Skip to the content
Global Data RulesData governance rules, country by country

Sweden

Part of the European Union, so bloc-wide rules apply here too. Checked today.

The answer

Depends on your industryWork: HighEnforcement: Active

Sweden has no general law forcing data to stay in the country. Personal data leaves under the ordinary European rules. But four walls override that: gambling systems must sit in Sweden, telecoms records kept for the police may never leave the European Union, classified material needs a state-to-state deal, and accounting books stay in Sweden unless you tell the tax agency.

Eight questions about Sweden

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do Sweden's rules apply to my company?

Yes. Sweden applies the European privacy rules, so a company anywhere in the world is caught if it offers goods or services to people in Sweden or watches what they do. There is no size or revenue floor to duck under. Sweden's own top-up law adds Swedish-only duties on top, and those apply to anyone processing data under Swedish law, not just Swedish companies. If you are outside Europe and caught, you normally have to name a representative inside Europe.

High confidenceNational rulesAppoint a local representative

Can I store my users' data outside Sweden?

In general, yes. Sweden has no law that says personal data must physically stay in Sweden, and European law actually bans Sweden from imposing storage rules on non-personal data except for national security reasons. The exceptions are what matter. Online gambling systems must be placed in Sweden. Telephone and internet records that operators keep for the police may not be stored outside the European Union. Security-classified material cannot go to a foreign body without a government-to-government agreement. And a Swedish company's accounting records must be kept in Sweden unless it tells the tax agency where they are instead.

High confidenceDepends on your industryNo restriction

What do I need in place before data leaves Sweden?

Sweden adds nothing of its own here — it uses the European toolkit unchanged. The model is an allowlist of approved destinations, and that list is well populated: the United Kingdom, Switzerland, Japan, South Korea, Canada, Brazil and about a dozen others are approved. For everywhere else you sign the European Commission's standard contract, or use group-wide rules approved by a regulator, and you write down why you think the data will still be safe. United States transfers work only if the receiving company has signed up to the European Union–United States Data Privacy Framework, and that arrangement is under legal pressure.

High confidenceAllowlistOfficial 'this country is safe' decisionStandard contract clausesApproved group rulesExplicit consent

Who enforces the rules in Sweden, and what can they do?

The main privacy regulator is the Swedish Authority for Privacy Protection, and it is fully staffed and working. It published supervisory decisions in May, June and July 2026, including a reprimand to a large security company over filming its own staff, and in June 2026 it was also made Sweden's market surveillance authority for the European artificial intelligence rules. Other regulators matter just as much in their own lanes: the financial supervisor, the telecoms and post authority, the gambling authority, the Security Service and the Armed Forces.

High confidenceActive

How long do I have to keep the data?

Sweden has a hard floor and a soft ceiling, and they pull in opposite directions. You must keep company accounting records for seven years after the end of the year they relate to, and patient records for at least ten years after the last entry. Against that, European privacy law says you must delete personal data once you no longer need it. Sweden resolves the clash the same way most of Europe does: a specific legal duty to keep something beats the general duty to delete it, so you keep it, lock it down and use it for nothing else.

High confidenceKeep data for a minimum periodDelete data after a periodKeep the data in the countryKeep logs

What happens if there is a breach?

Count at least three clocks, and they do not agree. For a personal data breach you have 72 hours to tell the privacy regulator, and you must tell the affected people without undue delay if the risk to them is high. Since 15 January 2026, organisations in important sectors must send an early warning to their cybersecurity supervisor within 24 hours of noticing a significant incident, then a fuller report within 72 hours — but trust service providers get only 24 hours for the full report. Financial firms have a fourth clock under the European digital resilience rules. The 24-hour warning is the one that catches people out.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What trips people up in Sweden?

Five things that are not in any summary. One: a child can consent from age 13 in Sweden, the youngest age Europe allows, so a global default of 16 is wrong here. Two: you may only use a person's Swedish identity number without their consent when it is clearly justified — a Swedish-only rule with no European equivalent. Three: anything you send to a Swedish public authority can become a public document that any member of the public, including a competitor or a journalist, can demand a copy of. Four: giving a supplier access to a public authority's secret files is allowed only for purely technical processing or storage, and only if it is not inappropriate in the circumstances — the ordinary supplier contract is not enough. Five: mapping and sea-depth data is criminal law, not paperwork — spreading it without a permit can mean up to a year in prison.

High confidenceGet a parent's consent for childrenExtra vendor secrecy termsWritten vendor contractCriminal liability

What is changing soon in Sweden?

Two dated items. On 1 January 2027 a new law on the resilience of critical operators is proposed to start, covering eleven sectors and adding another 24-hour incident report. Also on 12 January 2027, European rules make it illegal for cloud providers to charge you to move your data out. Watch the government's national cloud policy, adopted on 28 May 2026: today it is only advice with no penalties, but it is the obvious vehicle for a future rule that public bodies must use European providers.

High confidenceProposedMake switching cloud provider possible

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    Bloc rules

    Made by a group of countries together. Applies inside every member country.

    2 rules here

  2. Layer 2

    National rules

    Added by this country on top of any bloc rules.

    4 rules here

  3. Layer 3

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    8 rules here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

Bloc rules2 rules

EU:s dataskyddsförordning (General Data Protection Regulation)

Directly binding regulation · Regulation (EU) 2016/679

In forceYes, with paperwork

The European privacy law that forms Sweden's base layer. It does not require data to stay in Europe; it sets conditions for data leaving. Approved destinations need nothing extra, everywhere else needs a standard contract or group-wide rules plus a written risk assessment.

In force since 25 May 2018

Enforced by Swedish Authority for Privacy Protection

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims

High confidence

Förordning om fri rörlighet för andra data än personuppgifter

Directly binding regulation · Regulation (EU) 2018/1807

In forceYes — store it anywhere

European law that actively forbids Sweden from making non-personal data stay in the country, except where it can justify the rule on public security grounds. This is why Sweden's remaining storage rules are framed around gambling supervision, law enforcement, protective security and tax control rather than as general localisation.

In force since 28 May 2019

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

National rules4 rules

Lag (2018:218) med kompletterande bestämmelser till EU:s dataskyddsförordning

Act of parliament · SFS 2018:218

In forceYes, with paperwork

Sweden's national top-up to the European privacy law. It imposes no storage location rule. Its two distinctive rules are an age of digital consent of 13 and a restriction on using a person's Swedish identity number without consent. It also caps fines on public authorities at 5 and 10 million Swedish kronor (roughly 500,000 and 1 million US dollars).

In force since 25 May 2018

Enforced by Swedish Authority for Privacy Protection

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules

High confidence

Cybersäkerhetslag (2025:1506)

Act of parliament · SFS 2025:1506, with Cybersäkerhetsförordning (2025:1507)

In forceYes — store it anywhere

Sweden's implementation of the European cybersecurity directive, in force since 15 January 2026. It sets no storage location rule but adds a 24-hour early warning duty, a registration duty and, unusually, the power to bar a named person from a management role for up to three years.

In force since 15 January 2026

Enforced by Swedish Post and Telecom Authority

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Bokföringslagen (1999:1078), 7 kap.

Act of parliament · SFS 1999:1078, chapter 7 sections 2, 3, 3a and 4

In forceYes, with paperwork

The Swedish rule almost everyone misses. A company's accounting records must be kept in Sweden for seven years. Electronic records may sit in another European Union country if you tell the Swedish Tax Agency where they are, give it immediate online access and can print them in Sweden. Outside the European Union you need a mutual assistance arrangement or the Tax Agency's specific permission.

In force since 1 January 2000

Enforced by Swedish Tax Agency

Transfer model: Approval each time · Accepted routes: Government sign-off needed, Nothing required

High confidence

Industry rules8 rules

Förordning (2022:511) om elektronisk kommunikation, 9 kap. 4 §

Directly binding regulation · SFS 2022:511, under Lag (2022:482) om elektronisk kommunikation, 9 kap. 19 § · Telecoms

In forceNo — it stays put

A genuine, absolute storage wall. Telephone and internet records that Swedish operators must keep so the police can request them may not be stored outside the European Union at all. There is no consent, contract or approval route around it.

In force since 3 August 2022

Enforced by Swedish Post and Telecom Authority

Transfer model: Not allowed

High confidence

Spellagen (2018:1138), 16 kap. 2 §

Act of parliament · SFS 2018:1138 · Online gaming

In forceNo — it stays put

The hardest location rule in Swedish law. A gambling licensee's gaming system must be placed in Sweden. Two ways out exist: hold a licence in another supervised country whose regulator has an agreement with the Swedish Gambling Authority, or give the Swedish Gambling Authority remote access to the system. Both are in the regulator's gift and can be withdrawn.

In force since 1 January 2019

Enforced by Swedish Gambling Authority

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence

Säkerhetsskyddslagen (2018:585) och Säkerhetsskyddsförordningen (2021:955)

Act of parliament · SFS 2018:585 chapter 4 sections 1, 9 and 11; SFS 2021:955 chapter 3 sections 2 and 9 · Defence

In forceNo — it stays put

If any part of your business is security-sensitive, this overrides everything else. You must sign a protective security agreement before a supplier gets access, consult the Security Service in writing before deploying a system that handles classified information, and the supervisor can simply forbid a planned cloud deal. Sending classified material to a foreign body needs a government-to-government undertaking, not a commercial contract.

In force since 1 April 2019But only enforceable from 1 December 2021

Enforced by Swedish Security Service

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence

Who you would hear from

  • Integritetsskyddsmyndigheten (IMY)

    Data protection, camera surveillance, credit reporting; market surveillance for the EU AI Regulation since June 2026

    Fully staffed and issuing decisions. Its public register showed supervisory decisions dated 27 May, 16 June, 2 July and 3 July 2026. Fines are frequent but moderate; national law caps penalties on public authorities at 5 and 10 million Swedish kronor.

  • Post- och telestyrelsen (PTS)

    Telecoms and postal services, digital infrastructure, digital service providers and IT service management under the Cybersecurity Act; supports the national cloud policy

  • Försvarets radioanstalt (FRA)

    National computer security incident response team, single point of contact and cyber crisis management authority under the Cybersecurity Ordinance; hosts the national cybersecurity centre

    Designated by Cybersäkerhetsförordning (2025:1507), in force 15 January 2026, and by Förordning (2025:237) on the national cybersecurity centre.

  • Säkerhetspolisen

    Protective security supervision for most civil sectors; can prohibit a planned outsourcing involving security-sensitive activity

  • Försvarsmakten

    Protective security supervision in the defence sector; permits for hydrographic surveying and aerial photography

  • Finansinspektionen

    Banking, payments, insurance and securities; digital operational resilience; cybersecurity supervision for banking and financial market infrastructure

  • Spelinspektionen

    Gambling licensing, including where the gaming system may be located

  • Skatteverket

    Notifications and permissions for keeping accounting records outside Sweden

  • Lantmäteriet

    Dissemination permits for geographic information gathered from aircraft; also one of four state IT service provider agencies

  • Sjöfartsverket

    Dissemination permits for geographic information about Swedish waters

  • Inspektionen för vård och omsorg (IVO)

    Healthcare providers, including cybersecurity supervision under the Cybersecurity Act

  • Försäkringskassan

    Coordinating agency for shared secure state IT operations under Förordning (2024:1005)

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • The exact retention periods, in months, for each category of telecoms data Swedish operators must keep for law enforcement

    The European Union storage ban is in Förordning (2022:511) chapter 9 section 4, which we read directly, but the periods sit in chapter 9 of Lag (2022:482) and in the Post and Telecom Authority's own regulations. The parliament's full-text service truncated the statute before chapter 9 and the authority's site refused automated fetching. The location rule is high confidence; the durations are not stated in this record.

  • Whether the commencement date of the technical-processing exception in the secrecy act (chapter 10 section 2 a, inserted by Lag (2023:335)) is 1 July 2023

    The consolidated statute text shows the amending act number but not its commencement date, and we could not open the amending act itself. The provision is certainly in force today; only the start date is inferred from normal Swedish practice.

  • Whether uploading a protected compilation of Swedish geographic information to a cloud service outside Sweden counts as 'spreading' it under Lag (2016:319)

    The statute does not define 'sprida' and we found no published decision or official guidance on the point. Because breach is a criminal offence, this gap is material and should be resolved with Lantmäteriet before designing such a system.

  • That Swedish banking, payments, insurance and securities regulation contains no data storage location requirement

    This is a negative. We verified that the Swedish statutes complementing the European digital resilience regulation exist and impose no localisation, but Finansinspektionen's own website returned errors to automated fetching, so we could not check its circulars and guidance directly. Confidence medium.

  • Whether any Swedish preparedness rules for payments in crisis or war require domestic payment capability that amounts in practice to localisation

    The Riksbank Act requires the central bank itself to keep payments working in crisis and at heightened readiness, but we could not confirm whether corresponding obligations on commercial banks require systems or data to be held in Sweden.

  • The full official text and legal status of the national cloud policy adopted on 28 May 2026

    We evidenced its existence, date and non-binding character from a minister's written answer and an interpellation debate on parliament's own site, but the government's own publication page returned an error, so the policy text itself was not read. Rated medium confidence.

  • Whether the Bookkeeping Act's requirement to keep accounting records in Sweden has been amended or relaxed since the consolidated text we read

    The consolidated statute on parliament's site still shows chapter 7 section 2 requiring storage in Sweden, with the notification and permission routes intact. Digitalisation reform in this area has been under discussion, so the position should be re-checked with the Swedish Tax Agency before relying on it.

90-day cadence: the statutory picture is stable and the regulator is active, but three things move — the national cloud policy could be reissued with binding procurement requirements at any time, the critical entities bill is due to commence on 1 January 2027, and the European Union-United States Data Privacy Framework is under appeal.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 90 days. Next check due 16 November 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.