SWEDEN Law and Practice Contributed by: Anders Bergsten and Victoria Nordenberg, Mannheimer Swartling Advokatbyrå AB
breaches. A personal data breach involves a security incident resulting in accidental or unlawful destruc - tion, loss, alteration, unauthorised disclosure of or access to personal data. A breach is reportable depending on the risk to indi - viduals’ rights and freedoms: (i) notification to the supervisory authority is required unless the breach is unlikely to result in a risk; and (ii) communication to data subjects is generally required if the breach is likely to result in a high risk. If a breach risks individuals’ rights and freedoms, the controller must notify IMY within 72 hours of aware - ness without undue delay and, where feasible, within 72 hours of becoming aware. If notification is made later than 72 hours, the controller shall be able to jus - tify the delay. Where not all information is available at the same time, the notification may be provided in phases without undue further delay. The notification shall at least include a description of: • the nature of the breach, including (where pos - sible) the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned; • the likely consequences of the breach; • the measures taken or proposed to mitigate the consequences of the breach; and • contact information for further inquiries (eg, data protection officer or other contact point). If a breach likely poses a high risk to individuals’ rights and freedoms, the data subject should generally be informed without undue delay. The communication to data subjects should describe in clear and plain lan - guage the nature of the breach and include at least: contact information, the likely consequences, and the measures taken or proposed to mitigate the conse - quences. However, communication to data subjects is generally not required if, for example: • the controller has implemented appropriate techni - cal and organisational protection measures (such
as encryption) that render the personal data unin - telligible to unauthorised persons; • the controller has taken subsequent measures which ensure that the high risk is no longer likely to materialise; or • it would involve disproportionate effort (in which case a public communication or similar measure may be used instead). All breaches must be documented by the controller, regardless of risk level. This includes facts relating to the breach, its effects and the remedial action taken. However, it should be noted that the Data Protection Act stipulates that if an incident which constitutes a personal data breach is to be notified under the Pro - tective Security Act, then the notification and informa - tion obligations under Article 33 and 34 of the GDPR shall not be applicable. 6.2 Cybersecurity and AI The AI Act The AI Act became effective from 1 August 2024 and is applied in phases, with most obligations applying from 2 August 2026 (and GP-AI model obligations from 2 August 2025) establishes a unified framework for AI development and use within the EU. It categorises AI systems based on risk levels, imposing stricter require - ments on high-risk applications, such as those in criti - cal infrastructure, healthcare, and law enforcement. For Sweden, this means adapting national regulations to comply with EU standards, ensuring AI systems are human-centred, reliable, and aligned with funda - mental rights. This includes mechanisms for oversight and enforcement to maintain high protection levels for health, safety, and fundamental rights. Sweden is preparing supplementary national measures (including authority allocation and enforcement), and the inquiry’s final report SOU 2025:101 “Adaptations to the AI Regu - lation: Safe use, effective control and support for inno - vation” is currently out for consultation. Under the AI Act, cybersecurity obligations arise pri - marily for providers (and, in some cases, deployers and other actors in the supply chain), in particular for high-risk AI systems and general-purpose AI (GPAI) models with systemic risk.
366 CHAMBERS.COM
Powered by FlippingBook