Traffic-light rationale — GreenComprehensive omnibus regime in force with an active, well-resourced supervisory authority and clear statutory architecture.
Sub-modules (5)
Regulator And AuthorityGreen
IMY is Sweden's data protection authority responsible for GDPR compliance oversight.
Claims: CLM-SE-a1b2c3d4
Act And InstrumentsGreen
SFS 2018:218 supplements the GDPR at national level; sectoral instruments (Criminal Data Act, Camera Surveillance Act, Credit Information Act) sit alongside it.
Claims: CLM-SE-b2c3d4e5, CLM-SE-c3d4e5f6
Material ScopeGreen
Material scope follows GDPR Art 2/4 definitions as applied by IMY guidance for organisations and individuals.
Territorial ScopeGreen
GDPR Art 3 territorial scope applies directly in Sweden as an EU Member State; no SE-specific derogation identified in this research pass.
Absence provenance: not recorded. Searched: IMY territorial scope guidance, GDPR Art 3 Sweden.
Regulator Registration And FilingAmber
No general controller registration regime exists, but sector permits/notifications apply: credit information activity requires an IMY licence, and DPO appointments must be notified to IMY under Art 37.
Claims: CLM-SE-d4e5f6a7, CLM-SE-e5f6a7b8
Category narrative55 words
Sweden is an EU Member State and applies the GDPR directly, supplemented nationally by the Act with Supplementary Provisions to the GDPR (SFS 2018:218). The Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) is the competent supervisory authority under GDPR Art 51, and also supervises sector-specific instruments (Criminal Data Act, Camera Surveillance Act, Credit Information Act).
Sources and claims (5)
ConfirmedIMY — <cite index="2-19,2-20">IMY is Sweden's data protection authority whose mission is to work to ensure that individuals' fundamental rights and freedoms are protected in connection with the processing of personal data.</cite>
ConfirmedGovernment of Sweden / hosted via DataGuidance — <cite index="21-1,21-2">The Act with Supplementary Provisions to the EU General Data Protection Regulation (SFS 2018:218) supplements Regulation (EU) 2016/679 within Sweden.</cite>
ConfirmedIMY — <cite index="31-1">IMY supervises that the provisions in the Criminal Data Act and the Camera Surveillance Act are complied with</cite>, in addition to GDPR compliance.
ConfirmedIMY — <cite index="38-1">IMY is the supervisory authority for the Credit Information Act and issues licences for those who wish to conduct credit information activity.</cite>
ConfirmedIMY — <cite index="4-18">IMY handles personal data concerning appointed data protection officers to be able to administrate notifications of data protection officers received in accordance with Article 37 of the GDPR.</cite>
Traffic-light rationale — GreenCore lawful-basis and special-category framework is GDPR-aligned with active national derogations exercised and enforced.
Sub-modules (4)
Lawful BasesGreen
GDPR Art 6 bases (consent, contract, legal obligation, vital interest, public task, legitimate interest) apply directly; SFS 2018:218 provides public-interest grounds for authorities.
IMY treats purchase data for certain non-prescription health/wellness products as revealing Art 9 sensitive data where linked to third-party ad transfers.
Claims: CLM-SE-b8c9d0e1
Pseudonymisation And AnonymisationAmber
No SE-specific statutory safe-harbour beyond GDPR Recitals 26/28-29 identified in this pass.
Absence provenance: not recorded. Searched: IMY pseudonymisation guidance, Sweden anonymisation safe harbour.
Category narrative55 words
GDPR Art 6 lawful bases and Art 9 special-category rules apply directly, supplemented by SFS 2018:218 grounds for public-interest processing. Sweden exercised the Art 8 Member State derogation to set the digital age of consent at 13. IMY enforcement (e.g., the Apohem decision) shows an expansive reading of what constitutes health/sex-life data under Art 9.
Sources and claims (4)
ConfirmedIMY — <cite index="6-3,6-5">Organisations processing personal data in Sweden must comply with the GDPR and must have a lawful ground in order to process personal data.</cite>
ConfirmedIMY — <cite index="41-40,41-41">For consent to be valid it must be provided voluntarily, meaning the data subject has a genuinely free choice and control over their personal data</cite>, and must be as easy to withdraw as to give.
ConfirmedDataGuidance — In the Apohem decision, IMY found that <cite index="52-2,52-4">personal data affected by unlawful Meta Pixel transfers included names, social security numbers, email addresses, IP addresses, and phone numbers, and that both companies violated Article 32(1) of the GDPR</cite> in a context IMY treated as involving sensitive health/sex-life-adjacent purchase data.
ConfirmedGovernment of Sweden / hosted via DataGuidance — <cite index="43-1">When information society services are offered directly to a child living in Sweden, the child's personal data may be processed with the child's consent if the child is at least 13 years old.</cite>
Traffic-light rationale — GreenFull GDPR rights suite in force with demonstrated enforcement of the objection-to-erasure pathway.
Sub-modules (5)
Access RightGreen
Data subjects may request confirmation of processing and a free copy of their data plus contextual information.
Claims: CLM-SE-e1f2a3b4
Rectification And ErasureGreen
Erasure available where data is no longer needed, consent withdrawn, unlawfully processed, or (for minors) collected via a childhood social-media profile.
Claims: CLM-SE-f2a3b4c5, CLM-SE-c5d6e7f8
Restriction And ObjectionAmber
Objection to direct marketing triggers mandatory erasure; IMY has fined a company for obstructing exercise of this right.
Claims: CLM-SE-a3b4c5d6, CLM-SE-b4c5d6e7
Data PortabilityGreen
Portability right applies per GDPR Art 20; no SE-specific derogation identified.
Absence provenance: not recorded. Searched: IMY data portability guidance Sweden.
Deadlines And Response WindowsAmber
GDPR's one-month standard response window applies; no SE-specific shortening/extension found in this pass.
GDPR Arts 12-22 rights apply directly, with IMY publishing consumer-facing guidance on access, rectification, erasure and objection. Enforcement activity (H&M direct-marketing case) shows IMY actively polices the objection/erasure interface.
Sources and claims (5)
ConfirmedIMY — <cite index="9-20,9-21">The right of access means individuals can contact companies, authorities or other organisations to find out whether they are processing their personal data and, if so, receive a copy of it and information about how it is used.</cite>
ConfirmedIMY — <cite index="9-11,9-12">Data subjects have the right to contact a company or authority processing their personal data and request erasure where, among other grounds, the data is no longer needed for the purposes for which it was collected.</cite>
ConfirmedIMY — <cite index="9-14">Erasure must occur if the processing is carried out for direct marketing and the data subject objects to the data being processed.</cite>
ConfirmedEDPB / IMY — IMY reviewed complaints and found that <cite index="17-1,17-2">a company did not have sufficient systems and routines to make it easier for those who complained to exercise their right to object to direct marketing, issuing a fine of SEK 350,000</cite>.
ConfirmedIMY — <cite index="9-18">Erasure is required if the personal data is about a child and was collected when the child created a profile on a social media platform.</cite>
Framework is comprehensive and enforced robustly, but repeated large fines (SEK 6m, 37m, 8m) indicate ongoing systemic security-measure compliance gaps among controllers.
Primary frameworkGDPR Arts 5, 24-43; SFS 2018:218 Ch.1 §8
Traffic-light rationale — AmberFramework is comprehensive and enforced robustly, but repeated large fines (SEK 6m, 37m, 8m) indicate ongoing systemic security-measure compliance gaps among controllers.
Sub-modules (7)
Accountability And DpiaGreen
DPIA required for high-risk processing per GDPR Art 35 and EDPB-derived IMY criteria (e.g., large-scale sensitive data or systematic large-scale public surveillance).
Claims: CLM-SE-d6e7f8a9
Dpo RequirementsGreen
DPO appointment thresholds follow GDPR Art 37, supplemented by SFS 2018:218 Ch.1 §8.
Claims: CLM-SE-e7f8a9b0
Ropa RequirementsGreen
ROPA obligations follow GDPR Art 30 directly; no SE-specific derogation identified.
Absence provenance: not recorded. Searched: IMY records of processing guidance.
Joint Controller ArrangementsAmber
The Apohem Meta Pixel decision treated the retailer and Meta as separately data-controller-responsible parties for different aspects of the pixel processing.
Claims: CLM-SE-b0c1d2e3
Security MeasuresRed
Art 32 security-of-processing is IMY's most heavily enforced provision, with multi-million SEK fines for inadequate technical/organisational measures.
Claims: CLM-SE-f8a9b0c1, CLM-SE-b0c1d2e3
Breach NotificationAmber
Controllers must notify IMY of qualifying personal data breaches; failures compound Art 32 penalties.
Claims: CLM-SE-a9b0c1d2
Retention And DisposalAmber
Retention periods (e.g., for camera surveillance) must be specifically justified and regularly reassessed.
Claims: CLM-SE-c1d2e3f4
Category narrative43 words
GDPR Arts 5, 24-43 apply directly with SFS 2018:218 Chapter 1 Section 8 supplementing Art 37-39 DPO rules. Enforcement history (Sportadmin, Apoteket/Apohem) shows IMY treats Art 32 security-of-processing failures as a top fining priority, including large-scale breach exposure of children's and health-adjacent data.
Sources and claims (6)
ConfirmedIMY — <cite index="41-19,41-21">GDPR requires an impact assessment for processing on a large scale of sensitive personal data and for systematic surveillance of a public space on a large scale</cite>, per criteria IMY has published drawing on EDPB guidance.
ConfirmedDataGuidance — <cite index="29-3">Chapter 1, Section 8 of the Act with Supplementary Provisions to the GDPR (SFS 2018:218) supplements Articles 37-39 of the GDPR on DPO appointment.</cite>
ConfirmedIMY — IMY supervised Sportadmin after a leak affecting over 2 million individuals and found <cite index="11-7,11-8">the review shows that Sportadmin did not have an appropriate level of security to protect the personal data the company processed, and IMY therefore decided to impose an administrative fine of SEK 6 million</cite>.
ConfirmedIMY — <cite index="6-9">Data controllers are obligated to report certain personal data breaches to IMY.</cite>
ConfirmedIMY — <cite index="51-3,51-4">IMY imposed administrative fines of SEK 37 million on Apoteket AB and SEK 8 million on Apohem AB after the companies used the Meta Pixel on their websites and transferred sensitive personal data to Meta.</cite>
ConfirmedIMY — <cite index="34-1,34-33">Where a controller has an actual need of a longer camera-surveillance storage time it must provide a specific motivation, and the need for surveillance must be regularly reassessed.</cite>
Traffic-light rationale — AmberFramework is GDPR-standard, but enforcement record shows repeated transfer-related transparency and security failures involving US ad-tech processors.
Sub-modules (6)
Transfer MechanismsAmber
SCCs, adequacy, and derogations under GDPR Ch.V apply directly; IMY applies these when assessing third-country transfer notices.
Claims: CLM-SE-d2e3f4a5, CLM-SE-f4a5b6c7
Adequacy ReceivedGreen
As an EU Member State, adequacy findings are made centrally by the European Commission; no Sweden-specific inbound adequacy determination applies.
Absence provenance: not recorded. Searched: Sweden adequacy decision received.
Adequacy GrantedGreen
Adequacy decisions granted to third countries are made by the European Commission for all Member States collectively, not by Sweden individually.
Absence provenance: not recorded. Searched: Sweden adequacy decision granted.
Sccs And BcrsAmber
SCCs/BCRs available per GDPR Art 46; IMY's Klarna decision criticised incomplete transfer-safeguard information provided to data subjects.
Claims: CLM-SE-e3f4a5b6
Transfer Impact AssessmentAmber
TIA obligations follow GDPR/Schrems II standards as applied EU-wide; no SE-specific TIA template identified in this pass.
Absence provenance: not recorded. Searched: IMY transfer impact assessment guidance.
Data LocalisationGreen
No general data-localisation mandate identified for Sweden beyond sector-specific security/confidentiality rules (e.g., law-enforcement data under the Criminal Data Act).
Absence provenance: not recorded. Searched: Sweden data localisation requirement.
Category narrative63 words
GDPR Chapter V transfer rules apply directly in Sweden; IMY enforcement (Klarna) has penalised failure to inform data subjects about third-country transfers and safeguards, and the Apoteket/Apohem cases involved unintended data flows to a US-based processor (Meta). Adequacy decisions themselves are an EU Commission competence rather than a Swedish national one; this research pass did not identify any Sweden-specific adequacy or localisation derogation.
Sources and claims (3)
ConfirmedIMY — <cite index="6-11">When personal data is sent outside the EU/EEA, the rules for transfer to third countries apply under the GDPR as applied in Sweden.</cite>
ConfirmedEDPB / IMY — In the Klarna decision, IMY found the company <cite index="16-18">did not provide information on to which countries outside the EU/EEA personal data were transferred or on where and how individuals could obtain information on the safeguards that applied to the transfer to third countries</cite>, contributing to a SEK 7.5 million fine.
ConfirmedIMY — The Apoteket/Apohem cases arose because <cite index="51-6,51-8">the companies used Meta's analytics tool, Meta Pixel, on their websites, and by activating a new sub-feature transferred sensitive personal data to Meta concerning a large number of customers</cite>, a US-headquartered processor/joint controller.
Traffic-light rationale — AmberMultiple active sectoral overlays with demonstrated enforcement gaps, particularly in financial transparency and health-data security.
Sub-modules (7)
Financial Sector OverlayAmber
Credit information activity requires an IMY licence; Klarna Bank was fined for GDPR transparency violations concerning credit-information sharing.
Claims: CLM-SE-a5b6c7d8, CLM-SE-b6c7d8e9
Health Sector OverlayRed
Regional healthcare bodies have been fined/criticised for inadequate security of health data in physical mail and email.
Claims: CLM-SE-c7d8e9f0
Telecoms And EprivacyAmber
LEK (Electronic Communications Act) Ch.9 §28, implementing ePrivacy Directive Art 5(3), governs cookie/tracker storage and access consent, enforced alongside GDPR in the Meta Pixel cases.
Claims: CLM-SE-d8e9f0a1
Employment DataAmber
SFS 2018:218 supplements GDPR grounds for employment-context processing; IMY has fined employers for unlawful processing of employee sobriety-test data.
Claims: CLM-SE-e9f0a1b2, CLM-SE-f0a1b2c3
Credit And ScoringAmber
Credit-scoring/information activity is licensed and supervised by IMY under the Credit Information Act, requiring good business practice.
Claims: CLM-SE-a5b6c7d8
EducationAmber
No education-sector-specific statutory overlay identified beyond general GDPR application in this research pass.
Absence provenance: not recorded. Searched: IMY education sector data protection guidance.
InsuranceAmber
No insurance-sector-specific statutory overlay identified beyond general GDPR application in this research pass.
Absence provenance: not recorded. Searched: IMY insurance sector data protection guidance.
Category narrative45 words
IMY overlays sector-specific supervision on top of GDPR for credit information (Credit Information Act), law enforcement (Criminal Data Act), telecoms/ePrivacy (Electronic Communications Act, LEK), and employment. Enforcement spans financial services (Klarna), health (Region Dalarna/Uppsala), telecoms-adjacent cookie tracking (LEK Ch.9 §28), and employment (SL/WÅAB sobriety-test data).
Sources and claims (6)
ConfirmedIMY — <cite index="31-2">IMY monitors that those who carry out credit information activity follow good business practice</cite> and issues permits for such activity.
ConfirmedEDPB / IMY — <cite index="16-3,16-4">Klarna, a financial company processing personal data about many people in many ways, was found to have violated Articles 5(1)(a), 5.2, 12.1, 13.1 and 14.2(g) GDPR for failing to fulfil the transparency principle and data subjects' right to information</cite>, resulting in a SEK 7.5 million fine.
ConfirmedIMY — <cite index="59-1,59-2">IMY found that Region Dalarna had not taken sufficient security measures to protect sensitive personal data against unauthorized disclosure in connection with sending physical invitations to healthcare visits, issuing an administrative sanction of SEK 200,000</cite>.
ConfirmedIMY — Under <cite index="55-24">Chapter 9, Section 28 of the Electronic Communications Act (LEK), which implements Article 5.3 of the ePrivacy Directive, data may be stored in or retrieved from a subscriber's or user's terminal equipment only if the subscriber or user has access to information about the purpose of the processing and consents to it</cite>.
ConfirmedDataGuidance — <cite index="25-4">The Act with Supplementary Provisions to the GDPR (SFS 2018:218) supplements the GDPR and outlines grounds for processing of personal data left to Member States' discretion</cite>, including employment-context processing.
ConfirmedIMY — <cite index="14-12,14-13">IMY fined Aktiebolaget Storstockholms Lokaltrafik (SL) and Waxholms Ångfartygs AB (WÅAB) SEK 75,000 each for processing personal data relating to sobriety tests conducted by employees in breach of the GDPR.</cite>
Repeated, large enforcement actions (Google Analytics, Meta Pixel across two retailers) indicate systemic non-compliance in the adtech/commercial tracking space.
Primary frameworkGDPR plus Electronic Communications Act (LEK) Ch.9 §28
Traffic-light rationale — RedRepeated, large enforcement actions (Google Analytics, Meta Pixel across two retailers) indicate systemic non-compliance in the adtech/commercial tracking space.
Sub-modules (6)
Cookies And TrackersRed
LEK Ch.9 §28 requires consent for storage/access to terminal-equipment data (cookies); enforced jointly with GDPR Art 32 in the Meta Pixel cases.
Claims: CLM-SE-a1b2c3e4, CLM-SE-c3e4f5a6
Dark PatternsAmber
No SE-specific dark-pattern statute or IMY decision identified beyond general GDPR transparency/fairness principles in this pass.
Absence provenance: not recorded. Searched: IMY dark patterns enforcement.
Opt Out SignalsAmber
No SE-specific recognition of Global Privacy Control or equivalent browser-level opt-out signal identified in this pass.
Absence provenance: not recorded. Searched: IMY Global Privacy Control recognition.
Clean Rooms And DcrAmber
No SE-specific clean-room/data-collaboration-room regime identified; GDPR joint-controller and processor rules apply generally.
Absence provenance: not recorded. Searched: IMY data clean room guidance.
Cross Context AdvertisingRed
IMY's Google Analytics and Meta Pixel enforcement actions function as de facto cross-context-advertising audits under GDPR Arts 5/32.
Claims: CLM-SE-b2c3e4f5, CLM-SE-c3e4f5a6
Direct MarketingAmber
Objection to direct marketing must be honoured and leads to erasure; H&M was fined for failing to operationalise this.
Claims: CLM-SE-d4f5a6b7
Category narrative40 words
Cookie/tracker consent is governed by LEK Ch.9 §28 (ePrivacy transposition) alongside GDPR. IMY has run structured audits of adtech tools (Google Analytics, Meta Pixel) resulting in multiple large fines and cease-processing orders, and has enforced direct-marketing opt-out rights against H&M.
Sources and claims (4)
ConfirmedIMY — Cookie and tracker storage/retrieval is governed by <cite index="55-24">Chapter 9, Section 28 LEK, which permits storage in or retrieval from terminal equipment only where the subscriber or user has access to information about the purpose and consents to it</cite>.
ConfirmedIMY — <cite index="14-27,14-28">IMY audited how four companies use Google Analytics for web statistics and issued administrative fines against two of them</cite> as part of a cross-context-advertising/tracker enforcement sweep.
ConfirmedIMY — <cite index="12-1">IMY found that Sportadmin's counterpart cases and the Apoteket/Apohem investigations established that companies violated Article 32 of the GDPR through inadequate control of ad-tech pixel data flows</cite>, resulting in fines of SEK 37 million and SEK 8 million respectively.
ConfirmedEDPB / IMY — <cite index="17-1,17-2">IMY fined a company SEK 350,000 for not having sufficient systems and routines in place to make it easier for those who complained to exercise their right to object to direct marketing.</cite>
Traffic-light rationale — AmberBinding biometric/surveillance rules exist (Camera Surveillance Act, Criminal Data Act) but AI-specific governance remains largely soft-law/guidance stage pending fuller EU AI Act interface.
Sub-modules (6)
Profiling RestrictionsGreen
Profiling must comply with GDPR rules generally, per IMY guidance.
Claims: CLM-SE-e5a6b7c8
Automated Decision Making TransparencyAmber
ADM transparency follows GDPR Art 13-15/22 directly; no SE-specific ADM statute identified beyond general GDPR application.
Absence provenance: not recorded. Searched: IMY automated decision-making transparency guidance.
Ai Risk AssessmentsAmber
IMY published a June 2026 report clarifying controller/processor roles for AI developers, and issued (with Digg) non-binding generative-AI guidelines for public administration in January 2025.
Claims: CLM-SE-f6b7c8d9, CLM-SE-c9e0f1a2
Biometric RegimeAmber
The Camera Surveillance Act covers optical-electronic instruments including LiDAR sensors capable of identifying individuals by body movement, constitution and clothing.
Claims: CLM-SE-a7c8d9e0
Genetic DataAmber
No SE-specific genetic-data statute identified beyond GDPR Art 9 special-category treatment in this pass.
Absence provenance: not recorded. Searched: Sweden genetic data regime IMY.
State Surveillance CarveoutsAmber
The Criminal Data Act creates a distinct regime for law-enforcement authorities' processing, with the Security Service subject to its own separate legislation outside the Criminal Data Act.
Claims: CLM-SE-b8d9e0f1
Category narrative70 words
Profiling is governed via GDPR as applied by IMY. IMY's 2026 priorities and June 2026 report on AI controller/processor roles reflect active (but largely non-binding, guidance-stage) engagement with AI governance. The Camera Surveillance Act extends biometric-adjacent coverage to optical-electronic sensors (including LiDAR) capable of identifying individuals via body movement or gait. Law-enforcement processing sits under the separate Criminal Data Act, with the Security Service subject to its own bespoke legislation.
Sources and claims (5)
ConfirmedIMY — <cite index="9-19">Profiling is a type of personal data processing and therefore must follow the rules in the GDPR.</cite>
ConfirmedDataGuidance — <cite index="3-1,3-2">In June 2026, IMY published a report clarifying the roles and responsibilities of companies under the GDPR when developing and fine-tuning AI applications, distinguishing between controllers and processors based on data processing activities.</cite>
ConfirmedIMY — <cite index="7-6,7-7">IMY found that LiDAR sensors are typically covered by the term "other optical-electronic instruments" under the Swedish Camera Surveillance Act, and it is highly probable that individuals can be distinguished and identified based on body movements, body constitution, and clothing in LiDAR output.</cite>
ConfirmedIMY — <cite index="36-3,36-12">The Criminal Data Act applies to personal data processing within law enforcement activities at authorities including the Swedish Police Authority, Customs, Tax Agency and Prosecution Authority, while the Swedish Security Service is not subject to the Criminal Data Act but has special legislation of its own.</cite>
ConfirmedIMY — <cite index="1-10">In January 2025, the Swedish Agency for Digital Government (Digg) together with IMY launched guidelines to encourage the use of generative AI in public administration.</cite>
Clear statutory age-of-consent rule exists and is actively supervised, but a major 2026 breach affecting children's data shows continuing real-world exposure risk.
Primary frameworkGDPR Art 8, as implemented by SFS 2018:218
Traffic-light rationale — AmberClear statutory age-of-consent rule exists and is actively supervised, but a major 2026 breach affecting children's data shows continuing real-world exposure risk.
Sub-modules (5)
Age VerificationAmber
No SE-specific mandatory age-verification technology standard identified beyond general "reasonable efforts" language under GDPR Art 8(2).
Absence provenance: not recorded. Searched: Sweden age verification mandate children.
Parental ConsentGreen
Below age 13, information-society-service processing requires consent of the holder of parental responsibility.
Claims: CLM-SE-e1a2b3c4
Minor Profiling BansAmber
No blanket statutory ban on profiling of minors identified beyond general GDPR fairness/transparency principles and IMY's children's-rights guidance emphasising age/maturity-appropriate treatment.
Absence provenance: not recorded. Searched: Sweden minor profiling ban IMY.
Education SettingsAmber
No education-setting-specific children's data statute identified in this pass beyond general GDPR/children's-rights guidance.
Absence provenance: not recorded. Searched: IMY education settings children data protection.
Dependent AdultsAmber
No SE-specific dependent-adult/incapacitated-persons data protection statute identified in this pass.
Absence provenance: not recorded. Searched: Sweden dependent adults data protection IMY.
Category narrative59 words
Sweden exercised the GDPR Art 8 Member State option to set the digital age of consent at 13, with parental/guardian consent required below that age. Children and young people are a named 2026 IMY supervisory priority, reinforced by enforcement after the Sportadmin breach exposed sensitive data (including health data) of over 2 million individuals, largely children in sports clubs.
Sources and claims (4)
ConfirmedIMY — <cite index="41-2,41-4">Every EU Member State has had the opportunity to lower the age indicated in GDPR Article 8, and Sweden has decided that children over the age of 13 years can give consent to processing for information society services.</cite>
ConfirmedGovernment of Sweden / hosted via DataGuidance — <cite index="43-1,43-2">If a child is under 13 years old, their personal data may only be processed with the consent of the holder of parental responsibility, per the Act with Supplementary Provisions to the GDPR.</cite>
ConfirmedIMY — <cite index="12-9,12-11">The Sportadmin breach, initiated following a January 2025 cyber attack, exposed data on more than 2.1 million individuals, mainly concerning children and young people, including names, contact details, personal identity numbers, and sport/club affiliations.</cite>
ConfirmedIMY — <cite index="1-1,1-2">IMY is focusing on three areas in its guidance and supervision during 2026: crime prevention, children and young people, and AI in the public sector.</cite>
Traffic-light rationale — AmberStrong, well-documented enforcement powers and activity, but no confirmed Swedish-specific collective-redress/class-action mechanism was located.
Sub-modules (6)
Regulator Powers And PenaltiesAmber
IMY may issue warnings, reprimands, processing-cessation orders and administrative fines; public-authority fines are capped at SEK 5m (less serious) / SEK 10m (serious).
Claims: CLM-SE-c5e6f7a8
Enforcement Activity IndexRed
Recent high-value fines include Sportadmin (SEK 6m, Jan 2026), Apoteket/Apohem (SEK 37m/8m), Spotify (SEK 58m), Trygg-Hansa (SEK 35m) and Klarna (SEK 7.5m, cross-border OSS).
No specific IMY budget/headcount figures were identified in this research pass.
Absence provenance: not recorded. Searched: IMY budget headcount capacity 2026.
Collective Redress And Class ActionsRed
No Sweden-specific collective-redress or class-action mechanism for data protection claims was identified in this research pass.
Absence provenance: not recorded. Searched: Sweden data protection collective redress class action GDPR Art 80.
Private Right Of ActionAmber
No Sweden-specific private-right-of-action provision beyond the general GDPR Art 79/82 judicial-remedy and compensation rights was identified in this pass.
Absence provenance: not recorded. Searched: Sweden private right of action GDPR damages.
Recent Developments 180DAmber
Within the last 180 days: IMY's June 2026 AI-roles report, 2026 supervisory priorities (crime prevention, children, AI in public sector), and the January 2026 Sportadmin fine.
IMY can issue warnings, reprimands, cease-processing orders and administrative fines, with a public-authority-specific cap (SEK 5m/10m). Its decisions are appealable. 2025-2026 enforcement activity has been intense and high-value (Sportadmin SEK 6m, Apoteket/Apohem SEK 45m combined, historically Spotify SEK 58m and Trygg-Hansa SEK 35m), and it participates actively in cross-border One-Stop-Shop cooperation (Klarna). Collective redress and private-right-of-action mechanisms specific to Sweden were not identified in this research pass.
Sources and claims (9)
ConfirmedIMY — <cite index="13-1,13-2">In Sweden, authorities must also be able to be fined: for less serious infringements the fine amounts to a maximum of SEK 5 million and for serious infringements a maximum of SEK 10 million.</cite> <cite index="13-5,13-6">IMY can also issue warnings for planned processing likely to contravene the GDPR, issue reprimands for ongoing contraventions, and order cessation of processing.</cite>
ConfirmedIMY — <cite index="13-7">IMY's decisions can be appealed.</cite>
ConfirmedIMY — <cite index="11-7,11-8">IMY imposed an administrative fine of SEK 6 million against Sportadmin after finding it did not have an appropriate level of security to protect the personal data it processed.</cite>
ConfirmedIMY — <cite index="51-1">IMY decided to impose administrative fines of SEK 37 million on Apoteket AB and SEK 8 million on Apohem AB for improper Meta Pixel data transfers.</cite>
ConfirmedIMY — <cite index="54-11,54-12">IMY audited how Spotify handles customers' right to access their personal data, and the deficiencies discovered caused IMY to issue an administrative fine of SEK 58 million against the company.</cite>
ConfirmedIMY — <cite index="14-24,14-25">Trygg-Hansa's security flaws meant information about 650,000 customers was accessible to unauthorized persons via the internet, leading IMY to issue an administrative fine of SEK 35 million against the company.</cite>
ConfirmedEDPB / IMY — <cite index="16-11,16-12">In a One-Stop-Shop procedure involving Germany, Austria, Italy, Netherlands, Norway, Finland and Denmark as concerned supervisory authorities, IMY as lead authority issued an administrative fine of SEK 7.5 million against Klarna Bank AB.</cite>
ConfirmedDataGuidance — <cite index="3-1">On June 10, 2026, IMY published a report clarifying the roles and responsibilities of companies under the GDPR when developing and fine-tuning AI applications.</cite>
ConfirmedIMY — <cite index="1-1,1-2">IMY's guidance and supervision priorities for 2026 are crime prevention, children and young people, and AI in the public sector.</cite>
No categories match.
Filters combine as OR inside a group and AND across
groups.
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for Sweden
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
not recorded
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 51 claim(s), 23 source(s) in the cumulative register.