{
  "attribution": {
    "source": "legal.exploreworldai.com",
    "canonical": "https://legal.exploreworldai.com/api/public/v1/topic-node?topic=dataskydd",
    "cite_as": "NovaCopilot, legal.exploreworldai.com (https://legal.exploreworldai.com/api/public/v1/topic-node?topic=dataskydd)",
    "license": "https://legal.exploreworldai.com/revision",
    "version": "legal-2026-10-02",
    "fingerprint": "ewai:shared:3fa481",
    "proof": "sha256:69951d9cd7de5e6a0b1a4302671dcdfae7276c62db34dd2489e348f5c921f65a",
    "jurisdiction": "shared",
    "publisher": "NovaCopilot by ExploreWorld Legal",
    "terms": "https://legal.exploreworldai.com/om"
  },
  "brand_source": "Source: NovaCopilot",
  "brand": {
    "product": "NovaCopilot",
    "platform": "ExploreWorldAI",
    "infrastructure": "ExploreWorld Legal",
    "infrastructure_url": "legal.exploreworldai.com",
    "legal_entity": "Valkiv Ventures AB",
    "permanent_url": "https://legal.exploreworldai.com/novacopilot",
    "source": "Source: NovaCopilot",
    "powered_by": "Powered by NovaCopilot",
    "license": "https://legal.exploreworldai.com/licensvillkor",
    "contact": "stig@valkiv.com"
  },
  "schema_version": 1,
  "topic": "dataskydd",
  "label": {
    "sv": "Dataskydd",
    "en": "Data privacy"
  },
  "read_at": "2026-10-01",
  "page": {
    "sv": "https://legal.exploreworldai.com/amnen/dataskydd",
    "en": "https://legal.exploreworldai.com/en/amnen/dataskydd"
  },
  "nodes": [
    {
      "id": "topic:se:dataskydd",
      "jurisdiction": "se",
      "label": "Dataskydd",
      "answers": [
        {
          "question": "Hur snabbt ska en personuppgiftsincident anmälas?",
          "answer": "En personuppgiftsincident ska anmälas till Integritetsskyddsmyndigheten utan onödigt dröjsmål och om möjligt inom 72 timmar, om den inte sannolikt saknar risk för de registrerade.",
          "source": {
            "identifier": "Artikel 33 förordning (EU) 2016/679",
            "publisher": "EUR-Lex",
            "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj",
            "read_at": "2026-10-01"
          }
        }
      ],
      "questions": [
        "https://legal.exploreworldai.com/fragor/foretag/kundavtal-villkor-och-gdpr"
      ],
      "sha256": "802830de4ed35b8b96ba91dedf045eff68d8999bc1db6917d17d1979c39b44dc",
      "proof": [
        {
          "source": {
            "label": "Artikel 33 förordning (EU) 2016/679",
            "publisher": "EUR-Lex",
            "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj",
            "read_at": "2026-10-01"
          },
          "precedent": {
            "status": "not_in_register",
            "label": null,
            "url": null
          },
          "provision": {
            "label": "Artikel 33 förordning (EU) 2016/679",
            "urls": []
          },
          "object": {
            "id": "topic:se:dataskydd",
            "url": "https://legal.exploreworldai.com/api/public/v1/topic-node?topic=dataskydd&jurisdiction=se"
          },
          "cite_as": "Source: NovaCopilot"
        }
      ],
      "jurisdiction_name": "Sweden",
      "laws": [],
      "chain": [],
      "chain_status": "not_in_register",
      "coverage_status": "source_bound"
    },
    {
      "id": "topic:us:dataskydd",
      "jurisdiction": "us",
      "label": "Data privacy",
      "answers": [
        {
          "question": "Does the CCPA apply to a small business?",
          "answer": "The CCPA applies to a for-profit business that does business in California and meets one threshold: inflation-adjusted annual revenue over the statutory amount, buying, selling or sharing data of 100,000 or more consumers or households, or earning half its revenue from selling or sharing personal information.",
          "source": {
            "identifier": "Cal. Civ. Code § 1798.140(d)",
            "publisher": "California Legislative Information",
            "url": "https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=1798.140",
            "read_at": "2026-10-01"
          }
        }
      ],
      "questions": [
        "https://legal.exploreworldai.com/fragor/us/do-privacy-laws-apply-to-a-small-business",
        "https://legal.exploreworldai.com/fragor/us/which-us-state-privacy-laws-apply",
        "https://legal.exploreworldai.com/fragor/us/ccpa-compared-with-gdpr"
      ],
      "sha256": "ba189597e2b35e61b2c2736986e9ba7344bedad20bbb8c01931896938ccbc2c8",
      "proof": [
        {
          "source": {
            "label": "Cal. Civ. Code § 1798.140(d)",
            "publisher": "California Legislative Information",
            "url": "https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=1798.140",
            "read_at": "2026-10-01"
          },
          "precedent": {
            "status": "linked",
            "label": "compliance:us:ccpa",
            "url": "https://legal.exploreworldai.com/api/public/v1/compliance-chain?act=ccpa"
          },
          "provision": {
            "label": "Cal. Civ. Code § 1798.140(d)",
            "urls": []
          },
          "object": {
            "id": "topic:us:dataskydd",
            "url": "https://legal.exploreworldai.com/api/public/v1/topic-node?topic=dataskydd&jurisdiction=us"
          },
          "cite_as": "Source: NovaCopilot"
        }
      ],
      "jurisdiction_name": "United States",
      "laws": [],
      "chain": [
        {
          "compliance_id": "compliance:us:ccpa~business",
          "act": "ccpa",
          "role": "business",
          "url": "https://legal.exploreworldai.com/api/public/v1/compliance-chain?act=ccpa&role=business"
        },
        {
          "compliance_id": "compliance:us:ftc-act~covered-entity",
          "act": "ftc-act",
          "role": "covered-entity",
          "url": "https://legal.exploreworldai.com/api/public/v1/compliance-chain?act=ftc-act&role=covered-entity"
        }
      ],
      "chain_status": "linked",
      "coverage_status": "source_bound"
    },
    {
      "id": "topic:us-ny:dataskydd",
      "jurisdiction": "us-ny",
      "label": "Data privacy",
      "answers": [
        {
          "question": "Who must maintain reasonable safeguards under the SHIELD Act?",
          "answer": "A person or business owning or licensing computerized data containing a New York resident's private information must develop, implement and maintain reasonable safeguards appropriate to the business.",
          "source": {
            "identifier": "N.Y. Gen. Bus. Law § 899-bb",
            "publisher": "New York State Senate Open Legislation",
            "url": "https://www.nysenate.gov/legislation/laws/GBS/899-BB",
            "read_at": "2026-09-22"
          }
        }
      ],
      "questions": [
        "https://legal.exploreworldai.com/us/new-york/questions/shield-reasonable-safeguards"
      ],
      "sha256": "c7cf1c2069cc60a05843a761ca520b32b9e199c76fe9115544b00bb370df001d",
      "proof": [
        {
          "source": {
            "label": "N.Y. Gen. Bus. Law § 899-bb",
            "publisher": "New York State Senate Open Legislation",
            "url": "https://www.nysenate.gov/legislation/laws/GBS/899-BB",
            "read_at": "2026-09-22"
          },
          "precedent": {
            "status": "not_in_register",
            "label": null,
            "url": null
          },
          "provision": {
            "label": "N.Y. Gen. Bus. Law § 899-bb",
            "urls": []
          },
          "object": {
            "id": "topic:us-ny:dataskydd",
            "url": "https://legal.exploreworldai.com/api/public/v1/topic-node?topic=dataskydd&jurisdiction=us-ny"
          },
          "cite_as": "Source: NovaCopilot"
        }
      ],
      "jurisdiction_name": "New York",
      "laws": [],
      "chain": [],
      "chain_status": "not_in_register",
      "coverage_status": "source_bound"
    },
    {
      "id": "topic:us-ca:dataskydd",
      "jurisdiction": "us-ca",
      "label": "Data privacy",
      "answers": [
        {
          "question": "Which businesses are covered by the CCPA?",
          "answer": "The CCPA covers a for-profit entity doing business in California that determines processing purposes and meets at least one statutory revenue, data-volume or revenue-share threshold, plus specified controlled entities and joint ventures.",
          "source": {
            "identifier": "Cal. Civ. Code § 1798.140(d)",
            "publisher": "California Legislative Information",
            "url": "https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=1798.140.",
            "read_at": "2026-09-22"
          }
        }
      ],
      "questions": [
        "https://legal.exploreworldai.com/us/california/questions/ccpa-business-thresholds"
      ],
      "sha256": "3b10ea7d54bafb2785eb7f8c76f9692614abeb965f037d35201a1875a27dd3d8",
      "proof": [
        {
          "source": {
            "label": "Cal. Civ. Code § 1798.140(d)",
            "publisher": "California Legislative Information",
            "url": "https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=1798.140.",
            "read_at": "2026-09-22"
          },
          "precedent": {
            "status": "not_in_register",
            "label": null,
            "url": null
          },
          "provision": {
            "label": "Cal. Civ. Code § 1798.140(d)",
            "urls": []
          },
          "object": {
            "id": "topic:us-ca:dataskydd",
            "url": "https://legal.exploreworldai.com/api/public/v1/topic-node?topic=dataskydd&jurisdiction=us-ca"
          },
          "cite_as": "Source: NovaCopilot"
        }
      ],
      "jurisdiction_name": "California",
      "laws": [],
      "chain": [],
      "chain_status": "not_in_register",
      "coverage_status": "source_bound"
    },
    {
      "id": "topic:us-de:dataskydd",
      "jurisdiction": "us-de",
      "label": "Data privacy",
      "answers": [],
      "questions": [],
      "sha256": "288f7211ba82519f8a77e4f8988d230fd4faf8f488f87e9d06ee98592990c851",
      "proof": [],
      "jurisdiction_name": "Delaware",
      "laws": [],
      "chain": [],
      "chain_status": "not_in_register",
      "coverage_status": "not_yet_covered"
    },
    {
      "id": "topic:no:dataskydd",
      "jurisdiction": "no",
      "label": "Data privacy",
      "answers": [
        {
          "question": "Kan arbeidsgiver se i den ansattes e-post?",
          "answer": "Bare i to tilfeller: når det er nødvendig for å ivareta den daglige driften eller andre berettigede interesser i virksomheten, eller ved begrunnet mistanke om grovt pliktbrudd eller straffbart forhold. Den ansatte skal så langt som mulig varsles og gis anledning til å uttale seg og til å være til stede, og innsynet skal dokumenteres. Regelen står i forskrift 2. juli 2018 nr. 1108, gitt med hjemmel i arbeidsmiljøloven § 9-5, og behandlingen må i tillegg oppfylle personopplysningsloven og GDPR.",
          "source": {
            "identifier": "Forskrift om arbeidsgivers innsyn i e-postkasse §§ 2 og 3, jf. arbeidsmiljøloven § 9-5",
            "publisher": "Lovdata",
            "url": "https://lovdata.no/dokument/NL/lov/2018-06-15-38",
            "read_at": "2026-09-22"
          }
        }
      ],
      "questions": [
        "https://legal.exploreworldai.com/no/norge/sporsmal/personvern-ansatte-innsyn"
      ],
      "sha256": "176d1dc48de5fa3f811ad7e0f0be7329d9851f16c66abd09100431967613baf5",
      "proof": [
        {
          "source": {
            "label": "Forskrift om arbeidsgivers innsyn i e-postkasse §§ 2 og 3, jf. arbeidsmiljøloven § 9-5",
            "publisher": "Lovdata",
            "url": "https://lovdata.no/dokument/NL/lov/2018-06-15-38",
            "read_at": "2026-09-22"
          },
          "precedent": {
            "status": "not_in_register",
            "label": null,
            "url": null
          },
          "provision": {
            "label": "Forskrift om arbeidsgivers innsyn i e-postkasse §§ 2 og 3, jf. arbeidsmiljøloven § 9-5",
            "urls": [
              "https://legal.exploreworldai.com/no/norge/lov/personopplysningsloven"
            ]
          },
          "object": {
            "id": "topic:no:dataskydd",
            "url": "https://legal.exploreworldai.com/api/public/v1/topic-node?topic=dataskydd&jurisdiction=no"
          },
          "cite_as": "Source: NovaCopilot"
        }
      ],
      "jurisdiction_name": "Norway",
      "laws": [
        "https://legal.exploreworldai.com/no/norge/lov/personopplysningsloven"
      ],
      "chain": [],
      "chain_status": "not_in_register",
      "coverage_status": "source_bound"
    },
    {
      "id": "topic:dk:dataskydd",
      "jurisdiction": "dk",
      "label": "Data privacy",
      "answers": [
        {
          "question": "Hvornår skal et brud på persondatasikkerheden anmeldes til Datatilsynet?",
          "answer": "Den dataansvarlige skal anmelde bruddet uden unødig forsinkelse og om muligt senest 72 timer efter, at bruddet er konstateret, medmindre det er usandsynligt, at bruddet medfører en risiko for de registrerede. Ved høj risiko skal de registrerede også underrettes. Alle brud skal dokumenteres internt, også de der ikke anmeldes.",
          "source": {
            "identifier": "Databeskyttelsesforordningen artikel 33 og 34, sammen med databeskyttelsesloven",
            "publisher": "Retsinformation",
            "url": "https://www.retsinformation.dk/eli/lta/2018/502",
            "read_at": "2026-10-01"
          }
        }
      ],
      "questions": [
        "https://legal.exploreworldai.com/danmark/spoergsmaal/brud-paa-persondatasikkerheden"
      ],
      "sha256": "3190857c178b83ea0412c2f1b48f70c0b72c9780efa87bb2bbc2457877af5fd1",
      "proof": [
        {
          "source": {
            "label": "Databeskyttelsesforordningen artikel 33 og 34, sammen med databeskyttelsesloven",
            "publisher": "Retsinformation",
            "url": "https://www.retsinformation.dk/eli/lta/2018/502",
            "read_at": "2026-10-01"
          },
          "precedent": {
            "status": "not_in_register",
            "label": null,
            "url": null
          },
          "provision": {
            "label": "Databeskyttelsesforordningen artikel 33 og 34, sammen med databeskyttelsesloven",
            "urls": [
              "https://legal.exploreworldai.com/danmark/lov/databeskyttelsesloven"
            ]
          },
          "object": {
            "id": "topic:dk:dataskydd",
            "url": "https://legal.exploreworldai.com/api/public/v1/topic-node?topic=dataskydd&jurisdiction=dk"
          },
          "cite_as": "Source: NovaCopilot"
        }
      ],
      "jurisdiction_name": "Denmark",
      "laws": [
        "https://legal.exploreworldai.com/danmark/lov/databeskyttelsesloven"
      ],
      "chain": [],
      "chain_status": "not_in_register",
      "coverage_status": "source_bound"
    },
    {
      "id": "topic:fi:dataskydd",
      "jurisdiction": "fi",
      "label": "Data privacy",
      "answers": [
        {
          "question": "Milloin tietoturvaloukkauksesta on ilmoitettava tietosuojavaltuutetulle?",
          "answer": "Rekisterinpitäjän on ilmoitettava henkilötietojen tietoturvaloukkauksesta ilman aiheetonta viivytystä ja mahdollisuuksien mukaan 72 tunnin kuluessa siitä, kun loukkaus on tullut tietoon, jollei loukkauksesta todennäköisesti aiheudu riskiä rekisteröidyille. Korkean riskin tilanteessa myös rekisteröidyille on ilmoitettava. Kaikki loukkaukset on dokumentoitava sisäisesti.",
          "source": {
            "identifier": "Tietosuoja-asetuksen 33 ja 34 artikla yhdessä tietosuojalain kanssa",
            "publisher": "Finlex",
            "url": "https://www.finlex.fi/fi/lainsaadanto/2018/1050",
            "read_at": "2026-10-01"
          }
        }
      ],
      "questions": [
        "https://legal.exploreworldai.com/suomi/kysymykset/tietoturvaloukkaus-ilmoitus"
      ],
      "sha256": "1620596987a29e9b7bacb9fa98e9928168304f533134e2d50ef6947dab9bf1e2",
      "proof": [
        {
          "source": {
            "label": "Tietosuoja-asetuksen 33 ja 34 artikla yhdessä tietosuojalain kanssa",
            "publisher": "Finlex",
            "url": "https://www.finlex.fi/fi/lainsaadanto/2018/1050",
            "read_at": "2026-10-01"
          },
          "precedent": {
            "status": "not_in_register",
            "label": null,
            "url": null
          },
          "provision": {
            "label": "Tietosuoja-asetuksen 33 ja 34 artikla yhdessä tietosuojalain kanssa",
            "urls": [
              "https://legal.exploreworldai.com/suomi/laki/tietosuojalaki"
            ]
          },
          "object": {
            "id": "topic:fi:dataskydd",
            "url": "https://legal.exploreworldai.com/api/public/v1/topic-node?topic=dataskydd&jurisdiction=fi"
          },
          "cite_as": "Source: NovaCopilot"
        }
      ],
      "jurisdiction_name": "Finland",
      "laws": [
        "https://legal.exploreworldai.com/suomi/laki/tietosuojalaki"
      ],
      "chain": [],
      "chain_status": "not_in_register",
      "coverage_status": "source_bound"
    },
    {
      "id": "topic:de:dataskydd",
      "jurisdiction": "de",
      "label": "Data privacy",
      "answers": [
        {
          "question": "Wann muss ein Unternehmen einen Datenschutzbeauftragten benennen?",
          "answer": "Nicht-öffentliche Stellen benennen einen Datenschutzbeauftragten, soweit sie in der Regel mindestens zwanzig Personen ständig mit der automatisierten Verarbeitung personenbezogener Daten beschäftigen. Unabhängig davon besteht die Pflicht, wenn nach der Verordnung eine Datenschutz-Folgenabschätzung durchzuführen ist oder Daten geschäftsmäßig zur Übermittlung verarbeitet werden.",
          "source": {
            "identifier": "Bundesdatenschutzgesetz, § 38",
            "publisher": "Bundesministerium der Justiz, Gesetze im Internet",
            "url": "https://www.gesetze-im-internet.de/bdsg_2018/",
            "read_at": "2026-10-01"
          }
        }
      ],
      "questions": [
        "https://legal.exploreworldai.com/deutschland/fragen/datenschutzbeauftragter-benennen"
      ],
      "sha256": "5958cf43d457a7ea478d2900074eb43c8a539ad885f3aa288c2ecf60852ee34e",
      "proof": [
        {
          "source": {
            "label": "Bundesdatenschutzgesetz, § 38",
            "publisher": "Bundesministerium der Justiz, Gesetze im Internet",
            "url": "https://www.gesetze-im-internet.de/bdsg_2018/",
            "read_at": "2026-10-01"
          },
          "precedent": {
            "status": "not_in_register",
            "label": null,
            "url": null
          },
          "provision": {
            "label": "Bundesdatenschutzgesetz, § 38",
            "urls": [
              "https://legal.exploreworldai.com/deutschland/gesetz/bundesdatenschutzgesetz"
            ]
          },
          "object": {
            "id": "topic:de:dataskydd",
            "url": "https://legal.exploreworldai.com/api/public/v1/topic-node?topic=dataskydd&jurisdiction=de"
          },
          "cite_as": "Source: NovaCopilot"
        }
      ],
      "jurisdiction_name": "Germany",
      "laws": [
        "https://legal.exploreworldai.com/deutschland/gesetz/bundesdatenschutzgesetz"
      ],
      "chain": [],
      "chain_status": "not_in_register",
      "coverage_status": "source_bound"
    },
    {
      "id": "topic:fr:dataskydd",
      "jurisdiction": "fr",
      "label": "Data privacy",
      "answers": [
        {
          "question": "Quel est le rôle de la CNIL dans le contrôle des traitements de données ?",
          "answer": "La Commission nationale de l'informatique et des libertés est l'autorité de contrôle française au sens du règlement général sur la protection des données. Elle informe, conseille, contrôle sur place et sur pièces, instruit les plaintes et peut prononcer des mesures correctrices et des sanctions.",
          "source": {
            "identifier": "Loi n° 78-17, article 8",
            "publisher": "Légifrance",
            "url": "https://www.legifrance.gouv.fr/loda/id/JORFTEXT000000886460/",
            "read_at": "2026-10-01"
          }
        }
      ],
      "questions": [
        "https://legal.exploreworldai.com/france/questions/role-de-la-cnil"
      ],
      "sha256": "8433b5f7698d5a258c46be848d90a2e62a9687adfa9c7f6073b54bf6f45607d7",
      "proof": [
        {
          "source": {
            "label": "Loi n° 78-17, article 8",
            "publisher": "Légifrance",
            "url": "https://www.legifrance.gouv.fr/loda/id/JORFTEXT000000886460/",
            "read_at": "2026-10-01"
          },
          "precedent": {
            "status": "not_in_register",
            "label": null,
            "url": null
          },
          "provision": {
            "label": "Loi n° 78-17, article 8",
            "urls": [
              "https://legal.exploreworldai.com/france/loi/loi-informatique-et-libertes"
            ]
          },
          "object": {
            "id": "topic:fr:dataskydd",
            "url": "https://legal.exploreworldai.com/api/public/v1/topic-node?topic=dataskydd&jurisdiction=fr"
          },
          "cite_as": "Source: NovaCopilot"
        }
      ],
      "jurisdiction_name": "France",
      "laws": [
        "https://legal.exploreworldai.com/france/loi/loi-informatique-et-libertes"
      ],
      "chain": [],
      "chain_status": "not_in_register",
      "coverage_status": "source_bound"
    }
  ],
  "cite_as": "Source: NovaCopilot",
  "hash": "sha256:69951d9cd7de5e6a0b1a4302671dcdfae7276c62db34dd2489e348f5c921f65a",
  "version": "legal-2026-10-02",
  "expires": "2026-10-03T12:00:00.000Z",
  "dependency": {
    "index_version": "legal-2026-10-02+legal-2026-10-02+2026-10-02T17:16:21",
    "content_hash": "sha256:69951d9cd7de5e6a0b1a4302671dcdfae7276c62db34dd2489e348f5c921f65a",
    "revalidate_after": "2026-10-03T04:48:39.754Z",
    "max_copy_age_seconds": 3600,
    "policy": "revalidate-required; attribution-preferred",
    "changelog": "https://legal.exploreworldai.com/api/public/v1/dependency",
    "verify": "https://legal.exploreworldai.com/api/public/v1/verify",
    "stale_copy_invalid": true
  },
  "canonical": "https://legal.exploreworldai.com/api/public/v1/topic-node?topic=dataskydd",
  "disclaimer": "Källhänvisning med officiell identifierare. Ingen juridisk rådgivning och inget efterlevnadsbeslut.",
  "content_notice": {
    "legal_advice": false,
    "nature": "Källregister. Endast information, inte juridisk rådgivning och ingen bedömning av ett enskilt ärende.",
    "kinds": {
      "official_text": "Officiell källtext, ordagrann och ej tolkad",
      "summary": "Sammanfattning, ej juristgranskad. Läs alltid källtexten",
      "classification": "Automatisk märkning ur källans egen text, ej juristgranskad"
    },
    "rule": "Endast fält märkta official_text är lagens egen lydelse. Allt annat pekar på den.",
    "report_error": "https://legal.exploreworldai.com/api/public/v1/corrections",
    "ai_act_declaration": "https://legal.exploreworldai.com/api/public/v1/ai-act-declaration"
  },
  "usageInfo": "https://legal.exploreworldai.com/citering"
}