← Regulators
GDPR EU 2016/679 Sweden

Who is the IMY: Sweden's data protection authority, heir to the world's first privacy law

IMY (Integritetsskyddsmyndigheten) is Sweden's GDPR supervisory authority — the modern name of Datainspektionen, founded in 1973 to enforce what is widely regarded as the world's first national data protection law. This guide covers what it does, the mandate that runs beyond the GDPR, who runs it after the 2024 leadership change, and the Google, Spotify and Klarna fines — every fact sourced.

Data protection did not begin with the GDPR — it began in Sweden. The country’s Data Act (Datalagen) of 1973 is widely regarded as the world’s first national data protection law, and the authority created to enforce it, Datainspektionen, is now called the Integritetsskyddsmyndigheten (IMY) — the Swedish Authority for Privacy Protection. So Sweden’s regulator is not a creature of the GDPR; it is older than the problem the GDPR set out to solve. This is a profile of what the IMY is, what it does, and who runs it — with every fact sourced.

Quick facts

  • Full name: Integritetsskyddsmyndigheten (IMY) — the Swedish Authority for Privacy Protection
  • Earlier name: Datainspektionen (the Data Inspection Board), 1973–2020; renamed IMY on 1 January 2021 (IMY)
  • Founded: 1973, to enforce the Data Act (Datalagen, SFS 1973:289) — widely regarded as the first national data protection law in the world (Sveriges Riksdag; Internetmuseum)
  • Role: Sweden’s GDPR supervisory authority and a member of the EDPB; also the national regulator for three other data laws (see below)
  • Director-General: Eric Leijonram, in office since 1 October 2024 — previously Chief Legal Counsel at Sweden’s financial regulator (Finansinspektionen) (Regeringen.se)
  • Structure: a single-head authority (enrådighetsmyndighet) — the Director-General alone decides — with a transparency council (insynsråd); around 160 staff, most of them lawyers (IMY)
  • Budget (2025): a framework appropriation of SEK 225.1 million (about €20 million) (IMY, Årsredovisning 2025)
  • Largest fine to date: SEK 75,000,000 against Google in 2020 over the “right to be forgotten” — reduced to SEK 52,000,000 by the Administrative Court of Stockholm in November 2020 (EDPB; JURIST)
  • Seat: Stockholm
  • Website: imy.se

What “IMY” actually stands for

IMY is short for Integritetsskyddsmyndigheten — literally “the Privacy Protection Authority” in Swedish. It is Sweden’s national personal-data regulator: the body that enforces GDPR within Sweden.

Every EU country has one (in GDPR’s own language they are supervisory authorities, or DPAs — Data Protection Authorities). For comparison: CNIL in France, DPC in Ireland (where Meta, Google and Apple’s EU headquarters sit, so most big-tech enforcement lands there), Garante in Italy, AEPD in Spain, AKI in Estonia. IMY is the Swedish equivalent, scaled to a country of about 10.6 million people (Statistics Sweden, end of 2025).

What distinguishes IMY from most peers is age and breadth:

  • Age. Sweden enacted the world’s first national data protection statute in 1973 and stood up Datainspektionen to enforce it — decades before the GDPR generalised these rules across the EU. The 2021 rename to IMY was a rebrand of a half-century-old institution, not a new creation.
  • Breadth. Beyond the GDPR, IMY is the Swedish regulator for camera surveillance, credit-reference information and criminal-justice data — areas that in many countries sit with separate bodies.

What it is not: it is not Sweden’s AI Act authority and not a court. Like every DPA, its AI-relevant work runs through the GDPR.

What the IMY actually does

The core job is the standard GDPR toolkit — it receives complaints, investigates, runs proactive audits, issues corrective orders, and fines — plus supervision under three additional Swedish laws. Each of those three is worth a one-line explanation, because together they make IMY’s remit wider than “GDPR enforcement”:

  • Criminal Data Act (brottsdatalagen) — the rules for how police, prosecutors, courts and customs may process personal data when fighting crime. This is the EU Law Enforcement Directive (Directive 2016/680) written into Swedish law; it sits outside the GDPR. The Clearview AI case below was decided under this Act, not the GDPR.
  • Camera Surveillance Act (kamerabevakningslagen) — when you may film public spaces with CCTV, and when you need a permit to do so. IMY both grants those permits and supervises camera use. Example: a shopping centre or a municipality pointing cameras at a public square.
  • Credit Information Act (kreditupplysningslagen) — the rules for companies that compile data on people’s creditworthiness and sell credit reports. IMY licenses and supervises those credit-reference agencies. Example: the firm a landlord or lender queries to score you before signing.

In its 2025 work IMY put particular weight on AI in law enforcement and on children’s data and rights online, publishing guidance aimed at children aged 8–13 and their guardians (IMY, Årsredovisning 2025).

EU-level coordination

IMY is one of the national authorities on the European Data Protection Board (EDPB) — the EU-wide body that coordinates all EEA DPAs. When a Swedish resident complains about a service headquartered in another EU country, the case routes through the one-stop-shop mechanism. The EDPB also issues guidance that IMY follows when applying the GDPR.

From the world’s first data law to the IMY: a 50-year history

Sweden’s lead in this field is not a marketing line — it is documented in the dates.

  • 1973 — the Data Act (Datalagen) and Datainspektionen. As computers began centralising records on citizens, Sweden’s parliament passed the Data Act and, in the same move, created Datainspektionen to enforce it. It is widely regarded as the first national data protection law in the world (Internetmuseum). (A regional law in the German state of Hesse came earlier in 1970, but Sweden’s was the first at national level.)
  • 24 October 1998 — the Personal Data Act (Personuppgiftslagen, PUL). PUL replaced the 1973 Act and implemented the EU’s first data-protection directive (Directive 95/46/EC). This is the regime most Swedish businesses operated under until 2018.
  • 25 May 2018 — the GDPR. The directly applicable EU regulation replaced PUL and harmonised the rules across the bloc. Datainspektionen became Sweden’s GDPR supervisory authority overnight.
  • 1 January 2021 — the rename to IMY. Datainspektionen became Integritetsskyddsmyndigheten to signal more clearly what it protects: personal privacy, not just “data” (IMY). Same institution, broader name.

The takeaway: when you read “Datainspektionen” in an older fine or court ruling, that is the same authority now called IMY.

Leadership — and the long handover of 2023–2024

IMY is a single-head authority (enrådighetsmyndighet): the Director-General alone takes the authority’s decisions, advised — but not outvoted — by a transparency council (insynsråd) of nine members drawn from parliament, public agencies, municipalities and academia (IMY). The Director-General is appointed by the Swedish government.

The current Director-General is Eric Leijonram, appointed by the government on 8 July 2024 and in office since 1 October 2024; he came from the role of Chief Legal Counsel at Finansinspektionen, Sweden’s financial regulator (Regeringen.se).

He inherited an authority that had spent more than a year without a permanent head — a useful reminder to verify the current name rather than rely on an older one:

  • Lena Lindgren Schelin led the authority from 2018; her last day was 31 August 2023, after which she became Director-General of the Swedish Coast Guard (IMY).
  • Karin Lönnheden, IMY’s chief of staff, was acting Director-General from 1 September to 31 December 2023 (IMY).
  • David Törngren then served as acting Director-General from 1 January 2024 until Leijonram took over (Regeringen.se).

The regulator’s independence is locked in by GDPR itself (Article 52: “complete independence”) — no minister can tell IMY how to investigate a specific case or what to decide. This is universal across EU DPAs, precisely so the executive cannot lean on the regulator over fines against politically connected companies.

Resources and 2025 in numbers

By EU standards IMY is mid-sized: around 160 employees, most of them lawyers, organised into four departments and fifteen units (IMY). For 2025 it was funded by a framework appropriation of SEK 219.1 million, topped up mid-year by a further SEK 6 millionSEK 225.1 million in total (about €20 million) (IMY, Årsredovisning 2025).

For the most recent reporting year, 2025, the volumes jumped sharply (IMY, Årsredovisning 2025):

  • 7,434 complaints and tips received about data protection — up 102% on the year before.
  • 12,276 personal-data-breach notifications received — up 89%. The rise came mainly from several larger incidents at data processors serving many clients, affecting more than 1.5 million people in total (in some cases children and people with protected identities). A number were ransomware extortion attacks in which data was stolen and then published — among them two of the larger breaches Sweden has seen, both of which IMY opened investigations into.
  • 1,887 notifications of Data Protection Officers (the internal compliance leads GDPR requires for many organisations) received.
  • Fines issued in just three supervisory cases — and small ones (SEK 75,000–100,000). The pattern holds: Sweden issues few fines, but the rare big ones land on large companies.

Enforcement: built around transparency and access rights

IMY’s flagship cases share a theme — telling people clearly what is done with their data, and letting them see and remove it — rather than the cross-border transfer questions that dominate in Ireland. It is also notably willing to take on Sweden’s own technology champions.

Skellefteå facial recognition — SEK 200,000 (about €20,000), 22 August 2019. Sweden’s first GDPR fine went to the school board of Skellefteå municipality (Gymnasienämnden i Skellefteå) for a three-week trial that used facial recognition to register the attendance of 22 students. IMY found the school had processed sensitive biometric data unlawfully, relied on a consent that was not valid (students cannot freely consent to their school, given the power imbalance), and skipped the required impact assessment (EDPB). The amount looks small because Swedish public authorities face a statutory cap of SEK 10 million (about €1 million), far below the GDPR’s headline maximums.

Google — SEK 75,000,000 (about €7 million), 2020. IMY’s predecessor fined Google for failing to properly honour the “right to be forgotten” — a person’s right under Article 17 GDPR to have outdated or irrelevant search results about them delisted. Google had interpreted delisting requests too narrowly and notified site owners in a way that could deter people from exercising the right (EDPB). On appeal, in November 2020 the Administrative Court of Stockholm confirmed the violations but reduced the fine to SEK 52,000,000 (about €5 million) (JURIST). It remains the largest fine the authority has imposed.

Swedish Police — SEK 2,500,000 (about €250,000), 12 February 2021. IMY fined the Police Authority for officers’ use of the Clearview AI facial-recognition app without authorisation. Crucially, this case ran under the Criminal Data Act, not the GDPR, because it concerned law-enforcement processing. IMY also ordered the police to train staff and to ensure data sent to Clearview AI was deleted (EDPB).

Klarna — SEK 7,500,000 (about €724,000), 28 March 2022. The “buy now, pay later” fintech was fined for giving customers incomplete and misleading information about how it processed their data — purposes, legal bases, recipients, international transfers and their own rights (EDPB). The case then bounced through the courts: the Administrative Court (Förvaltningsrätten) cut the fine to SEK 6 million in 2023, but the Administrative Court of Appeal (Kammarrätten) restored the full SEK 7.5 million in March 2024 (Sveriges Domstolar).

Spotify — SEK 58,000,000 (about €5 million), 12 June 2023. IMY fined the streaming company over the right of access under Article 15 GDPR — the right to get a copy of your data and a clear explanation of how it is used. Spotify did hand over data, but its explanations were too technical and often only in English; IMY found this breached the transparency rules of Article 12. Spotify appealed (EDPB).

How to contact the IMY

  • File a complaint: through the GDPR complaint form on imy.se — free of charge. You can complain about any organisation that you believe is processing your personal data in breach of the GDPR.
  • Report a data breach (for organisations): via the breach-notification e-service — required within 72 hours of becoming aware of a qualifying breach.
  • Cross-border cases: if the organisation is headquartered in another EU country, IMY routes the case through the EDPB one-stop-shop — you do not need to file separately in that country.

What this means for you

  • If you process personal data and reach Swedish users: IMY is your supervisory authority — a genuinely active one, unafraid of large domestic brands. Sweden issues few fines, but the ones it does issue are substantial and survive appeal (Klarna).
  • If your issue is transparency or access rights: the Google, Spotify and Klarna cases show this is exactly where IMY bites. Tell people clearly what you collect and why, in language they understand and in their own language — and make the right to access and delete their data genuinely easy to use.
  • If you run camera surveillance, credit-scoring, or process criminal-justice data in Sweden: IMY is your regulator for those too, under the Camera Surveillance Act, the Credit Information Act and the Criminal Data Act respectively — its remit is broader than the GDPR alone.
  • If you are a journalist or researcher: “Sweden’s privacy regulator” = the Integritetsskyddsmyndigheten (IMY), formerly Datainspektionen, founded 1973, seated in Stockholm, led by Director-General Eric Leijonram since 1 October 2024.

TL;DR

The IMY (Integritetsskyddsmyndigheten) is Sweden’s GDPR supervisory authority and a member of the EDPB — but it is far older than the GDPR, having begun in 1973 as Datainspektionen, enforcer of what is widely regarded as the world’s first national data protection law. Renamed IMY on 1 January 2021, it supervises not only the GDPR but also camera surveillance, credit information and criminal-justice data. It is a low-volume, high-impact enforcer: its biggest case is the SEK 75 million fine on Google over the right to be forgotten (reduced to SEK 52 million on appeal), followed by SEK 58 million on Spotify and SEK 7.5 million on Klarna — all built around transparency and access rights. After more than a year with acting heads, it has been led by Director-General Eric Leijonram since 1 October 2024.

Sources