How quickly must a personal data breach be reported in Sweden?
The notification to the Swedish Authority for Privacy Protection must be made without undue delay and no later than 72 hours after the controller became aware of the breach. A later notification must be accompanied by reasons for the delay. Where the risk to the rights and freedoms of data subjects is unlikely, no notification is needed, but the assessment must be documented. Where the risk is high, the data subjects must also be informed.
Source
- Reference
- GDPR (EU) 2016/679 Articles 33 and 34
- Acts
- Dataskyddslagen
- Area
- Data protection and cybersecurity
- Read date
- 2026-09-09
Acts the answer rests on
- Dataskyddslagen · SFS 2018:218
- Swedish Authority for Privacy Protection
Other acts in the same area
- Kamerabevakningslagen · SFS 2018:1200
- Kreditupplysningslagen · SFS 1973:1173
- NIS-lagen · SFS 2018:1174
- LEK · SFS 2022:482
Questions and answers
Ready-made pack
GDPR incident pack
€79, one-time purchase
What you need once a personal data breach has happened: the notification articles, the risk profile and a ready evidence chain.
Next step
Three ways to put the register to work in your own practice.
Start with your task
Litigation
Find support in a judgment
Search guiding decisions, see what became final and follow changes in the law.
In-house, deals
Map the rules in a transaction
Move from theme to act and on to the article that carries the duty.
Compliance
Assess the risk in a process
Risk scoring per legal area, with the sources behind every score.