Rättskällor med officiella primärkällor

Utskrivet ·

Skip to main content
Skip to the answer

Dataskyddslagen

Swedish act SFS 2018:218, in force since 2018-05-25: Lag med kompletterande bestämmelser till EU:s dataskyddsförordning. The responsible authority is Integritetsskyddsmyndigheten. The act is tied to EU legislation.

Share this page

Register

Reference
SFS 2018:218
In force
2018-05-25
Responsible authority
Integritetsskyddsmyndigheten
Area
Data protection and cybersecurity
EU legislation
Kompletterar förordning (EU) 2016/679
Read date
2026-08-16

Official text

Preparatory works

  • Prop. 2017/18:105Ny dataskyddslag
  • SOU 2017:39Ny dataskyddslag

Regulations

  • DIFS 2018:2Föreskrifter om behandling av personuppgifter

Standards

  • Information security management systems, requirements

    SS-EN ISO/IEC 27001:2022Svenska institutet för standarder (SIS)

    The requirements for an information security management system: scope, risk assessment, risk treatment, statement of applicability and management review. It is the most common basis when a business must show appropriate technical and organisational measures.

  • Extension to the management system for privacy information management

    SS-EN ISO/IEC 27701:2021Svenska institutet för standarder (SIS)

    The extension that turns the information security management system into a privacy information management system, with roles for controller and processor and controls tied to data subject rights.

  • Artificial intelligence management systems, requirements

    SS-ISO/IEC 42001:2023Svenska institutet för standarder (SIS)

    The requirements for governing AI systems: accountability, impact assessment, data, life cycle, logging and monitoring. It serves as a method when an organisation must show AI governance to customers and supervisors.

  • Information security incident management, principles

    SS-EN ISO/IEC 27035-1:2023Svenska institutet för standarder (SIS)

    The principles of incident management: preparation, detection, assessment, response and lessons learned. Used alongside the duty to report personal data breaches and incidents in essential services.

Questions resting on the act

Supervision

Other acts in the same area

Swedish law

Ready-made pack

GDPR incident pack

€79, one-time purchase

What you need once a personal data breach has happened: the notification articles, the risk profile and a ready evidence chain.

Next step

Three ways to put the register to work in your own practice.

Start with your task