Sweden
Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Sweden — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Sweden has no general law forcing data to stay in the country. Personal data leaves under the ordinary European rules. But four rules override that. Gambling systems must sit in Sweden. Telecoms records kept for the police may never leave the European Union. Classified material needs a state-to-state deal. And accounting books stay in Sweden unless you tell the tax agency.
Data governance in Sweden
The eight things that decide how you handle data about people in Sweden. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. Sweden applies the European privacy rules. A company anywhere in the world is caught if it offers goods or services to people in Sweden, or watches what they do. There is no size or revenue floor to duck under. Sweden's own top-up law adds Swedish-only duties on top. Those apply to anyone handling data under Swedish law, not just Swedish companies. If you are outside Europe and caught, you normally have to name a representative inside Europe.
- What you have to do here:
- Appoint a representative
Sweden's national top-up law is Lag (2018:218), which sits alongside the European privacy rules. It has been in force since 25 May 2018. It does not narrow who the European General Data Protection Regulation reaches. It adds Swedish-only rules on top. Two stand out. Chapter 2 section 4 covers the age at which a child can consent. Chapter 3 section 10 covers Swedish personal identity numbers. Industry laws such as the Gambling Act and the Protective Security Act have their own separate reach. The Gambling Act binds anyone who holds or needs a Swedish licence, wherever the company is registered.
Sources
- Official sourceSveriges riksdag — Svensk författningssamlingLag (2018:218) med kompletterande bestämmelser till EU:s dataskyddsförordning (Swedish Data Protection Act)
data.riksdagen.se
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation), Articles 3 and 27
eur-lex.europa.eu
Link checked 18 August 2026
Where the data is allowed to live
In general, yes. No Swedish law says personal data must physically stay in Sweden. European law even bans Sweden from making non-personal data stay here, except for national security reasons. The exceptions are what matter. Online gambling systems must be placed in Sweden. Telephone and internet records that operators keep for the police may not be stored outside the European Union. Security-classified material cannot go to a foreign body without a government-to-government agreement. And a Swedish company's accounting records must be kept in Sweden, unless it tells the tax agency where they are instead.
Industry by industry, all checked 18 August 2026: - Online gambling: data must stay in the country Gambling Act chapter 16 section 2 says the licence holder's gaming system must be placed in Sweden. Two ways out exist. Hold a licence in another supervised country whose regulator has an agreement with the Swedish Gambling Authority. Or give the Swedish Gambling Authority remote access to the system. - Telecoms records kept for law enforcement: data must stay in the country at European Union level. Ordinance (2022:511) chapter 9 section 4, third paragraph, says the data may not be stored outside the European Union. Storage anywhere inside the European Union is fine. Storage in the United States or the United Kingdom is not. - Security-sensitive activity and classified information: data must stay in the country Protective Security Ordinance (2021:955) chapter 3 section 9 requires an international protective security undertaking before classified information goes to a foreign authority or an international organisation. Chapter 3 section 2 requires written consultation with the Swedish Security Service before you deploy any system handling material classified confidential or above. - Accounting records: data can leave only if conditions are met, with Sweden as the default. Bookkeeping Act chapter 7 section 2 says the records must be kept in Sweden. Chapter 7 section 3a allows electronic storage in another European Union country. You must tell the Swedish Tax Agency, give it immediate online access, and be able to print the records in Sweden. Outside the European Union you need a mutual assistance arrangement, or the Tax Agency's specific permission under chapter 7 section 4. - Mapping, aerial imagery and sea-depth data: data can leave only if conditions are met Act (2016:319) bans spreading a compilation of geographic information about Swedish waters, or gathered from aircraft, without a permit. Breaking that ban is a crime. - Public sector: data can leave only if conditions are met There is no law about where the data must sit. Secrecy law is what stops you instead. See Q7. - Health, banking, payments, insurance, securities, telecom subscriber data and education: we found no rule about where data must be stored, checked 18 August 2026. Swedish patient records law sets a ten-year minimum for keeping records but says nothing about where they sit.
Sources
- Official sourceSveriges riksdag — Svensk författningssamlingSpellagen (2018:1138), chapter 16 section 2 — gaming system must be located in Sweden
data.riksdagen.se
“Licenshavarens spelsystem ska vara placerat i Sverige.”
Link checked 18 August 2026
- Official sourceSveriges riksdag — Svensk författningssamlingFörordning (2022:511) om elektronisk kommunikation, chapter 9 section 4 — retained traffic data may not be stored outside the European Union
data.riksdagen.se
“Uppgifterna får inte lagras utanför Europeiska unionen.”
Link checked 18 August 2026
- Official sourceSveriges riksdag — Svensk författningssamlingBokföringslagen (1999:1078), chapter 7 sections 2, 3a and 4 — accounting records kept in Sweden
data.riksdagen.se
“De ska bevaras fram till och med det sjunde året efter utgången av det kalenderår då räkenskapsåret avslutades (bevarandetid). De ska förvaras i Sverige, i ett ordnat skick och på ett betryggande och överskådligt sätt.”
Link checked 18 August 2026
- Official sourceSveriges riksdag — Svensk författningssamlingSäkerhetsskyddsförordningen (2021:955), chapter 3 sections 2 and 9
data.riksdagen.se
“Säkerhetsskyddsklassificerade uppgifter som lämnas till en utländsk myndighet eller en mellanfolklig organisation ska omfattas av ett internationellt säkerhetsskyddsåtagande”
Link checked 18 August 2026
What to do: Check your own industry against the restricted list before you pick a hosting region.
Sending data out of the country
Sweden adds nothing of its own here. It uses the European rules unchanged. You can send data freely to approved countries only, and that approved list is long. The United Kingdom, Switzerland, Japan, South Korea, Canada, Brazil and about a dozen others are approved. For everywhere else you sign the European Commission's standard contract, or use group-wide rules approved by a regulator. You also write down why you think the data will still be safe. Transfers to the United States work only if the receiving company has signed up to the European Union–United States Data Privacy Framework. That arrangement is under legal pressure.
- Ways to send data out:
- Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Explicit consent
Sweden's data protection authority publishes guidance that mirrors the European position. That means official decisions that a country is safe enough, standard contractual clauses with extra safeguards, group-wide binding rules, and narrow one-off exceptions. Sweden has issued no national transfer rules and no national list of its own. Two Swedish points sit outside privacy law. Retained telecoms data cannot leave the European Union at all, even to an approved country. And classified information needs a state-level protective security undertaking rather than a commercial contract. On 3 July 2026 the Swedish authority published a note that a United States Supreme Court decision may affect transfers to the United States. That note tracks the European Data Protection Board's letter to the Commission of 31 July 2026.
Sources
- Official sourceIntegritetsskyddsmyndigheten (Swedish Authority for Privacy Protection)Överföring till tredjeland — transfers outside the European Union
imy.se
Link checked 18 August 2026
- Official sourceIntegritetsskyddsmyndighetenIMY news, 3 July 2026 — United States Supreme Court decision may affect transfers to the USA
imy.se
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionCommission Implementing Decision (EU) 2021/914 — standard contractual clauses
eur-lex.europa.eu
Link checked 18 August 2026
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
The regulator, and whether it actually acts
The main privacy regulator is the Swedish Authority for Privacy Protection. It is fully staffed and working. It published supervision decisions in May, June and July 2026. One was a reprimand to a large security company for filming its own staff. In June 2026 it also became Sweden's market surveillance authority for the European artificial intelligence rules. Other regulators matter just as much in their own areas. Those are the financial supervisor, the telecoms and post authority, the gambling authority, the Security Service and the Armed Forces.
The Swedish Authority for Privacy Protection, Integritetsskyddsmyndigheten, was renamed from Datainspektionen in 2021. Its public supervision register showed 129 supervision cases. Decisions are dated 27 May 2026 (Svensk Bakgrundsanalys) and 16 June 2026 (Securitas Sverige). Two more are dated 2 July 2026 (Coast Guard) and 3 July 2026 (Police Authority, Visa Information System). Its style is active rather than aggressive. Decisions come often, but Swedish fines are moderate by European standards. National law caps fines on public authorities at 5 million Swedish kronor (about 500,000 US dollars) for lesser breaches. For serious ones the cap is 10 million kronor (about 1 million US dollars). Under the Cybersecurity Act, in force since 15 January 2026, supervision is split across industry regulators. Those are the Energy Agency, the Transport Agency, Finansinspektionen and the Health and Social Care Inspectorate. They also include the Medical Products Agency, the Food Agency, the Post and Telecom Authority and six county administrative boards. The National Defence Radio Establishment is the national incident response team and single point of contact.
Sources
- Official sourceIntegritetsskyddsmyndighetenIMY supervision decisions register — decisions dated 27 May, 16 June, 2 July and 3 July 2026
imy.se
Link checked 18 August 2026
- Official sourceIntegritetsskyddsmyndighetenIMY news — 15 June 2026, IMY appointed market surveillance authority for the AI Regulation; 16 June 2026, Securitas reprimanded
imy.se
Link checked 18 August 2026
- Official sourceSveriges riksdag — Svensk författningssamlingCybersäkerhetsförordning (2025:1507) — designation of supervisory authorities and of the national incident response unit
data.riksdagen.se
Link checked 18 August 2026
How long you must keep it — and when to delete it
Sweden has a firm minimum and a soft maximum, and they pull in opposite directions. You must keep company accounting records for seven years after the end of the year they relate to. You must keep patient records for at least ten years after the last entry. Against that, European privacy law says you must delete personal data once you no longer need it. Sweden settles the clash the way most of Europe does. A specific legal duty to keep something beats the general duty to delete it. So you keep it, lock it down, and use it for nothing else.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period
Minimums. The Bookkeeping Act chapter 7 section 2 sets seven years, counted from the end of the calendar year in which the financial year ended. The records must be kept in Sweden unless you meet the conditions in chapter 7 sections 3a to 4. The Patient Data Act chapter 3 section 17 covers patient records. Each one must be kept for at least ten years after the last entry. Longer periods are possible by ordinance. Telecoms operators covered by the law-enforcement keeping duty must hold specified traffic and subscriber data. They may not store it outside the European Union. Public authorities are also bound by the Archives Act, which starts from keeping records rather than deleting them. That is the opposite default to the private sector. Maximums. Article 5(1)(e) of the European General Data Protection Regulation limits how long you may keep data, and the Swedish Authority for Privacy Protection enforces it. Camera surveillance footage has no fixed period in law, so you fall back on what is necessary. Note that Sweden's exact telecoms keeping periods for each type of data are set below the level of statute. They are flagged as unconfirmed in this record.
Sources
- Official sourceSveriges riksdag — Svensk författningssamlingBokföringslagen (1999:1078), chapter 7 section 2 — seven-year retention, stored in Sweden
data.riksdagen.se
Link checked 18 August 2026
- Official sourceSveriges riksdag — Svensk författningssamlingPatientdatalag (2008:355), chapter 3 section 17 — ten-year minimum retention of patient records
data.riksdagen.se
“En journalhandling ska bevaras minst tio år efter det att den sista uppgiften fördes in i handlingen.”
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
Count at least three deadlines, and they do not agree. For a personal data breach you have 72 hours to tell the privacy regulator. You must tell the affected people without undue delay if the risk to them is high. Since 15 January 2026, organisations in important industries must send an early warning to their cybersecurity supervisor within 24 hours of noticing a significant incident. A fuller report follows within 72 hours. Trust service providers get only 24 hours for the full report. Financial firms have a fourth deadline under the European digital resilience rules. The 24-hour warning is the one that catches people out.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
Deadline 1. Article 33 of the European General Data Protection Regulation gives you 72 hours to tell the Swedish Authority for Privacy Protection. Article 34 says you tell the people affected without undue delay where the risk is high. Deadline 2. The Swedish Cybersecurity Act, Cybersäkerhetslagen (2025:1506), chapter 2 section 5, requires an early warning within 24 hours of learning about the incident. Chapter 2 section 6 requires an incident report within 72 hours. That drops to 24 hours for trust service providers. Deadline 3. The European digital resilience regulation, Regulation (EU) 2022/2554, is topped up by Lag (2024:1278). Financial firms report major information and communication technology incidents to Finansinspektionen. Deadline 4, from 1 January 2027 if it is passed. The proposed Critical Entities Resilience Act would add a 24-hour incident report for critical operators in eleven industries. Separately, a security incident in security-sensitive activity is reported to the Security Service or the Armed Forces under protective security rules.
Sources
- Official sourceSveriges riksdag — Svensk författningssamlingCybersäkerhetslag (2025:1506), chapter 2 sections 5 and 6 — 24-hour early warning and 72-hour report
data.riksdagen.se
“24 timmar efter det att verksamhetsutövaren har fått kännedom om incidenten”
Link checked 18 August 2026
- Official sourceIntegritetsskyddsmyndighetenAnmäla personuppgiftsincident — how to report a personal data breach to IMY
imy.se
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things that are not in any summary. One. A child can consent from age 13 in Sweden, the youngest age Europe allows, so a global default of 16 is wrong here. Two. You may only use a person's Swedish identity number without their consent when it is clearly justified. That is a Swedish-only rule with no European equivalent. Three. Anything you send to a Swedish public authority can become a public document. Any member of the public can then demand a copy, including a competitor or a journalist. Four. Giving a supplier access to a public authority's secret files is allowed only for purely technical handling or storage. It must also not be inappropriate in the circumstances. An ordinary supplier contract is not enough. Five. Mapping and sea-depth data is criminal law, not paperwork. Spreading it without a permit can mean up to a year in prison.
- What you have to do here:
- Get a parent's consent for children · Extra vendor secrecy terms · Written vendor contract
- What it costs if you get it wrong:
- Criminal liability
(1) Lag (2018:218) chapter 2 section 4 lets a child living in Sweden consent to online services from the age of 13. (2) Chapter 3 section 10 says Swedish personal identity numbers and coordination numbers may be used without consent only where clearly justified by the purpose. (3) Public access to official documents is a constitutional principle in Sweden. A document that reaches an authority is in principle public, unless a ground for secrecy applies. (4) Offentlighets- och sekretesslagen (2009:400) chapter 3 section 1 defines secrecy. It is a ban on disclosure by speech, by handing over an official document, or in any other way at all. That is why simply making data technically reachable by a provider is legally risky. Chapter 10 section 2 a, added by Lag (2023:335), creates a narrow exception. It covers a provider engaged only to handle or store the data technically, and only where using it is not inappropriate. (5) Lag (2016:319) section 12 sets the penalty at a fine or up to one year in prison. A sixth, softer trap. Swedish law caps fines on public authorities at 5 million and 10 million kronor. That sounds lenient until you see the effect. It removes the fear factor and pushes Swedish regulators towards orders to stop using the data instead.
Sources
- Official sourceSveriges riksdag — Svensk författningssamlingLag (2018:218), chapter 2 section 4 (age 13) and chapter 3 section 10 (personal identity numbers)
data.riksdagen.se
“Personnummer och samordningsnummer får behandlas utan samtycke endast när det är klart motiverat med hänsyn till ändamålet med behandlingen.”
Link checked 18 August 2026
- Official sourceSveriges riksdag — Svensk författningssamlingOffentlighets- och sekretesslag (2009:400), chapter 3 section 1, chapter 8 section 1 and chapter 10 section 2 a
data.riksdagen.se
“Sekretess hindrar inte att en uppgift lämnas till en enskild eller till en annan myndighet som för den utlämnande myndighetens räkning har i uppdrag att endast tekniskt bearbeta eller tekniskt lagra uppgiften, om det med hänsyn till omständigheterna inte är olämpligt att uppgiften lämnas ut.”
Link checked 18 August 2026
- Official sourceSveriges riksdag — Svensk författningssamlingLag (2016:319) om skydd för geografisk information, sections 9 and 12 — permit requirement and imprisonment
data.riksdagen.se
“döms till böter eller fängelse i högst ett år”
Link checked 18 August 2026
What's changing next
Two dated items. A new law on the resilience of critical operators is proposed to start on 1 January 2027. It would cover eleven industries and add another 24-hour incident report. Then on 12 January 2027, European rules make it illegal for cloud providers to charge you to move your data out. Also watch the government's national cloud policy, adopted on 28 May 2026. Today it is only advice, with no penalties. But it is the obvious vehicle for a future rule that public bodies must use European providers.
- What you have to do here:
- Make switching cloud provider possible
Dated items. Proposition 2025/26:303 is a bill for a new law on the resilience of critical operators. It puts the European Critical Entities Resilience Directive into Swedish law. The bill proposes that the new law and the other changes start on 1 January 2027. It is a bill, not a law, and must not be planned around as binding. The European Data Act's deadline for zero cloud exit fees, 12 January 2027, applies in Sweden automatically. The proposed European Cloud and Artificial Intelligence Development Act was presented on 3 June 2026 and is years from adoption. The Swedish government says it will take an active part in the negotiations. Powers that can be used at any time, which matter more than pending bills: - The Gambling Authority controls whether a licence holder may keep its gaming system abroad. If it withdrew the remote-access arrangement, systems would have to come back to Sweden with no new law needed. - The Security Service can order that a planned outsourcing may not go ahead, under Protective Security Act chapter 4 section 11. That is a veto over a signed cloud contract. It is used case by case and is not published. - The Armed Forces, Lantmäteriet and Sjöfartsverket control permits for geographic information and can tighten the conditions without new law. The government can also switch on restrictions on aerial photography at times it designates. - The national cloud policy can be reissued with binding purchasing requirements, with no new law. - The European Union–United States Data Privacy Framework remains valid, but it is under appeal at the Court of Justice. The European Data Protection Board formally questioned it on 31 July 2026. The Swedish Authority for Privacy Protection flagged the issue on 3 July 2026.
Sources
- Official sourceSveriges riksdag / RegeringskanslietProposition 2025/26:303 — En ny lag för ökad motståndskraft hos kritiska verksamhetsutövare, proposed entry into force 1 January 2027
data.riksdagen.se
“Den nya lagen och övriga lagändringar föreslås träda i kraft den 1 januari 2027.”
Link checked 18 August 2026
- Official sourceSveriges riksdag — minister's written answerSvar på skriftlig fråga 2025/26:932 — Myndigheters beroende av amerikanska molntjänster, 9 July 2026
data.riksdagen.se
“Regeringens molnpolicy som beslutades den 28 maj ska kunna användas som stöd”
Link checked 18 August 2026
- Official sourceSveriges riksdagInterpellation 2025/26:542 and debate — Den nationella molnpolicyn och Sveriges digitala suveränitet
data.riksdagen.se
“Policyn innehåller inte heller några tydliga krav på efterlevnad eller några uttalade konsekvenser om dess principer inte beaktas”
Link checked 18 August 2026
What to do: Diarise 1 January 2027 — that is the date this changes.
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries8 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Telecoms data must stay in the country
Official name: Förordning (2022:511) om elektronisk kommunikation, 9 kap. 4 § · SFS 2022:511, under Lag (2022:482) om elektronisk kommunikation, 9 kap. 19 § · Directly binding regulation
An absolute rule with no way around it. Telephone and internet records that Swedish operators must keep so the police can request them may not be stored outside the European Union at all. There is no consent, contract or approval route around it.
Enforced by Swedish Post and Telecom Authority
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the countryRetained data may be stored anywhere inside the European Union, but nowhere outside it. Storage in the United Kingdom, the United States or Norway is not permitted.
- Secure the dataThe data must have the same quality and protection as before it was stored. Access is limited to specially authorised staff.
- Keep logs
What it costs if you get it wrong
- Order to stopOrders and injunctions by the Post and Telecom Authority
- Loss of your licencePersistent breach of electronic communications obligations
Sources
- Official sourceSveriges riksdag — Svensk författningssamlingFörordning (2022:511) om elektronisk kommunikation, chapter 9 section 4
data.riksdagen.se
“Uppgifterna får inte lagras utanför Europeiska unionen.”
Link checked 18 August 2026
Online gaming data rules
Official name: Spellagen (2018:1138), 16 kap. 2 § · SFS 2018:1138 · Act of parliament
The strictest location rule in Swedish law. A gambling licence holder's gaming system must be placed in Sweden. There are two ways out. Hold a licence in another supervised country whose regulator has an agreement with the Swedish Gambling Authority. Or give the Swedish Gambling Authority remote access to the system. The regulator grants both, and it can withdraw both.
Enforced by Swedish Gambling Authority
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryThe gaming system itself must be physically in Sweden unless one of two exceptions is met.
- Independent auditThe Gambling Authority may require compliance testing at any time during the licence.
What it costs if you get it wrong
- Loss of your licenceBreach of licence conditions
- Fixed maximum fineAdministrative penalty set by the Gambling Authority
Sources
- Official sourceSveriges riksdag — Svensk författningssamlingSpellagen (2018:1138), chapter 16 sections 2 and 4
data.riksdagen.se
“Licenshavarens spelsystem ska vara placerat i Sverige.”
Link checked 18 August 2026
Cloud and outsourcing rules
Official name: Säkerhetsskyddslagen (2018:585) och Säkerhetsskyddsförordningen (2021:955) · SFS 2018:585 chapter 4 sections 1, 9 and 11; SFS 2021:955 chapter 3 sections 2 and 9 · Act of parliament
If any part of your business is security-sensitive, this overrides everything else. You must sign a protective security agreement before a supplier gets access. You must consult the Security Service in writing before deploying a system that handles classified information. The supervisor can simply forbid a planned cloud deal. Sending classified material to a foreign body needs a government-to-government undertaking, not a commercial contract.
Enforced by Swedish Security Service
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Extra vendor secrecy termsA protective security agreement must be signed before a supplier gets any access to security-sensitive activity or classified information.
- Secure the data
- Independent auditWritten consultation with the Security Service before deploying an information system that handles confidential-or-above classified information.
- Do not hand data to foreign authorities on demandClassified information may only reach a foreign authority or international organisation under an international protective security undertaking.
What it costs if you get it wrong
- Fixed maximum fine: SEK 25,000 to SEK 50,000,000 — about $5 millionPrivate operators
- Fixed maximum fine: SEK 10,000,000 — about $1 millionState bodies, municipalities and regions
- Order to stopThe supervisor can order that a planned outsourcing or procurement must not go ahead
Sources
- Official sourceSveriges riksdag — Svensk författningssamlingSäkerhetsskyddslag (2018:585), chapter 4 sections 1, 9 and 11 and chapter 7 section 4
data.riksdagen.se
“besluta att det planerade förfarandet inte får genomföras”
Link checked 18 August 2026
- Official sourceSveriges riksdag — Svensk författningssamlingSäkerhetsskyddsförordning (2021:955), chapter 3 sections 2 and 9 and chapter 8 section 1
data.riksdagen.se
“Säkerhetsskyddsklassificerade uppgifter som lämnas till en utländsk myndighet eller en mellanfolklig organisation ska omfattas av ett internationellt säkerhetsskyddsåtagande”
Link checked 18 August 2026
Secrecy duties for regulated professions
Official name: Offentlighets- och sekretesslagen (2009:400), 10 kap. 2 a § · SFS 2009:400, inserted by Lag (2023:335) · Act of parliament
There is no law saying a Swedish public authority's data must stay in Sweden. Secrecy law is what stops you instead. Secrecy is defined as a ban on disclosure by any means at all. So letting a supplier reach secret data can itself be unlawful. A 2023 change created a narrow way out for suppliers doing purely technical handling or storage. It applies only where using them is not inappropriate. That is a judgement each authority makes, and can get wrong.
Enforced by Swedish Authority for Privacy Protection
How this country controls where data goes: Approval each time · Accepted routes: Nothing required
What you have to do
- Extra vendor secrecy termsThe supplier's role must be limited to purely technical handling or storage. Using that supplier must also not be inappropriate in the circumstances.
- Written vendor contract
- Secure the data
What it costs if you get it wrong
- Criminal liabilityBreach of official secrecy is a criminal offence for the individual involved, not an administrative fine
Sources
- Official sourceSveriges riksdag — Svensk författningssamlingOffentlighets- och sekretesslag (2009:400), chapter 3 section 1, chapter 8 section 1, chapter 10 sections 2 and 2 a
data.riksdagen.se
“Ett förbud att röja en uppgift, vare sig det sker muntligen, genom utlämnande av en allmän handling eller på något annat sätt”
Link checked 18 August 2026
Government data needs a sovereign cloud
Official name: Regeringens nationella molnpolicy; Förordning (2024:1005) om samordnad och säker statlig it-drift · Government decision 28 May 2026; SFS 2024:1005 as amended by SFS 2025:936 · Government policy document
Sweden's national cloud policy, adopted on 28 May 2026, is guidance and nothing more. It sets no requirement to store data in Sweden or the European Union, and it carries no penalty. Alongside it, a 2024 regulation lets central government bodies buy shared secure information technology operations from four state provider agencies. Joining is voluntary.
Enforced by Swedish Post and Telecom Authority
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Assess high-risk projectsEach authority does its own risk assessment. The policy sets principles, not requirements.
- Prove the data stays under local controlA goal only. The policy asks authorities to reduce their strategic dependence on non-European suppliers. There is no consequence for ignoring it.
Sources
- Official sourceSveriges riksdagMinister's written answer 2025/26:932, 9 July 2026 — no legal requirement to keep public data in Sweden; cloud policy decided 28 May 2026
data.riksdagen.se
Link checked 18 August 2026
- Official sourceSveriges riksdag — Svensk författningssamlingFörordning (2024:1005) om samordnad och säker statlig it-drift — Försäkringskassan coordinating, four provider agencies, voluntary participation
data.riksdagen.se
“En myndighet som vill ta del av det samordnade statliga tjänsteutbudet ska anmäla sitt intresse”
Link checked 18 August 2026
Cloud and outsourcing rules (Mapping and location)
Official name: Lag (2016:319) om skydd för geografisk information och Förordning (2016:320) · SFS 2016:319 sections 3, 6, 9 and 12; SFS 2016:320 sections 2, 4 and 6 · Act of parliament
Detailed Swedish mapping, aerial imagery and sea-depth data is treated as a security matter, not a data matter. Spreading a compilation of it without a permit is a crime, carrying up to a year in prison. Whether uploading such a dataset to a foreign cloud counts as 'spreading' is not settled. That makes this a live risk for anyone building mapping products about Sweden.
Enforced by Swedish Mapping, Cadastral and Land Registration Authority
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Register or notifyPermit needed before spreading a compilation of geographic information about Swedish waters (Maritime Administration) or gathered from aircraft (Lantmäteriet).
- Keep the data in the countryHydrographic surveying inside Swedish territorial waters needs the Armed Forces' permission; aerial photography can be restricted by government decision at times of heightened readiness.
What it costs if you get it wrong
- Criminal liability: Fine or up to one year's imprisonmentSpreading protected geographic information without a permit, or surveying without permission
Sources
- Official sourceSveriges riksdag — Svensk författningssamlingLag (2016:319) om skydd för geografisk information
data.riksdagen.se
“förbjudet att sprida en sammanställning av geografisk information”
Link checked 18 August 2026
- Official sourceSveriges riksdag — Svensk författningssamlingFörordning (2016:320) — permit authorities: Armed Forces, Maritime Administration and Lantmäteriet
data.riksdagen.se
Link checked 18 August 2026
Cloud and outsourcing rules (Health and social care)
Official name: Patientdatalag (2008:355) · SFS 2008:355, chapter 3 section 17 and chapter 4 sections 1-3 · Act of parliament
Swedish health data has no rule about where it must be stored. There is no counterpart to France's certified health data hosting. What Sweden has instead is a strict rule on who inside your organisation may look. Access must be logged, with systematic spot checks. Records must be kept for at least ten years. Public healthcare is also covered by the secrecy act, and that is where the real cloud difficulty sits.
Enforced by Health and Social Care Inspectorate
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What you have to do
- Keep data for a minimum period — 10 yearsAt least ten years after the last entry in the record.
- Secure the dataStaff may only see a patient's record if they are involved in that patient's care or otherwise need it for their job.
- Keep logsAccess must be logged and checked systematically and repeatedly.
What it costs if you get it wrong
- Criminal liabilityLooking at a patient record without a work reason is prosecuted as unlawful data intrusion and breach of professional secrecy
Sources
- Official sourceSveriges riksdag — Svensk författningssamlingPatientdatalag (2008:355), chapter 3 section 17 and chapter 4 sections 1-3
data.riksdagen.se
“Sådan behörighet ska begränsas till vad som behövs för att den enskilde ska kunna fullgöra sina arbetsuppgifter.”
Link checked 18 August 2026
Payment data rules
Official name: Lag (2024:1278) med kompletterande bestämmelser till EU:s förordning om digital operativ motståndskraft för finanssektorn · SFS 2024:1278, with Förordning (2024:1292); implements Regulation (EU) 2022/2554 (DORA) · Act of parliament
Swedish banking, payments, insurance and securities have no rule about where data must be stored, checked 18 August 2026. Since 17 January 2025 the European digital resilience regulation applies instead. It requires you to know and record exactly where your data sits. It requires you to be able to audit your provider and to leave them. It never says the data must stay in Sweden.
Enforced by Swedish Financial Supervisory Authority
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What you have to do
- Written vendor contractOutsourcing contracts must say where data is used and stored. They must give you audit and exit rights.
- Report cyber incidentsMajor information and communication technology incidents are reported to Finansinspektionen on the European timetable.
- Keep records of how you use dataRegister of information on all outsourcing arrangements.
- Independent audit
What it costs if you get it wrong
- Fixed maximum fineAdministrative penalties by Finansinspektionen
- Loss of your licenceSerious or repeated breach
Sources
- Official sourceSveriges riksdagSvensk författningssamling — Lag (2024:1278) and Förordning (2024:1292) complementing the EU digital operational resilience regulation
data.riksdagen.se
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2022/2554 (DORA)
eur-lex.europa.eu
Link checked 18 August 2026
Applies to every company4 rules
These bind you whatever business you are in, once the country's rules reach you.
General data protection law
Official name: Lag (2018:218) med kompletterande bestämmelser till EU:s dataskyddsförordning · SFS 2018:218 · Act of parliament
Sweden's national top-up to the European privacy law. It sets no rule about where data must be stored. Its two distinctive rules are an age of digital consent of 13, and a limit on using a person's Swedish identity number without consent. It also caps fines on public authorities at 5 and 10 million Swedish kronor (roughly 500,000 and 1 million US dollars).
Enforced by Swedish Authority for Privacy Protection
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What you have to do
- Get a parent's consent for children — applies at: under 13A child living in Sweden can consent to online services from the age of 13. That is the youngest age European law permits.
- Get consentYou may use Swedish personal identity numbers without consent only where the purpose clearly justifies it.
What it costs if you get it wrong
- Fixed maximum fine: SEK 5,000,000 — about $500 thousandPublic authority, lesser breaches
- Fixed maximum fine: SEK 10,000,000 — about $1 millionPublic authority, serious breaches
Sources
- Official sourceSveriges riksdag — Svensk författningssamlingLag (2018:218), chapters 2, 3 and 6
data.riksdagen.se
“Vid erbjudande av informationssamhällets tjänster direkt till ett barn som bor i Sverige ska behandling av personuppgifter vara tillåten med stöd av barnets samtycke, om barnet är minst 13 år.”
Link checked 18 August 2026
Cyber security rules
Official name: Cybersäkerhetslag (2025:1506) · SFS 2025:1506, with Cybersäkerhetsförordning (2025:1507) · Act of parliament
Sweden's version of the European cybersecurity directive, in force since 15 January 2026. It sets no rule about where data must be stored. It adds a 24-hour early warning duty and a registration duty. Unusually, it also lets the regulator bar a named person from a management role for up to three years.
Enforced by Swedish Post and Telecom Authority
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Register or notifyOperators must register with the designated authority 'as soon as it can be done', and report changes within 14 days.
- Secure the data
- Report cyber incidents — within 24 hoursEarly warning within 24 hours of becoming aware of a significant incident.
- Report cyber incidents — within 72 hoursFull incident report within 72 hours. That drops to 24 hours for trust service providers.
- Written vendor contractSupply chain security is an explicit duty.
What it costs if you get it wrong
- Percentage of global turnover: 2% of total global annual turnover, or €10 million if higher — about $12 millionEssential private operators
- Percentage of global turnover: 1.4% of total global annual turnover, or €7 million if higher — about $8 millionImportant private operators
- Fixed maximum fine: SEK 10,000,000 — about $1 millionPublic operators
- Order to stopA named individual can be banned from a management role at the operator for one to three years
Sources
- Official sourceSveriges riksdag — Svensk författningssamlingCybersäkerhetslag (2025:1506)
data.riksdagen.se
“Denna lag träder i kraft den 15 januari 2026.”
Link checked 18 August 2026
- Official sourceSveriges riksdag — Svensk författningssamlingCybersäkerhetsförordning (2025:1507) — supervisory authorities and national incident response unit
data.riksdagen.se
Link checked 18 August 2026
Record-keeping rules for tax and accounts (2000)
Official name: Bokföringslagen (1999:1078), 7 kap. · SFS 1999:1078, chapter 7 sections 2, 3, 3a and 4 · Act of parliament
The Swedish rule almost everyone misses. A company's accounting records must be kept in Sweden for seven years. Electronic records may sit in another European Union country. You must tell the Swedish Tax Agency where they are, give it immediate online access, and be able to print them in Sweden. Outside the European Union you need a mutual assistance arrangement or the Tax Agency's specific permission.
Enforced by Swedish Tax Agency
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed, Nothing required
What you have to do
- Keep the data in the countryDefault position: accounting records and the equipment needed to read them are kept in Sweden.
- Keep data for a minimum period — 7 yearsSeven years counted from the end of the calendar year in which the financial year ended.
- Register or notifyNotify the Swedish Tax Agency of the storage location if electronic records are kept in another European Union country.
What it costs if you get it wrong
- Criminal liabilityBookkeeping offences are prosecuted under the Criminal Code, not fined administratively
Sources
- Official sourceSveriges riksdag — Svensk författningssamlingBokföringslagen (1999:1078), chapter 7
data.riksdagen.se
“De ska förvaras i Sverige, i ett ordnat skick och på ett betryggande och överskådligt sätt.”
Link checked 18 August 2026
Breach reporting rules
Official name: En ny lag för ökad motståndskraft hos kritiska verksamhetsutövare · Proposition 2025/26:303 · Draft law
A bill, not a law. It would add resilience duties, staff background checks and another 24-hour incident report for critical operators in eleven sectors from 1 January 2027. It imposes no storage location requirement. Do not plan around it as binding.
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Report cyber incidents — within 24 hours, from 1 January 2027Proposed only. Not binding today.
- Assess high-risk projects — from 1 January 2027Risk assessment and resilience plan for critical operators.
Sources
- Official sourceSveriges riksdag / RegeringskanslietProposition 2025/26:303 — En ny lag för ökad motståndskraft hos kritiska verksamhetsutövare
data.riksdagen.se
“Den nya lagen och övriga lagändringar föreslås träda i kraft den 1 januari 2027.”
Link checked 18 August 2026
Applies across the European Union2 rules
Written once for the whole bloc, and in force in every member country.
Europe's main privacy law
Official name: EU:s dataskyddsförordning (General Data Protection Regulation) · Regulation (EU) 2016/679 · Directly binding regulation
The European privacy law that forms Sweden's base layer. It does not require data to stay in Europe. It sets conditions for data leaving. Approved destinations need nothing extra. Everywhere else needs a standard contract or group-wide rules, plus a written risk assessment.
Enforced by Swedish Authority for Privacy Protection
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims
What you have to do
- Tell people what you do
- Keep records of how you use data
- Secure the data
- Assess high-risk projects
- Appoint a data protection officerRequired for public authorities, and for large-scale monitoring or handling of special categories of data.
- Put a transfer safeguard in place
- Written vendor contract
- Report breaches to the regulator — within 72 hours
- Tell affected people
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Delete data after a period
What it costs if you get it wrong
- Percentage of global turnover: 4% of worldwide group turnoverBasic principles, individual rights, unlawful transfers, defying a regulator order
- Fixed maximum fine: €20 million — about $23 millionSame, where higher than the percentage
- Order to stopOrder to stop processing or suspend a transfer
- Claims by individualsCompensation claims by individuals
Sources
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 — General Data Protection Regulation
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceIntegritetsskyddsmyndighetenIMY guidance on transfers to third countries
imy.se
Link checked 18 August 2026
Record-keeping rules for tax and accounts
Official name: Förordning om fri rörlighet för andra data än personuppgifter · Regulation (EU) 2018/1807 · Directly binding regulation
European law that actively forbids Sweden from making non-personal data stay in the country. The only exception is where Sweden can justify the rule on public security grounds. That is why Sweden's remaining storage rules are built around gambling supervision, law enforcement, protective security and tax control. There is no general rule that data must stay here.
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Make switching cloud provider possibleBacked up by the European Data Act. All charges for switching cloud provider or moving data out must be zero from 12 January 2027.
Sources
- Official sourcePublications Office of the European UnionRegulation (EU) 2018/1807 on a framework for the free flow of non-personal data
eur-lex.europa.eu
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
The exact retention periods, in months, for each category of telecoms data Swedish operators must keep for law enforcement
We could not confirm how long telecoms data must be kept for each type of data. The ban on storing it outside the European Union is in Förordning (2022:511) chapter 9 section 4, which we read directly. The periods themselves sit in chapter 9 of Lag (2022:482) and in the Post and Telecom Authority's own rules, which we could not read. Treat the location rule as solid, and check the periods with the authority.
Whether the commencement date of the technical-processing exception in the secrecy act (chapter 10 section 2 a, inserted by Lag (2023:335)) is 1 July 2023
We could not confirm the exact date this rule started. The combined statute text names the amending act but not its start date, and we could not open that act. The rule is certainly in force today. Only the start date is worked out from normal Swedish practice.
Whether uploading a protected compilation of Swedish geographic information to a cloud service outside Sweden counts as 'spreading' it under Lag (2016:319)
We could not confirm what counts as 'spreading' this data. The law does not define the Swedish word 'sprida', and we found no published decision or official guidance. Breaking this rule is a crime, so the gap matters. Settle it with Lantmäteriet before you design such a system.
That Swedish banking, payments, insurance and securities regulation contains no data storage location requirement
We found no rule requiring financial data to stay in Sweden. We confirmed that the Swedish laws sitting alongside the European digital resilience regulation say nothing about where data must be stored. We could not read Finansinspektionen's own circulars and guidance. Our confidence is medium. If you are a financial firm, check with Finansinspektionen.
Whether any Swedish preparedness rules for payments in crisis or war require domestic payment capability that amounts in practice to localisation
We could not confirm whether commercial banks must hold systems or data in Sweden. The Riksbank Act requires the central bank itself to keep payments working in a crisis and at heightened readiness. Whether the matching duties on commercial banks go that far is unclear. Check with your supervisor.
The full official text and legal status of the national cloud policy adopted on 28 May 2026
We could not read the text of this policy. We confirmed that it exists, its date, and that it is not binding, from a minister's written answer and a parliamentary debate on parliament's own site. The government's own publication page would not open. Our confidence is medium.
Whether the Bookkeeping Act's requirement to keep accounting records in Sweden has been amended or relaxed since the consolidated text we read
The combined statute on parliament's site still shows chapter 7 section 2 requiring storage in Sweden. The notification and permission routes are intact. Reform in this area has been under discussion. Check the position with the Swedish Tax Agency before you rely on it.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 90 days. Next check due 16 November 2026.