Sweden

Fourteen Eyes SIGINT partner bound by a secret 1954 treaty and wired into Europol, Schengen, Prüm and Nordic sharing, its FRA cable-tapping ruled ECHR-violating amid rapid biometric expansion

← Back to Privacy Law Directory

Overview

EU Member State: Sweden is subject to the GDPR, the Law Enforcement Directive, and the ePrivacy Directive. For the EU framework, see the EU Framework page. This page covers national laws, intelligence and surveillance, and Sweden’s role in international data sharing.

Sweden operates one of Europe’s most extensive bulk cable interception programmes, granting its signals intelligence agency (FRA) direct access to fibre-optic cables crossing its borders. The European Court of Human Rights ruled in Centrum för Rättvisa v. Sweden (2021) that this regime violated Article 8 of the ECHR.[1]

Despite two centuries of official political neutrality, Sweden maintained a secret SIGINT-sharing treaty with the Five Eyes nations from 1954, and the Snowden disclosures confirmed that Sweden provided the NSA with cable access yielding “unique collection on high-priority Russian targets.” The NSA classified the relationship as top-secret “because of the country’s political neutrality.”[2][3] Sweden is a member of the Fourteen Eyes (SIGINT Seniors Europe), a founding member of the secret Maximator SIGINT partnership (1976), and is now establishing a new civilian foreign intelligence agency by January 2027.[4]

Sweden’s outward data-sharing runs through its alliances and treaties, each detailed below. Beyond the Fourteen Eyes and Maximator signals-intelligence alliances, it is a party to the 1959 Council of Europe Mutual Assistance Convention and the Budapest Convention on Cybercrime, belongs to the Schengen and Prüm frameworks and to Europol, and holds bilateral mutual legal assistance treaties with the United States, Hungary, Poland, France, and the United Kingdom. These are the channels through which the domestic protections described below are, in practice, bypassed.

International Data Sharing Agreements

Mutual Legal Assistance: Layered Framework

EU Member States (26 countries): The EU Convention on Mutual Assistance in Criminal Matters (2000) and the Schengen Convention provide the primary MLA framework. The European Investigation Order (EIO) enables binding cross-border evidence requests. Direct communication between judicial authorities is the default for EU-convention requests.[20]

European Convention on Mutual Assistance in Criminal Matters (1959, ETS 30): Sweden has acceded to this Council of Europe instrument and its 1978 Additional Protocol. As of July 2026 it has 51 parties: all 46 Council of Europe member states (Albania, Andorra, Armenia, Austria, Azerbaijan, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Georgia, Germany, Greece, Hungary, Iceland, Ireland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Montenegro, the Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye, Ukraine, and the United Kingdom) plus five non-members (Chile, Israel, Mongolia, the Republic of Korea, and the Russian Federation).[36]

Convention on Cybercrime (the Budapest Convention, 2001, ETS 185): Sweden is a party to the Council of Europe’s cybercrime convention, which governs the expedited preservation and cross-border disclosure of stored computer and subscriber data. As of July 2026 it has 82 parties: 45 Council of Europe member states (every one of the 46 except Ireland, which has signed but not ratified), namely Albania, Andorra, Armenia, Austria, Azerbaijan, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Georgia, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Montenegro, the Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye, Ukraine, and the United Kingdom; together with 37 non-member states: Argentina, Australia, Benin, Brazil, Cabo Verde, Cameroon, Canada, Chile, Colombia, Costa Rica, Côte d’Ivoire, the Dominican Republic, Ecuador, Fiji, Ghana, Grenada, Israel, Japan, Kiribati, Mauritius, Morocco, New Zealand, Nigeria, Panama, Papua New Guinea, Paraguay, Peru, the Philippines, Rwanda, São Tomé and Príncipe, Senegal, Sierra Leone, Sri Lanka, Tonga, Tunisia, the United States, and Vanuatu.[37]

Bilateral MLATs: Sweden maintains bilateral mutual legal assistance treaties with the United States (signed December 17, 2001), Hungary (1986), Poland (1990), France, and the United Kingdom (asset confiscation). The bilateral treaties with EU states are seldom applied since the EU MLA Convention and Council of Europe Convention provide more comprehensive frameworks. The Ministry of Justice serves as Sweden’s Central Authority for MLA requests. Sweden’s treaties are published in the government’s official treaty series, Sveriges internationella överenskommelser (SÖ).[21][22]

Fourteen Eyes, Maximator, and Sweden’s Intelligence Alliance History

The 1954 Secret Treaty: A classified SIGINT-sharing treaty placed the FRA within the UKUSA “third party” framework, binding FRA to share signals intelligence with the NSA and GCHQ while Sweden maintained its public neutrality. The treaty was wound up in 2004 and replaced by bilateral agreements drawing FRA even closer to the NSA.[2]

Snowden Revelations (2013): FRA provided the NSA with cable access yielding “unique collection on high-priority Russian targets such as leadership, internal politics, and energy.” The NSA granted FRA access to XKeyscore, its global search and analysis system. Sweden’s strategic position (approximately 80% of Russian internet traffic passes through Swedish cables) makes FRA’s cable-tapping capabilities particularly valuable to Five Eyes partners.[3][23]

SIGINT Seniors Europe (Fourteen Eyes): Sweden is a formal member. Its fourteen members are the Five Eyes (Australia, Canada, New Zealand, the United Kingdom, and the United States) plus Belgium, Denmark, France, Germany, Italy, the Netherlands, Norway, Spain, and Sweden. Formed 1982, expanded post-9/11.[24]

Maximator Alliance: Sweden is a founding member of Maximator (1976), a secret European SIGINT partnership co-founded with Denmark, focused on intercepting and decrypting diplomatic communications. Germany joined at founding, the Netherlands in 1978, France in 1985, making its five members Denmark, France, Germany, the Netherlands, and Sweden. Publicly revealed in 2020 after nearly fifty years of secret operation.[4]

EU Law Enforcement Data Sharing

SIS II: Swedish police query and contribute to the EU’s largest law enforcement database in real time across the Schengen Area (29 states: Austria, Belgium, Bulgaria, Croatia, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, the Netherlands, Norway, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden, and Switzerland).[38] Prüm: Automated DNA, fingerprint, and vehicle-registration exchange binding 31 states (all 27 EU members plus the non-EU Schengen associates Iceland, Liechtenstein, Norway, and Switzerland); Prüm II (2024) adds facial images and police records.[39]

EU-US Data Sharing

EU-US Umbrella Agreement: Entered into force February 2017, granting Swedish citizens judicial redress before US courts. SWIFT/TFTP: International wire transfers subject to US Treasury subpoena. PNR: Passenger data transferred to US CBP.

Multilateral Frameworks

Interpol I-24/7: Sweden participates in the global police network (195 countries). Egmont Group: Swedish FIU shares financial intelligence across 164+ FIUs. Nordic-Baltic Eight (NB8): Sweden takes part in the Nordic-Baltic Eight (Denmark, Estonia, Finland, Iceland, Latvia, Lithuania, Norway, and Sweden), pairing the five Nordic states with the three Baltic states for cybersecurity and hybrid-threat intelligence cooperation.[41]

Europol

As an EU member state, Sweden is one of the 27 EU members that constitute Europol, the EU Agency for Law Enforcement Cooperation (Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, and Sweden). Europol also holds operational agreements permitting personal-data exchange with 17 non-EU states (Albania, Australia, Bosnia and Herzegovina, Canada, Colombia, Georgia, Iceland, Liechtenstein, Moldova, Monaco, Montenegro, North Macedonia, Norway, Serbia, Switzerland, Ukraine, and the United States) and cooperates with US law enforcement including the FBI, so Swedish person data flowing through Europol is reachable onward.[40]

The Privacy Backdoor Effect

Despite the Foreign Intelligence Court, SIUN oversight, and IMY GDPR enforcement, international agreements create alternative access pathways:

Club de Berne and the Counter Terrorism Group

Sweden’s Säpo takes part in the Club de Berne (founded 1969), the forum of the heads of the domestic intelligence and security services of the 27 EU member states (Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, and Sweden) together with Norway and Switzerland. The Club is a broad, all-source intelligence-sharing body, not a counterterrorism-specific one; its separate offshoot, the Counter Terrorism Group (CTG), created in September 2001, shares terrorism intelligence among the same services plus the United Kingdom and has run a joint operational platform in The Hague with a common database and real-time information system since 2016.[42]

Surveillance and Intelligence

FRA (Försvarets radioanstalt) – National Defence Radio Establishment

Sweden’s signals intelligence agency, responsible for collecting foreign intelligence through interception of electronic communications.[9]

The FRA Law (2008): Cable-Tapping Sweden’s Borders

The Signals Intelligence Act (SFS 2008:717) extended FRA’s interception authority from radio signals to cable-bound communications, granting access to all fibre-optic traffic crossing Swedish borders. Providers must transfer cable communications to designated “interaction points” for FRA access. Though framed as cross-border only, internet routing means significant domestic Swedish traffic crosses borders and returns, rendering the distinction largely meaningless. The bill passed by a single vote (143-138) after critics called it “much worse than the Stasi.”[9][10]

2009 Amendments added safeguards: all cable interception requires prior authorisation from a Foreign Intelligence Court, a privacy protection representative advocates for affected individuals, the Foreign Intelligence Inspectorate (SIUN) provides independent oversight, permits are limited to six months, and irrelevant material must be destroyed.[9]

Centrum för Rättvisa v. Sweden: The ECtHR Strikes Down the Regime

On May 25, 2021, the Grand Chamber ruled Sweden’s bulk interception regime violated Article 8 ECHR, finding three specific deficiencies: absence of clear rules on destroying non-content intercepted data, absence of privacy safeguards when transmitting intelligence to foreign partners (a direct rebuke of FRA-NSA sharing), and absence of effective after-the-fact review. The Court did not hold bulk interception per se incompatible with the Convention. As of early 2026, reforms to address these deficiencies remain in progress.[1][11]

Säpo (Säkerhetspolisen) – Swedish Security Service

Domestic security and civilian counterintelligence, separated from the National Police as an independent agency on January 1, 2015. Responsible for counterterrorism, counterespionage, and dignitary protection. Budget increased 114% between 2015 and 2024. A January 2025 National Audit Office report identified weaknesses in internal management and background investigation procedures.[12][13]

MUST – Military Intelligence and Security Service

Foreign military intelligence and counterintelligence within the Swedish Armed Forces. Legally prohibited from gathering intelligence on domestic affairs except for threats directly against the armed forces.[14]

Oversight

The Foreign Intelligence Court issues warrants for FRA cable interception (six-month permits with privacy representative participation). SIUN (Foreign Intelligence Inspectorate) oversees FRA, MUST, and FOI, with power to stop collection and order data deletion. The Commission on Security and Integrity Protection supervises law enforcement surveillance and Säpo data processing. Critics note the Foreign Intelligence Court operates in total secrecy with no published statistics.[15][16][17]

Recent Developments

Encryption Backdoor Bill Postponed (2025)

The proposed “Data Storage and Access to Electronic Information” legislation would have compelled messaging services to store and provide law enforcement with access to all communications, including end-to-end encrypted content. Signal president Meredith Whittaker stated Signal would “rather leave the Swedish market completely.” 237 organisations (Mozilla, Proton, Wire, Tuta Mail, Signal) signed a joint letter urging rejection. The Swedish Armed Forces warned the requirement would introduce critical security vulnerabilities. The bill was postponed in May 2025 and is expected to be revised to remove the encryption backdoor requirement.[25][26]

Surveillance Expansion (2025)

Camera surveillance (April 2025): Public sector actors no longer require IMY permits for camera surveillance in public spaces. Law enforcement received expanded powers and nationwide automatic number plate recognition (ANPR) authorisation.[27]

Biometrics in law enforcement (July 2025): Police granted facial recognition against Migration Agency registers and authorisation for DNA forensic investigative genetic genealogy (FIGG) for murder and aggravated rape investigations.[28]

AI real-time facial recognition proposal (DS 2025:7, March 2025): Proposed law allowing police to deploy AI-powered real-time facial recognition in public spaces for crimes carrying four-year minimum sentences. The government’s own investigator acknowledged the systems could enable “constant monitoring of the public.”[29]

New Civilian Intelligence Agency by January 2027

Following Sweden’s 2024 NATO accession, the government confirmed plans for a civilian foreign intelligence service (a Swedish counterpart to CIA/MI6), led by a National Intelligence Chief, with investments in cloud infrastructure, OSINT, and cross-sector cooperation. Special investigator Annika Brändström appointed to prepare the agency, operational by January 1, 2027.[30]

NCSC Reorganised Under FRA (November 2024)

The National Cybersecurity Centre was brought under FRA control after failing to achieve expected results as a multi-agency collaboration, concentrating offensive SIGINT and defensive cybersecurity within a single organisation.[31]

Chat Control: Sweden Shifts to Undecided (October 2025)

Sweden moved from supporting to undecided on the EU’s proposed CSA Regulation (“Chat Control”), a shift influenced by the concurrent domestic encryption backdoor controversy and opposition from the Swedish Armed Forces and cybersecurity community.[32]

Post-ECtHR Reform Still Pending

Reforms to address the Grand Chamber’s three identified deficiencies (data destruction, foreign sharing safeguards, after-the-fact review) remain ongoing. FRA continues operating under the existing framework.[1]

NIS2 Transposition: Cybersäkerhetslagen (Effective January 15, 2026)

Sweden’s new Cybersäkerhetslagen (Cybersecurity Act) implementing NIS2 entered into force January 15, 2026. Distinctively, Sweden adopted a whole-entity approach: once an entity falls within scope on sectoral and size criteria, the entire organisation is regulated, not only the specific service line that triggered coverage. The size threshold follows the EU SME definition (50 employees or €10M turnover/balance sheet); essential and important categories follow NIS2 Annex I and II. The MSB (Civil Contingencies Agency) opened the registration portal alongside entry into force.[33]

Privacy Framework

The Integritetsskyddsmyndigheten (IMY) is Sweden’s data protection authority, renamed from Datainspektionen in January 2021. In 2024, IMY closed 326 supervisory matters and imposed fines totalling SEK 60.6 million (~EUR 5.5M), including SEK 37M against Apotek Hjärtat and SEK 15M against Avanza Bank for Meta Pixel transmitting health and financial data to Meta Platforms.[5][6]

The Swedish Data Protection Act (Dataskyddslagen, SFS 2018:218) supplements the GDPR with national provisions: age of digital consent set at 13, public authorities subject to fines (capped at SEK 5M for government agencies), and specific rules on sensitive data processing. The Electronic Communications Act (LEK, SFS 2022:482) implements the ePrivacy Directive and contains data retention provisions. The Camera Surveillance Act regulates surveillance camera deployment.[7][8]

Data Retention

In Tele2 Sverige AB v. Post- och telestyrelsen (C-203/15, December 2016), the CJEU ruled that general and indiscriminate retention of all traffic and location data is incompatible with EU law, a landmark case that originated in Sweden when Tele2 stopped retaining data after Digital Rights Ireland. The Court held that targeted retention is permitted for serious crime, but only if limited by data categories, persons, and retention period, with prior judicial review.[18]

The current LEK (2022:482) requires retention of certain traffic and location data for up to one year. Access does not require a court decision, a point civil liberties organisations have flagged as non-compliant with CJEU requirements. New proposals include general retention for national security (justified by the Ukraine threat environment and NATO membership) and geographically targeted retention for municipalities exceeding national crime rates.[19]

Pending Legislation

Sources

[1] HUDOC: Centrum för rättvisa v. Sweden (Grand Chamber, 25 May 2021) – Bulk interception violates Article 8 ECHR; deficiencies in foreign sharing, data destruction, ex post review
[3] Sveriges Radio: NSA “Asking For” Specific Exchanges from FRA (December 2013) – FRA cable access yielding “unique collection on high-priority Russian targets”
[5] IMY: About Us – Renamed from Datainspektionen, January 2021
[6] CMS: GDPR Enforcement Tracker – Sweden – 2024: 326 matters, SEK 60.6M in fines
[7] Government of Sweden: Dataskyddslagen (SFS 2018:218) – Age of consent 13, public authority fines
[8] DLA Piper: Data Protection – Sweden – Camera Surveillance Act, Electronic Communications Act
[9] Wikipedia: FRA Law – 2008 Signals Intelligence Act, cable-tapping, 2009 amendments
[10] The Local: “Much Worse Than the Stasi” (June 2008) – Public opposition to FRA Law
[11] Verfassungsblog: Centrum för Rättvisa v. Sweden – Legal analysis of Grand Chamber judgment
[12] Wikipedia: Swedish Security Service (Säpo) – 2015 separation, constitutional autonomy
[13] Riksrevisionen: Swedish Security Service Activities (January 2025) – Audit findings, 114% budget increase
[14] Wikipedia: MUST – Foreign military intelligence, domestic collection prohibition
[15] Library of Congress: Foreign Intelligence Gathering – Sweden – Foreign Intelligence Court, six-month permits
[16] SIUN: Foreign Intelligence Inspectorate – Oversight of FRA, MUST, FOI
[17] Commission on Security and Integrity Protection – Law enforcement surveillance oversight
[18] CCDCOE: Tele2 Sverige – Blanket data retention incompatible with EU law
[19] Nordic Council: Data Retention – Sweden (2024) – Current regime, geographic targeting, national security retention
[20] Government of Sweden: Legal Assistance in Criminal Matters – EU MLA Convention, direct communication, Ministry of Justice as Central Authority
[21] Council of Europe: Sweden MLA Procedures – CoE Convention 1959, bilateral treaties with Hungary (1986), Poland (1990), France, UK
[22] US State Department: Sweden MLAT – Signed December 17, 2001
[24] The Intercept: SIGINT Seniors Europe – Fourteen Eyes structure, 1982 founding
[28] Riksdagen: Biometrics in Law Enforcement (February 2025) – Facial recognition, DNA genealogy
[33] Deloitte: NIS2 Now in Force, Sweden’s Cybersecurity Act (January 15, 2026) – Whole-entity scope; EU SME size threshold (50 employees or €10M turnover); essential and important categories; MSB registration portal opened on entry into force
[34] Sveriges riksdag: En lag om socialdataregister (Proposition 2025/26:165) – National social data register held by Socialstyrelsen as sole data controller; covers recipients of social services and LSS disability support across all municipalities; identification data and personnummer, assessments, decisions, services, needs and outcomes, and next-of-kin data where absolutely necessary; mandatory reporting by providers, no individual consent (GDPR Article 6(1)(e), task in the public interest); absolute statistical secrecy under OSL 24:8, restricted searches on sensitive data, monitored access; main provisions in force August 1, 2026, reporting obligations August 1, 2027; Lagrådet sought an explicit purpose statement and clarification of controller responsibility, both incorporated
[35] Sveriges riksdag: Lagändringar för ett stärkt nationellt cybersäkerhetscenter (Proposition 2025/26:214) – Statutory amendments strengthening Sweden’s national cybersecurity centre; entry into force July 15, 2026
[36] Council of Europe Treaty Office: European Convention on Mutual Assistance in Criminal Matters (ETS No. 30) – Chart of signatures and ratifications; 51 parties as of July 2026 (all 46 Council of Europe member states plus Chile, Israel, Mongolia, the Republic of Korea and Russia), Sweden among them
[37] Council of Europe Treaty Office: Convention on Cybercrime (ETS No. 185) – Chart of signatures and ratifications; 82 parties as of July 2026 (45 Council of Europe member states plus 37 non-member states), Sweden among them
[38] European Commission: Schengen Area – The 29 states of the Schengen Area (all EU members except Ireland and Cyprus, plus the non-EU associates Iceland, Liechtenstein, Norway and Switzerland; Bulgaria and Romania became full members January 1, 2025), Sweden among them
[39] Wikipedia: Prüm Convention – The Prüm framework for automated DNA, fingerprint and vehicle-data exchange; binds all 27 EU member states plus the non-EU Schengen associates Iceland, Liechtenstein, Norway and Switzerland (31 in all), Sweden among them; Prüm II (2024) adds facial images and police records
[40] Europol: Operational Agreements – Europol is constituted by the 27 EU member states (Sweden among them) and maintains operational cooperation agreements permitting exchange of personal data with 17 non-EU states (Albania, Australia, Bosnia and Herzegovina, Canada, Colombia, Georgia, Iceland, Liechtenstein, Moldova, Monaco, Montenegro, North Macedonia, Norway, Serbia, Switzerland, Ukraine, the United States) plus Denmark under a separate agreement, and with Eurojust, Frontex and Interpol
[41] Wikipedia: Nordic-Baltic Eight (NB8) – Nordic-Baltic cooperation among Denmark, Estonia, Finland, Iceland, Latvia, Lithuania, Norway and Sweden (the five Nordic states plus the three Baltic states); cybersecurity and hybrid-threat coordination
[42] Wikipedia: Club de Berne – informal forum (founded 1969) of the heads of the domestic intelligence and security services of the 27 EU member states plus Norway and Switzerland; its separate post-9/11 offshoot the Counter Terrorism Group (September 2001) additionally includes the United Kingdom and has operated a joint platform in The Hague with a common database and real-time information system since 2016
← Back to Privacy Law Directory