and control over their personal data</cite>, and must be as easy to withdraw as to give.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IMY",
     "source_url": "https://www.imy.se/globalassets/dokument/rapporter/the-rights-of-children-and-young-people-on-digital-platforms_accessible.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In the Apohem decision, IMY found that <cite index=\"52-2,52-4\">personal data affected by unlawful Meta Pixel transfers included names, social security numbers, email addresses, IP addresses, and phone numbers, and that both companies violated Article 32(1) of the GDPR</cite> in a context IMY treated as involving sensitive health/sex-life-adjacent purchase data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/sweden-imy-fines-apoteket-sek-37m-and-apohem-sek-8m",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"43-1\">When information society services are offered directly to a child living in Sweden, the child's personal data may be processed with the child's consent if the child is at least 13 years old.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Government of Sweden / hosted via DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/swedish_code_of_statuses_2018218_pdf_1_1_0.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "green",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/sweden/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Full GDPR rights suite in force with demonstrated enforcement of the objection-to-erasure pathway.",
   "claims": [
    {
     "statement": "<cite index=\"9-20,9-21\">The right of access means individuals can contact companies, authorities or other organisations to find out whether they are processing their personal data and, if so, receive a copy of it and information about how it is used.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IMY",
     "source_url": "https://www.imy.se/en/individuals/data-protection/your-rights-as-a-data-subject/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"9-11,9-12\">Data subjects have the right to contact a company or authority processing their personal data and request erasure where, among other grounds, the data is no longer needed for the purposes for which it was collected.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IMY",
     "source_url": "https://www.imy.se/en/individuals/data-protection/your-rights-as-a-data-subject/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"9-14\">Erasure must occur if the processing is carried out for direct marketing and the data subject objects to the data being processed.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IMY",
     "source_url": "https://www.imy.se/en/individuals/data-protection/your-rights-as-a-data-subject/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "IMY reviewed complaints and found that <cite index=\"17-1,17-2\">a company did not have sufficient systems and routines to make it easier for those who complained to exercise their right to object to direct marketing, issuing a fine of SEK 350,000</cite>.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB / IMY",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2023/sweden-sa-imy-issues-administrative-fine-against-hm-making-it-difficult_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"9-18\">Erasure is required if the personal data is about a child and was collected when the child created a profile on a social media platform.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IMY",
     "source_url": "https://www.imy.se/en/individuals/data-protection/your-rights-as-a-data-subject/",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/sweden/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Framework is comprehensive and enforced robustly, but repeated large fines (SEK 6m, 37m, 8m) indicate ongoing systemic security-measure compliance gaps among controllers.",
   "claims": [
    {
     "statement": "<cite index=\"41-19,41-21\">GDPR requires an impact assessment for processing on a large scale of sensitive personal data and for systematic surveillance of a public space on a large scale</cite>, per criteria IMY has published drawing on EDPB guidance.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IMY",
     "source_url": "https://www.imy.se/globalassets/dokument/rapporter/the-rights-of-children-and-young-people-on-digital-platforms_accessible.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"29-3\">Chapter 1, Section 8 of the Act with Supplementary Provisions to the GDPR (SFS 2018:218) supplements Articles 37-39 of the GDPR on DPO appointment.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/notes/sweden-data-protection-officer-appointment",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "IMY supervised Sportadmin after a leak affecting over 2 million individuals and found <cite index=\"11-7,11-8\">the review shows that Sportadmin did not have an appropriate level of security to protect the personal data the company processed, and IMY therefore decided to impose an administrative fine of SEK 6 million</cite>.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IMY",
     "source_url": "https://www.imy.se/en/news/administrative-fine-against-sportadmin/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"6-9\">Data controllers are obligated to report certain personal data breaches to IMY.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IMY",
     "source_url": "https://www.imy.se/en/news/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"51-3,51-4\">IMY imposed administrative fines of SEK 37 million on Apoteket AB and SEK 8 million on Apohem AB after the companies used the Meta Pixel on their websites and transferred sensitive personal data to Meta.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IMY",
     "source_url": "https://www.imy.se/en/news/administrative-fines-against-apoteket-and-apohem-for-transferring-personal-data-to-meta/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"34-1,34-33\">Where a controller has an actual need of a longer camera-surveillance storage time it must provide a specific motivation, and the need for surveillance must be regularly reassessed.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IMY",
     "source_url": "https://www.imy.se/en/organisations/camera-surveillance/for-those-considering-the-use-of-camera-surveillance/",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "amber",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/sweden/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "Framework is GDPR-standard, but enforcement record shows repeated transfer-related transparency and security failures involving US ad-tech processors.",
   "claims": [
    {
     "statement": "<cite index=\"6-11\">When personal data is sent outside the EU/EEA, the rules for transfer to third countries apply under the GDPR as applied in Sweden.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IMY",
     "source_url": "https://www.imy.se/en/news/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In the Klarna decision, IMY found the company <cite index=\"16-18\">did not provide information on to which countries outside the EU/EEA personal data were transferred or on where and how individuals could obtain information on the safeguards that applied to the transfer to third countries</cite>, contributing to a SEK 7.5 million fine.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB / IMY",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2022/swedish-authority-privacy-protection-imy-issues-administrative-fine-against_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Apoteket/Apohem cases arose because <cite index=\"51-6,51-8\">the companies used Meta's analytics tool, Meta Pixel, on their websites, and by activating a new sub-feature transferred sensitive personal data to Meta concerning a large number of customers</cite>, a US-headquartered processor/joint controller.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IMY",
     "source_url": "https://www.imy.se/en/news/administrative-fines-against-apoteket-and-apohem-for-transferring-personal-data-to-meta/",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/sweden/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Multiple active sectoral overlays with demonstrated enforcement gaps, particularly in financial transparency and health-data security.",
   "claims": [
    {
     "statement": "<cite index=\"31-2\">IMY monitors that those who carry out credit information activity follow good business practice</cite> and issues permits for such activity.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IMY",
     "source_url": "https://www.imy.se/en/about-us/swedish-authority-for-privacy-protections-assignment/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"16-3,16-4\">Klarna, a financial company processing personal data about many people in many ways, was found to have violated Articles 5(1)(a), 5.2, 12.1, 13.1 and 14.2(g) GDPR for failing to fulfil the transparency principle and data subjects' right to information</cite>, resulting in a SEK 7.5 million fine.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB / IMY",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2022/swedish-authority-privacy-protection-imy-issues-administrative-fine-against_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"59-1,59-2\">IMY found that Region Dalarna had not taken sufficient security measures to protect sensitive personal data against unauthorized disclosure in connection with sending physical invitations to healthcare visits, issuing an administrative sanction of SEK 200,000</cite>.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IMY",
     "source_url": "https://www.imy.se/en/news/fine-against-region-dalarna/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under <cite index=\"55-24\">Chapter 9, Section 28 of the Electronic Communications Act (LEK), which implements Article 5.3 of the ePrivacy Directive, data may be stored in or retrieved from a subscriber's or user's terminal equipment only if the subscriber or user has access to information about the purpose of the processing and consents to it</cite>.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IMY",
     "source_url": "https://www.imy.se/globalassets/dokument/beslut/2024/beslut-tillsyn-apohem.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"25-4\">The Act with Supplementary Provisions to the GDPR (SFS 2018:218) supplements the GDPR and outlines grounds for processing of personal data left to Member States' discretion</cite>, including employment-context processing.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/notes/sweden-employment",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"14-12,14-13\">IMY fined Aktiebolaget Storstockholms Lokaltrafik (SL) and Waxholms Ångfartygs AB (WÅAB) SEK 75,000 each for processing personal data relating to sobriety tests conducted by employees in breach of the GDPR.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IMY",
     "source_url": "https://www.imy.se/en/news/",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "red",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/sweden/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Repeated, large enforcement actions (Google Analytics, Meta Pixel across two retailers) indicate systemic non-compliance in the adtech/commercial tracking space.",
   "claims": [
    {
     "statement": "Cookie and tracker storage/retrieval is governed by <cite index=\"55-24\">Chapter 9, Section 28 LEK, which permits storage in or retrieval from terminal equipment only where the subscriber or user has access to information about the purpose and consents to it</cite>.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IMY",
     "source_url": "https://www.imy.se/globalassets/dokument/beslut/2024/beslut-tillsyn-apohem.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"14-27,14-28\">IMY audited how four companies use Google Analytics for web statistics and issued administrative fines against two of them</cite> as part of a cross-context-advertising/tracker enforcement sweep.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IMY",
     "source_url": "https://www.imy.se/en/news/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"12-1\">IMY found that Sportadmin's counterpart cases and the Apoteket/Apohem investigations established that companies violated Article 32 of the GDPR through inadequate control of ad-tech pixel data flows</cite>, resulting in fines of SEK 37 million and SEK 8 million respectively.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IMY",
     "source_url": "https://www.imy.se/en/news/administrative-fines-against-apoteket-and-apohem-for-transferring-personal-data-to-meta/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"17-1,17-2\">IMY fined a company SEK 350,000 for not having sufficient systems and routines in place to make it easier for those who complained to exercise their right to object to direct marketing.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB / IMY",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2023/sweden-sa-imy-issues-administrative-fine-against-hm-making-it-difficult_en",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/sweden/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Binding biometric/surveillance rules exist (Camera Surveillance Act, Criminal Data Act) but AI-specific governance remains largely soft-law/guidance stage pending fuller EU AI Act interface.",
   "claims": [
    {
     "statement": "<cite index=\"9-19\">Profiling is a type of personal data processing and therefore must follow the rules in the GDPR.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IMY",
     "source_url": "https://www.imy.se/en/individuals/data-protection/your-rights-as-a-data-subject/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"3-1,3-2\">In June 2026, IMY published a report clarifying the roles and responsibilities of companies under the GDPR when developing and fine-tuning AI applications, distinguishing between controllers and processors based on data processing activities.</cite>",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/sweden-imy-publishes-report-gdpr-responsibility-roles",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"7-6,7-7\">IMY found that LiDAR sensors are typically covered by the term \"other optical-electronic instruments\" under the Swedish Camera Surveillance Act, and it is highly probable that individuals can be distinguished and identified based on body movements, body constitution, and clothing in LiDAR output.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IMY",
     "source_url": "https://www.imy.se/globalassets/dokument/rapporter/english-summary---the-swedish-authority-for-privacy-protection-imy-finishes-its-second-regulatory-sandbox-pilot.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"36-3,36-12\">The Criminal Data Act applies to personal data processing within law enforcement activities at authorities including the Swedish Police Authority, Customs, Tax Agency and Prosecution Authority, while the Swedish Security Service is not subject to the Criminal Data Act but has special legislation of its own.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IMY",
     "source_url": "https://www.imy.se/en/organisations/data-protection/data-protection-within-different-areas/personal-data-within-law-enforcement/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"1-10\">In January 2025, the Swedish Agency for Digital Government (Digg) together with IMY launched guidelines to encourage the use of generative AI in public administration.</cite>",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IMY",
     "source_url": "https://www.imy.se/en/",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/sweden/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Clear statutory age-of-consent rule exists and is actively supervised, but a major 2026 breach affecting children's data shows continuing real-world exposure risk.",
   "claims": [
    {
     "statement": "<cite index=\"41-2,41-4\">Every EU Member State has had the opportunity to lower the age indicated in GDPR Article 8, and Sweden has decided that children over the age of 13 years can give consent to processing for information society services.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IMY",
     "source_url": "https://www.imy.se/globalassets/dokument/rapporter/the-rights-of-children-and-young-people-on-digital-platforms_accessible.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"43-1,43-2\">If a child is under 13 years old, their personal data may only be processed with the consent of the holder of parental responsibility, per the Act with Supplementary Provisions to the GDPR.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Government of Sweden / hosted via DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/swedish_code_of_statuses_2018218_pdf_1_1_0.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"12-9,12-11\">The Sportadmin breach, initiated following a January 2025 cyber attack, exposed data on more than 2.1 million individuals, mainly concerning children and young people, including names, contact details, personal identity numbers, and sport/club affiliations.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IMY",
     "source_url": "https://www.imy.se/en/news/administrative-fine-against-sportadmin/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"1-1,1-2\">IMY is focusing on three areas in its guidance and supervision during 2026: crime prevention, children and young people, and AI in the public sector.</cite>",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IMY",
     "source_url": "https://www.imy.se/en/",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/sweden/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Strong, well-documented enforcement powers and activity, but no confirmed Swedish-specific collective-redress/class-action mechanism was located.",
   "claims": [
    {
     "statement": "<cite index=\"13-1,13-2\">In Sweden, authorities must also be able to be fined: for less serious infringements the fine amounts to a maximum of SEK 5 million and for serious infringements a maximum of SEK 10 million.</cite> <cite index=\"13-5,13-6\">IMY can also issue warnings for planned processing likely to contravene the GDPR, issue reprimands for ongoing contraventions, and order cessation of processing.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IMY",
     "source_url": "https://www.imy.se/en/about-us/swedish-authority-for-privacy-protections-assignment/sa-arbetar-vi-med-tillsyn/fines-and-warnings/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"13-7\">IMY's decisions can be appealed.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IMY",
     "source_url": "https://www.imy.se/en/about-us/swedish-authority-for-privacy-protections-assignment/sa-arbetar-vi-med-tillsyn/fines-and-warnings/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"11-7,11-8\">IMY imposed an administrative fine of SEK 6 million against Sportadmin after finding it did not have an appropriate level of security to protect the personal data it processed.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IMY",
     "source_url": "https://www.imy.se/en/news/administrative-fine-against-sportadmin/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"51-1\">IMY decided to impose administrative fines of SEK 37 million on Apoteket AB and SEK 8 million on Apohem AB for improper Meta Pixel data transfers.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IMY",
     "source_url": "https://www.imy.se/en/news/administrative-fines-against-apoteket-and-apohem-for-transferring-personal-data-to-meta/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"54-11,54-12\">IMY audited how Spotify handles customers' right to access their personal data, and the deficiencies discovered caused IMY to issue an administrative fine of SEK 58 million against the company.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IMY",
     "source_url": "https://www.imy.se/en/news/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"14-24,14-25\">Trygg-Hansa's security flaws meant information about 650,000 customers was accessible to unauthorized persons via the internet, leading IMY to issue an administrative fine of SEK 35 million against the company.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IMY",
     "source_url": "https://www.imy.se/en/news/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"16-11,16-12\">In a One-Stop-Shop procedure involving Germany, Austria, Italy, Netherlands, Norway, Finland and Denmark as concerned supervisory authorities, IMY as lead authority issued an administrative fine of SEK 7.5 million against Klarna Bank AB.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB / IMY",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2022/swedish-authority-privacy-protection-imy-issues-administrative-fine-against_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"3-1\">On June 10, 2026, IMY published a report clarifying the roles and responsibilities of companies under the GDPR when developing and fine-tuning AI applications.</cite>",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/sweden-imy-publishes-report-gdpr-responsibility-roles",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"1-1,1-2\">IMY's guidance and supervision priorities for 2026 are crime prevention, children and young people, and AI in the public sector.</cite>",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IMY",
     "source_url": "https://www.imy.se/en/",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}