Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Biometric privacy
cite Regulation (EU) 2016/679, Art. 9; Dataskyddslagen, ch. 3; IMY decision Di-2019-2221
stage In effect
since 2018-05-25
source Dataskyddslagen ch. 3 (direct read)
General Data Protection Regulation (GDPR) Article 9 special categories apply directly; Dataskyddslagen Chapter 3 supplies domestic legal bases letting a public authority process sensitive data for employment-law or important-public-interest purposes, confirmed by reading the chapter directly, with no biometric-specific definition or carve-out.
IMY's landmark biometric decision, Di-2019-2221 (20 August 2019, verified from IMY's own decision list), fined the Skelleftea municipal school board 200,000 SEK for using facial-recognition cameras to register student attendance, finding the processing violated Article 9 (no valid legal basis) and Article 5 (data minimization).
IMY's current guidance cites this decision for the rule that biometric attendance tracking is, as a rule, not permitted, and that employer consent is generally not a valid basis given the power imbalance in an employment relationship. No dedicated IMY guidance or enforcement on voiceprints specifically was found in the pages checked.
What it asks of an app →
Breach notification
cite Regulation (EU) 2016/679, Arts. 33-34
stage In effect
since 2018-05-25
source GDPR Arts. 33-34
A controller must notify IMY within 72 hours of becoming aware of a personal-data breach, and notify the affected individual without undue delay where the breach is likely to result in a high risk. No Sweden-specific derogation from this timeline or threshold was found in Dataskyddslagen.
What it asks of an app →
Comprehensive regime
cite Dataskyddslagen, SFS 2018:218
stage In effect
since 2018-05-25
source riksdagen.se, Dataskyddslagen SFS 2018:218 (direct read)
Sweden gives the General Data Protection Regulation (GDPR) domestic effect through Dataskyddslagen (SFS 2018:218), enacted 19 April 2018 and in force 25 May 2018. Confirmed by reading its seven chapters directly: the Act is genuinely light touch, filling only the gaps GDPR leaves open (member-state legal bases for public-authority processing, a reduced fine scale for public authorities, appeal routes) and adding no separate biometric-specific chapter or general criminal-penalties chapter.
Sweden separately has a distinct Kamerabevakningslagen (SFS 2018:1200, Camera Surveillance Act) regulating any camera or optical-electronic monitoring equipment through an impact-assessment and registry duty rather than data-category rules.
What it asks of an app →
cite Kamerabevakningslag, SFS 2018:1200
stage In effect
since 2018-08-01
source riksdagen.se, Kamerabevakningslag SFS 2018:1200 (direct read)
Kamerabevakningslagen (SFS 2018:1200), enacted 20 June 2018 and in force 1 August 2018, regulates any TV camera or optical-electronic equipment enabling persistent or regularly repeated monitoring of persons in Sweden, regardless of where the operator is based, confirmed against the statute text. As of 1 April 2025 it eliminated the earlier permit regime in favor of a documented impact assessment, a registry of ongoing surveillance, and a signage duty.
The Act does not itself define or specifically regulate facial recognition or biometric identification; a facial-recognition-capable camera falls within its scope only as surveillance equipment generally, with the biometric-processing duty supplied separately by General Data Protection Regulation (GDPR) Article 9 and Dataskyddslagen Chapter 3.
This is a distinct instrument from the general comprehensive regime and does not cleanly fit any other registered family; it is filed here as the closest match to a self-contained mini-regime for one collection channel.
What it asks of an app →
Cross border transfer
cite Regulation (EU) 2016/679, Arts. 44-49, 83(5)
stage In effect
since 2018-05-25
source GDPR Arts. 44-49, 83(5)
A transfer of personal data outside the EEA requires an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5) top fine tier. Dataskyddslagen's seven chapters, confirmed against the statute text, contain no separate chapter addressing cross-border transfer, so Chapter V governs unmodified with no Sweden-specific derogation identified.
What it asks of an app →
Data subject rights
cite Dataskyddslagen, ch. 7
stage In effect
since 2018-05-25
source riksdagen.se, Dataskyddslagen ch. 7 (direct read)
General Data Protection Regulation (GDPR) Articles 12-23 apply directly: access, rectification, erasure, restriction, portability, objection, and Article 22 automated-decision rights.
Dataskyddslagen Chapter 7, read directly, adds a domestic procedural layer: a controller's own decision on a rights request may be appealed directly to the general administrative courts (Sec. 2), separately from complaining to IMY, and IMY's own decisions are likewise appealable with IMY as the opposing party (Sec. 3), requiring permission for further appeal to kammarratten.
What it asks of an app →
Enforcement supervision
cite Regulation (EU) 2016/679, Arts. 82-83; Dataskyddslagen, ch. 6-7; Lag (2002:599) om grupprattegang
stage In effect
since 2018-05-25
source Dataskyddslagen ch. 6-7 (direct read)
Integritetsskyddsmyndigheten (IMY) is Sweden's supervisory authority. Dataskyddslagen Chapter 6 caps administrative fines against public authorities below General Data Protection Regulation (GDPR)'s own ceiling (SEK 5,000,000 for Article 83.4 violations, SEK 10,000,000 for Article 83.5-83.6), confirmed by reading the chapter directly, and the Act contains no separate criminal-penalties chapter at all.
GDPR Article 82 arms an individual with a direct private right of action, restated for the Swedish Act's own violations by Dataskyddslagen Chapter 7 Section 1.
Sweden separately has a general civil group-litigation mechanism, Lag (2002:599) om grupprattegang, permitting private, organizational, and public group actions; its scope provision covers any claim that could be brought before a general court under civil-dispute rules, with no data-protection-specific text confirming actual use for a GDPR claim.
What it asks of an app →