Database

Browse Database

SWEDEN

Since April 2016, entry into force in May 2018
Since April 2018
Since April 2019

Pillar Domestic data policies  |  Indicator Framework for data protection
General Data Protection Regulation (Regulation 2016/679)

Act with Supplementary Provisions to the GDPR (SFS 2018:218) (Lag (2018:218) med kompletterande bestämmelser till EU:s dataskyddsförordning)

Ordinance with Supplementary Provisions to the GDPR (SFS 2018:219) (Förordning (2018:219) med kompletterande bestämmelser till EU:s dataskyddsförordning)
The European Union General Data Protection Regulation (GDPR) provides a comprehensive framework for data protection that applies to all EU Member States. The GDPR was implemented in Sweden through a variety of pieces of legislation including the Act with supplementary provisions to the GDPR (SFS 2018:218) and the Ordinance with Supplementary Provisions to the GDPR (SFS 2018:219).
Coverage Horizontal

SWEDEN

Since May 2006
In April 2014
Since May 2022
Since June 2003, as amended in 2019, until 2022

Pillar Domestic data policies  |  Indicator Minimum period for data retention
Data Retention Directive 2006/24/EC

Judgment European Court of Justice in Joined Cases C-293/12 and C-594/12 Digital Rights Ireland and Seitlinger and Others

Electronic Communications Act (SFS 2022:482) (Lag (2022:482) om elektronisk kommunikation)

Act (2003:389) on Electronic Communication (Lag (2003:389) om elektronisk kommunikation)
Under the EU Directive on Data Retention, operators were required to retain certain categories of traffic and location data (excluding the content of those communications) for a period between six months and two years and to make them available, on request, to law enforcement authorities for the purposes of investigating, detecting and prosecuting serious crime and terrorism. On 8 April 2014, the Court of Justice of the European Union declared the Directive invalid. However, not all national laws that implemented the Directive have been overturned.
In Sweden, Section 22 of Chapter 9 of the Electronic Communications Act (SFS 2022:482) stipulates minimum periods of retention for certain types of data in order to aid law enforcement. This requires, inter alia, that telecommunications operators retain internet access data for ten months, location information for two months, and call data for six months. These requirements were previously outlined in Section 16 d of Chapter 6 of the Act (2003:389) on Electronic Communication (as amended in 2019), which has been superseded by the 2022 Act.
Coverage Telecommunications sector

SWEDEN

Since July 2000
Since June 2002, entry into force in July 2002, last amended in December 2024

Pillar Intermediary liability  |  Indicator Safe harbour for intermediaries for copyright infringement
Directive 2000/31/EC (E-Commerce Directive)

Act on Electronic Commerce and Information Society Services (2002) (Lag (2002:562) om elektronisk handel och andra informationssamhällets tjänster)
The Directive 2000/31/EC (E-Commerce Directive) is the legal basis governing the liability of Internet Services Providers (ISPs) in the EU Member States and includes a conditional safe harbour. Not all Member States have transposed the relevant articles consistently, leading to divergent national case law that could cause legal insecurity on an EU level.
The Act on Electronic Commerce and Information Society Services (2002) implements Directive 2000/31/EC (E-Commerce Directive), however it fails to establish a conditional safe harbour for Internet Service Providers (ISPs) in Sweden.
Coverage Internet intermediaries

SWEDEN

Since July 2000
Since June 2002, entry into force in July 2002, last amended in December 2024

Pillar Intermediary liability  |  Indicator Safe harbour for intermediaries for any activity other than copyright infringement
Directive 2000/31/EC (E-Commerce Directive)

Act on Electronic Commerce and Information Society Services (2002) (Lag (2002:562) om elektronisk handel och andra informationssamhällets tjänster)
The Directive 2000/31/EC (E-Commerce Directive) is the legal basis governing the liability of Internet Services Providers (ISPs) in the EU Member States and includes a conditional safe harbour. Not all Member States have transposed the relevant articles consistently, leading to divergent national case law that could cause legal insecurity on an EU level.
The Act on Electronic Commerce and Information Society Services (2002) implements Directive 2000/31/EC (E-Commerce Directive), however it fails to establish a conditional safe harbour for Internet Service Providers (ISPs) in Sweden.
Coverage Internet intermediaries

SWEDEN

Since May 2022, as amended in August 2022

Pillar Intermediary liability  |  Indicator User identity requirement
Electronic Communications Act (SFS 2022:482) (Lag (2022:482) om elektronisk kommunikation)
As stipulated in Art. 24 of Law 2022:482 on Electronic Communications, as amended by the Swedish statute book (SFS) 2022:1086, any individual or entity offering an interpersonal communication service based on publicly available prepaid numbers or a prepaid Internet connection service is prohibited from providing access to the service without first registering the following details: (1) the name and postal address of the subscriber, (2) the subscriber's social security number, coordination number, organisation number, or other identification number, and (3) the number or other designation of the service. Additionally, the provider must record the time of registration, and this information must be retained and made available for up to one year after the cessation of service provision.
Coverage Providers of prepaid publicly available number-based interpersonal communication services and prepaid Internet access services

SWEDEN

Since April 2019

Pillar Intermediary liability  |  Indicator Monitoring requirement
Directive (EU) 2019/790 on copyright and related rights in the Digital Single Market and amending Directives 96/9/EC and 2001/29/EC
Art. 17 of Directive 2019/790 on Copyright in the Digital Single Market (DSM Directive) mandates that providers of content-sharing services seek authorisation from rights holders and implement technical solutions to remove and prevent unauthorised uploads by their users (so-called upload filters), under penalty of losing their liability safe harbour. Further arrangements are envisaged for complaints and dispute resolution mechanisms. Such upload filters are reported to be a significant cost for online platforms. Graduated exemptions are expected to be put in place for new providers active in the EU for less than three years with a turnover under EUR 10 million, and with fewer than five million users. The provision is subject to a challenge in the Court of Justice by Poland (C-401/19).
Sweden has not yet implemented the Directive 2019/790.
Coverage Online content sharing service

SWEDEN

Since March 1998

Pillar Intermediary liability  |  Indicator Monitoring requirement
Act on Responsibility for Electronic Bulletin Boards (1998:112)
The Act on Responsibility for Electronic Bulletin Board requires internet sites, where users can post comments about a particular issue or topic and reply to other users' postings (i.e. bulletin boards), to monitor the service regularly and to an extent that may reasonably be required taking into account the scope and nature of the service. An intentional or grossly negligent violation of the obligation to remove illegal content is considered as a criminal offence. The Act includes an information duty (Section 3), a supervision duty (Section 4), and a duty to erase certain messages (Section 5).
This is despite Art. 15 of Directive 2000/31/EC (e-Commerce Directive) stating that Member States should not impose on providers a general obligation to monitor the information which they transmit or store, nor a general obligation actively to seek facts or circumstances indicating illegal activity.
Coverage Online bulletin boards

SWEDEN

Since May 2018, last amended in October 2023

Pillar Quantitative trade restrictions for ICT goods and online services  |  Indicator Import ban applied on ICT goods or online services
Protective Security Act 2018 (Säkerhetsskyddslagen 2018)
The Protective Security Act, which was amended in 2019 to allow Swedish security and intelligence forces to recommend the revocation of operating licenses for firms in sectors important to national security if they are found to pose a security risk. The law was used in 2020 to ban Huawei and ZTE equipment from being used in the Swedish network. Specifically, the Swedish Post and Telecom Authority (PTS) has told telecommunications operators in Sweden vying for licensing rights at auction that bids including Huawei or ZTE equipment will not be considered, and pre-existing Huawei and ZTE infrastructure would need to be decommissioned by 2025. This effective ban on Huawei and ZTE equipment has been challenged in court, but so far, the decision has been upheld in the Swedish court.
Coverage Huawei and ZTE

SWEDEN

Since June 2016
Since May 2018

Pillar Intellectual Property Rights (IPRs)  |  Indicator Effective protection covering trade secrets
Directive (EU) 2016/943 of the European Parliament and of the Council of 8 June 2016 on the protection of undisclosed know-how and business information (trade secrets)

Act (2018:558) on Trade Secrets. (Lag (2018:558) om företagshemligheter)
The Directive 2016/943 on the protection of undisclosed know-how and business information (trade secrets) is key in harmonising national laws concerning trade secrets. Sweden transposed the Directive through a series of amendments to existing legislation as well as the Trade Secrets Act of 2018.
Coverage Horizontal

SWEDEN

Since May 2022

Pillar Telecom infrastructure & competition  |  Indicator Passive infrastructure sharing obligation
Electronic Communications Act (SFS 2022:482) (Lag (2022:482) om elektronisk kommunikation)
In Sweden, the sharing of passive infrastructure is mandated to support the delivery of telecommunications services to end users. Pursuant to Sections 15 and 16 of Chapter 5 of the Electronic Communications Act, operators classified as undertakings with significant market power may be required to comply with reasonable requests for access to and use of infrastructure essential for the construction of electronic communications networks, as well as networks and associated facilities necessary for providing electronic communications services.
Coverage Telecommunications sector

SWEDEN

Since 1993

Pillar Telecom infrastructure & competition  |  Indicator Presence of shares owned by the government in telecom companies
Presence of shares owned by the government in the telecom sector
The Swedish government owns a 39.5% stake in Telia, one of Sweden's largest telecommunications firms. The government had full ownership of Telia up until 2006, when Telia merged with Sonera, and the Swedish government's stake fell to 46%. They have since divested further, bringing the current stake to 39.5%
Coverage Telecommunications sector

SWEDEN

Since May 2022

Pillar Telecom infrastructure & competition  |  Indicator Functional/accounting separation for operators with significant market power
Electronic Communications Act (SFS 2022:482) (Lag (2022:482) om elektronisk kommunikation)
Sweden requires functional separation for operators with significant market power (SMP) in the telecommunications sector. Section 24 of Chapter 5 of the Electronic Communications Act provides that, in exceptional circumstances, the regulatory authority may require a vertically integrated operator, subject to an access obligation, to organisationally separate the activities related to that obligation. This separation must ensure that the activities are managed by an independent business unit. A vertically integrated operator is defined as an entity supplying services to undertakings with which it competes in downstream markets.
Coverage Telecommunications sector

SWEDEN

Since May 2018, last amended in October 2023

Pillar Telecom infrastructure & competition  |  Indicator Licensing restrictions to operate in the telecom market
Swedish Protective Security Act 2018 (Säkerhetsskyddslag (2018:585))
The Protective Security Act, which was amended in 2019 to allow Swedish security and intelligence forces to recommend the revocation of operating licenses for firms in sectors important to national security if they are found to pose a security risk, was used in 2020 to ban Huawei and ZTE equipment from being used in the Swedish network. Specifically, the Swedish Post and Telecom Authority (PTS) has told telecommunications operators in Sweden vying for licensing rights at auction that bids including Huawei or ZTE equipment will not be considered, and pre-existing Huawei and ZTE infrastructure would need to be decommissioned by 2025. This effective ban on Huawei and ZTE equipment has been challenged in court, but so far, the decision has been upheld in the Swedish court.
Coverage Huawei and ZTE

SWEDEN

Since March 2004, last amended in February 2014
Since December 2016
Since December 2016

Pillar Public procurement of ICT goods and online services  |  Indicator Other limitations on foreign participation in public procurement
Utilities Directive (2014/25/EU)

Law (2016:1146) on Procurement in the Utilities Sector (Lag (2016:1146) om upphandling inom försörjningssektorerna)

Procurement Regulations (Upphandlingsförordning (2016:1162)
Art. 85 of the Utilities Directive (2014/25/EU) contains provisions allowing contracting public entities to reject foreign goods not covered by any EU international commitments from its tender procedures. In these cases, a tender submitted for the award of a supply contract may be rejected where the proportion of the products originating in third countries exceeds 50% of the total value of the products constituting the tender (Art. 85.2). Additionally, in cases of equivalent offers, the provisions provide for a preference for European tenders and tenders covered by EU's international obligations. In practice, this possibility has rarely been used.
In Sweden, the Directive has been transposed with the Law (2016:1146) on Procurement in the Utilities Sector and the Procurement Regulations.
Coverage Any product sold to a utility provider including software used in telecommunication network equipment

SWEDEN

Since December 2023

Pillar Foreign Direct Investment (FDI) in sectors relevant to digital trade  |  Indicator Maximum foreign equity share
Act (2023:560) on the Screening of Foreign Direct Investments (Lag (2023:560) om granskning av utländska direktinvesteringar)
There are no foreign ownership limitations in sectors relevant for digital trade.
Coverage Horizontal

Report issue     Report new measure