Sweden
Part of the European Union, so bloc-wide rules apply here too. Checked today.
The answer
Sweden has no general law forcing data to stay in the country. Personal data leaves under the ordinary European rules. But four walls override that: gambling systems must sit in Sweden, telecoms records kept for the police may never leave the European Union, classified material needs a state-to-state deal, and accounting books stay in Sweden unless you tell the tax agency.
Eight questions about Sweden
The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.
Do Sweden's rules apply to my company?
Yes. Sweden applies the European privacy rules, so a company anywhere in the world is caught if it offers goods or services to people in Sweden or watches what they do. There is no size or revenue floor to duck under. Sweden's own top-up law adds Swedish-only duties on top, and those apply to anyone processing data under Swedish law, not just Swedish companies. If you are outside Europe and caught, you normally have to name a representative inside Europe.
Sweden's national top-up is Lag (2018:218) med kompletterande bestämmelser till EU:s dataskyddsförordning, in force since 25 May 2018. It does not narrow the territorial reach of the EU General Data Protection Regulation; it adds Swedish-specific rules, notably chapter 2 section 4 (age of consent) and chapter 3 section 10 (Swedish personal identity numbers). Sector statutes such as the Gambling Act and the Protective Security Act have their own, separate reach: the Gambling Act binds anyone holding or needing a Swedish licence, wherever incorporated.
Sources
- Official sourceSveriges riksdag — Svensk författningssamlingLag (2018:218) med kompletterande bestämmelser till EU:s dataskyddsförordning (Swedish Data Protection Act)
data.riksdagen.se
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation), Articles 3 and 27
eur-lex.europa.eu
Link checked 18 August 2026
Can I store my users' data outside Sweden?
In general, yes. Sweden has no law that says personal data must physically stay in Sweden, and European law actually bans Sweden from imposing storage rules on non-personal data except for national security reasons. The exceptions are what matter. Online gambling systems must be placed in Sweden. Telephone and internet records that operators keep for the police may not be stored outside the European Union. Security-classified material cannot go to a foreign body without a government-to-government agreement. And a Swedish company's accounting records must be kept in Sweden unless it tells the tax agency where they are instead.
Sector-by-sector ratings, all checked 18 August 2026: - Online gambling: data must stay in the country. Gambling Act chapter 16 section 2 — 'Licenshavarens spelsystem ska vara placerat i Sverige.' Two escapes exist: a licence in another supervised country whose regulator has an agreement with the Swedish Gambling Authority, or giving the Swedish Gambling Authority remote access to the system. - Telecoms records retained for law enforcement: data must stay in the country at European Union level. Ordinance (2022:511) chapter 9 section 4, third paragraph — 'Uppgifterna får inte lagras utanför Europeiska unionen.' Storage anywhere in the European Union is fine; storage in the United States or United Kingdom is not. - Security-sensitive activity and classified information: data must stay in the country. Protective Security Ordinance (2021:955) chapter 3 section 9 requires an international protective security undertaking before classified information goes to a foreign authority or an international organisation, and chapter 3 section 2 requires written consultation with the Swedish Security Service before any information system handling confidential-or-above material is deployed. - Accounting records: data can leave with the right paperwork with a Sweden-first default. Bookkeeping Act chapter 7 section 2 — 'De ska förvaras i Sverige.' Chapter 7 section 3a permits electronic storage in another European Union country on notification to the Swedish Tax Agency plus immediate online access and the ability to print in Sweden; outside the European Union only where mutual assistance arrangements exist, or with the Tax Agency's specific permission under chapter 7 section 4. - Mapping, aerial imagery and sea-depth data: data can leave with the right paperwork. Act (2016:319) bans disseminating a compilation of geographic information about Swedish waters or gathered from aircraft without a permit, and breach is a criminal offence. - Public sector: data can leave with the right paperwork. No localisation statute, but secrecy law bites — see Q7. - Health, banking, payments, insurance, securities, telecom subscriber data, education: no storage-location rule found, checked 18 August 2026. Swedish patient records law sets a ten-year minimum retention but says nothing about where records sit.
Sources
- Official sourceSveriges riksdag — Svensk författningssamlingSpellagen (2018:1138), chapter 16 section 2 — gaming system must be located in Sweden
data.riksdagen.se
“Licenshavarens spelsystem ska vara placerat i Sverige.”
Link checked 18 August 2026
- Official sourceSveriges riksdag — Svensk författningssamlingFörordning (2022:511) om elektronisk kommunikation, chapter 9 section 4 — retained traffic data may not be stored outside the European Union
data.riksdagen.se
“Uppgifterna får inte lagras utanför Europeiska unionen.”
Link checked 18 August 2026
- Official sourceSveriges riksdag — Svensk författningssamlingBokföringslagen (1999:1078), chapter 7 sections 2, 3a and 4 — accounting records kept in Sweden
data.riksdagen.se
“De ska bevaras fram till och med det sjunde året efter utgången av det kalenderår då räkenskapsåret avslutades (bevarandetid). De ska förvaras i Sverige, i ett ordnat skick och på ett betryggande och överskådligt sätt.”
Link checked 18 August 2026
- Official sourceSveriges riksdag — Svensk författningssamlingSäkerhetsskyddsförordningen (2021:955), chapter 3 sections 2 and 9
data.riksdagen.se
“Säkerhetsskyddsklassificerade uppgifter som lämnas till en utländsk myndighet eller en mellanfolklig organisation ska omfattas av ett internationellt säkerhetsskyddsåtagande”
Link checked 18 August 2026
What do I need in place before data leaves Sweden?
Sweden adds nothing of its own here — it uses the European toolkit unchanged. The model is an allowlist of approved destinations, and that list is well populated: the United Kingdom, Switzerland, Japan, South Korea, Canada, Brazil and about a dozen others are approved. For everywhere else you sign the European Commission's standard contract, or use group-wide rules approved by a regulator, and you write down why you think the data will still be safe. United States transfers work only if the receiving company has signed up to the European Union–United States Data Privacy Framework, and that arrangement is under legal pressure.
Sweden's data protection authority publishes guidance mirroring the European position: adequacy decisions, standard contractual clauses with supplementary measures, binding corporate rules, and narrow one-off derogations. Sweden has issued no national transfer instrument and no national list. Two Swedish-specific twists sit outside privacy law: retained telecoms data cannot leave the European Union at all even to an approved country, and classified information needs a state-level protective security undertaking rather than a commercial contract. On 3 July 2026 the Swedish authority published a note that a United States Supreme Court decision may affect transfers to the United States, tracking the European Data Protection Board's 31 July 2026 letter to the Commission.
Sources
- Official sourceIntegritetsskyddsmyndigheten (Swedish Authority for Privacy Protection)Överföring till tredjeland — transfers outside the European Union
imy.se
Link checked 18 August 2026
- Official sourceIntegritetsskyddsmyndighetenIMY news, 3 July 2026 — United States Supreme Court decision may affect transfers to the USA
imy.se
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionCommission Implementing Decision (EU) 2021/914 — standard contractual clauses
eur-lex.europa.eu
Link checked 18 August 2026
Who enforces the rules in Sweden, and what can they do?
The main privacy regulator is the Swedish Authority for Privacy Protection, and it is fully staffed and working. It published supervisory decisions in May, June and July 2026, including a reprimand to a large security company over filming its own staff, and in June 2026 it was also made Sweden's market surveillance authority for the European artificial intelligence rules. Other regulators matter just as much in their own lanes: the financial supervisor, the telecoms and post authority, the gambling authority, the Security Service and the Armed Forces.
Integritetsskyddsmyndigheten (IMY) was renamed from Datainspektionen in 2021. Its public supervision register showed 129 supervision cases and decisions dated 27 May 2026 (Svensk Bakgrundsanalys), 16 June 2026 (Securitas Sverige), 2 July 2026 (Coast Guard) and 3 July 2026 (Police Authority, Visa Information System). Enforcement style is active rather than aggressive: decisions are frequent, but Swedish fines are moderate by European standards and public authorities are capped by national law at 5 million Swedish kronor (about 500,000 US dollars) for lesser breaches and 10 million kronor (about 1 million US dollars) for serious ones. Under the Cybersecurity Act in force since 15 January 2026, supervision is split across sector regulators — the Energy Agency, the Transport Agency, Finansinspektionen, the Health and Social Care Inspectorate, the Medical Products Agency, the Food Agency, the Post and Telecom Authority and six county administrative boards — while the National Defence Radio Establishment is the national incident response team and single point of contact.
Sources
- Official sourceIntegritetsskyddsmyndighetenIMY supervision decisions register — decisions dated 27 May, 16 June, 2 July and 3 July 2026
imy.se
Link checked 18 August 2026
- Official sourceIntegritetsskyddsmyndighetenIMY news — 15 June 2026, IMY appointed market surveillance authority for the AI Regulation; 16 June 2026, Securitas reprimanded
imy.se
Link checked 18 August 2026
- Official sourceSveriges riksdag — Svensk författningssamlingCybersäkerhetsförordning (2025:1507) — designation of supervisory authorities and of the national incident response unit
data.riksdagen.se
Link checked 18 August 2026
How long do I have to keep the data?
Sweden has a hard floor and a soft ceiling, and they pull in opposite directions. You must keep company accounting records for seven years after the end of the year they relate to, and patient records for at least ten years after the last entry. Against that, European privacy law says you must delete personal data once you no longer need it. Sweden resolves the clash the same way most of Europe does: a specific legal duty to keep something beats the general duty to delete it, so you keep it, lock it down and use it for nothing else.
Floors: Bookkeeping Act chapter 7 section 2 — seven years from the end of the calendar year in which the financial year ended, and the records must be kept in Sweden unless the chapter 7 sections 3a-4 conditions are met. Patient Data Act chapter 3 section 17 — 'En journalhandling ska bevaras minst tio år efter det att den sista uppgiften fördes in i handlingen', with longer periods possible by ordinance. Telecoms operators subject to the law-enforcement retention duty must keep specified traffic and subscriber data and may not store it outside the European Union. Public authorities are also bound by the Archives Act, which starts from a presumption of preservation rather than deletion — the opposite default to the private sector. Ceilings: GDPR Article 5(1)(e) storage limitation, enforced by IMY; camera surveillance material has no fixed statutory period and falls back on necessity. Note that Sweden's exact telecoms retention periods per data category are set below statute level and are flagged as unconfirmed in this record.
Sources
- Official sourceSveriges riksdag — Svensk författningssamlingBokföringslagen (1999:1078), chapter 7 section 2 — seven-year retention, stored in Sweden
data.riksdagen.se
Link checked 18 August 2026
- Official sourceSveriges riksdag — Svensk författningssamlingPatientdatalag (2008:355), chapter 3 section 17 — ten-year minimum retention of patient records
data.riksdagen.se
“En journalhandling ska bevaras minst tio år efter det att den sista uppgiften fördes in i handlingen.”
Link checked 18 August 2026
What happens if there is a breach?
Count at least three clocks, and they do not agree. For a personal data breach you have 72 hours to tell the privacy regulator, and you must tell the affected people without undue delay if the risk to them is high. Since 15 January 2026, organisations in important sectors must send an early warning to their cybersecurity supervisor within 24 hours of noticing a significant incident, then a fuller report within 72 hours — but trust service providers get only 24 hours for the full report. Financial firms have a fourth clock under the European digital resilience rules. The 24-hour warning is the one that catches people out.
Clock 1 — GDPR Article 33: 72 hours to IMY; Article 34: notify individuals without undue delay where the risk is high. Clock 2 — Cybersäkerhetslagen (2025:1506) chapter 2 section 5: early warning within '24 timmar efter det att verksamhetsutövaren har fått kännedom om incidenten'; chapter 2 section 6: incident report within 72 hours, reduced to 24 hours for trust service providers. Clock 3 — DORA (Regulation (EU) 2022/2554) as supplemented by Lag (2024:1278), for financial entities reporting major information and communication technology incidents to Finansinspektionen. Clock 4 (from 1 January 2027, if enacted) — the proposed Critical Entities Resilience Act would add a 24-hour incident report for critical operators in eleven sectors. Separately, a security incident in security-sensitive activity is reported to the Security Service or the Armed Forces under protective security rules.
Sources
- Official sourceSveriges riksdag — Svensk författningssamlingCybersäkerhetslag (2025:1506), chapter 2 sections 5 and 6 — 24-hour early warning and 72-hour report
data.riksdagen.se
“24 timmar efter det att verksamhetsutövaren har fått kännedom om incidenten”
Link checked 18 August 2026
- Official sourceIntegritetsskyddsmyndighetenAnmäla personuppgiftsincident — how to report a personal data breach to IMY
imy.se
Link checked 18 August 2026
What trips people up in Sweden?
Five things that are not in any summary. One: a child can consent from age 13 in Sweden, the youngest age Europe allows, so a global default of 16 is wrong here. Two: you may only use a person's Swedish identity number without their consent when it is clearly justified — a Swedish-only rule with no European equivalent. Three: anything you send to a Swedish public authority can become a public document that any member of the public, including a competitor or a journalist, can demand a copy of. Four: giving a supplier access to a public authority's secret files is allowed only for purely technical processing or storage, and only if it is not inappropriate in the circumstances — the ordinary supplier contract is not enough. Five: mapping and sea-depth data is criminal law, not paperwork — spreading it without a permit can mean up to a year in prison.
(1) Lag (2018:218) chapter 2 section 4: 'Vid erbjudande av informationssamhällets tjänster direkt till ett barn som bor i Sverige ska behandling av personuppgifter vara tillåten med stöd av barnets samtycke, om barnet är minst 13 år.' (2) Chapter 3 section 10: 'Personnummer och samordningsnummer får behandlas utan samtycke endast när det är klart motiverat med hänsyn till ändamålet med behandlingen.' (3) The principle of public access to official documents is constitutional; a document that reaches an authority is in principle public unless a secrecy ground applies. (4) Offentlighets- och sekretesslagen (2009:400) chapter 3 section 1 defines secrecy as a ban on disclosure 'muntligen, genom utlämnande av en allmän handling eller på något annat sätt', which is why merely making data technically reachable by a provider is legally fraught; chapter 10 section 2 a, added by Lag (2023:335), creates a narrow exception for a provider engaged 'endast tekniskt bearbeta eller tekniskt lagra uppgiften' and only where it is 'inte olämpligt'. (5) Lag (2016:319) section 12: 'döms till böter eller fängelse i högst ett år.' A sixth, softer trap: public-authority fines under Swedish law are capped at 5 million and 10 million kronor, which sounds lenient until you realise it removes the fear factor and pushes Swedish regulators towards orders to stop processing instead.
Sources
- Official sourceSveriges riksdag — Svensk författningssamlingLag (2018:218), chapter 2 section 4 (age 13) and chapter 3 section 10 (personal identity numbers)
data.riksdagen.se
“Personnummer och samordningsnummer får behandlas utan samtycke endast när det är klart motiverat med hänsyn till ändamålet med behandlingen.”
Link checked 18 August 2026
- Official sourceSveriges riksdag — Svensk författningssamlingOffentlighets- och sekretesslag (2009:400), chapter 3 section 1, chapter 8 section 1 and chapter 10 section 2 a
data.riksdagen.se
“Sekretess hindrar inte att en uppgift lämnas till en enskild eller till en annan myndighet som för den utlämnande myndighetens räkning har i uppdrag att endast tekniskt bearbeta eller tekniskt lagra uppgiften, om det med hänsyn till omständigheterna inte är olämpligt att uppgiften lämnas ut.”
Link checked 18 August 2026
- Official sourceSveriges riksdag — Svensk författningssamlingLag (2016:319) om skydd för geografisk information, sections 9 and 12 — permit requirement and imprisonment
data.riksdagen.se
“döms till böter eller fängelse i högst ett år”
Link checked 18 August 2026
What is changing soon in Sweden?
Two dated items. On 1 January 2027 a new law on the resilience of critical operators is proposed to start, covering eleven sectors and adding another 24-hour incident report. Also on 12 January 2027, European rules make it illegal for cloud providers to charge you to move your data out. Watch the government's national cloud policy, adopted on 28 May 2026: today it is only advice with no penalties, but it is the obvious vehicle for a future rule that public bodies must use European providers.
Dated: Proposition 2025/26:303, 'En ny lag för ökad motståndskraft hos kritiska verksamhetsutövare', implementing the European Critical Entities Resilience Directive — 'Den nya lagen och övriga lagändringar föreslås träda i kraft den 1 januari 2027.' It is a bill, not law, and must not be planned around as binding. The EU Data Act's zero cloud-egress-fee deadline of 12 January 2027 applies in Sweden automatically. The proposed EU Cloud and AI Development Act was presented on 3 June 2026 and is years from adoption; the Swedish government says it will engage actively in the negotiations. Dormant switches, which matter more than pending bills: - The Gambling Authority controls whether a licensee may keep its gaming system abroad; withdrawing the remote-access accommodation would force repatriation with no legislation needed. - The Security Service can, under Protective Security Act chapter 4 section 11, order that a planned outsourcing 'inte får genomföras' — a veto over a signed cloud contract, exercised case by case and not published. - The Armed Forces, Lantmäteriet and Sjöfartsverket control geographic-information permits and can tighten conditions administratively; aerial photography restrictions can be switched on by the government at times it designates. - The national cloud policy can be reissued with binding procurement requirements without new legislation. - The European Union–United States Data Privacy Framework remains valid but is under appeal at the Court of Justice and was formally questioned by the European Data Protection Board on 31 July 2026; IMY flagged the issue on 3 July 2026.
Sources
- Official sourceSveriges riksdag / RegeringskanslietProposition 2025/26:303 — En ny lag för ökad motståndskraft hos kritiska verksamhetsutövare, proposed entry into force 1 January 2027
data.riksdagen.se
“Den nya lagen och övriga lagändringar föreslås träda i kraft den 1 januari 2027.”
Link checked 18 August 2026
- Official sourceSveriges riksdag — minister's written answerSvar på skriftlig fråga 2025/26:932 — Myndigheters beroende av amerikanska molntjänster, 9 July 2026
data.riksdagen.se
“Regeringens molnpolicy som beslutades den 28 maj ska kunna användas som stöd”
Link checked 18 August 2026
- Official sourceSveriges riksdagInterpellation 2025/26:542 and debate — Den nationella molnpolicyn och Sveriges digitala suveränitet
data.riksdagen.se
“Policyn innehåller inte heller några tydliga krav på efterlevnad eller några uttalade konsekvenser om dess principer inte beaktas”
Link checked 18 August 2026
The rules, layer by layer
Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.
Layer 1
Bloc rules
Made by a group of countries together. Applies inside every member country.
2 rules here
Layer 2
National rules
Added by this country on top of any bloc rules.
4 rules here
Layer 3
Industry rules
Made by an industry regulator. These usually beat the general position.
8 rules here
Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.
Bloc rules2 rules
EU:s dataskyddsförordning (General Data Protection Regulation)
Directly binding regulation · Regulation (EU) 2016/679
The European privacy law that forms Sweden's base layer. It does not require data to stay in Europe; it sets conditions for data leaving. Approved destinations need nothing extra, everywhere else needs a standard contract or group-wide rules plus a written risk assessment.
Enforced by Swedish Authority for Privacy Protection
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims
What it makes you do
- Tell people what you do
- Keep records of processing
- Secure the data
- Assess high-risk projects
- Appoint a data protection officerRequired for public authorities and for large-scale monitoring or special-category processing.
- Put a transfer safeguard in place
- Written vendor contract
- Report breaches to the regulator — within 72 hours
- Tell affected people
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Delete data after a period
What it costs if you get it wrong
- Percentage of global turnover: 4% of worldwide group turnoverBasic principles, individual rights, unlawful transfers, defying a regulator order
- Fixed maximum fine: €20 million — about $23 millionSame, where higher than the percentage
- Order to stopOrder to stop processing or suspend a transfer
- Claims by individualsCompensation claims by individuals
Sources
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 — General Data Protection Regulation
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceIntegritetsskyddsmyndighetenIMY guidance on transfers to third countries
imy.se
Link checked 18 August 2026
Förordning om fri rörlighet för andra data än personuppgifter
Directly binding regulation · Regulation (EU) 2018/1807
European law that actively forbids Sweden from making non-personal data stay in the country, except where it can justify the rule on public security grounds. This is why Sweden's remaining storage rules are framed around gambling supervision, law enforcement, protective security and tax control rather than as general localisation.
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Make switching cloud provider possibleReinforced by the EU Data Act: all cloud switching and data egress charges must be zero from 12 January 2027.
Sources
- Official sourcePublications Office of the European UnionRegulation (EU) 2018/1807 on a framework for the free flow of non-personal data
eur-lex.europa.eu
Link checked 18 August 2026
National rules4 rules
Lag (2018:218) med kompletterande bestämmelser till EU:s dataskyddsförordning
Act of parliament · SFS 2018:218
Sweden's national top-up to the European privacy law. It imposes no storage location rule. Its two distinctive rules are an age of digital consent of 13 and a restriction on using a person's Swedish identity number without consent. It also caps fines on public authorities at 5 and 10 million Swedish kronor (roughly 500,000 and 1 million US dollars).
Enforced by Swedish Authority for Privacy Protection
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What it makes you do
- Get a parent's consent for children — applies at: under 13A child living in Sweden can consent to online services from age 13 — the youngest age European law permits.
- Get consentSwedish personal identity numbers may be processed without consent only where clearly justified by the purpose.
What it costs if you get it wrong
- Fixed maximum fine: SEK 5,000,000 — about $500 thousandPublic authority, lesser breaches
- Fixed maximum fine: SEK 10,000,000 — about $1 millionPublic authority, serious breaches
Sources
- Official sourceSveriges riksdag — Svensk författningssamlingLag (2018:218), chapters 2, 3 and 6
data.riksdagen.se
“Vid erbjudande av informationssamhällets tjänster direkt till ett barn som bor i Sverige ska behandling av personuppgifter vara tillåten med stöd av barnets samtycke, om barnet är minst 13 år.”
Link checked 18 August 2026
Cybersäkerhetslag (2025:1506)
Act of parliament · SFS 2025:1506, with Cybersäkerhetsförordning (2025:1507)
Sweden's implementation of the European cybersecurity directive, in force since 15 January 2026. It sets no storage location rule but adds a 24-hour early warning duty, a registration duty and, unusually, the power to bar a named person from a management role for up to three years.
Enforced by Swedish Post and Telecom Authority
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Register or notifyOperators must register with the designated authority 'as soon as it can be done', and report changes within 14 days.
- Secure the data
- Report cyber incidents — within 24 hoursEarly warning within 24 hours of becoming aware of a significant incident.
- Report cyber incidents — within 72 hoursFull incident report within 72 hours — reduced to 24 hours for trust service providers.
- Written vendor contractSupply chain security is an explicit duty.
What it costs if you get it wrong
- Percentage of global turnover: 2% of total global annual turnover, or €10 million if higher — about $12 millionEssential private operators
- Percentage of global turnover: 1.4% of total global annual turnover, or €7 million if higher — about $8 millionImportant private operators
- Fixed maximum fine: SEK 10,000,000 — about $1 millionPublic operators
- Order to stopA named individual can be banned from a management role at the operator for one to three years
Sources
- Official sourceSveriges riksdag — Svensk författningssamlingCybersäkerhetslag (2025:1506)
data.riksdagen.se
“Denna lag träder i kraft den 15 januari 2026.”
Link checked 18 August 2026
- Official sourceSveriges riksdag — Svensk författningssamlingCybersäkerhetsförordning (2025:1507) — supervisory authorities and national incident response unit
data.riksdagen.se
Link checked 18 August 2026
Bokföringslagen (1999:1078), 7 kap.
Act of parliament · SFS 1999:1078, chapter 7 sections 2, 3, 3a and 4
The Swedish rule almost everyone misses. A company's accounting records must be kept in Sweden for seven years. Electronic records may sit in another European Union country if you tell the Swedish Tax Agency where they are, give it immediate online access and can print them in Sweden. Outside the European Union you need a mutual assistance arrangement or the Tax Agency's specific permission.
Enforced by Swedish Tax Agency
Transfer model: Approval each time · Accepted routes: Government sign-off needed, Nothing required
What it makes you do
- Keep the data in the countryDefault position: accounting records and the equipment needed to read them are kept in Sweden.
- Keep data for a minimum period — 7 yearsSeven years counted from the end of the calendar year in which the financial year ended.
- Register or notifyNotify the Swedish Tax Agency of the storage location if electronic records are kept in another European Union country.
What it costs if you get it wrong
- Criminal liabilityBookkeeping offences are prosecuted under the Criminal Code, not fined administratively
Sources
- Official sourceSveriges riksdag — Svensk författningssamlingBokföringslagen (1999:1078), chapter 7
data.riksdagen.se
“De ska förvaras i Sverige, i ett ordnat skick och på ett betryggande och överskådligt sätt.”
Link checked 18 August 2026
En ny lag för ökad motståndskraft hos kritiska verksamhetsutövare
Draft law · Proposition 2025/26:303
A bill, not a law. It would add resilience duties, staff background checks and another 24-hour incident report for critical operators in eleven sectors from 1 January 2027. It imposes no storage location requirement. Do not plan around it as binding.
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Report cyber incidents — within 24 hours, from 1 January 2027Proposed only. Not binding today.
- Assess high-risk projects — from 1 January 2027Risk assessment and resilience plan for critical operators.
Sources
- Official sourceSveriges riksdag / RegeringskanslietProposition 2025/26:303 — En ny lag för ökad motståndskraft hos kritiska verksamhetsutövare
data.riksdagen.se
“Den nya lagen och övriga lagändringar föreslås träda i kraft den 1 januari 2027.”
Link checked 18 August 2026
Industry rules8 rules
Förordning (2022:511) om elektronisk kommunikation, 9 kap. 4 §
Directly binding regulation · SFS 2022:511, under Lag (2022:482) om elektronisk kommunikation, 9 kap. 19 § · Telecoms
A genuine, absolute storage wall. Telephone and internet records that Swedish operators must keep so the police can request them may not be stored outside the European Union at all. There is no consent, contract or approval route around it.
Enforced by Swedish Post and Telecom Authority
Transfer model: Not allowed
What it makes you do
- Keep the data in the countryRetained data may be stored anywhere inside the European Union, but nowhere outside it. Storage in the United Kingdom, the United States or Norway is not permitted.
- Secure the dataSame quality and protection as before storage; access limited to specially authorised staff.
- Keep logs
What it costs if you get it wrong
- Order to stopOrders and injunctions by the Post and Telecom Authority
- Loss of your licencePersistent breach of electronic communications obligations
Sources
- Official sourceSveriges riksdag — Svensk författningssamlingFörordning (2022:511) om elektronisk kommunikation, chapter 9 section 4
data.riksdagen.se
“Uppgifterna får inte lagras utanför Europeiska unionen.”
Link checked 18 August 2026
Spellagen (2018:1138), 16 kap. 2 §
Act of parliament · SFS 2018:1138 · Online gaming
The hardest location rule in Swedish law. A gambling licensee's gaming system must be placed in Sweden. Two ways out exist: hold a licence in another supervised country whose regulator has an agreement with the Swedish Gambling Authority, or give the Swedish Gambling Authority remote access to the system. Both are in the regulator's gift and can be withdrawn.
Enforced by Swedish Gambling Authority
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryThe gaming system itself must be physically in Sweden unless one of two exceptions is met.
- Independent auditThe Gambling Authority may require compliance testing at any time during the licence.
What it costs if you get it wrong
- Loss of your licenceBreach of licence conditions
- Fixed maximum fineAdministrative penalty set by the Gambling Authority
Sources
- Official sourceSveriges riksdag — Svensk författningssamlingSpellagen (2018:1138), chapter 16 sections 2 and 4
data.riksdagen.se
“Licenshavarens spelsystem ska vara placerat i Sverige.”
Link checked 18 August 2026
Säkerhetsskyddslagen (2018:585) och Säkerhetsskyddsförordningen (2021:955)
Act of parliament · SFS 2018:585 chapter 4 sections 1, 9 and 11; SFS 2021:955 chapter 3 sections 2 and 9 · Defence
If any part of your business is security-sensitive, this overrides everything else. You must sign a protective security agreement before a supplier gets access, consult the Security Service in writing before deploying a system that handles classified information, and the supervisor can simply forbid a planned cloud deal. Sending classified material to a foreign body needs a government-to-government undertaking, not a commercial contract.
Enforced by Swedish Security Service
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Extra vendor secrecy termsA protective security agreement must be signed before a supplier gets any access to security-sensitive activity or classified information.
- Secure the data
- Independent auditWritten consultation with the Security Service before deploying an information system that handles confidential-or-above classified information.
- Do not hand data to foreign authorities on demandClassified information may only reach a foreign authority or international organisation under an international protective security undertaking.
What it costs if you get it wrong
- Fixed maximum fine: SEK 25,000 to SEK 50,000,000 — about $5 millionPrivate operators
- Fixed maximum fine: SEK 10,000,000 — about $1 millionState bodies, municipalities and regions
- Order to stopThe supervisor can order that a planned outsourcing or procurement must not go ahead
Sources
- Official sourceSveriges riksdag — Svensk författningssamlingSäkerhetsskyddslag (2018:585), chapter 4 sections 1, 9 and 11 and chapter 7 section 4
data.riksdagen.se
“besluta att det planerade förfarandet inte får genomföras”
Link checked 18 August 2026
- Official sourceSveriges riksdag — Svensk författningssamlingSäkerhetsskyddsförordning (2021:955), chapter 3 sections 2 and 9 and chapter 8 section 1
data.riksdagen.se
“Säkerhetsskyddsklassificerade uppgifter som lämnas till en utländsk myndighet eller en mellanfolklig organisation ska omfattas av ett internationellt säkerhetsskyddsåtagande”
Link checked 18 August 2026
Offentlighets- och sekretesslagen (2009:400), 10 kap. 2 a §
Act of parliament · SFS 2009:400, inserted by Lag (2023:335) · Government
There is no law saying a Swedish public authority's data must stay in Sweden. What bites instead is secrecy law: secrecy is defined as a ban on disclosure by any means at all, so letting a supplier reach secret data can itself be unlawful. A 2023 amendment created a narrow escape for suppliers doing purely technical processing or storage — but only where it is not inappropriate, which is a judgement call each authority makes and can lose.
Enforced by Swedish Authority for Privacy Protection
Transfer model: Approval each time · Accepted routes: Nothing required
What it makes you do
- Extra vendor secrecy termsThe supplier's role must be limited to purely technical processing or storage, and using it must not be inappropriate in the circumstances.
- Written vendor contract
- Secure the data
What it costs if you get it wrong
- Criminal liabilityBreach of official secrecy is a criminal offence for the individual involved, not an administrative fine
Sources
- Official sourceSveriges riksdag — Svensk författningssamlingOffentlighets- och sekretesslag (2009:400), chapter 3 section 1, chapter 8 section 1, chapter 10 sections 2 and 2 a
data.riksdagen.se
“Ett förbud att röja en uppgift, vare sig det sker muntligen, genom utlämnande av en allmän handling eller på något annat sätt”
Link checked 18 August 2026
Regeringens nationella molnpolicy; Förordning (2024:1005) om samordnad och säker statlig it-drift
Government policy document · Government decision 28 May 2026; SFS 2024:1005 as amended by SFS 2025:936 · Government
Sweden's national cloud policy, adopted on 28 May 2026, is guidance and nothing more. It sets no requirement to store data in Sweden or the European Union and carries no penalty. Alongside it, a 2024 regulation lets central government bodies buy shared secure IT operations from four state provider agencies, but joining is voluntary.
Enforced by Swedish Post and Telecom Authority
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Assess high-risk projectsEach authority does its own risk assessment; the policy sets principles, not requirements.
- Prove the data stays under local controlAspirational only. The policy asks authorities to reduce strategic dependence on non-European suppliers but attaches no consequence for ignoring it.
Sources
- Official sourceSveriges riksdagMinister's written answer 2025/26:932, 9 July 2026 — no legal requirement to keep public data in Sweden; cloud policy decided 28 May 2026
data.riksdagen.se
Link checked 18 August 2026
- Official sourceSveriges riksdag — Svensk författningssamlingFörordning (2024:1005) om samordnad och säker statlig it-drift — Försäkringskassan coordinating, four provider agencies, voluntary participation
data.riksdagen.se
“En myndighet som vill ta del av det samordnade statliga tjänsteutbudet ska anmäla sitt intresse”
Link checked 18 August 2026
Lag (2016:319) om skydd för geografisk information och Förordning (2016:320)
Act of parliament · SFS 2016:319 sections 3, 6, 9 and 12; SFS 2016:320 sections 2, 4 and 6 · Mapping and location
Detailed Swedish mapping, aerial imagery and sea-depth data is treated as a security matter, not a data matter. Spreading a compilation of it without a permit is a criminal offence carrying up to a year in prison. Whether uploading such a dataset to a foreign cloud counts as 'spreading' is not settled, which makes this a live risk for anyone building geospatial products about Sweden.
Enforced by Swedish Mapping, Cadastral and Land Registration Authority
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Register or notifyPermit needed before spreading a compilation of geographic information about Swedish waters (Maritime Administration) or gathered from aircraft (Lantmäteriet).
- Keep the data in the countryHydrographic surveying inside Swedish territorial waters needs the Armed Forces' permission; aerial photography can be restricted by government decision at times of heightened readiness.
What it costs if you get it wrong
- Criminal liability: Fine or up to one year's imprisonmentSpreading protected geographic information without a permit, or surveying without permission
Sources
- Official sourceSveriges riksdag — Svensk författningssamlingLag (2016:319) om skydd för geografisk information
data.riksdagen.se
“förbjudet att sprida en sammanställning av geografisk information”
Link checked 18 August 2026
- Official sourceSveriges riksdag — Svensk författningssamlingFörordning (2016:320) — permit authorities: Armed Forces, Maritime Administration and Lantmäteriet
data.riksdagen.se
Link checked 18 August 2026
Patientdatalag (2008:355)
Act of parliament · SFS 2008:355, chapter 3 section 17 and chapter 4 sections 1-3 · Health and social care
Swedish health data has no storage location rule — no counterpart to France's certified health data hosting. What it has instead is a strict internal access rule, mandatory access logging with systematic spot checks, and a ten-year minimum retention. Public healthcare is also covered by the secrecy act, which is where the real cloud difficulty lives.
Enforced by Health and Social Care Inspectorate
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What it makes you do
- Keep data for a minimum period — 10 yearsAt least ten years after the last entry in the record.
- Secure the dataStaff may only see a patient's record if they are involved in that patient's care or otherwise need it for their job.
- Keep logsAccess must be logged and checked systematically and repeatedly.
What it costs if you get it wrong
- Criminal liabilityLooking at a patient record without a work reason is prosecuted as unlawful data intrusion and breach of professional secrecy
Sources
- Official sourceSveriges riksdag — Svensk författningssamlingPatientdatalag (2008:355), chapter 3 section 17 and chapter 4 sections 1-3
data.riksdagen.se
“Sådan behörighet ska begränsas till vad som behövs för att den enskilde ska kunna fullgöra sina arbetsuppgifter.”
Link checked 18 August 2026
Lag (2024:1278) med kompletterande bestämmelser till EU:s förordning om digital operativ motståndskraft för finanssektorn
Act of parliament · SFS 2024:1278, with Förordning (2024:1292); implements Regulation (EU) 2022/2554 (DORA) · Finance
Swedish banking, payments, insurance and securities have no storage location rule, checked 18 August 2026. Since 17 January 2025 the European digital resilience regulation governs instead, and it demands that you know and record exactly where your data sits, can audit the provider and can exit — but it never says the data must stay in Sweden.
Enforced by Swedish Financial Supervisory Authority
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What it makes you do
- Written vendor contractOutsourcing contracts must state where data is processed and stored, and give audit and exit rights.
- Report cyber incidentsMajor information and communication technology incidents are reported to Finansinspektionen on the European timetable.
- Keep records of processingRegister of information on all outsourcing arrangements.
- Independent audit
What it costs if you get it wrong
- Fixed maximum fineAdministrative penalties by Finansinspektionen
- Loss of your licenceSerious or repeated breach
Sources
- Official sourceSveriges riksdagSvensk författningssamling — Lag (2024:1278) and Förordning (2024:1292) complementing the EU digital operational resilience regulation
data.riksdagen.se
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2022/2554 (DORA)
eur-lex.europa.eu
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
The exact retention periods, in months, for each category of telecoms data Swedish operators must keep for law enforcement
The European Union storage ban is in Förordning (2022:511) chapter 9 section 4, which we read directly, but the periods sit in chapter 9 of Lag (2022:482) and in the Post and Telecom Authority's own regulations. The parliament's full-text service truncated the statute before chapter 9 and the authority's site refused automated fetching. The location rule is high confidence; the durations are not stated in this record.
Whether the commencement date of the technical-processing exception in the secrecy act (chapter 10 section 2 a, inserted by Lag (2023:335)) is 1 July 2023
The consolidated statute text shows the amending act number but not its commencement date, and we could not open the amending act itself. The provision is certainly in force today; only the start date is inferred from normal Swedish practice.
Whether uploading a protected compilation of Swedish geographic information to a cloud service outside Sweden counts as 'spreading' it under Lag (2016:319)
The statute does not define 'sprida' and we found no published decision or official guidance on the point. Because breach is a criminal offence, this gap is material and should be resolved with Lantmäteriet before designing such a system.
That Swedish banking, payments, insurance and securities regulation contains no data storage location requirement
This is a negative. We verified that the Swedish statutes complementing the European digital resilience regulation exist and impose no localisation, but Finansinspektionen's own website returned errors to automated fetching, so we could not check its circulars and guidance directly. Confidence medium.
Whether any Swedish preparedness rules for payments in crisis or war require domestic payment capability that amounts in practice to localisation
The Riksbank Act requires the central bank itself to keep payments working in crisis and at heightened readiness, but we could not confirm whether corresponding obligations on commercial banks require systems or data to be held in Sweden.
The full official text and legal status of the national cloud policy adopted on 28 May 2026
We evidenced its existence, date and non-binding character from a minister's written answer and an interpellation debate on parliament's own site, but the government's own publication page returned an error, so the policy text itself was not read. Rated medium confidence.
Whether the Bookkeeping Act's requirement to keep accounting records in Sweden has been amended or relaxed since the consolidated text we read
The consolidated statute on parliament's site still shows chapter 7 section 2 requiring storage in Sweden, with the notification and permission routes intact. Digitalisation reform in this area has been under discussion, so the position should be re-checked with the Swedish Tax Agency before relying on it.
90-day cadence: the statutory picture is stable and the regulator is active, but three things move — the national cloud policy could be reissued with binding procurement requirements at any time, the critical entities bill is due to commence on 1 January 2027, and the European Union-United States Data Privacy Framework is under appeal.
Freshness and refresh
Freshness
Checked today — on 18 August 2026.
Re-checked every 90 days. Next check due 16 November 2026.
Compare with
- Sweden versus Argentina
- Sweden versus Armenia
- Sweden versus Australia
- Sweden versus Austria
- Sweden versus Azerbaijan
- Sweden versus Brazil
- Sweden versus Bulgaria
- Sweden versus Cambodia
- Sweden versus Canada
- Sweden versus China
- Sweden versus Croatia
- Sweden versus Cyprus
- Sweden versus Estonia
- Sweden versus France
- Sweden versus Georgia
- Sweden versus Germany
- Sweden versus Greece
- Sweden versus Hong Kong SAR
- Sweden versus Hungary
- Sweden versus Iceland
- Sweden versus India
- Sweden versus Indonesia
- Sweden versus Ireland
- Sweden versus Israel
- Sweden versus Italy
- Sweden versus Japan
- Sweden versus Latvia
- Sweden versus Lithuania
- Sweden versus Luxembourg
- Sweden versus Malta
- Sweden versus Mexico
- Sweden versus Mongolia
- Sweden versus Nepal
- Sweden versus Netherlands
- Sweden versus Poland
- Sweden versus Russia
- Sweden versus Saudi Arabia
- Sweden versus Serbia
- Sweden versus Singapore
- Sweden versus Slovakia
- Sweden versus Slovenia
- Sweden versus South Korea
- Sweden versus Spain
- Sweden versus Sri Lanka
- Sweden versus Switzerland
- Sweden versus Taiwan
- Sweden versus Thailand
- Sweden versus Turkey
- Sweden versus Ukraine
- Sweden versus United Arab Emirates
- Sweden versus United Kingdom
- Sweden versus United States
- Sweden versus Uzbekistan