Sweden
Fourteen Eyes SIGINT partner bound by a secret 1954 treaty and wired into Europol, Schengen, Prüm and Nordic sharing, its FRA cable-tapping ruled ECHR-violating amid rapid biometric expansion
Overview
EU Member State: Sweden is subject to the GDPR, the Law Enforcement Directive, and the ePrivacy Directive. For the EU framework, see the EU Framework page. This page covers national laws, intelligence and surveillance, and Sweden’s role in international data sharing.
Sweden operates one of Europe’s most extensive bulk cable interception programmes, granting its signals intelligence agency (FRA) direct access to fibre-optic cables crossing its borders. The European Court of Human Rights ruled in Centrum för Rättvisa v. Sweden (2021) that this regime violated Article 8 of the ECHR.[1]
Despite two centuries of official political neutrality, Sweden maintained a secret SIGINT-sharing treaty with the Five Eyes nations from 1954, and the Snowden disclosures confirmed that Sweden provided the NSA with cable access yielding “unique collection on high-priority Russian targets.” The NSA classified the relationship as top-secret “because of the country’s political neutrality.”[2][3] Sweden is a member of the Fourteen Eyes (SIGINT Seniors Europe), a founding member of the secret Maximator SIGINT partnership (1976), and is now establishing a new civilian foreign intelligence agency by January 2027.[4]
Sweden’s outward data-sharing runs through its alliances and treaties, each detailed below. Beyond the Fourteen Eyes and Maximator signals-intelligence alliances, it is a party to the 1959 Council of Europe Mutual Assistance Convention and the Budapest Convention on Cybercrime, belongs to the Schengen and Prüm frameworks and to Europol, and holds bilateral mutual legal assistance treaties with the United States, Hungary, Poland, France, and the United Kingdom. These are the channels through which the domestic protections described below are, in practice, bypassed.
International Data Sharing Agreements
Mutual Legal Assistance: Layered Framework
EU Member States (26 countries): The EU Convention on Mutual Assistance in Criminal Matters (2000) and the Schengen Convention provide the primary MLA framework. The European Investigation Order (EIO) enables binding cross-border evidence requests. Direct communication between judicial authorities is the default for EU-convention requests.[20]
European Convention on Mutual Assistance in Criminal Matters (1959, ETS 30): Sweden has acceded to this Council of Europe instrument and its 1978 Additional Protocol. As of July 2026 it has 51 parties: all 46 Council of Europe member states (Albania, Andorra, Armenia, Austria, Azerbaijan, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Georgia, Germany, Greece, Hungary, Iceland, Ireland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Montenegro, the Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye, Ukraine, and the United Kingdom) plus five non-members (Chile, Israel, Mongolia, the Republic of Korea, and the Russian Federation).[36]
Convention on Cybercrime (the Budapest Convention, 2001, ETS 185): Sweden is a party to the Council of Europe’s cybercrime convention, which governs the expedited preservation and cross-border disclosure of stored computer and subscriber data. As of July 2026 it has 82 parties: 45 Council of Europe member states (every one of the 46 except Ireland, which has signed but not ratified), namely Albania, Andorra, Armenia, Austria, Azerbaijan, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Georgia, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Montenegro, the Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye, Ukraine, and the United Kingdom; together with 37 non-member states: Argentina, Australia, Benin, Brazil, Cabo Verde, Cameroon, Canada, Chile, Colombia, Costa Rica, Côte d’Ivoire, the Dominican Republic, Ecuador, Fiji, Ghana, Grenada, Israel, Japan, Kiribati, Mauritius, Morocco, New Zealand, Nigeria, Panama, Papua New Guinea, Paraguay, Peru, the Philippines, Rwanda, São Tomé and Príncipe, Senegal, Sierra Leone, Sri Lanka, Tonga, Tunisia, the United States, and Vanuatu.[37]
Bilateral MLATs: Sweden maintains bilateral mutual legal assistance treaties with the United States (signed December 17, 2001), Hungary (1986), Poland (1990), France, and the United Kingdom (asset confiscation). The bilateral treaties with EU states are seldom applied since the EU MLA Convention and Council of Europe Convention provide more comprehensive frameworks. The Ministry of Justice serves as Sweden’s Central Authority for MLA requests. Sweden’s treaties are published in the government’s official treaty series, Sveriges internationella överenskommelser (SÖ).[21][22]
Fourteen Eyes, Maximator, and Sweden’s Intelligence Alliance History
The 1954 Secret Treaty: A classified SIGINT-sharing treaty placed the FRA within the UKUSA “third party” framework, binding FRA to share signals intelligence with the NSA and GCHQ while Sweden maintained its public neutrality. The treaty was wound up in 2004 and replaced by bilateral agreements drawing FRA even closer to the NSA.[2]
Snowden Revelations (2013): FRA provided the NSA with cable access yielding “unique collection on high-priority Russian targets such as leadership, internal politics, and energy.” The NSA granted FRA access to XKeyscore, its global search and analysis system. Sweden’s strategic position (approximately 80% of Russian internet traffic passes through Swedish cables) makes FRA’s cable-tapping capabilities particularly valuable to Five Eyes partners.[3][23]
SIGINT Seniors Europe (Fourteen Eyes): Sweden is a formal member. Its fourteen members are the Five Eyes (Australia, Canada, New Zealand, the United Kingdom, and the United States) plus Belgium, Denmark, France, Germany, Italy, the Netherlands, Norway, Spain, and Sweden. Formed 1982, expanded post-9/11.[24]
Maximator Alliance: Sweden is a founding member of Maximator (1976), a secret European SIGINT partnership co-founded with Denmark, focused on intercepting and decrypting diplomatic communications. Germany joined at founding, the Netherlands in 1978, France in 1985, making its five members Denmark, France, Germany, the Netherlands, and Sweden. Publicly revealed in 2020 after nearly fifty years of secret operation.[4]
EU Law Enforcement Data Sharing
SIS II: Swedish police query and contribute to the EU’s largest law enforcement database in real time across the Schengen Area (29 states: Austria, Belgium, Bulgaria, Croatia, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, the Netherlands, Norway, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden, and Switzerland).[38] Prüm: Automated DNA, fingerprint, and vehicle-registration exchange binding 31 states (all 27 EU members plus the non-EU Schengen associates Iceland, Liechtenstein, Norway, and Switzerland); Prüm II (2024) adds facial images and police records.[39]
EU-US Data Sharing
EU-US Umbrella Agreement: Entered into force February 2017, granting Swedish citizens judicial redress before US courts. SWIFT/TFTP: International wire transfers subject to US Treasury subpoena. PNR: Passenger data transferred to US CBP.
Multilateral Frameworks
Interpol I-24/7: Sweden participates in the global police network (195 countries). Egmont Group: Swedish FIU shares financial intelligence across 164+ FIUs. Nordic-Baltic Eight (NB8): Sweden takes part in the Nordic-Baltic Eight (Denmark, Estonia, Finland, Iceland, Latvia, Lithuania, Norway, and Sweden), pairing the five Nordic states with the three Baltic states for cybersecurity and hybrid-threat intelligence cooperation.[41]
Europol
As an EU member state, Sweden is one of the 27 EU members that constitute Europol, the EU Agency for Law Enforcement Cooperation (Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, and Sweden). Europol also holds operational agreements permitting personal-data exchange with 17 non-EU states (Albania, Australia, Bosnia and Herzegovina, Canada, Colombia, Georgia, Iceland, Liechtenstein, Moldova, Monaco, Montenegro, North Macedonia, Norway, Serbia, Switzerland, Ukraine, and the United States) and cooperates with US law enforcement including the FBI, so Swedish person data flowing through Europol is reachable onward.[40]
The Privacy Backdoor Effect
Despite the Foreign Intelligence Court, SIUN oversight, and IMY GDPR enforcement, international agreements create alternative access pathways:
- FRA-NSA Sharing: FRA provides NSA with cable intercepts; NSA queries shared XKeyscore database for Swedish communications
- 80% Russian Traffic: FRA cable-tapping captures Russian traffic passing through Sweden, shared with Five Eyes partners
- ECtHR-Identified Gap: Grand Chamber found no privacy safeguards when transmitting intelligence to foreign partners
- EU Framework Sharing: Swedish person data in SIS II, Prüm, or EIO channels accessible to 27 EU states and through Europol to US FBI
- MLAT/CoE Conventions: the US, the 51 parties to the 1959 Convention and the 82 parties to the Budapest Convention can request data through MLA channels
- SWIFT/PNR: Financial transactions and air travel data subject to US access
Club de Berne and the Counter Terrorism Group
Sweden’s Säpo takes part in the Club de Berne (founded 1969), the forum of the heads of the domestic intelligence and security services of the 27 EU member states (Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, and Sweden) together with Norway and Switzerland. The Club is a broad, all-source intelligence-sharing body, not a counterterrorism-specific one; its separate offshoot, the Counter Terrorism Group (CTG), created in September 2001, shares terrorism intelligence among the same services plus the United Kingdom and has run a joint operational platform in The Hague with a common database and real-time information system since 2016.[42]
Surveillance and Intelligence
FRA (Försvarets radioanstalt) – National Defence Radio Establishment
Sweden’s signals intelligence agency, responsible for collecting foreign intelligence through interception of electronic communications.[9]
The FRA Law (2008): Cable-Tapping Sweden’s Borders
The Signals Intelligence Act (SFS 2008:717) extended FRA’s interception authority from radio signals to cable-bound communications, granting access to all fibre-optic traffic crossing Swedish borders. Providers must transfer cable communications to designated “interaction points” for FRA access. Though framed as cross-border only, internet routing means significant domestic Swedish traffic crosses borders and returns, rendering the distinction largely meaningless. The bill passed by a single vote (143-138) after critics called it “much worse than the Stasi.”[9][10]
2009 Amendments added safeguards: all cable interception requires prior authorisation from a Foreign Intelligence Court, a privacy protection representative advocates for affected individuals, the Foreign Intelligence Inspectorate (SIUN) provides independent oversight, permits are limited to six months, and irrelevant material must be destroyed.[9]
Centrum för Rättvisa v. Sweden: The ECtHR Strikes Down the Regime
On May 25, 2021, the Grand Chamber ruled Sweden’s bulk interception regime violated Article 8 ECHR, finding three specific deficiencies: absence of clear rules on destroying non-content intercepted data, absence of privacy safeguards when transmitting intelligence to foreign partners (a direct rebuke of FRA-NSA sharing), and absence of effective after-the-fact review. The Court did not hold bulk interception per se incompatible with the Convention. As of early 2026, reforms to address these deficiencies remain in progress.[1][11]
Säpo (Säkerhetspolisen) – Swedish Security Service
Domestic security and civilian counterintelligence, separated from the National Police as an independent agency on January 1, 2015. Responsible for counterterrorism, counterespionage, and dignitary protection. Budget increased 114% between 2015 and 2024. A January 2025 National Audit Office report identified weaknesses in internal management and background investigation procedures.[12][13]
MUST – Military Intelligence and Security Service
Foreign military intelligence and counterintelligence within the Swedish Armed Forces. Legally prohibited from gathering intelligence on domestic affairs except for threats directly against the armed forces.[14]
Oversight
The Foreign Intelligence Court issues warrants for FRA cable interception (six-month permits with privacy representative participation). SIUN (Foreign Intelligence Inspectorate) oversees FRA, MUST, and FOI, with power to stop collection and order data deletion. The Commission on Security and Integrity Protection supervises law enforcement surveillance and Säpo data processing. Critics note the Foreign Intelligence Court operates in total secrecy with no published statistics.[15][16][17]
Recent Developments
Encryption Backdoor Bill Postponed (2025)
The proposed “Data Storage and Access to Electronic Information” legislation would have compelled messaging services to store and provide law enforcement with access to all communications, including end-to-end encrypted content. Signal president Meredith Whittaker stated Signal would “rather leave the Swedish market completely.” 237 organisations (Mozilla, Proton, Wire, Tuta Mail, Signal) signed a joint letter urging rejection. The Swedish Armed Forces warned the requirement would introduce critical security vulnerabilities. The bill was postponed in May 2025 and is expected to be revised to remove the encryption backdoor requirement.[25][26]
Surveillance Expansion (2025)
Camera surveillance (April 2025): Public sector actors no longer require IMY permits for camera surveillance in public spaces. Law enforcement received expanded powers and nationwide automatic number plate recognition (ANPR) authorisation.[27]
Biometrics in law enforcement (July 2025): Police granted facial recognition against Migration Agency registers and authorisation for DNA forensic investigative genetic genealogy (FIGG) for murder and aggravated rape investigations.[28]
AI real-time facial recognition proposal (DS 2025:7, March 2025): Proposed law allowing police to deploy AI-powered real-time facial recognition in public spaces for crimes carrying four-year minimum sentences. The government’s own investigator acknowledged the systems could enable “constant monitoring of the public.”[29]
New Civilian Intelligence Agency by January 2027
Following Sweden’s 2024 NATO accession, the government confirmed plans for a civilian foreign intelligence service (a Swedish counterpart to CIA/MI6), led by a National Intelligence Chief, with investments in cloud infrastructure, OSINT, and cross-sector cooperation. Special investigator Annika Brändström appointed to prepare the agency, operational by January 1, 2027.[30]
NCSC Reorganised Under FRA (November 2024)
The National Cybersecurity Centre was brought under FRA control after failing to achieve expected results as a multi-agency collaboration, concentrating offensive SIGINT and defensive cybersecurity within a single organisation.[31]
Chat Control: Sweden Shifts to Undecided (October 2025)
Sweden moved from supporting to undecided on the EU’s proposed CSA Regulation (“Chat Control”), a shift influenced by the concurrent domestic encryption backdoor controversy and opposition from the Swedish Armed Forces and cybersecurity community.[32]
Post-ECtHR Reform Still Pending
Reforms to address the Grand Chamber’s three identified deficiencies (data destruction, foreign sharing safeguards, after-the-fact review) remain ongoing. FRA continues operating under the existing framework.[1]
NIS2 Transposition: Cybersäkerhetslagen (Effective January 15, 2026)
Sweden’s new Cybersäkerhetslagen (Cybersecurity Act) implementing NIS2 entered into force January 15, 2026. Distinctively, Sweden adopted a whole-entity approach: once an entity falls within scope on sectoral and size criteria, the entire organisation is regulated, not only the specific service line that triggered coverage. The size threshold follows the EU SME definition (50 employees or €10M turnover/balance sheet); essential and important categories follow NIS2 Annex I and II. The MSB (Civil Contingencies Agency) opened the registration portal alongside entry into force.[33]
Privacy Framework
The Integritetsskyddsmyndigheten (IMY) is Sweden’s data protection authority, renamed from Datainspektionen in January 2021. In 2024, IMY closed 326 supervisory matters and imposed fines totalling SEK 60.6 million (~EUR 5.5M), including SEK 37M against Apotek Hjärtat and SEK 15M against Avanza Bank for Meta Pixel transmitting health and financial data to Meta Platforms.[5][6]
The Swedish Data Protection Act (Dataskyddslagen, SFS 2018:218) supplements the GDPR with national provisions: age of digital consent set at 13, public authorities subject to fines (capped at SEK 5M for government agencies), and specific rules on sensitive data processing. The Electronic Communications Act (LEK, SFS 2022:482) implements the ePrivacy Directive and contains data retention provisions. The Camera Surveillance Act regulates surveillance camera deployment.[7][8]
Data Retention
In Tele2 Sverige AB v. Post- och telestyrelsen (C-203/15, December 2016), the CJEU ruled that general and indiscriminate retention of all traffic and location data is incompatible with EU law, a landmark case that originated in Sweden when Tele2 stopped retaining data after Digital Rights Ireland. The Court held that targeted retention is permitted for serious crime, but only if limited by data categories, persons, and retention period, with prior judicial review.[18]
The current LEK (2022:482) requires retention of certain traffic and location data for up to one year. Access does not require a court decision, a point civil liberties organisations have flagged as non-compliant with CJEU requirements. New proposals include general retention for national security (justified by the Ukraine threat environment and NATO membership) and geographically targeted retention for municipalities exceeding national crime rates.[19]
Pending Legislation
- Data Storage and Access to Electronic Information (encryption backdoor): the bill that would compel messaging services to store and hand over communications, including end-to-end encrypted content, was postponed in May 2025 after Signal threatened to exit and 237 organisations objected; it is expected to be revised to drop the backdoor requirement but has not been formally withdrawn.[25][26]
- AI real-time facial recognition (DS 2025:7): proposed authority for police to deploy real-time facial recognition in public spaces for serious crimes; the government’s own investigator warned it could enable “constant monitoring of the public.” Not yet enacted.[29]
- New civilian foreign intelligence service: legislation and structures are being prepared for a civilian foreign-intelligence agency to be operational January 1, 2027.[30]
- Post-ECtHR FRA reform: reforms to cure the three deficiencies the ECtHR Grand Chamber identified in Sweden’s bulk cable-interception regime (data destruction, foreign-sharing safeguards, after-the-fact review) remain pending; FRA continues under the existing framework.[1]
- Data retention: geographic and national-security-based retention proposals continue to be debated following CJEU constraints on general retention.
- Social Data Register Act (Proposition 2025/26:165): creates a national socialdataregister held by the National Board of Health and Welfare (Socialstyrelsen) as sole controller, compiling identification data and personnummer, assessments, decisions, services received, needs and outcomes for every person who has received social services or support under the Disability Support Act (LSS) in any Swedish municipality, plus next-of-kin details where strictly necessary. Reporting by service providers is mandatory and no individual consent is required, the legal basis being a task carried out in the public interest under GDPR Article 6(1)(e). Absolute statistical secrecy applies, searches on sensitive categories are restricted, and access is limited and monitored. Main provisions enter into force August 1, 2026, reporting obligations August 1, 2027.[34]
- Strengthened National Cybersecurity Centre (Proposition 2025/26:214): statutory amendments reinforcing Sweden’s national cybersecurity centre, in force July 15, 2026.[35]
