FineME
Run assessment

Jurisdictional Intelligence · SE

Sweden

Active Nordic enforcer with strong scrutiny of healthcare, schools, and facial recognition.

Sweden's IMY inherits decades of data protection precedent — methodical, thorough, and consistent

Total Fines Tracked

€23.5M

EUR equivalent

Average Fine

€2.3M

per enforcement action

Top Sector

health

most-fined industry

Authorities

active regulators

Regulators

Authorities

No authority data yet.

Enforcement

Landmark Cases

View all

Region Uppsala

technology
IMY2023

IMY fined Region Uppsala after unauthorized staff access to patient records revealed inadequate access reviews and logging controls under GDPR Articles 5, 24 and 32.

€650,000.0

Kry International AB

technology
IMY2023

IMY investigated digital healthcare provider Kry over excessive employee access to patient records and insufficient logging controls, citing GDPR Articles 5, 24 and 32.

€900,000.0

Stockholm School of Economics

technology
IMY2022

IMY sanctioned the school for retaining student and alumni personal data longer than necessary and for incomplete information notices, implicating GDPR Articles 5, 13 and 14.

€180,000.0

Apoteket AB

technology
IMY2022

IMY fined Apoteket for insufficient access controls around prescription and customer data, finding failures to ensure confidentiality and role-based access under GDPR Articles 5 and 32.

€1.2M

H&M Hennes & Mauritz GBC AB

technology
IMY2021

IMY reviewed Swedish employee-data governance following broader H&M workforce monitoring concerns and emphasized purpose limitation, minimization, and lawful basis under GDPR Articles 5 and 6.

€350,000.0

Polismyndigheten

technology
IMY2021

IMY sanctioned the Swedish Police Authority for unlawful use of Clearview AI facial recognition searches without prior impact assessment, adequate instructions, or lawful basis, engaging GDPR Articles 5, 6, 35 and law-enforcement data protection rules.

€2.5M

Klarna Bank AB

technology
IMY2021

IMY fined Klarna for insufficient transparency in privacy notices, including incomplete information about recipients, retention periods, and data subject rights under GDPR Articles 12, 13 and 14.

€7.5M

1177 Vårdguiden

technology
IMY2020

IMY imposed sanctions after sensitive call recordings from the healthcare service 1177 were exposed online due to inadequate processor oversight and security controls, raising issues under GDPR Articles 5, 24, 28 and 32.

€3M

Google LLC

technology
IMY2020

IMY sanctioned Google for failing to properly comply with delisting requests under the right to erasure and for not adequately informing website operators when search results were removed, implicating GDPR Articles 5, 6, 17 and 19.

€7M

School Board of Skellefteå Municipality

technology
IMY2019

IMY fined a Swedish municipality for using facial recognition to monitor student attendance without a valid legal basis and without satisfying necessity and proportionality requirements for biometric processing under GDPR Articles 5, 6, 9 and 35.

€200,000.0

Legal Framework

Regulations by Domain

Marketplace

Regulatory Experts