Law / Sweden

Dataskyddslagen (Data Protection Act), GDPR-Complementing Provisions

Dataskyddslagen, SFS 2018:218

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 25 May 2018.

A comprehensive regime rule binding public and private bodies.

As of 24 August 2026.

What it requires

  • Establish a General Data Protection Regulation (GDPR) Article 6 lawful basis before processing personal data of a person in Sweden; Dataskyddslagen adds domestic legal bases mainly for public-sector processing, not a modification of the private-sector Article 6 list.

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Sweden gives the General Data Protection Regulation (GDPR) domestic effect through Dataskyddslagen (SFS 2018:218), enacted 19 April 2018 and in force 25 May 2018. Confirmed against its seven chapters: the Act is genuinely light touch, filling only the gaps GDPR leaves open (member-state legal bases for public-authority processing, a reduced fine scale for public authorities, appeal routes) and adding no separate biometric-specific chapter or general criminal-penalties chapter.

Sweden separately has a distinct Kamerabevakningslagen (SFS 2018:1200, Camera Surveillance Act) regulating any camera or optical-electronic monitoring equipment through an impact-assessment and registry duty rather than data-category rules.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot

Read the law

riksdagen.se, Dataskyddslagen SFS 2018:218

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app