Does a small Swedish company need a data protection officer?
No, not merely because the company is small or processes personal data. An officer is required when the body is a public authority, when the core activity consists of regular and systematic monitoring of data subjects on a large scale, or when the core activity consists of large-scale processing of special categories of data or data on criminal offences. A company may appoint one voluntarily, and the same rules on position and tasks then apply.
Source
- Reference
- GDPR (EU) 2016/679 Article 37, read together with the Swedish Data Protection Act (2018:218)
- Acts
- Dataskyddslagen
- Area
- Data protection and cybersecurity
- Read date
- 2026-09-09
Acts the answer rests on
- Dataskyddslagen · SFS 2018:218
- Swedish Authority for Privacy Protection
Other acts in the same area
- Kamerabevakningslagen · SFS 2018:1200
- Kreditupplysningslagen · SFS 1973:1173
- NIS-lagen · SFS 2018:1174
- LEK · SFS 2022:482
Questions and answers
Ready-made pack
GDPR incident pack
€79, one-time purchase
What you need once a personal data breach has happened: the notification articles, the risk profile and a ready evidence chain.
Next step
Three ways to put the register to work in your own practice.
Start with your task
Litigation
Find support in a judgment
Search guiding decisions, see what became final and follow changes in the law.
In-house, deals
Map the rules in a transaction
Move from theme to act and on to the article that carries the duty.
Compliance
Assess the risk in a process
Risk scoring per legal area, with the sources behind every score.