Law / Sweden

Sweden

European Union law applies in Sweden Sweden is a member state of the European Union, whose 37 researched instruments are listed on the European Union page, not here. The law of Sweden, described on this page below, applies here too.

16 of 17 named instruments researched to a stage, across all six areas of law we track: 15 in force and 1 proposed. As of 15 September 2026.

When they take effect15 of 16 carry a date, 1 does not. Earlier is before 2014.
Before 2014: 1 instrument (1 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 7 instruments (7 in force) 2019: 0 instruments 2020: 2 instruments (2 in force) ’20 2021: 0 instruments 2022: 0 instruments 2023: 2 instruments (2 in force) 2024: 0 instruments 2025: 0 instruments 2026: 3 instruments (3 in force) ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 2
  2. Privacy law 7
  3. Scraping law 3
  4. Cybersecurity law 2
  5. Age gating law 1
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law2 instruments, 1 in force, 1 proposed

Research summary (145 words)

The EU AI Act (Regulation (EU) 2024/1689) applies directly in Sweden and is not restated here as Swedish law.

As of September 2026 Sweden has not enacted a national implementing statute naming its own market surveillance authorities or penalties: Statens offentliga utredningar (SOU) 2025:101, a government inquiry report, proposes designating Post- och telestyrelsen (PTS) as the coordinating market surveillance authority and single point of contact under the AI Act, with Integritetsskyddsmyndigheten (IMY) responsible for market surveillance of the Article 5 prohibited AI practices, but that proposal carries the placeholder citation "lagen (2026:000)" and has not been enacted.

Separately, and without regard to whether an image was produced with artificial intelligence, Brottsbalken 16 kap. 10 a-10 b §§ criminalizes depicting, producing, distributing, or possessing a pornographic image of a child, a prohibition that binds a generative-AI system's output on the same terms as any other image.

AI governance

SOU 2025:101, Proposed National Implementation of the EU AI Act

Statens offentliga utredningar 2025:101, Anpassningar till AI-förordningenStatens offentliga utredningar (SOU) 2025:101, published by the Government of Sweden and hosted on riksdagen.se

Proposed: draft date not recorded. Binds public and private bodies.

What this law does

Not yet in force. The inquiry submitted its report to the Government in October 2025, proposing a new law and ordinance, both still carrying the placeholder citation "lagen (2026:000) med kompletterande bestämmelser till EU:s förordning om artificiell intelligens", to designate Sweden's national market surveillance authorities under the EU AI Act.

As proposed, Post- och telestyrelsen (PTS) would be the market surveillance authority with the primary, residual responsibility for matters not assigned to another authority. PTS would separately be the coordinating market surveillance authority and the single point of contact under AI Act Article 70.2. Integritetsskyddsmyndigheten (IMY) would be responsible for market surveillance of the Article 5 prohibited AI practices, except where that responsibility is assigned elsewhere.

IMY would separately be responsible for market surveillance of the Article 50.3 transparency duties for certain AI system providers. PTS would also be the body establishing regulatory sandboxes for AI under the proposal, alongside IMY and Finansinspektionen for approving real-world testing of high-risk AI systems outside a sandbox. As proposed, a sanktionsavgift (administrative sanction fee) imposed under the future implementing law would be paid to Kammarkollegiet.

What it requires

AI prohibited practices

Brottsbalken 16 kap. 10 a-10 b §§, Child Pornography Offence (Barnpornografibrott)

Brottsbalk (1962:700) 16 kap. 10 a-10 b §§riksdagen.se, consolidated text of Brottsbalk (1962:700)

In force since 1 May 2020. Binds public and private bodies.

What this law does

Section 10 a of chapter 16 of the Criminal Code makes it an offence to depict a child in a pornographic image, or to distribute, transfer, offer, display, otherwise make available, acquire, offer, broker, possess, or view such an image. A child is defined as a person whose pubertal development is not complete or who is under eighteen years of age. A gross offence under section 10 a carries imprisonment of one to six years.

Section 10 b exempts a person who produces a pornographic image of a child from the section 10 a prohibitions on depiction and possession only where the age and developmental difference between the person depicted and the person producing the image is minor and the surrounding circumstances do not call for liability.

The definition in section 10 a turns on the depicted subject's apparent developmental and age characteristics rather than on any requirement that the image be a photograph of an identified real person. Section 10 a's current wording took effect on 1 May 2020 under Lag (2020:173), the most recent of several amendments since the offence was first added to the Criminal Code.

What it requires

Privacy law7 instruments, 7 in force

Research summary (67 words)

Sweden's private-sector personal-data regime is the General Data Protection Regulation (GDPR) as given domestic effect by Dataskyddslagen (SFS 2018:218), a genuinely light-touch complementing act with no separate biometric-specific or general criminal-penalties chapter. Sweden separately has a distinct Kamerabevakningslagen regulating camera and optical-electronic monitoring equipment through an impact-assessment and registry duty.

Integritetsskyddsmyndigheten (IMY) issued Sweden's landmark biometric enforcement decision in 2019 against a school board's use of facial recognition for attendance tracking.

Biometric privacy

GDPR Article 9, Dataskyddslagen Chapter 3, and the IMY Skelleftea Facial-Recognition Decision

Regulation (EU) 2016/679, Art. 9; Dataskyddslagen, ch. 3; IMY decision Di-2019-2221Dataskyddslagen ch. 3

In force since 25 May 2018. Binds public and private bodies.

What this law does

General Data Protection Regulation (GDPR) Article 9 special categories apply directly; Dataskyddslagen Chapter 3 supplies domestic legal bases letting a public authority process sensitive data for employment-law or important-public-interest purposes, confirmed against the chapter, with no biometric-specific definition or carve-out.

IMY's landmark biometric decision, Di-2019-2221 (20 August 2019, verified from IMY's own decision list), fined the Skelleftea municipal school board 200,000 SEK for using facial-recognition cameras to register student attendance, finding the processing violated Article 9 (no valid legal basis) and Article 5 (data minimization).

IMY's current guidance cites this decision for the rule that biometric attendance tracking is, as a rule, not permitted, and that employer consent is generally not a valid basis given the power imbalance in an employment relationship. No dedicated IMY guidance or enforcement on voiceprints specifically was found in the pages checked.

What it requires

Breach notification

GDPR Articles 33-34, Breach Notification

Regulation (EU) 2016/679, Arts. 33-34GDPR Arts. 33-34

In force since 25 May 2018. Binds public and private bodies.

What this law does

A controller must notify IMY within 72 hours of becoming aware of a personal-data breach, and notify the affected individual without undue delay where the breach is likely to result in a high risk. No Sweden-specific derogation from this timeline or threshold was found in Dataskyddslagen.

What it requires

Comprehensive regime

Dataskyddslagen (Data Protection Act), GDPR-Complementing Provisions

Dataskyddslagen, SFS 2018:218riksdagen.se, Dataskyddslagen SFS 2018:218

In force since 25 May 2018. Binds public and private bodies.

What this law does

Sweden gives the General Data Protection Regulation (GDPR) domestic effect through Dataskyddslagen (SFS 2018:218), enacted 19 April 2018 and in force 25 May 2018. Confirmed against its seven chapters: the Act is genuinely light touch, filling only the gaps GDPR leaves open (member-state legal bases for public-authority processing, a reduced fine scale for public authorities, appeal routes) and adding no separate biometric-specific chapter or general criminal-penalties chapter.

Sweden separately has a distinct Kamerabevakningslagen (SFS 2018:1200, Camera Surveillance Act) regulating any camera or optical-electronic monitoring equipment through an impact-assessment and registry duty rather than data-category rules.

What it requires

Kamerabevakningslagen (Camera Surveillance Act)

Kamerabevakningslag, SFS 2018:1200riksdagen.se, Kamerabevakningslag SFS 2018:1200

In force since 1 August 2018. Binds public and private bodies.

What this law does

Kamerabevakningslagen (SFS 2018:1200), enacted 20 June 2018 and in force 1 August 2018, regulates any TV camera or optical-electronic equipment enabling persistent or regularly repeated monitoring of persons in Sweden, regardless of where the operator is based, confirmed against the statute text. As of 1 April 2025 it eliminated the earlier permit regime in favor of a documented impact assessment, a registry of ongoing surveillance, and a signage duty.

The Act does not itself define or specifically regulate facial recognition or biometric identification; a facial-recognition-capable camera falls within its scope only as surveillance equipment generally, with the biometric-processing duty supplied separately by General Data Protection Regulation (GDPR) Article 9 and Dataskyddslagen Chapter 3.

This is a distinct instrument from the general comprehensive regime and does not cleanly fit any other registered family; it is filed here as the closest match to a self-contained mini-regime for one collection channel.

What it requires

Cross border transfer

GDPR Chapter V, Cross-Border Transfer Restrictions

Regulation (EU) 2016/679, Arts. 44-49, 83(5)GDPR Arts. 44-49, 83(5)

In force since 25 May 2018. Binds public and private bodies.

What this law does

A transfer of personal data outside the EEA requires an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5) top fine tier. Dataskyddslagen's seven chapters, confirmed against the statute text, contain no separate chapter addressing cross-border transfer, so Chapter V governs unmodified with no Sweden-specific derogation identified.

What it requires

Data subject rights

Dataskyddslagen Chapter 7, Data-Subject Rights and Appeal Routes

Dataskyddslagen, ch. 7riksdagen.se, Dataskyddslagen ch. 7

In force since 25 May 2018. Binds public and private bodies.

What this law does

General Data Protection Regulation (GDPR) Articles 12-23 apply directly: access, rectification, erasure, restriction, portability, objection, and Article 22 automated-decision rights.

Dataskyddslagen Chapter 7 adds a domestic procedural layer: a controller's own decision on a rights request may be appealed directly to the general administrative courts (Sec. 2), separately from complaining to IMY, and IMY's own decisions are likewise appealable with IMY as the opposing party (Sec. 3), requiring permission for further appeal to kammarratten.

What it requires

Enforcement supervision

IMY Enforcement, GDPR Article 82, Dataskyddslagen Chapter 6-7, and Group Proceedings

Regulation (EU) 2016/679, Arts. 82-83; Dataskyddslagen, ch. 6-7; Lag (2002:599) om grupprattegangDataskyddslagen ch. 6-7

In force since 25 May 2018. Binds public and private bodies.

What this law does

Integritetsskyddsmyndigheten (IMY) is Sweden's supervisory authority. Dataskyddslagen Chapter 6 caps administrative fines against public authorities below General Data Protection Regulation (GDPR)'s own ceiling (SEK 5,000,000 for Article 83.4 violations, SEK 10,000,000 for Article 83.5-83.6), confirmed against the chapter, and the Act contains no separate criminal-penalties chapter at all.

GDPR Article 82 arms an individual with a direct private right of action, restated for the Swedish Act's own violations by Dataskyddslagen Chapter 7 Section 1.

Sweden separately has a general civil group-litigation mechanism, Lag (2002:599) om grupprattegang, permitting private, organizational, and public group actions; its scope provision covers any claim that could be brought before a general court under civil-dispute rules, with no data-protection-specific text confirming actual use for a GDPR claim.

What it requires

Scraping law3 instruments, 3 in force

Research summary (169 words)

Sweden has no scraping-specific statute, so general law governs each dimension separately. Brottsbalken 4 kap. 9 c § criminalizes unauthorized access to data intended for automated processing, reaching a person who unlawfully gains access without requiring that a security measure be circumvented, unlike some other jurisdictions' computer-misuse offences.

Upphovsrättslagen 49 § confers a sui generis right on the maker of a database (a catalogue, table, or similar work compiling a large number of items, or the result of a substantial investment) against unauthorized extraction, running fifteen years from completion, and transposes the same underlying protection as the EU Database Directive.

Upphovsrättslagen 15 a-15 c §§, added by the 2022 transposition of the EU Digital Single Market Copyright Directive, permits a person with lawful access to a work to reproduce it for text and data mining, subject to an opt-out a rightsholder may exercise by an appropriate, including machine-readable, means, with a separate, unconditional exception for research organizations, libraries, museums, archives, and film or sound heritage institutions mining for research.

Computer misuse

Brottsbalken 4 kap. 9 c §, Unauthorized Computer Access (Dataintrång)

Brottsbalk (1962:700) 4 kap. 9 c §riksdagen.se, consolidated text of Brottsbalk (1962:700)

In force 53 days, effective 1 August 2026. Binds public and private bodies.

What this law does

Section 9 c of chapter 4 of the Criminal Code makes it an offence for a person to unlawfully gain access to information intended for automated processing, or to unlawfully alter, delete, block, or enter such information into a register, or to unlawfully and seriously disturb or hinder the use of such information by another similar means.

The ordinary offence carries a fine or imprisonment of up to two years; a gross offence carries imprisonment of one to eight years, with gravity assessed by whether the act caused serious damage, concerned a large volume of information, or was otherwise of a particularly dangerous nature.

The provision's trigger is unlawful access, not the circumvention of a security measure, so it reaches a broader range of conduct than a statute conditioned on defeating an access control, and its reach to a scraper reading a public, unauthenticated page has not been tested by a reported Swedish decision. Section 9 c's current wording took effect on 1 August 2026 under Lag (2026:1318), the most recent of several amendments since the offence was first added to the Criminal Code.

What it requires

Copyright and text and data mining (TDM)

Upphovsrättslagen 15 a-15 c §§, Text and Data Mining Exception

Upphovsrättslag (1960:729) 15 a-15 c §§, as added by Lag (2022:1712)riksdagen.se, consolidated text of Upphovsrättslag (1960:729)

In force since 1 January 2023. Binds public and private bodies.

What this law does

A person with lawful access to a work may make copies of it for text and data mining purposes under section 15 a, provided the copies are not kept longer than necessary and are not used for other purposes. This general exception does not apply where the author has, in an appropriate manner, reserved that right, which is the opt-out.

A separate exception in section 15 b lets research organizations, libraries and museums accessible to the public, archives, and film or sound heritage institutions make copies of works they lawfully access, except computer programs, to carry out text and data mining for research purposes, without the section 15 a opt-out.

Section 15 c defines text and data mining as an automated technique used to analyze text and data in digital form for the purpose of generating information, and defines a qualifying research organization. A contractual term restricting the right to use a work under these sections is void, and an author may still take proportionate measures to secure the integrity and security of networks and databases containing the work.

What it requires

Database right

Upphovsrättslagen 49 §, Sui Generis Database Right (Katalogskydd)

Upphovsrättslag (1960:729) 49 §riksdagen.se, consolidated text of Upphovsrättslag (1960:729)

In force since 1 January 1998. Binds public and private bodies.

What this law does

The maker of a catalogue, table, or other similar work in which a large number of items has been compiled, or which is the result of a substantial investment, has the exclusive right to make copies of the work and make it available to the public, running for fifteen years from a date set elsewhere in the section. Its current wording took effect on 1 January 1998 under Lag (1997:790), whose own transitional provisions name section 49 specifically.

The provision applies to a work whose maker is a Swedish citizen or has habitual residence in Sweden, and also to a work whose maker is a Swedish legal person with its registered office, head office, or principal place of business in Sweden. This is the same sui generis database right created by the EU Database Directive, sitting alongside ordinary copyright protection for a database whose selection or arrangement is an original creation.

What it requires

Cybersecurity law2 instruments, 2 in force

Research summary (521 words)

Sweden transposed NIS2 through the Cybersäkerhetslag (2025:1506, the Cybersecurity Act), issued by the government on 11 December 2025 and in force since 15 January 2026, which outright repealed the earlier lag (2018:1174) om informationssäkerhet för samhällsviktiga och digitala tjänster, Sweden's NIS1 transposition; a companion Cybersäkerhetsförordning (2025:1507) sets sector-specific supervisory authorities and, as amended, designates Försvarets radioanstalt (FRA), through its Nationellt cybersäkerhetscenter (NCSC), as the single point of contact, the CSIRT unit and the cyber crisis management authority, a role the government decided on 20 November 2025 to transfer to FRA from Myndigheten för samhällsskydd och beredskap (MSB) effective 1 July 2026.

The Law binds a väsentlig (essential) or viktig (important) verksamhetsutövare (operator) by sector and, for most sectors, a medium-or-large size gate (Chapter 1 §§3-9); Chapter 1 §7(1) names a provider of cloud services, data-centre services, content-delivery networks, outsourced operational or security services, an online marketplace, a search engine, or a social-networking-platform service among the digital providers the Act reaches, and the catch-all rule in §9 classifies such a provider as important rather than essential absent a further ground.

The Law also binds certain state authorities, regions, municipalities and kommunalförbund directly (Chapter 1 §3), so it reaches a government duty-bearer as well as a private one, while Chapter 1 §12 carves out an authority whose activity is predominantly security-classified under säkerhetsskyddslagen (2018:585) or predominantly law-enforcement, and Chapter 1 §11 exempts a financial entity already covered by Regulation (EU) 2022/2554 (DORA) from the Law's own Chapter 2 §§3-10 duties.

Chapter 2 §3 sets the core risk-management duty (appropriate and proportionate technical, operational and organisational measures on an all-hazards basis) and §4 requires management-level training; Chapter 2 §§5-8 set NIS2's own graduated significant-incident notification clock to the designated authority (a 24-hour early warning, a 72-hour initial report, or 24 hours for a trust service provider, and a one-month final report), which Cybersäkerhetsförordning (2025:1507) 6 § routes to Försvarets radioanstalt acting as the CSIRT-enhet.

Chapter 4 §§9-10 set NIS2's own two-tier administrative sanktionsavgift (sanction fee): up to the higher of 2 percent of an entity's global turnover or a kronor amount equivalent to EUR 10,000,000 for an essential private operator, up to the higher of 1.4 percent or an equivalent of EUR 7,000,000 for an important one, and a flat SEK 10,000,000 with no turnover component for a public-sector operator, imposed by the sector's own tillsynsmyndighet (supervisory authority) under Chapter 3-4, with no criminal offence and no private right of action; Cybersäkerhetsförordning (2025:1507) 7 § names Post- och telestyrelsen (PTS, the Swedish Post and Telecom Authority) as the tillsynsmyndighet for the 'Digital infrastructure' / 'Digital providers' sector, so PTS supervises an online marketplace, search engine or social-networking-platform provider specifically.

No instrument reviewed here sets a product-security or market-placement duty on a manufacturer independent of the directly applicable EU Cyber Resilience Act, which is documented at the European Union level and is not restated here, and Sweden has no general reasonable-security or information-security-programme statute with no sector gate; the closest general duty is General Data Protection Regulation (GDPR) Article 32's security-of-processing obligation, and Sweden's personal-data breach notification under GDPR Articles 33-34 sits in the privacy topic rather than here.

Sector security regimes

Cybersäkerhetslag, Cybersecurity Risk-Management Measures

Cybersäkerhetslag (2025:1506), 2 kap. 3-4 §§Cybersäkerhetslag (2025:1506), Svensk författningssamling, Sveriges riksdag, Chapters 1-2

In force 8 months, effective 15 January 2026. Binds public and private bodies.

What this law does

Chapter 2 §3 requires a väsentlig (essential) or viktig (important) verksamhetsutövare (operator) to take appropriate and proportionate technical, operational and organisational measures, on an all-hazards basis, to protect the network and information systems it uses for its operations or to provide its services, and their physical environment, against an incident, covering at minimum risk-analysis strategy, incident handling, business continuity and crisis management, supply-chain security, security in system acquisition and development, effectiveness assessment, cyber hygiene and staff training, cryptography, personnel security and access control, and, where relevant, authentication and secure communications.

Chapter 1 §7(1) names a provider of cloud services, data-centre services, content-delivery networks, outsourced operational or security services, an online marketplace, a search engine or a social-networking-platform service expressly among the digital providers this duty reaches, classified as important under the Chapter 1 §9 catch-all absent a further ground.

Chapter 2 §4 additionally requires the operator's management to undergo training on these measures, and Chapter 2 §2 requires the operator to register with the designated authority. Chapter 1 §11 exempts a financial entity already covered by Regulation (EU) 2022/2554 (DORA) from this duty.

What it requires

Vulnerability and incident reporting

Cybersäkerhetslag, Incident Notification

Cybersäkerhetslag (2025:1506), 2 kap. 5-10 §§Cybersäkerhetslag (2025:1506), Svensk författningssamling, Sveriges riksdag, Chapter 2

In force 8 months, effective 15 January 2026. Binds public and private bodies.

What this law does

Chapter 2 §5 requires a väsentlig or viktig verksamhetsutövare to inform the designated authority of a significant incident (betydande incident) as soon as it can and no later than 24 hours after becoming aware of it; an incident is significant if it has caused or could cause serious operational disruption or financial loss, or has affected or could affect other persons by causing significant harm.

Chapter 2 §6 requires the operator to follow with a formal incident notification, within 24 hours of awareness for a trust service provider and within 72 hours for others; §7 requires an interim status report on the authority's request, and §8 requires a final report within one month of the notification, or a progress report followed by a final report within a month of resolution if the incident is still ongoing.

Chapter 2 §9-10 add duties to inform affected service recipients, where appropriate, of a significant incident and of protective measures against a significant cyber threat. This is NIS2 Article 23's own clock; Cybersäkerhetsförordning (2025:1507) 6 § routes the notification itself to Försvarets radioanstalt acting as the CSIRT-enhet.

What it requires

Age gating law1 instrument, 1 in force

Research summary (126 words)

Sweden has no dedicated adult-content age-verification statute, social-media minor-access restriction, app-store age-verification requirement, or age-appropriate design code outside its transposition of the EU Audiovisual Media Services Directive.

Radio- och tv-lagen's video-sharing platform chapter requires a provider established in Sweden to take appropriate measures so that user-generated videos, TV programs, and audiovisual commercial communications with graphic depictions of violence of a realistic nature or with pornographic images are not made available in a way that creates a significant risk that children may see them, and separately to take appropriate measures against certain criminal content, including child pornography under the Criminal Code.

The chapter does not itself mandate a specific verification method such as identity or age checks, leaving the provider to choose measures appropriate to the risk.

Adult content age verification (AV)

Radio- och tv-lagen 9 a kap., Video-Sharing Platform Protection of Minors

Radio- och tv-lag (2010:696) 9 a kap. 1-3 §§riksdagen.se, consolidated text of Radio- och tv-lag (2010:696)

In force since 1 December 2020. Binds public and private bodies.

What this law does

A provider of a video-sharing platform established in Sweden under the Audiovisual Media Services Directive's establishment test must take appropriate measures so that user-generated videos, TV programs, and audiovisual commercial communications carrying graphic depictions of violence of a realistic nature or pornographic images are not made available in a manner creating a significant risk that children may see them, unless justifiable for particular reasons.

Personal data collected or otherwise generated by a video-sharing platform provider to meet that requirement may not be processed for commercial purposes.

A separate duty in the same chapter requires appropriate measures against user-generated videos, TV programs, or audiovisual commercial communications whose content amounts to specified criminal offences, including unlawful threat, incitement to rebellion, agitation against a population group, child pornography under the Criminal Code, unlawful depiction of violence, or public incitement to terrorism or particularly serious crime.

Mediemyndigheten (the Swedish Media Authority) supervises compliance with these measures and may issue an order, which may carry a conditional fine, to secure compliance; the chapter does not itself specify age verification, identity checks, or another particular technical method as the required measure.

Note and primary source

News aggregation law1 instrument, 1 in force

Research summary (144 words)

Sweden transposed the EU Digital Single Market Copyright Directive's press-publisher neighbouring right into Upphovsrättslagen 48 b-48 d §§, giving a press publication's maker an exclusive online reproduction and making-available right, exempted for private or non-commercial use, hyperlinking, and single words or very short extracts, and running two years from publication.

Upphovsrättslagen 48 d § gives the authors whose work appears in a press publication a share of the revenue the publisher collects from information-society service providers for that right. No compelled platform-to-publisher bargaining regime, comparable to Australia's News Media Bargaining Code or Canada's Online News Act, was located in Upphovsrättslagen, and no hot-news or misappropriation doctrine distinct from the press-publisher right was located either.

Sweden's general text-and-data-mining exception, Upphovsrättslagen 15 a-15 c §§, also reaches the mining of press content and is described under the scraping topic, where the duty of reproduction-for-mining is researched.

Press publishers' right

Upphovsrättslagen 48 b-48 d §§, Press Publisher Neighbouring Right

Upphovsrättslag (1960:729) 48 b-48 d §§, as added by Lag (2022:1712)riksdagen.se, consolidated text of Upphovsrättslag (1960:729)

In force since 1 January 2023. Binds private bodies.

What this law does

The maker of a press publication has, subject to the limitations stated in Upphovsrättslagen, an exclusive right to control that publication through an information-society service and for online use, by making copies of it and by making it available to the public in a way that lets individuals access it from a place and at a time they individually choose.

That right does not reach private or non-commercial use by individual users, hyperlinking, or the use of single words or very short extracts of a press publication. It runs until the end of the second year after the year the press publication was published.

Authors whose works form part of a press publication are entitled to an appropriate share of the revenue the publication's maker receives from information-society service providers for exploitation under this right, collected and distributed by an organization representing a substantial number of authors of works used in Sweden in the relevant field.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.