SWEDEN Trends and Developments Contributed by: John Neway Herrman, Erik Ålander, Dahae Roland and Agne Lindberg, Advokatfirman Delphi AB
EU directives, it is more important than ever to prioritise cybersecurity at all levels of corporate management and governance. Cybersecurity should be viewed as a strategic issue, not merely an operational concern of the IT department. Fintech: Navigating Regulatory Challenges Sweden has long been a standout in the tech world, boasting a remarkably large tech sector relative to the size of the economy. The coun - try has also made significant strides in fintech, serving as the birthplace of globally recognised companies like Klarna, Zettle (formerly iZettle), and Trustly. However, this dynamic sector faces hurdles, including an increasingly complex reg - ulatory environment and economic pressures. Rising interest rates have made it harder for start-ups to secure venture capital, with funding now more closely tied to profitability rather than to pure growth. Despite these challenges, many fintech companies remain optimistic about future growth, with plans to expand their workforce. Some of the key regulatory developments shap - ing the fintech landscape are outlined below. DORA is here: what this means for compliance The Digital Operational Resilience Act (DORA), effective from 17 January 2025, introduces extensive IT security requirements for financial entities such as banks, insurance firms, and investment companies. Its objective is to ensure that the financial sector can withstand severe operational disruptions. In Sweden, DORA is expected to enhance the oversight powers of both Swedish and European supervisory authorities. Financial entities must comply with obligations including information and communication technology (ICT) risk man - agement, incident reporting, third-party risk monitoring, and operational resilience testing.
This necessitates transparent communication with supervisory bodies to keep them informed about compliance status and major ICT devel - opments. A key emphasis of DORA is on supply chain control, which, among other things, requires significant investment from financial entities to renegotiate supplier contracts to meet the Act’s requirements on obligations related to, for exam - ple, service levels, business continuity meas - ures, audit rights, and termination clauses tied to compliance. Consequently, this has forced sup - pliers who are not covered to align with stricter cybersecurity standards, as the requirements are passed down through contractual arrange - ments. Blockchain: driving innovation and regulation Sweden’s strong commitment to innovation is reflected in its continued investment in block - chain technology. Both the public and private sectors are exploring blockchain’s potential to enhance trust and security through traceabil - ity. Projects such as the Swedish Land Regis - try’s ( Lantmäteriet ) blockchain experiments and the Swedish Companies Registration Office’s ( Bolagsverket ) Proof of Business initiative show - case blockchain’s diverse applications, from land transfers to real-time company data access. Regulatory oversight is increasing, particularly in the crypto-space. The Swedish Financial Super - visory Authority ( Finansinspektionen ) or SFSA is intensifying its focus on anti-money laundering compliance, supported by the EU’s Markets in Crypto-Assets Regulation (MiCA). MiCA, effec - tive since summer 2024, will expand the SFSA’s supervision of crypto-related activities, providing enhanced consumer protection while fostering industry stability.
451 CHAMBERS.COM
Powered by FlippingBook