Skip to content

Evidence request lists

Sweden Data Protection Act (Dataskyddslag, 2018:218)

Evidence request list. 18 controls, 18 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Breach

SWEDEN-4
Breach, Enforcement

Per Swedish DPA: 72-hr breach + IMY enforcement.

Artefacts an auditor will ask for
  • Sweden DPA evidence for SWEDEN-4
Where this commonly fails
  • personal ID processing + IMY partial

Restrictions and Exemptions

SWE-10
Freedom of Expression Exemption

Exemptions for journalistic, academic, artistic, and literary purposes

Artefacts an auditor will ask for
  • Consent capture records with timestamps and scope
  • Data subject request log with response evidence
  • Privacy notice versions with change history
  • Content moderation policy with appeal pathways
  • Moderation decision logs and reviewer training records
  • Transparency report on takedowns and reinstatements
Where this commonly fails
  • Consent capture mechanisms do not record granularity required by law
  • Data subject request workflow exceeds statutory response deadlines
  • Moderation outcomes not consistently logged with rationale
  • Appeal mechanism response times exceed published commitments
SWE-9
Restrictions on Rights

Permitted restrictions on GDPR data subject rights under Swedish law

Artefacts an auditor will ask for
  • Consent capture records with timestamps and scope
  • Data subject request log with response evidence
  • Privacy notice versions with change history
Where this commonly fails
  • Consent capture mechanisms do not record granularity required by law
  • Data subject request workflow exceeds statutory response deadlines
  • Documentation exists but lacks evidence of periodic refresh

Rights

SWEDEN-2
Data Subject Rights and Sensitive Categories

Per Swedish DPA: GDPR rights + sensitive categories handling.

Artefacts an auditor will ask for
  • Sweden DPA evidence for SWEDEN-2
Where this commonly fails
  • personal ID processing + IMY partial

Scope

SWEDEN-1
Scope, GDPR Implementation, Swedish Supplements

Per Sweden Dataskyddslag 2018:218: scope + GDPR + national supplements including processing of personal identity numbers + public interest tasks.

Artefacts an auditor will ask for
  • Sweden DPA evidence for SWEDEN-1
Where this commonly fails
  • personal ID processing + IMY partial

Scope and Relationship to GDPR

SWE-1
Scope and Purpose

Supplementary provisions to the EU GDPR governing data protection in Sweden

Artefacts an auditor will ask for
  • Statutory mapping document linking definitions to internal terms
  • Scope statement signed by accountable owner
  • Glossary version control with effective dates
  • AI system inventory with risk classification
  • Model evaluation reports including bias and safety testing
  • AI ethics committee review records
Where this commonly fails
  • Internal terminology drifts from statutory definitions
  • Scope statement not refreshed after recent acquisitions or divestments
  • AI inventory missing shadow deployments by business units
  • Bias and safety testing not performed at required cadence
SWE-2
Relationship to GDPR

Defines the relationship between the Act and the EU General Data Protection Regulation

Artefacts an auditor will ask for
  • AI system inventory with risk classification
  • Model evaluation reports including bias and safety testing
  • AI ethics committee review records
Where this commonly fails
  • AI inventory missing shadow deployments by business units
  • Bias and safety testing not performed at required cadence
  • Documentation exists but lacks evidence of periodic refresh

Security

SWEDEN-3
Security, Cross-Border, DPO

Per Swedish DPA: security + cross-border + DPO + IMY (Integritetsskyddsmyndigheten) cooperation.

Artefacts an auditor will ask for
  • Sweden DPA evidence for SWEDEN-3
Where this commonly fails
  • personal ID processing + IMY partial

Sensitive Data and National Identifiers

SWE-5
Sensitive Data Processing

Conditions for processing special categories of data under Swedish law

Artefacts an auditor will ask for
  • Approved policy or procedure document covering the requirement
  • Operational records demonstrating implementation
  • Periodic internal review evidencing ongoing compliance
  • Training or awareness records for accountable personnel
Where this commonly fails
  • Documentation exists but lacks evidence of periodic refresh
  • Roles assigned without measurable performance accountabilities
  • Audit trail incomplete for key control activities
SWE-6
Personal Identity Numbers (§3:1)

Conditions for processing personal identity numbers and coordination numbers

Artefacts an auditor will ask for
  • Access provisioning and review records
  • Multi-factor authentication configuration evidence
  • Privileged access management logs
Where this commonly fails
  • Documentation exists but lacks evidence of periodic refresh
  • Roles assigned without measurable performance accountabilities
  • Audit trail incomplete for key control activities
SWE-7
Criminal Convictions Data (§3:2)

Processing of data relating to criminal convictions and offences

Artefacts an auditor will ask for
  • Penalty exposure register with mitigation actions
  • Sanction history log and remediation evidence
  • Legal review memoranda on enforcement risk
Where this commonly fails
  • Enforcement risk register reactive rather than predictive
  • Legal hold processes not aligned with sanctions register triggers
  • Documentation exists but lacks evidence of periodic refresh

Supervisory Authority and Sanctions

SWE-11
Integritetsskyddsmyndigheten (IMY)

The Swedish Authority for Privacy Protection as the supervisory authority

Artefacts an auditor will ask for
  • Internal audit charter and annual audit plan
  • Audit working papers and finding registers
  • Supervisory correspondence and response logs
  • ISO management system documentation
  • External certification reports and surveillance audit findings
  • Nonconformity register with closure evidence
Where this commonly fails
  • Documentation exists but lacks evidence of periodic refresh
  • Roles assigned without measurable performance accountabilities
  • Audit trail incomplete for key control activities
SWE-12
Investigatory Powers

Powers of the supervisory authority to investigate and enforce compliance

Artefacts an auditor will ask for
  • Internal audit charter and annual audit plan
  • Audit working papers and finding registers
  • Supervisory correspondence and response logs
  • ISO management system documentation
  • External certification reports and surveillance audit findings
  • Nonconformity register with closure evidence
Where this commonly fails
  • Documentation exists but lacks evidence of periodic refresh
  • Roles assigned without measurable performance accountabilities
  • Audit trail incomplete for key control activities
SWE-13
Fines for Public Authorities (§6:2)

Administrative fines that IMY may impose on public authorities for violations

Artefacts an auditor will ask for
  • Penalty exposure register with mitigation actions
  • Sanction history log and remediation evidence
  • Legal review memoranda on enforcement risk
Where this commonly fails
  • Enforcement risk register reactive rather than predictive
  • Legal hold processes not aligned with sanctions register triggers
  • Documentation exists but lacks evidence of periodic refresh
SWE-14
Sanctions Framework

Framework for determining and imposing administrative penalties

Artefacts an auditor will ask for
  • Penalty exposure register with mitigation actions
  • Sanction history log and remediation evidence
  • Legal review memoranda on enforcement risk
Where this commonly fails
  • Enforcement risk register reactive rather than predictive
  • Legal hold processes not aligned with sanctions register triggers
  • Documentation exists but lacks evidence of periodic refresh

Swedish Legal Bases

SWE-3
Legal Obligation as Basis

Conditions under which legal obligation constitutes a legal basis for processing personal data

Artefacts an auditor will ask for
  • Approved policy or procedure document covering the requirement
  • Operational records demonstrating implementation
  • Periodic internal review evidencing ongoing compliance
  • Training or awareness records for accountable personnel
Where this commonly fails
  • Documentation exists but lacks evidence of periodic refresh
  • Roles assigned without measurable performance accountabilities
  • Audit trail incomplete for key control activities
SWE-4
Public Interest Processing

Rules for processing necessary for task carried out in the public interest or official authority

Artefacts an auditor will ask for
  • Refusal decision register with statutory basis cited
  • Third-party consultation correspondence
  • Public interest override assessment records
Where this commonly fails
  • Documentation exists but lacks evidence of periodic refresh
  • Roles assigned without measurable performance accountabilities
  • Audit trail incomplete for key control activities
SWE-8
Public Interest Balancing (§3:3)

General provision for processing representing an important public interest based on balancing test

Artefacts an auditor will ask for
  • Refusal decision register with statutory basis cited
  • Third-party consultation correspondence
  • Public interest override assessment records
Where this commonly fails
  • Documentation exists but lacks evidence of periodic refresh
  • Roles assigned without measurable performance accountabilities
  • Audit trail incomplete for key control activities
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.