Cybersecurity 2026

SWEDEN Law and Practice Contributed by: Anders Bergsten and Victoria Nordenberg, Mannheimer Swartling Advokatbyrå AB

The Swedish Cybersecurity Act MCF is the primary regulator, acting as a co-ordinator among sector-specific regulators and a national con - tact point in the EU co-operation regarding NIS2. The supervisory authorities for the different sectors can be viewed here . Supervisory authorities may demand information and documents, access premises, conduct regu - lar and targeted security audits and security scans, issue compliance injunctions with fines, and impose administrative sanction fees. MCF is designated as Sweden’s CSIRT unit under the Act, receiving incident reports, supporting affected entities, sharing incident information with supervisory authorities, and collect - ing and analysing forensic data. GDPR and the Data Protection Act IMY has the supervision mandate in Sweden. The Swedish Authority for Privacy Protection ensures that organisations implement robust security measures to protect personal data. Their authority covers all per - sonal data processing activities within Sweden. IMY has investigative powers (ordering provision of infor - mation, conducting audits, and accessing personal data and premises), corrective powers (warnings, reprimands, compliance orders, processing bans, administrative fines, and suspension of data flows), authorisation and advisory powers. The GDPR and Swedish Data Protection Act do not establish cyber- incident response teams. The Patient Data Act IMY is the supervisory authority that supervises the application of data protection rules by healthcare providers, which means, for example, checking that healthcare providers take security measures to pro - tect patient data. The Inspectorate for Health and Care (Sw: Inspektionen för vård och omsorg , IVO) exercises certain supervisory powers, including adjudication of questions concerning disclosure of patient records from private healthcare, and powers to require pro - vision of documents and information. IVO may also order seizure of patient records if there are probable grounds that they will not be handled in accordance with the law.

Armed Forces and other public and private actors, co- ordinates crisis planning and restoration of electronic communications infrastructure during peacetime cri - ses or heightened preparedness. The Accounting Act The Swedish Accounting Standards Board (BFN) is the supervisory authority, focusing on the secure handling and storage of financial data. Although pri - marily concerned with accounting practices, BFN’s role includes ensuring that financial data is protected against unauthorised access. The Swedish Account - ing Act does not establish cyber-incident response teams. The Camera Surveillance Act The Swedish Authority for Privacy Protection (IMY) is the supervisory authority under this act, balanc - ing security needs with privacy rights. The supervi - sion shall ensure that surveillance systems are secure against unauthorised access, protecting individuals’ privacy while allowing for necessary security meas - ures. IMY supervises compliance using the powers available under the GDPR framework. The Camera Surveillance Act does not establish cyber-incident response teams. The Protective Security Act The supervisory mandate is divided up according to the sector in which the supervised entity (referred to as ‘the operator’) is active and the following authorities are sharing the mandate; the Swedish Security Ser - vice, the Swedish Armed Forces, Svenska Kraftnät (The Swedish National Grid), the Swedish Transport Agency, PTS, the Swedish Defence Materiel Administration, the Swedish Financial Supervisory Authority, the Swedish Energy Agency, the Swedish Radiation Safety Author - ity, the County Administrative Boards of Stockholm, Skåne, Västra Götaland and Norrbotten. The supervi - sion shall ensure that the operators fulfil the obligations imposed and focus on protection of security sensitive activities from cyber threats. Their role is critical in safe - guarding national security and ensuring the protection of critical infrastructure. Supervisory authorities may demand information and documents, access premises, issue compliance injunctions with fines, and impose administrative sanction fees.

356 CHAMBERS.COM

Powered by