Cybersecurity 2026

SWEDEN Law and Practice Contributed by: Anders Bergsten and Victoria Nordenberg, Mannheimer Swartling Advokatbyrå AB

to guarantee that users are provided with adequate information regarding the relevant cybersecurity features. The EU framework is implemented through specific European cybersecurity certification schemes adopt - ed by the European Commission. The first adopted EU-wide scheme is the European Common Criteria- based cybersecurity certification scheme (EUCC), adopted in 2024 and amended in 2025. EUCC pri - marily targets ICT products and is intended to support mutual recognition across the EU. As with the overall framework, use of EUCC is generally voluntary, but it may be required in practice by customer requirements or procurement in high-assurance contexts. National Cybersecurity Certification Authority In Sweden, the Swedish Defence Materiel Adminis - tration acts as the national cybersecurity certifica - tion authority. It is the cybersecurity and certification department at the Swedish Defence Materiel Adminis - tration that is responsible for matters related to cyber - security certification, supervision, collaboration, and external monitoring. The department consists of the Swedish Certification Body for IT Security and the Swedish Cyber Security Certification Authority. Furthermore, the Swedish Defence Materiel Admin - istration is tasked with overseeing and co-ordinating certification activities at the national level and col - laborating with EU entities such as the EU Agency for Network and Information Security and the European Commission. It also serves as Sweden’s representa - tive in the European Cybersecurity Certification Group. Additionally, the Swedish Defence Materiel Admin - istration is responsible for notifying the EU about accredited bodies and those authorised under the Cybersecurity Act. 6. Cybersecurity in Other Regulations 6.1 Cybersecurity and Data Protection GDPR and Swedish Supplementation GDPR aims to protect natural persons when process - ing personal data. In Sweden, the GDPR is supple -

mented by the Data Protection Act, which contains supplementary provisions to the GDPR. Controller Responsibilities and Data Processing Agreements A legal entity that determines the purposes and means of processing personal data is a controller under GDPR. While a controller can appoint a processor to process data on its behalf, the ultimate responsibility for compliance remains with the controller. To ensure the processor adheres to GDPR requirements, the parties must enter into a data processing agreement that governs the processing activities and outlines both parties’ obligations and rights. A processor must notify the controller without undue delay after becom - ing aware of a personal data breach. Protective Measures and Data Subject’s Rights The GDPR requires controllers to implement appro - priate technical and organisational measures to pro - tect the processed personal data from unauthorised access. The appropriate measures should be deter - mined based on the risk of the processing. (taking into account, eg, state of the art, implementation costs, and the nature, scope, context and purposes of pro - cessing). This may include: • pseudonymisation and encryption of personal data; • ensuring ongoing confidentiality, integrity, availabil - ity, and resilience; • ensure data restoration, including timely restoration after an incident; and • regularly test, assess, and evaluate measures. The controller must also inform data subjects about the processing of their personal data and of their rights. The data subject’s rights include: • right to access to personal data and information; • right to rectification; • right to erasure; • right to restriction of processing; • right to data portability; and • right to object. Data Breaches and Thresholds Entities processing personal data must adhere to GDPR’s specific provisions regarding personal data

365 CHAMBERS.COM

Powered by