Sweden Data Protection Act (Dataskyddslag, 2018:218)
Evidence request list. 18 controls, 18 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Breach
Per Swedish DPA: 72-hr breach + IMY enforcement.
- Sweden DPA evidence for SWEDEN-4
- personal ID processing + IMY partial
Restrictions and Exemptions
Exemptions for journalistic, academic, artistic, and literary purposes
- Consent capture records with timestamps and scope
- Data subject request log with response evidence
- Privacy notice versions with change history
- Content moderation policy with appeal pathways
- Moderation decision logs and reviewer training records
- Transparency report on takedowns and reinstatements
- Consent capture mechanisms do not record granularity required by law
- Data subject request workflow exceeds statutory response deadlines
- Moderation outcomes not consistently logged with rationale
- Appeal mechanism response times exceed published commitments
Permitted restrictions on GDPR data subject rights under Swedish law
- Consent capture records with timestamps and scope
- Data subject request log with response evidence
- Privacy notice versions with change history
- Consent capture mechanisms do not record granularity required by law
- Data subject request workflow exceeds statutory response deadlines
- Documentation exists but lacks evidence of periodic refresh
Rights
Per Swedish DPA: GDPR rights + sensitive categories handling.
- Sweden DPA evidence for SWEDEN-2
- personal ID processing + IMY partial
Scope
Per Sweden Dataskyddslag 2018:218: scope + GDPR + national supplements including processing of personal identity numbers + public interest tasks.
- Sweden DPA evidence for SWEDEN-1
- personal ID processing + IMY partial
Scope and Relationship to GDPR
Supplementary provisions to the EU GDPR governing data protection in Sweden
- Statutory mapping document linking definitions to internal terms
- Scope statement signed by accountable owner
- Glossary version control with effective dates
- AI system inventory with risk classification
- Model evaluation reports including bias and safety testing
- AI ethics committee review records
- Internal terminology drifts from statutory definitions
- Scope statement not refreshed after recent acquisitions or divestments
- AI inventory missing shadow deployments by business units
- Bias and safety testing not performed at required cadence
Defines the relationship between the Act and the EU General Data Protection Regulation
- AI system inventory with risk classification
- Model evaluation reports including bias and safety testing
- AI ethics committee review records
- AI inventory missing shadow deployments by business units
- Bias and safety testing not performed at required cadence
- Documentation exists but lacks evidence of periodic refresh
Security
Per Swedish DPA: security + cross-border + DPO + IMY (Integritetsskyddsmyndigheten) cooperation.
- Sweden DPA evidence for SWEDEN-3
- personal ID processing + IMY partial
Sensitive Data and National Identifiers
Conditions for processing special categories of data under Swedish law
- Approved policy or procedure document covering the requirement
- Operational records demonstrating implementation
- Periodic internal review evidencing ongoing compliance
- Training or awareness records for accountable personnel
- Documentation exists but lacks evidence of periodic refresh
- Roles assigned without measurable performance accountabilities
- Audit trail incomplete for key control activities
Conditions for processing personal identity numbers and coordination numbers
- Access provisioning and review records
- Multi-factor authentication configuration evidence
- Privileged access management logs
- Documentation exists but lacks evidence of periodic refresh
- Roles assigned without measurable performance accountabilities
- Audit trail incomplete for key control activities
Processing of data relating to criminal convictions and offences
- Penalty exposure register with mitigation actions
- Sanction history log and remediation evidence
- Legal review memoranda on enforcement risk
- Enforcement risk register reactive rather than predictive
- Legal hold processes not aligned with sanctions register triggers
- Documentation exists but lacks evidence of periodic refresh
Supervisory Authority and Sanctions
The Swedish Authority for Privacy Protection as the supervisory authority
- Internal audit charter and annual audit plan
- Audit working papers and finding registers
- Supervisory correspondence and response logs
- ISO management system documentation
- External certification reports and surveillance audit findings
- Nonconformity register with closure evidence
- Documentation exists but lacks evidence of periodic refresh
- Roles assigned without measurable performance accountabilities
- Audit trail incomplete for key control activities
Powers of the supervisory authority to investigate and enforce compliance
- Internal audit charter and annual audit plan
- Audit working papers and finding registers
- Supervisory correspondence and response logs
- ISO management system documentation
- External certification reports and surveillance audit findings
- Nonconformity register with closure evidence
- Documentation exists but lacks evidence of periodic refresh
- Roles assigned without measurable performance accountabilities
- Audit trail incomplete for key control activities
Administrative fines that IMY may impose on public authorities for violations
- Penalty exposure register with mitigation actions
- Sanction history log and remediation evidence
- Legal review memoranda on enforcement risk
- Enforcement risk register reactive rather than predictive
- Legal hold processes not aligned with sanctions register triggers
- Documentation exists but lacks evidence of periodic refresh
Framework for determining and imposing administrative penalties
- Penalty exposure register with mitigation actions
- Sanction history log and remediation evidence
- Legal review memoranda on enforcement risk
- Enforcement risk register reactive rather than predictive
- Legal hold processes not aligned with sanctions register triggers
- Documentation exists but lacks evidence of periodic refresh
Swedish Legal Bases
Conditions under which legal obligation constitutes a legal basis for processing personal data
- Approved policy or procedure document covering the requirement
- Operational records demonstrating implementation
- Periodic internal review evidencing ongoing compliance
- Training or awareness records for accountable personnel
- Documentation exists but lacks evidence of periodic refresh
- Roles assigned without measurable performance accountabilities
- Audit trail incomplete for key control activities
Rules for processing necessary for task carried out in the public interest or official authority
- Refusal decision register with statutory basis cited
- Third-party consultation correspondence
- Public interest override assessment records
- Documentation exists but lacks evidence of periodic refresh
- Roles assigned without measurable performance accountabilities
- Audit trail incomplete for key control activities
General provision for processing representing an important public interest based on balancing test
- Refusal decision register with statutory basis cited
- Third-party consultation correspondence
- Public interest override assessment records
- Documentation exists but lacks evidence of periodic refresh
- Roles assigned without measurable performance accountabilities
- Audit trail incomplete for key control activities
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.