Cybersecurity 2026

SWEDEN Law and Practice Contributed by: Anders Bergsten and Victoria Nordenberg, Mannheimer Swartling Advokatbyrå AB

The Swedish Cybersecurity Act applies to essential public or private entities operating in Sweden within certain defined sectors deemed particularly critical and is supplemented by binding delegated regula - tions. The EU General Data Protection Regulation (Regu - lation (EU) 2016/679, GDPR) sets the standard for data protection and privacy in the EU, and requires organisations to implement robust security measures to protect personal data. The Data Protection Act (Sw. Lag (2018:218) med kompletterande bestämmelser till EU:s dataskyddsförordning ) supplements the GDPR by providing additional national rules for data protec - tion in Sweden, ensuring comprehensive data secu - rity. See 6.1 Cybersecurity and Data Protection . The Patient Data Act (Sw. Patientdatalag (2008:355)) and the Patient Data Regulation (Sw. Patientdata- förordning (2008:360)) supplements the GDPR and includes regulations for handling personal data in the healthcare sector. The Patient Data Act is supplement - ed by binding delegated regulations. The Critical Entities Resilience Directive (Directive (EU) 2022/2557, CER) strengthens the resilience of entities providing essential services (including, among oth - ers, banking and financial market infrastructure) by requiring member states to identify critical entities and ensure they implement proportionate organisational and technical measures to prevent, resist and recover from disruptive incidents. The EU Cyber Resilience Act (Regulation (EU) 2024/2847, CRA) introduces harmonised, horizontal cybersecurity requirements for products with digital elements placed on the EU market, imposing life cycle security obligations primarily on manufacturers (and, where relevant, other supply-chain actors). See 4. Cyber-Resilience . The EU Digital Operational Resilience Act (Regulation (EU) 2022/2554, DORA) aims to enhance digital oper - ational resilience within the financial sector by setting uniform requirements across the EU. The regulation covers nearly the entire EU financial sector and critical ICT third-party providers regardless of their location, as long as they serve EU financial entities. The regu -

lation is significantly supplemented through binding technical standards and implementing acts. See 3. Operational Resilience in the Financial Sector . The Cybersecurity Act (Regulation (EU) 2019/881) establishes the European Union Agency for Cyber - security (ENISA) and a framework for cybersecurity certification of ICT products. European cybersecurity certificates issued are recognised in all EU member states. ENISA compiles and publishes guidelines and develops good practices concerning cybersecurity requirements, though these are not directly binding. However, where a specific Union legal act provides, a certificate or EU statement of conformity may be used to demonstrate presumption of conformity with requirements of that legal act. See 5.1 Key Cyberse- curity Certification Legislation . The EU Artificial Intelligence Act (Regulation (EU) 2024/1689, “AI Act”) establishes rules for artificial intelligence, including security requirements for AI systems, to ensure they are safe and trustworthy. The AI Act applies to providers placing on the market or putting into service AI systems in the EU, regardless of their location. See 6.2 Cybersecurity and AI . The EU regulation on electronic identification and trust services (Regulation (EU) No 910/2014, eIDAS) gov - erns electronic identification and trust services, ensur - ing secure electronic transactions across the EU and setting the standards for secure electronic signatures and transactions. It applies to notified eID schemes and to trust service providers established in the EU. 1.3 Cybersecurity Regulators The Electronic Communications Act and the Electronic Communications Regulation The Swedish Post and Telecom Authority (PTS) super - vises compliance with the Acts and related EU instru - ments. PTS may issue corrective injunctions with fines (Sw: vite ), revoke permits or order cessation of busi - ness in cases of non-compliance, or impose admin - istrative sanction fees, and has investigative powers including access to premises and ordering compul - sory production of documents. A national telecom co- operation group (Sw: nationella telesamverkansgrup- pen ) led by PTS, which includes the Swedish Civil Defence and Resilience Agency (MCF), the Swedish

355 CHAMBERS.COM

Powered by