Skip to the content
Global Data RulesData governance rules, country by country

Sweden

Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Sweden — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: HighEnforcement: Active

Sweden has no general law forcing data to stay in the country. Personal data leaves under the ordinary European rules. But four rules override that. Gambling systems must sit in Sweden. Telecoms records kept for the police may never leave the European Union. Classified material needs a state-to-state deal. And accounting books stay in Sweden unless you tell the tax agency.

Data governance in Sweden

The eight things that decide how you handle data about people in Sweden. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. Sweden applies the European privacy rules. A company anywhere in the world is caught if it offers goods or services to people in Sweden, or watches what they do. There is no size or revenue floor to duck under. Sweden's own top-up law adds Swedish-only duties on top. Those apply to anyone handling data under Swedish law, not just Swedish companies. If you are outside Europe and caught, you normally have to name a representative inside Europe.

What you have to do here:
Appoint a representative

Where the data is allowed to live

In general, yes. No Swedish law says personal data must physically stay in Sweden. European law even bans Sweden from making non-personal data stay here, except for national security reasons. The exceptions are what matter. Online gambling systems must be placed in Sweden. Telephone and internet records that operators keep for the police may not be stored outside the European Union. Security-classified material cannot go to a foreign body without a government-to-government agreement. And a Swedish company's accounting records must be kept in Sweden, unless it tells the tax agency where they are instead.

What to do: Check your own industry against the restricted list before you pick a hosting region.

Sending data out of the country

Sweden adds nothing of its own here. It uses the European rules unchanged. You can send data freely to approved countries only, and that approved list is long. The United Kingdom, Switzerland, Japan, South Korea, Canada, Brazil and about a dozen others are approved. For everywhere else you sign the European Commission's standard contract, or use group-wide rules approved by a regulator. You also write down why you think the data will still be safe. Transfers to the United States work only if the receiving company has signed up to the European Union–United States Data Privacy Framework. That arrangement is under legal pressure.

Ways to send data out:
Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Explicit consent

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

The regulator, and whether it actually acts

The main privacy regulator is the Swedish Authority for Privacy Protection. It is fully staffed and working. It published supervision decisions in May, June and July 2026. One was a reprimand to a large security company for filming its own staff. In June 2026 it also became Sweden's market surveillance authority for the European artificial intelligence rules. Other regulators matter just as much in their own areas. Those are the financial supervisor, the telecoms and post authority, the gambling authority, the Security Service and the Armed Forces.

How long you must keep it — and when to delete it

Sweden has a firm minimum and a soft maximum, and they pull in opposite directions. You must keep company accounting records for seven years after the end of the year they relate to. You must keep patient records for at least ten years after the last entry. Against that, European privacy law says you must delete personal data once you no longer need it. Sweden settles the clash the way most of Europe does. A specific legal duty to keep something beats the general duty to delete it. So you keep it, lock it down, and use it for nothing else.

What you have to do here:
Keep data for a minimum period · Delete data after a period

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

Count at least three deadlines, and they do not agree. For a personal data breach you have 72 hours to tell the privacy regulator. You must tell the affected people without undue delay if the risk to them is high. Since 15 January 2026, organisations in important industries must send an early warning to their cybersecurity supervisor within 24 hours of noticing a significant incident. A fuller report follows within 72 hours. Trust service providers get only 24 hours for the full report. Financial firms have a fourth deadline under the European digital resilience rules. The 24-hour warning is the one that catches people out.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things that are not in any summary. One. A child can consent from age 13 in Sweden, the youngest age Europe allows, so a global default of 16 is wrong here. Two. You may only use a person's Swedish identity number without their consent when it is clearly justified. That is a Swedish-only rule with no European equivalent. Three. Anything you send to a Swedish public authority can become a public document. Any member of the public can then demand a copy, including a competitor or a journalist. Four. Giving a supplier access to a public authority's secret files is allowed only for purely technical handling or storage. It must also not be inappropriate in the circumstances. An ordinary supplier contract is not enough. Five. Mapping and sea-depth data is criminal law, not paperwork. Spreading it without a permit can mean up to a year in prison.

What you have to do here:
Get a parent's consent for children · Extra vendor secrecy terms · Written vendor contract
What it costs if you get it wrong:
Criminal liability

What's changing next

Two dated items. A new law on the resilience of critical operators is proposed to start on 1 January 2027. It would cover eleven industries and add another 24-hour incident report. Then on 12 January 2027, European rules make it illegal for cloud providers to charge you to move your data out. Also watch the government's national cloud policy, adopted on 28 May 2026. Today it is only advice, with no penalties. But it is the obvious vehicle for a future rule that public bodies must use European providers.

What you have to do here:
Make switching cloud provider possible

What to do: Diarise 1 January 2027 — that is the date this changes.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries8 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Telecoms

Telecoms data must stay in the country

Official name: Förordning (2022:511) om elektronisk kommunikation, 9 kap. 4 § · SFS 2022:511, under Lag (2022:482) om elektronisk kommunikation, 9 kap. 19 § · Directly binding regulation

In forceNo — it stays put

An absolute rule with no way around it. Telephone and internet records that Swedish operators must keep so the police can request them may not be stored outside the European Union at all. There is no consent, contract or approval route around it.

In force since 3 August 2022

Enforced by Swedish Post and Telecom Authority

How this country controls where data goes: Not allowed

Online gaming

Online gaming data rules

Official name: Spellagen (2018:1138), 16 kap. 2 § · SFS 2018:1138 · Act of parliament

In forceNo — it stays put

The strictest location rule in Swedish law. A gambling licence holder's gaming system must be placed in Sweden. There are two ways out. Hold a licence in another supervised country whose regulator has an agreement with the Swedish Gambling Authority. Or give the Swedish Gambling Authority remote access to the system. The regulator grants both, and it can withdraw both.

In force since 1 January 2019

Enforced by Swedish Gambling Authority

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Defence

Cloud and outsourcing rules

Official name: Säkerhetsskyddslagen (2018:585) och Säkerhetsskyddsförordningen (2021:955) · SFS 2018:585 chapter 4 sections 1, 9 and 11; SFS 2021:955 chapter 3 sections 2 and 9 · Act of parliament

In forceNo — it stays put

If any part of your business is security-sensitive, this overrides everything else. You must sign a protective security agreement before a supplier gets access. You must consult the Security Service in writing before deploying a system that handles classified information. The supervisor can simply forbid a planned cloud deal. Sending classified material to a foreign body needs a government-to-government undertaking, not a commercial contract.

In force since 1 April 2019Enforced from 1 December 2021

Enforced by Swedish Security Service

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Applies to every company4 rules

These bind you whatever business you are in, once the country's rules reach you.

General data protection law

Official name: Lag (2018:218) med kompletterande bestämmelser till EU:s dataskyddsförordning · SFS 2018:218 · Act of parliament

In forceYes, with paperwork

Sweden's national top-up to the European privacy law. It sets no rule about where data must be stored. Its two distinctive rules are an age of digital consent of 13, and a limit on using a person's Swedish identity number without consent. It also caps fines on public authorities at 5 and 10 million Swedish kronor (roughly 500,000 and 1 million US dollars).

In force since 25 May 2018

Enforced by Swedish Authority for Privacy Protection

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules

Cyber security rules

Official name: Cybersäkerhetslag (2025:1506) · SFS 2025:1506, with Cybersäkerhetsförordning (2025:1507) · Act of parliament

In forceYes — store it anywhere

Sweden's version of the European cybersecurity directive, in force since 15 January 2026. It sets no rule about where data must be stored. It adds a 24-hour early warning duty and a registration duty. Unusually, it also lets the regulator bar a named person from a management role for up to three years.

In force since 15 January 2026

Enforced by Swedish Post and Telecom Authority

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Record-keeping rules for tax and accounts (2000)

Official name: Bokföringslagen (1999:1078), 7 kap. · SFS 1999:1078, chapter 7 sections 2, 3, 3a and 4 · Act of parliament

In forceYes, with paperwork

The Swedish rule almost everyone misses. A company's accounting records must be kept in Sweden for seven years. Electronic records may sit in another European Union country. You must tell the Swedish Tax Agency where they are, give it immediate online access, and be able to print them in Sweden. Outside the European Union you need a mutual assistance arrangement or the Tax Agency's specific permission.

In force since 1 January 2000

Enforced by Swedish Tax Agency

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed, Nothing required

Applies across the European Union2 rules

Written once for the whole bloc, and in force in every member country.

Europe's main privacy law

Official name: EU:s dataskyddsförordning (General Data Protection Regulation) · Regulation (EU) 2016/679 · Directly binding regulation

In forceYes, with paperwork

The European privacy law that forms Sweden's base layer. It does not require data to stay in Europe. It sets conditions for data leaving. Approved destinations need nothing extra. Everywhere else needs a standard contract or group-wide rules, plus a written risk assessment.

In force since 25 May 2018

Enforced by Swedish Authority for Privacy Protection

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims

Record-keeping rules for tax and accounts

Official name: Förordning om fri rörlighet för andra data än personuppgifter · Regulation (EU) 2018/1807 · Directly binding regulation

In forceYes — store it anywhere

European law that actively forbids Sweden from making non-personal data stay in the country. The only exception is where Sweden can justify the rule on public security grounds. That is why Sweden's remaining storage rules are built around gambling supervision, law enforcement, protective security and tax control. There is no general rule that data must stay here.

In force since 28 May 2019

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Who you would hear from

  • Integritetsskyddsmyndigheten (IMY)

    Data protection, camera surveillance, credit reporting; market surveillance for the EU AI Regulation since June 2026

    Fully staffed and issuing decisions. Its public register showed supervision decisions dated 27 May, 16 June, 2 July and 3 July 2026. Fines are frequent but moderate. National law caps fines on public authorities at 5 and 10 million Swedish kronor.

  • Post- och telestyrelsen (PTS)

    Telecoms and postal services, digital infrastructure, digital service providers and IT service management under the Cybersecurity Act; supports the national cloud policy

  • Försvarets radioanstalt (FRA)

    National computer security incident response team, single point of contact and cyber crisis management authority under the Cybersecurity Ordinance; hosts the national cybersecurity centre

    Designated by Cybersäkerhetsförordning (2025:1507), in force 15 January 2026, and by Förordning (2025:237) on the national cybersecurity centre.

  • Säkerhetspolisen

    Protective security supervision for most civil sectors; can prohibit a planned outsourcing involving security-sensitive activity

  • Försvarsmakten

    Protective security supervision in the defence sector; permits for hydrographic surveying and aerial photography

  • Finansinspektionen

    Banking, payments, insurance and securities; digital operational resilience; cybersecurity supervision for banking and financial market infrastructure

  • Spelinspektionen

    Gambling licensing, including where the gaming system may be located

  • Skatteverket

    Notifications and permissions for keeping accounting records outside Sweden

  • Lantmäteriet

    Dissemination permits for geographic information gathered from aircraft; also one of four state IT service provider agencies

  • Sjöfartsverket

    Dissemination permits for geographic information about Swedish waters

  • Inspektionen för vård och omsorg (IVO)

    Healthcare providers, including cybersecurity supervision under the Cybersecurity Act

  • Försäkringskassan

    Coordinating agency for shared secure state IT operations under Förordning (2024:1005)

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • The exact retention periods, in months, for each category of telecoms data Swedish operators must keep for law enforcement

    We could not confirm how long telecoms data must be kept for each type of data. The ban on storing it outside the European Union is in Förordning (2022:511) chapter 9 section 4, which we read directly. The periods themselves sit in chapter 9 of Lag (2022:482) and in the Post and Telecom Authority's own rules, which we could not read. Treat the location rule as solid, and check the periods with the authority.

  • Whether the commencement date of the technical-processing exception in the secrecy act (chapter 10 section 2 a, inserted by Lag (2023:335)) is 1 July 2023

    We could not confirm the exact date this rule started. The combined statute text names the amending act but not its start date, and we could not open that act. The rule is certainly in force today. Only the start date is worked out from normal Swedish practice.

  • Whether uploading a protected compilation of Swedish geographic information to a cloud service outside Sweden counts as 'spreading' it under Lag (2016:319)

    We could not confirm what counts as 'spreading' this data. The law does not define the Swedish word 'sprida', and we found no published decision or official guidance. Breaking this rule is a crime, so the gap matters. Settle it with Lantmäteriet before you design such a system.

  • That Swedish banking, payments, insurance and securities regulation contains no data storage location requirement

    We found no rule requiring financial data to stay in Sweden. We confirmed that the Swedish laws sitting alongside the European digital resilience regulation say nothing about where data must be stored. We could not read Finansinspektionen's own circulars and guidance. Our confidence is medium. If you are a financial firm, check with Finansinspektionen.

  • Whether any Swedish preparedness rules for payments in crisis or war require domestic payment capability that amounts in practice to localisation

    We could not confirm whether commercial banks must hold systems or data in Sweden. The Riksbank Act requires the central bank itself to keep payments working in a crisis and at heightened readiness. Whether the matching duties on commercial banks go that far is unclear. Check with your supervisor.

  • The full official text and legal status of the national cloud policy adopted on 28 May 2026

    We could not read the text of this policy. We confirmed that it exists, its date, and that it is not binding, from a minister's written answer and a parliamentary debate on parliament's own site. The government's own publication page would not open. Our confidence is medium.

  • Whether the Bookkeeping Act's requirement to keep accounting records in Sweden has been amended or relaxed since the consolidated text we read

    The combined statute on parliament's site still shows chapter 7 section 2 requiring storage in Sweden. The notification and permission routes are intact. Reform in this area has been under discussion. Check the position with the Swedish Tax Agency before you rely on it.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 90 days. Next check due 16 November 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.