Digital Operational Resilience Act (DORA)

๐Ÿ‡ธ๐Ÿ‡ชDigital Operational Resilience Act in Sweden

A comprehensive guide to Digital Operational Resilience Act compliance for organisations operating in Sweden. Understand local enforcement, the national data protection authority, key focus areas, and notable enforcement actions.

About Digital Operational Resilience Act

The EU regulation establishing a comprehensive framework for digital operational resilience in the financial sector, covering ICT risk management, incident reporting, testing, and third-party risk.

Effective: 17 January 2025Max penalty: โ‚ฌ5,000,000 for entities; โ‚ฌ500,000 for individuals or 2% of total annual worldwide turnover for critical ICT third-party providers
Full Digital Operational Resilience Act overview

Digital Operational Resilience Act Enforcement in Sweden

Sweden's IMY (formerly Datainspektionen) has built a reputation for thoughtful, precedent-setting enforcement. Sweden supplemented the GDPR with the Data Protection Act (2018:218) and the Data Protection Ordinance, which include Sweden's strong tradition of public transparency (the principle of public access to official documents). The IMY has been notably active in enforcement against facial recognition technology, camera surveillance, and the use of Google Analytics (finding it incompatible with GDPR following the Schrems II ruling). The IMY coordinates with Swedish municipalities and government agencies on large-scale compliance projects. Sweden sets the digital consent age at 13.

Data Protection Authority

Integritetsskyddsmyndigheten (IMY)

Key Enforcement Focus Areas in Sweden

  • Camera surveillance and facial recognition enforcement
  • Google Analytics and international data transfer rulings
  • Public sector transparency and data protection balance
  • Police and law enforcement data processing
  • Municipal and government agency compliance

Notable Enforcement Actions in Sweden

Spotify AB

โ‚ฌ5,000,000(2023)

Failing to adequately inform users about how their personal data was processed in response to access requests

Klarna Bank AB

โ‚ฌ720,000(2022)

Insufficient transparency about how customer personal data was used and shared

Swedish Police Authority

โ‚ฌ250,000(2021)

Unlawful use of Clearview AI facial recognition technology without legal basis or impact assessment

Skellefteรฅ Municipality

โ‚ฌ18,500(2019)

Piloting facial recognition in a school for attendance monitoring without valid legal basis

Check Your Compliance Status

Take our free assessment to evaluate your organisation's compliance posture. Get a personalised report with actionable recommendations in minutes โ€” no sign-up required.

Start Free Assessment

Disclaimer: The information on this page is for educational purposes and does not constitute legal advice. For specific compliance guidance, consult a qualified legal professional in your jurisdiction.

Other Regulations Affecting Sweden