{"id":146050,"date":"2026-08-11T09:53:15","date_gmt":"2026-08-11T09:53:15","guid":{"rendered":"https:\/\/my.legal500.com\/guides\/?post_type=comparative_guide&#038;p=146050"},"modified":"2026-08-11T09:53:15","modified_gmt":"2026-08-11T09:53:15","slug":"sweden-tmt","status":"publish","type":"comparative_guide","link":"https:\/\/my.legal500.com\/guides\/chapter\/sweden-tmt\/","title":{"rendered":"Sweden: TMT"},"content":{"rendered":"","protected":false},"template":"","class_list":["post-146050","comparative_guide","type-comparative_guide","status-publish","hentry","guides-tmt","jurisdictions-sweden"],"acf":[],"appp":{"post_list":{"below_title":"<div class=\"guide-author-details\"><span class=\"guide-author\">Hellstr\u00f6m Law<\/span><span class=\"guide-author-logo\"><img src=\"https:\/\/my.legal500.com\/guides\/wp-content\/uploads\/sites\/1\/2019\/03\/hellstrom-advokatbyra.jpg\"\/><\/span><\/div>"},"post_detail":{"above_title":"<div class=\"guide-author-details\"><span class=\"guide-author\">Hellstr\u00f6m Law<\/span><span class=\"guide-author-logo\"><img src=\"https:\/\/my.legal500.com\/guides\/wp-content\/uploads\/sites\/1\/2019\/03\/hellstrom-advokatbyra.jpg\"\/><\/span><\/div>","below_title":"<span class=\"guide-intro\">This country specific Q&amp;A provides an overview of TMT laws and regulations applicable in Sweden<\/span><div class=\"guide-content\"><div class=\"filter\">\r\n\r\n\t\t\t\t<input type=\"text\" placeholder=\"Search questions and answers...\" class=\"filter-container__search-field\">\r\n\t\t\t<\/div>\r\n\r\n\t\t\t\r\n\r\n\r\n\t\t\t<ol class=\"custom-counter\">\r\n\r\n\t\t\t\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software \u2013 How are proprietary rights in software and associated materials protected?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Proprietary rights in software are protected through several acts, the most relevant being the Patent Act (Sw. patentlagen (2024:945)), the Act on the Right to Employee\u00b4s Inventions (Sw. lagen om r\u00e4tten till arbetstagares uppfinningar (1949:345)), the Circuit Pattern Protection Act (Sw. lagen om skydd f\u00f6r kretsm\u00f6nster f\u00f6r halvledarprodukter (1986:1425)), the Industrial Secrets Act (Sw. lagen om f\u00f6retagshemligheter (2018:558)), and the Copyright Act (Sw. lagen om upphovsr\u00e4tt till litter\u00e4ra och konstn\u00e4rliga verk (1960:729)).<\/p>\n<p>A software program, being an idea, does not possess the technical character required for patent protection, and thus, it cannot be patented. A technical invention that is executed by software can however be patentable, thus resulting in an indirect protection of the software according to the Patent Act.<\/p>\n<p>However, according to chapter 1, section 1, second paragraph of the Copyright Act, the creator of a computer software will obtain copyright protection if it is original in the sense that it is an intellectual creation of the creator. The owner of computer software holds the same rights as the owner of literary books and poems.<\/p>\n<p>According to the Circuit Pattern Protection Act the creator of (or the employer if an employee creates a circuit pattern within the framework of the employment) a circuit pattern is protected according to sections 1 and 3 of the Act, if the pattern is the result of an intellectual performance and not generally occurring. The protection only covers the circuit pattern itself. The software program that is included in the pattern is not protected, however such programs may be protected by copyright.<\/p>\n<p>According to the Act on the Right to Employees\u2019 Inventions, section 2, an employee has the right to her\/his inventions as any other inventor unless, according to section 3 of the act, the employer uses its preferential right to take over the invention if the invention falls within the scope of the employer\u2019s area of business.<\/p>\n<p>Industrial secrets are defined in section 2 of the Industrial Secrets Act. Industrial secrets cannot be registered to be protected but must be kept secret.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software \u2013 In the event that software is developed by a software developer, consultant or other party for a customer, who will own the resulting proprietary rights in the newly created software in the absence of any agreed contractual position?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The creator of a computer software will obtain copyright protection if it is original in the sense that it is an intellectual creation of the creator, according to the Copyright Act chapter 1, section 1, second paragraph.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software \u2013 Are there any specific laws that govern the harm \/ liability caused by Software \/ computer systems?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There are no specific laws in the Swedish law system that govern the harm\/liability caused by software\/computer systems per se. However, the Swedish Damages Act can be applicable to harm\/liability caused by software\/computer systems.<\/p>\n<p>The Product Liability Directive (EU) 2024\/2853 establishes rules regarding liability for compensation relating to property damage, personal injury and data loss, and includes software within the definition of &#8216;product&#8217;. The directive is being implemented in Sweden. Work on transposing the directive into Swedish national law is ongoing; no implementing legislation has yet been adopted.<\/p>\n<p>A Swedish government inquiry, SOU 2025:103, has proposed a new Product Liability Act to replace the current Product Liability Act (1992:18). The proposal explicitly expands the definition of a &#8216;product&#8217; to include standalone software, AI systems, and digital manufacturing files (such as files used in 3D printing). The new strict liability regime would, if adopted, also cover damage to data used for personal purposes and medically recognised harm to psychological health. The new rules are expected to apply to products placed on the market from 9 December 2026.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software \u2013 To the extent not covered by (3) above, are there any specific laws that govern the use (or misuse) of software \/ computer systems?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The Swedish Criminal Act, Chapter 4, Section 9 c governs misuse of computer programs, such as in the case of hacking, DOS\/DDOS-attacks and hacking.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software Transactions (Licence and SaaS) \u2013 Other than as identified elsewhere in this overview, are there any technology-specific laws that govern the provision of software between a software vendor and customer, including any laws that govern the use of cloud technology?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>No. However, several laws may apply to software contracts and the use of cloud technology such as inter alia the Swedish Contracts Act (Sw. avtalslagen (1915:218)), the Swedish Copyright Act, the GDPR and the Swedish Consumer Sales Act.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software Transactions (License and SaaS) \u2013 Is it typical for a software vendor to cap its maximum financial liability to a customer in a software transaction? If \u2018yes\u2019, what would be considered a market standard level of cap?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Often software vendors have a limited liability for errors and defects and damages and losses (nor direct or indirect) in their own standard form contracts. Cloud services are normally standard services, and it seems reasonable to have a quite far-reaching limitation of liability. There is no market standard level of cap but often in cloud services contracts e.g. the cloud service provider caps the liability to an amount corresponding to twelve months fee for the services.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software Transactions (License and SaaS) \u2013 Please comment on whether any of the following areas of liability would typically be excluded from any financial cap on the software vendor\u2019s liability to the customer or subject to a separate enhanced cap in a negotiated software transaction (i.e. unlimited liability): (a) confidentiality breaches; (b) data protection breaches; (c) data security breaches (including loss of data); (d) IPR infringement claims; (e) breaches of applicable law; (f) regulatory fines; (g) wilful or deliberate breaches; (h) claims arising out of or in relation to artificial intelligence.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>This is an emerging area in Swedish contract practice. It is likely that it will become more common to include AI-specific clauses following the AI Act (EU) 2024\/1689.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software Transactions (License and SaaS) \u2013 Is it normal practice for software source codes to be held in escrow for the benefit of the software licensee? If so, who are the typical escrow providers used? Is an equivalent service offered for cloud-based software?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>It is common that software source codes are held in escrow in cases where a license is valid for a longer period and if the license object is specially made for the customer. The Stockholm Chamber of Commerce is an escrow provider.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">IT Outsourcing \u2013 Other than as identified elsewhere in this questionnaire, are there any specific technology laws that govern IT outsourcing transactions?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There are no specific technology laws that govern IT outsourcing transactions in general. The Swedish Act on Confidentiality when Outsourcing Technical Processing or Data Storage (Sw. lagen (2020:914) om tystnadsplikt vid utkontraktering av teknisk bearbetning eller lagring av uppgifter) governs confidentiality when public authorities are outsourcing technical processing or storage of information.<\/p>\n<p>Entities falling under the scope of the Swedish Protective Security Act (Sw. s\u00e4kerhetskyddslagen (2018:585)) must enter into a security protection agreement before a counterparty can gain access to security-sensitive information.<\/p>\n<p>Financial actors (e.g. banks, investment funds, securities market companies) that wish to outsource certain financial services must notify the Swedish Financial Supervisory Authority (Finansinspektionen) and submit the outsourcing agreement.<\/p>\n<p>Financial actors subject to the Digital Operational Resilience Act (EU) 2022\/2554 (DORA), which has been in force since January 2025, must include minimum contractual requirements when entering into agreements with ICT third-party service providers.<\/p>\n<p>Directive (EU) 2022\/2555 (the NIS 2 Directive) sets out security requirements for the supply chain. The new Cybersecurity Act (Sw. cybers\u00e4kerhetslagen (2025:1506)), which entered into force on 15 January 2026, implements the NIS 2 Directive in Swedish law. The Act requires operators covered by its scope to address supply-chain security as part of their mandatory security measures. IT providers may be relevant as part of the supply chain for covered entities.<\/p>\n<p>The Gigabit Infrastructure Act (GIA), which was published in the Official Journal of the EU on 8 May 2024, has been fully applicable since November 2025, replacing the Broadband Cost Reduction Directive (EU) 2014\/61\/EU.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">IT Outsourcing \u2013 Please summarise the principal laws (present or impending), if any, that protect individual staff in the event that the service they perform is transferred to a third party IT outsource provider, including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The Swedish Employment Protection Act, section 6 b, protect individual staff if the service they perform is transferred to a third-party IT outsource provider. Under the Employment Act, the supplier to which a business is outsourced to assumes the rights and obligations owed to the employees of the company outsourcing the business. Employees have the right to object to the transfer and remain employed by the company outsourcing the business. However, there is an overwhelming risk that the employment may be terminated due to redundancy since the business as such has been transferred.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Telecommunications \u2013 Please summarise the principal laws (present or impending), if any, that govern telecommunications networks and\/or services, including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The primary legislative document governing telecommunication networks and services is the Electronic Communications Act (Sw. lagen (2022:482) om elektronisk kommunikation). The Act outlines the functions and responsibilities of the Swedish Post and Telecom Authority, the main regulatory body for these services, as well as regulations for network operations, spectrum licensing, consumer protection and more. The Electronic Communications Act applies to electronic communication networks and services and their corresponding installations, services, and other radio usage. The transmitted content itself does not fall within the scope of the act. According to the act, public communication networks that are normally provided in exchange for money, and publicly accessible communication services, may only be provided if the business has been reported to the Swedish Post and Telecom Authority (Sw. Post- och telestyrelsen).<\/p>\n<p>The General Data Protection Regulation (GDPR) governs how personal data must be handled, including by communications service providers.<\/p>\n<p>Legislation relevant to this topic is also found in the Radio Equipment Act (Sw. radioutrustningslagen (2016:392)) and The Radio and TV Act (Sw. radio- och tv-lag (2010:696)).<\/p>\n<p>The Electronic Commerce Act (Sw. lagen (2002:562) om elektronisk handel och andra informationssamh\u00e4llets tj\u00e4nster) regulates electronic commerce activities and other services related to the information society.<\/p>\n<p>Computer programs and databases are protected under the Swedish Copyright Act (Sw. lagen (1960:729) om upphovsr\u00e4tt till litter\u00e4ra och konstn\u00e4rliga verk). This Act protects the rights of creators and owners of literary and artistic works, including computer programs and databases.<\/p>\n<p>The Swedish Post and Telecom Authority is the primary regulatory body that oversees these matters. Several laws and regulations govern the operation of communication networks and services. They are both subjected to national and the European union&#8217;s legislation.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Telecommunications \u2013 Please summarise any licensing or authorisation requirements applicable to the provision or receipt of telecommunications services in your country. Please include a brief overview of the relevant licensing or authorisation regime in your response.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The Electronic Communications Act is the main regulatory framework governing the telecommunications market in Sweden, the Act outlines the functions and responsibilities of the Swedish Post and Telecom Authority (Sw. Post- och telestyrelsen), the main regulatory body for these services, as well as regulations for network operations, spectrum licensing, consumer protection and more. The Electronic Communications Act applies to electronic communication networks and services and their corresponding installations, services, and other radio usage. The transmitted content itself does not fall within the scope of the act.<\/p>\n<p>Most operators within telecommunications services must notify the responsible supervisory authority, the Swedish Post and Telecom Authority of their activities. In addition, notified operators must pay certain fees.<\/p>\n<p>Operators providing public electronic communications networks of a type normally provided for remuneration must notify the Swedish Post and Telecom Authority of their activities. This includes operators providing mobile networks, cable TV networks, fibre and fibre LAN (access), and submarine cables.<\/p>\n<p>Operators providing publicly available electronic communications services in the form of internet access services, number-based interpersonal communications services and services consisting wholly or mainly of the transmission of signals must also notify their activities to the Swedish Post and Telecom Authority. This includes operators providing fixed internet, mobile internet, mobile telephony (number-based interpersonal), data transmission services, roaming services for aircraft (MCA) and ships (MCV), interconnection (fixed and mobile) and M2M-services.<\/p>\n<p>Operators intending to use radio transmitters need to apply for licences at the Swedish Post and Telecom Authority. There are several types of licences, e.g. licence to use marine radio (VHF) on a recreational boat, maritime radio, radio link, land mobile radio, radio transmitters in earth stations, aeronautical radio, terrestrial television. One also need to apply for a local licence in the 3.7 GHz and 26 GHz bands. Furthermore, a licence is required to use radio transmitters for various types of testing (including 5G and 6G testing).<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Telecommunications \u2013 Please summarise the principal laws (present or impending) that govern access to communications data by law enforcement agencies, government bodies, and related organisations. In your response, please outline the scope of these laws, including the types of data that can typically be requested, how these laws are applied in practice (e.g., whether requests are confidential, subject to challenge, etc.), and any legal or procedural safeguards that apply.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The Swedish Electronic Communications Act requires operators to store certain subscription data that can be disclosed to law enforcement authorities, such as the Swedish Police Authority, when necessary. The information to be stored is specified in more detail in the Electronic Communications Ordinance (Sw. f\u00f6rordningen om elektronisk kommunikation (2022:511)).<\/p>\n<p>The ordinance stipulates that telephony services and messaging, only communications via a mobile access point, must be stored, including, among other things, the caller\u2019s and the called party\u2019s numbers or equivalent address, date and time when the communication was initiated and terminated, or a message was sent and received, location details when communication began and ended. The ordinance also stipulates that data with regard to internet access must be stored, such as users&#8217; IP addresses and other data necessary to identify a subscriber and registered user, and the date and time of logging on and off the service that provides Internet access.<\/p>\n<p>Communications data may be accessed for criminal investigations under the rules set out in the Procedural Code (Sw. r\u00e4tteg\u00e5ngsbalken) and for intelligence gathering by law enforcement authorities under the rules set out in the Electronic Intelligence Act (Sw. lagen (2012:278) om inh\u00e4mtning av uppgifter om elektronisk kommunikation i de brottsbek\u00e4mpande myndigheternas underr\u00e4ttelseverksamhet).<\/p>\n<p>For the purposes of a criminal investigation, law enforcement authorities may require the secret interception or surveillance of electronic communications. There are additional secret coercive measures. The public prosecutor&#8217;s application to use secret coercive measures will be tried by a general court. With regard to gathering information concerning electronic communications under the Electronic Intelligence Act, prosecutors at the Swedish Prosecution Authority make decisions on gathering information following a request from a law enforcement agency.<\/p>\n<p>The Act on Measures to Prevent Certain Serious Crimes (Sw. lagen (2007:979) om \u00e5tg\u00e4rder f\u00f6r att f\u00f6rhindra vissa s\u00e4rskilt allvarliga brott) grants certain authorities the power to conduct secret surveillance of electronic communications, for instance. A public counsel is appointed by a Swedish court in cases involving, e.g, secret interception of electronic communications under the Procedural Code, or equivalent preventive coercive measures under the Act on Measures to Prevent Certain Serious Crimes, in order to guarantee legal safeguards. The public counsel acts as the prosecutor&#8217;s counterpart at court hearings and is responsible for safeguarding individuals&#8217; rights and privacy interests. The public counsels must have access to all material on which the court&#8217;s examination is based, and they shall also have the opportunity to comment on the case and appeal the court&#8217;s decision.<\/p>\n<p>Defence intelligence activities may involve intercepting signals transmitted via a cable owned by an operator. Before signal intelligence activities can be initiated, the relevant authority must apply for a permit from the Defence Intelligence Court in accordance with the Signals Intelligence Act (Sw. lagen (2008:717) om signalspaning i f\u00f6rsvarsunderr\u00e4ttelseverksamhet).<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Telecommunications \u2013 Please summarise the principal laws (present or impending) that impose cyber security and\/or operational resiliency obligations applicable to the operation of telecommunications infrastructure and\/or provision of telecommunications services.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The new Cybersecurity Act (Sw. cybers\u00e4kerhetslagen (2025:1506)), which entered into force on 15 January 2026 and implements the NIS 2 Directive (EU) 2022\/2555, expressly covers providers of public electronic communications networks and publicly available electronic communications services. Such providers are classified as essential or important operators under the Act and must implement appropriate and proportionate technical, operational and organisational security measures and report significant incidents to the designated supervisory authority.<\/p>\n<p>The mandatory security measures must cover, at a minimum, risk analysis and security policies, incident handling, business continuity and crisis management, supply-chain security, secure acquisition\/development\/maintenance of systems, effectiveness testing, cyber hygiene and training, cryptography and encryption where needed, and access\/asset management.<\/p>\n<p>The DORA Regulation (EU) 2022\/2554, which has been in force since January 2025, applies to financial entities rather than telecommunications operators directly; however, telecommunications providers that supply ICT services to financial entities in scope of DORA will be affected through contractual requirements imposed on those entities.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Mobile communications and connected technologies \u2013 What are the principle standard setting organisations (SSOs) governing the development of technical standards in relation to mobile communications and newer connected technologies such as digital health or connected and autonomous vehicles?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>At EU level there are several ongoing and recently adopted legislation relating to mobile communications and connected technologies. The European Health Data Space (EHDS) was proposed by the EU Commission in 2022, and the European Parliament and the Councill recently reached a political agreement on that same proposal. The EHDS will, for example, allow citizens across the EU to access an electronic health record containing prescriptions, images and laboratory tests.<\/p>\n<p>The AI Act will apply to all sectors and will influence autonomous vehicles. AI systems deployed on or in connection with autonomous vehicles affecting driving and passenger safety may be classified as high-risk AI systems under the AI Act. The AI Act will also affect digital health, and the area of health tech, since medical devices or services incorporating AI systems may implicate certain risks. AI incorporation in medical devices that is subject to EU regulation on medical devices (EU) 2017\/745 and (EU) 2017\/746) will fall under the definition of a high-risk AI system and will therefore need to consider certain requirements.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Mobile communications and connected technologies \u2013 How do technical standards facilitating interoperability between connected devices impact the development of connected technologies?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>New technical standards such as 5G will enable the deployment of a high-quality infrastructure which affects many sectors of an innovative economy. Europe&#8217;s Digital Decade has as its aim to ensure that by 2030 a fixed gigabit network of a very high capacity (1 Gbps) will be covering all European households and that all populated areas will have 5G.<\/p>\n<p>The Gigabit Infrastructure Act (GIA) was published in the Official Journal of the European Union on 8 May 2024 and entered into force on 11 May 2024. It has been fully applicable since November 2025, replacing the Broadband Cost Reduction Directive (EU) 2014\/61\/EU. The GIA is intended to create a fast and efficient network applicable across the whole Union.<\/p>\n<p>Five Swedish projects have been granted EU support to further develop existing infrastructure and build new routes to strengthen Sweden&#8217;s connectivity to the outside world. Swedish actors are using EU funds to develop 5G solutions for smart communities and underwater infrastructure for electronic communications.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Data Protection \u2013 Please summarise the principal laws (present or impending), if any, that govern data protection, including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The General Data Protection Act (EU) 2016\/679, (\u201cGDPR\u201d) is the main legislative framework for data protection across all member countries, including Sweden. In addition, the Data Protection Act (2018:218) (the DPA) and the Data Protection Ordinance (2018:19) that contains further regulations regarding data protection on aspects allowed by the GDPR.<\/p>\n<p>The DPA contains regulations regarding the processing of data concerning criminal offences and processing of social security number. The DPA also contains regulations that the GDPR is applicable outside its actual scope. However, the DPA is subsidiary in relation to other law or regulation, which allows for deviating provisions. The general purpose of the DPA is to regulate the processing of personal data and rules relating to the free movement of personal data. The law is an addition to the GDPR and therefore has the same general purpose.<\/p>\n<p>Apart from the DPA there are several sector specific acts such as the Swedish Patient Data Act (Sw. patientdatalag (2008:355)), the Swedish Electronic Communications Act (2022:482), the Swedish Marketing Act (Sw. marknadsf\u00f6ringslag (2008:486), the Swedish Camera Surveillance Act (Sw. kamerabevakningslag (2018:1200)), the Swedish Credit Information Act (Sw. kreditupplysningslag (1973:1173)) and the Swedish Criminal Data Act (Sw. brottsdatalag (2018:1177)).<\/p>\n<p>The Swedish Authority for Privacy Protection, abbreviated IMY (Sw. Integritetsskyddsmyndigheten) is responsible for enforcing data protection regulations under the GDPR and the Swedish Data Protection Act (lag (2018:218) med kompletterande best\u00e4mmelser till EU:s dataskyddsf\u00f6rordning).<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Data Protection \u2013 What is the maximum sanction that can be imposed by a regulator in the event of a breach of any applicable data protection laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>According to article 83 in the GDPR, which is directly applicable in all EU countries, the maximum fine that can be applied for a breach is EUR 20,000,000, or 4 % of the company\u00b4s annual turnover of the previous financial year, whichever is higher.<\/p>\n<p>In Sweden it has been decided that also public authorities can be fined, however the administrative sanctions are lower; maximum SEK 10,000,000, according to the Act (2018:218) with supplementary provisions to the EU&#8217;s Data Protection Regulation (Swedish Data Protection Act).<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Cybersecurity \u2013 Please summarise the principal laws (present or impending), if any, that govern cybersecurity (to the extent they differ from those governing data protection), including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Sweden has adopted a new Cybersecurity Act (Sw. cybers\u00e4kerhetslagen (2025:1506)), which entered into force on 15 January 2026. Its purpose is to achieve a high level of cybersecurity in society. The Act implements the NIS 2 Directive (EU) 2022\/2555 and replaces the former Act on Information Security for Essential and Digital Services (Sw. lagen (2018:1174) om informationss\u00e4kerhet f\u00f6r samh\u00e4llsviktiga och digitala tj\u00e4nster).<\/p>\n<p>The new Act applies to both public entities and private operators that meet certain criteria. It distinguishes between &#8216;essential&#8217; (Sw. v\u00e4sentliga) and &#8216;important&#8217; (Sw. viktiga) operators. The scope is significantly broader than the former NIS 1 Act and covers a much larger number of organisations across sectors including digital infrastructure, cloud services, data centre services, content delivery networks, managed services, online marketplaces, search engines and social networking platforms.<\/p>\n<p>Operators subject to the Act must implement appropriate and proportionate technical, operational and organisational measures to protect network and information systems against incidents, covering at minimum: risk analysis and security policies, incident handling, business continuity and crisis management, supply-chain security, secure acquisition and development of systems, effectiveness testing, cyber hygiene and training, cryptography where needed, access and asset management, and secure communications.<\/p>\n<p>A complementary Cybersecurity Ordinance (Sw. cybers\u00e4kerhetsf\u00f6rordning (2025:1507)) supplements the Act. The Ordinance entered into force simultaneously with the Act on 15 January 2026 and contains complementary provisions.<\/p>\n<p>The DORA Regulation (EU) 2022\/2554 has been in force since January 2025 and strengthens the digital operational resilience of the financial sector, laying down requirements for ICT risk management, incident reporting, digital operational resilience testing and ICT third-party risk management.<\/p>\n<p>The EU Cyber Resilience Act (EU) 2024\/2874 applies from 11 December 2027 (with some exceptions) and aims to ensure that digital products placed on the EU market meet high cybersecurity standards throughout their lifecycle, introducing mandatory security requirements for manufacturers and software developers. In Sweden, an inquiry has been launched to analyse the need for, and propose, legislative measures and complementary provisions required to align Swedish law with the Cyber Resilience Act.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Cybersecurity \u2013 What is the maximum sanction that can be imposed by a regulator in the event of a breach of any applicable cybersecurity laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Under the new Cybersecurity Act (2025:1506), administrative fines may be imposed. For essential private operators, the maximum fine is the higher of 2% of global annual turnover or EUR 10,000,000. For important private operators, the maximum fine is the higher of 1.4% of global annual turnover or EUR 7,000,000. For public sector operators, the maximum fine is SEK 10,000,000.<\/p>\n<p>Under the Swedish Act (2024:1278) containing supplementary provisions to the DORA Regulation, the maximum administrative fine for certain specified financial entities is the highest of: an amount in Swedish kronor corresponding to EUR 1,000,000; 10% of the financial entity&#8217;s turnover for the most recent financial year (or, where applicable, corresponding turnover at group level); or three times the profit obtained by the financial entity as a result of the infringement, if that amount can be determined.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Cybersecurity \u2013 Are there any cybersecurity regulatory frameworks in your jurisdiction which require registration for certain sectors or services?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Under the new Cybersecurity Act (2025:1506), operators that fall within the Act&#8217;s scope must register with and notify themselves to The Swedish Civil Defence Agency (Sw. Myndigheten f\u00f6r civilt f\u00f6rsvar, MSB). Changes to the registered information must be reported as soon as possible and no later than 14 days after the change occurs. The same agency has also been designated in a Government assignment as the authority responsible for other NIS 2 functions, including acting as the national single point of contact and operating as the CSIRT under the Cybersecurity Act.<\/p>\n<p>The registration\/notification obligation applies to operators across designated sectors, including providers of public electronic communications networks and publicly available electronic communications services, cloud services, data centre services, content delivery networks, managed services, managed security services, online marketplaces, search engines and social networking platforms, as well as certain DNS and TLD-related services.<\/p>\n<p>In addition, under DORA, financial sector entities must manage ICT third-party risks through mandatory contractual provisions and register relevant ICT third-party providers with their competent authority (Finansinspektionen for Swedish entities).<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Cybersecurity \u2013 Please summarise the regulatory framework for the reporting of cybersecurity incidents.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Under the Cybersecurity Act (2025:1506), operators must follow a multi-step incident reporting procedure. Upon becoming aware of a significant incident, the operator must: (i) submit an early warning notification to the designated authority as soon as possible and no later than 24 hours after becoming aware; (ii) submit a fuller incident notification within 72 hours of becoming aware (or within 24 hours for trust service providers); (iii) provide interim reports upon request from the supervisory authority; and (iv) submit a final report within one month of submitting the incident notification (or, if the incident is still ongoing at that point, a status report followed by a final report within one month of the incident being resolved).<\/p>\n<p>Operators must also, where appropriate, inform recipients of their services about significant incidents that are likely to adversely affect the provision of services, and for significant cyber threats they must inform affected recipients of any protective or countermeasures available.<\/p>\n<p>Under DORA, financial entities must report major ICT-related incidents to their competent authority (Finansinspektionen for Swedish entities) following the timeframes and procedures set out in that Regulation.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Artificial Intelligence \u2013 Which body(ies), if any, is\/are responsible for the regulation of artificial intelligence?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Several Swedish authorities will be responsible for supervisory tasks to ensure compliance with the AI Act (EU) 2024\/1689. Significant progress has been made in clarifying the allocation of responsibilities.<\/p>\n<p>A government inquiry (SOU 2025:101, Anpassningar till AI-f\u00f6rordningen, published in October 2025) has proposed a market surveillance system consisting of several authorities, with the Swedish Post and Telecom Authority (Sw. Post- och telestyrelsen, PTS) as the market surveillance authority with primary responsibility for the AI Act overall. PTS would also act as the coordinating market surveillance authority and the single point of contact under the AI Act.<\/p>\n<p>The inquiry further proposes that PTS, the Swedish Authority for Privacy Protection (IMY) and Finansinspektionen (FI) would share responsibility for market surveillance over high-risk AI systems falling under Annex III to the AI Act.<\/p>\n<p>For prohibited AI practices under Article 5 of the AI Act, IMY is proposed as the authority with primary responsibility, with certain responsibility also for PTS and FI. For transparency requirements under Article 50, PTS and IMY would share responsibility.<\/p>\n<p>The inquiry also proposes that Swedac and the Medical Products Agency (L\u00e4kemedelsverket) act as notifying authorities under the AI Act \u2013 Swedac for all sectors except medtech-related high-risk AI systems, where L\u00e4kemedelsverket would be responsible.<\/p>\n<p>The proposed complementary Swedish law and ordinance to the AI Act are expected to enter into force on 2 August 2026, when the majority of the AI Act&#8217;s provisions become applicable. A national AI strategy has also been published by the Swedish Government (February 2026).<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Artificial Intelligence \u2013 Please summarise the principal laws (present or impending), if any, that govern the deployment and use of artificial intelligence, including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The AI Act (EU) 2024\/1689 applies from 2 August 2026 for most provisions; however, certain rules have been in effect since 2 August 2025, including those on the governance structure, penalties and obligations for providers of general-purpose AI models. The Act involves a definition of AI systems, classifies AI systems according to different risk levels, and includes definitions of AI systems that are prohibited (such as social scoring systems and manipulative AI). There are additional obligations that apply to providers of high-risk AI systems.<\/p>\n<p>In Sweden, the AI Act will be supplemented by provisions in Swedish law, including those outlining the responsibilities of the relevant authorities. The proposed complementary Swedish legislation is intended to enter into force on 2 August 2026.<\/p>\n<p>The AI Act applies to all sectors, including autonomous vehicles, and medical devices incorporating AI systems that fall under EU medical device regulations will be classified as high-risk AI systems.<\/p>\n<p>A new regulation on the use of real-time AI facial recognition systems for law enforcement purposes has also been adopted in Sweden (Sw. lag (2026:806) om anv\u00e4ndning av AI-system f\u00f6r ansiktsigenk\u00e4nning i realtid f\u00f6r brottsbek\u00e4mpande \u00e4ndam\u00e5l), with a complementary Ordinance (2026:815) entering into force on 1 July 2026. This regulation governs the specific conditions under which law enforcement may use real-time AI facial recognition.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Artificial Intelligence \u2013 Are there any specific legal provisions (present or impending) in respect of the deployment and use of Large Language Models and\/or generative AI (including agentic AI)?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>General-purpose AI (GPAI) models (including Large Language Models) are specifically regulated in the AI Act. GPAI models that create systemic risk because of their capabilities are subject to significant regulation, while other GPAI models have more limited obligations with a focus on copyright compliance. Requirements include technical documentation, information to those who intend to integrate the GPAI model into other AI systems, a policy to consider and comply with copyright issues when using and collecting training data, and documentation on the training data used.<\/p>\n<p>IMY has published guidance on the application of the GDPR to the use of generative AI (dated 5 February 2025), as part of the Government assignment to develop guidelines for the use of generative AI in the public sector. This guidance addresses how personal data protection rules apply when public sector bodies deploy or use generative AI systems.<\/p>\n<p>IMY has also published analysis regarding GDPR compliance roles (controller, joint controller, processor) when AI applications are fine-tuned, providing further sector guidance relevant to the deployment of generative AI.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Artificial Intelligence \u2013 Do technology contracts in your jurisdiction typically contain either mandatory (e.g. mandated by statute) or recommended provisions dealing with AI risk? If so, what issues or risks need to be addressed or considered in such provisions?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>No. However, it is likely that it will be more common to include such clauses following the AI Act.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Artificial Intelligence \u2013 Do software or technology contracts in your jurisdiction typically contain provisions regarding the application or treatment of copyright or other intellectual property rights, or the ownership of outputs in the context of the use of AI systems?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>No. It shall be noted that the Swedish legislation regarding intellectual property is written with the assumption that property is created by a physical person, leading to the consequence that what applies when it comes to development without human interaction is still unclear.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Blockchain \u2013 What are the principal laws (present or impending), if any, that govern (i) blockchain specifically (if any) and (ii) digital assets, including a brief explanation of the general purpose of those laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There are no principal laws that specifically govern blockchain. However, the EU has adopted rules covering crypto-assets and related services through Regulation (EU) 2023\/1114 on markets in crypto-assets (MiCA).<\/p>\n<p>Sweden has adopted a supplementary law to MiCA \u2013 the Act (2024:1159) with complementary provisions to the EU Regulation on markets in crypto-assets \u2013 which entered into force on 30 December 2024. Finansinspektionen is designated as the competent authority under MiCA for Sweden.<\/p>\n<p>Finansinspektionen is responsible for supervision of firms under MiCA and may prohibit offers to the public or trading in crypto-assets where there is reason to assume MiCA will be breached. It may also impose temporary prohibitions in specified circumstances.<\/p>\n<p>Firms operating before 30 December 2024 that require authorisation under MiCA Article 63 may continue operations until 30 September 2025 (and, where an authorisation application was filed before 1 October 2025, until the application has been finally determined).<\/p>\n<p>The EU Commission has also launched a regulatory sandbox for blockchain, to offer businesses a safe and confidential environment in which to try their products and services.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Search Engines and Marketplaces \u2013 Please summarise the principal laws (present or impending), if any, that govern search engines and marketplaces, including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The EU Digital Services Act (EU) 2022\/2065 (\u201cDSA\u201d) and the Digital Markets Act (EU) 2022\/1925 (\u201cDMA\u201d) regulate online platforms (such as social media platforms and marketplaces) and since 17 February 2024, both Acts are applicable and need to be considered in Sweden.<\/p>\n<p>The purpose of the DSA and DMA is to create a safer, fairer and more transparent environment online \u2013 to improve competition and ensure fair conditions in the digital sector. To achieve this, the EU wants to ensure a level playing field for all digital companies, with the aim of boosting innovation, growth and competitiveness, which can help smaller companies and start-ups to compete with larger businesses. The Regulation also aims to protect consumer&#8217;s privacy online, regulating the collection and use of data.<\/p>\n<p>The EU Regulation 2019\/1150 (the P2B Regulation) is also applicable and aims to ensure a fair, transparent, and predictable business environment for companies that use online platforms to offer goods or services to consumers. Examples of such platforms include search engines, online marketplaces, app stores, and social media providers, the P2B Regulation is also applicable for question 29, below.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Social Media \u2013 Please summarise the principal laws (present or impending), if any, that govern social media and online platforms, including a brief explanation of the general purpose of those laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>In addition to the regulations mentioned in question 28 above, the Bulletin Board System Act (Sw. lagen (1998:112) om ansvar f\u00f6r elektroniska anslagstavlor), the GDPR and the Electronic Communications Act are applicable on social media. As a starting point, the person who publishes something in social media that is regarded as personal information is responsible for the personal information that the publication entails. The company that provides the platform may also be liable if the company can influence posts or determine which posts shall be published. The Act is applicable on services for the electronic transmission of messages which include interactive internet sites with, for example, chat functions, comment fields or other forms of communication services that allow users to post various forms of information. The main responsibility that a provider bears, is the obligation to remove messages on the electronic bulletin board, if it violates the provision of Section 5 of the Act.<\/p>\n<p>In some cases, a publication may be covered by the so-called private exemption in the GDPR. According to the private exemption, the GDPR shall not apply to the processing of personal data carried out by a natural person during a purely personal or household activity. If a person publishes personal data for a wider audience, for example by publishing pictures or other things in social media, then it is not to be considered a matter of purely private nature. This means that the private exemption does not apply and the person who publishes becomes the data controller for the publication.<\/p>\n<p>According to the Bulletin Board System Act the provider\/administrator of an electronic bulletin board is required to provide information to anyone who uses the service about the provider\u2019s\/administrator\u2019s identity and the extent to which incoming messages become available to other users. The provider\/administrator should also have such oversight of the service that is &#8220;reasonably required with regard to the scope and direction of the business&#8221;. According to the Act, the provider of an electronic bulletin board is also responsible for removing or otherwise preventing messages from spreading if:<\/p>\n<ul>\n<li>the content obviously means unlawful threat, unlawful violation of personal integrity, incitement, agitation against an ethnic group, child pornography offense or unlawful depiction of violence, or<\/li>\n<li>it is evident that the user has infringed the copyright or rights protected by the copyright law by submitting the message (e.g. attached copyrighted material).<\/li>\n<\/ul>\n<p>If the provider\/administrator is responsible for electronic message boards and a message is posted that contains, for example, material infringing copyright or racist statements, the provider\/administrator is obliged to remove it as soon as possible. If the provider\/administrator does not do so within &#8220;reasonable time&#8221;, the provider\/administrator may be held liable for violations of the Bulletin Board System Act, which may result in a fine or even imprisonment for a maximum of two years.<\/p>\n<p>Notably, services protected by the Freedom of the Press Act, or the Fundamental Law on Freedom of Expression are exempted from this Act. According to the Swedish Electronic Communications Act, which entered into force on 3 June 2022, providers of electronic communications are liable for their platforms and what is posted on them.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Social Media \u2013 What is the maximum sanction that can be imposed by a regulator in the event of a breach of any applicable online safety laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>In accordance with the DMA, companies can be fined up to 10% of their total worldwide annual turnover for infringements, or up to 20% for repeated infringements. Periodic penalty payments of up to 5% of the average daily turnover can also be imposed. If gatekeepers systematically infringe the DMA obligations, additional remedies may be imposed on them after a market investigation. These remedies must be proportionate to the offences committed. As a last resort, non-financial remedies can also be imposed if necessary. These can include behavioural and structural remedies, e.g. the divestiture of a business or parts thereof.<\/p>\n<p>The European Commission can impose fines of up to 6% of a company&#8217;s worldwide annual turnover in the event of a breach of the DSA, following a non-compliance decision or a failure to comply with interim measures or commitments. The European Commission can also impose periodic penalties of up to 5% of the average daily worldwide turnover for each day of delay in complying with remedies, interim measures or commitments. As a final measure, if the infringement persists and causes serious harm to users, or if it involves criminal offences that threaten the life or safety of individuals, the European Commission can request the Digital Services Coordinator of the relevant Member State to request that the national courts temporarily restrict recipients&#8217; access to the service, following a specific procedure.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Spatial Computing \u2013 Please summarise the principal laws (present or impending), if any, that govern spatial computing, including a brief explanation of the general purpose of those laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There is no specific regulation that govern spatial computing.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Quantum Computing \u2013 Please summarise the principal laws (present or impending), if any, that govern quantum computing and\/or issues around quantum cryptography, including a brief explanation of the general purpose of those laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There is no specific regulation that govern quantum computing.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Datacentres \u2013 Does your jurisdiction have any specific regulations that apply to data centres?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The Act on Disclosure of Information on Data Centres&#8217; Energy Performance (Sw. lagen (2025:570) om offentligg\u00f6rande av information om datacenters energiprestanda) entered into force on 1 July 2025. It requires owners or operators of data centres to publicly disclose information about the energy performance of the data centre.<\/p>\n<p>The annual reporting obligation applies to data centres with an installed IT power demand of at least 500 kW, and is fulfilled by reporting to the database referred to in Article 12 of the Energy Efficiency Directive (EU) 2023\/1791.<\/p>\n<p>The Swedish Energy Agency (Sw. Energimyndigheten) has been designated as the supervisory authority under the Act.<\/p>\n<p>Certain data centres are exempted from the Act, including those used for security-sensitive activities, defence or crisis preparedness purposes, or where services are provided exclusively for such purposes.<\/p>\n<p>The supervisory authority may request information and access to premises and issue injunctions necessary for compliance, which may be combined with a conditional fine (Sw. vite).<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">General \u2013 What are your top 3 predictions for significant developments in technology law in the next 3 years?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The full application of the AI Act from 2 August 2026 will be up for discussion as AI technology develops quickly, and Sweden and other EU member states will face the challenge of implementing and enforcing the Act in practice. The entry into force of the Swedish complementary legislation to the AI Act on 2 August 2026 will trigger the first enforcement actions, shaping the obligations of both providers and deployers of AI systems in Sweden.<\/p>\n<p>The new Cybersecurity Act (2025:1506), which entered into force on 15 January 2026, significantly expands the range of entities subject to mandatory cybersecurity obligations and incident reporting requirements in Sweden.<\/p>\n<p>The status of the EU\u2013US Data Privacy Framework will continue to affect the need for further development of cloud-based storage and personal data transfer mechanisms.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">General \u2013 Do technology contracts in your country commonly include provisions to address sustainability \/ net-zero obligations or similar environmental commitments?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>No, not in general.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\r\n<div class=\"word-count-hidden\" style=\"display:none;\">Estimated word count: <span class=\"word-count\">7146<\/span><\/div>\r\n\r\n\t\t\t<\/ol>\r\n\r\n<script type=\"text\/javascript\" src=\"\/wp-content\/themes\/twentyseventeen\/src\/jquery\/components\/filter-guides.js\" async><\/script><\/div>"}},"_links":{"self":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/comparative_guide\/146050","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/comparative_guide"}],"about":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/types\/comparative_guide"}],"wp:attachment":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/media?parent=146050"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}