LODLINE
EN / SV

compliance-sanctions-cyber

Data protection supervision and how an inspection runs: cost and likely outcome

Data protection supervision and how an inspection runs: cost and likely outcome hinges on how an organisation produces its processing records once the supervisory authority makes contact. Inspections follow a fixed sequence: notice, document request, review, decision. Cost tracks the volume of processing under scrutiny; outcome ranges from no action to a corrective order, with fines reserved for repeated failures.

Who this concerns

Any organisation processing personal data in Sweden can become the subject of an inspection, but the profile of the ones that actually happen is narrower than the profile of the ones that could happen in theory. Controllers running large-scale profiling, organisations handling health, biometric or criminal-record data, and businesses whose processing depends heavily on third-party suppliers or subcontractors sit closer to the front of the queue.

Three routes lead to an inspection. A complaint from a data subject, often an employee, customer or job applicant, is the most common. A breach notification that raises questions about the underlying controls is the second. A sector sweep, where the authority selects a group of comparable organisations for a coordinated review, is the third and the least predictable, because there is no individual trigger event to point to.

Where a group has a parent company outside Sweden, or where the processing in question involves a data flow to a controller or processor abroad, the practical questions change early. It matters which entity in the group is named as the respondent, whether the Swedish entity has full visibility of the processing carried out by an affiliate, and whether a lead supervisory authority in another member state already has an open file on the same processing. None of that is resolved by the notice letter itself; it has to be worked out before the first response goes back.

What the law says

The mandate of the supervisory authority, and the powers it can exercise during an inspection, are set out under Swedish law as it currently stands, applied alongside the wider EU data protection framework. The authority can request information, require access to premises and systems, and order corrective measures where it finds a deficiency. Where the finding is serious, it can also issue an administrative fine, calculated against the specifics of the case rather than against a fixed schedule.

Where processing is genuinely cross-border, a lead authority mechanism can apply, meaning that a single supervisory authority in the member state of the controller's main establishment coordinates the response on behalf of authorities elsewhere. Whether that mechanism applies to a given case is a question of fact about where decisions on the processing are actually made, not a question of where the group's registered office happens to sit.

How it works in practice

What typically triggers an inspection

A single complaint rarely triggers an inspection on its own. What usually moves a file from a complaint register to an active inspection is a pattern: several complaints about the same processing activity, a complaint that surfaces a gap the authority has already flagged in a previous sector review, or a breach notification that reads as incomplete against what the authority already knows about the sector.

The notice and initial information request

The first contact is written, names the processing activity or activities under review, and sets a deadline for an initial response. The request is rarely open-ended; it usually asks for specific categories of document: the record of processing activities for the activity in question, the legal basis relied on, any data protection impact assessment, and the contracts with processors involved.

Documentation the authority expects to see

Beyond the record of processing itself, an inspection commonly asks for the internal policy that governs the activity, evidence that the policy is actually followed rather than just written down, logs showing who accessed the data and when, and the data processing agreements covering any supplier that touches the data. Gaps between the policy on paper and the practice on the ground are the single most common finding.

On-site or remote review

Many inspections are conducted entirely on paper, through document exchange. Some extend to a site visit or a remote session where the authority's case officer walks through the systems with the organisation's staff. A site visit is a signal that the paper record alone has not answered the authority's questions, not a routine step.

Interviews and follow-up requests

Where the paper trail is incomplete or inconsistent, the authority follows up with targeted questions, sometimes addressed to a named individual, such as the data protection officer or the system owner. These follow-up rounds are where inconsistencies between departments, or between what was written in a policy and what staff actually do, tend to surface.

The draft findings and right to respond

Before a final decision, the organisation is usually given the authority's provisional view and an opportunity to respond. This is the point at which additional context, corrective steps already taken, or evidence that a finding rests on a misunderstanding of the processing, can still change the outcome. Responses filed after this stage carry materially less weight.

The decision and possible outcomes

The decision can close the file with no further action, require specific corrective measures within a set timeframe, or, in the more serious cases, impose a fine. A decision requiring corrective measures is far more common than a fine; fines are reserved for cases involving a clear and either repeated or wilful failure, not for a single documentation gap corrected promptly once identified.

What to check before responding

  • Whether the request names a specific processing activity or is drafted broadly enough to cover activities not yet identified internally.
  • Which legal entity within the group is named as the respondent, and whether that entity actually controls the processing in question.
  • Whether the stated deadline is calendar days or working days, and whether an extension has ever been requested in a comparable case.
  • Whether any of the material requested is covered by legal privilege and needs to be identified as such before it is produced.
  • Whether a data processing agreement with the relevant supplier or subcontractor covers the specific systems the request refers to.
  • Whether a previous incident involving the same processing activity was reported, and whether that report is consistent with the current file.

Frequently asked questions

How does responding to a data protection inspection differ from dealing with the Economic Crime Authority?

The two bodies act under different mandates and rarely run in parallel on the same facts, though a data protection finding can trigger a separate referral where the underlying conduct looks criminal rather than administrative. Dealing with the Economic Crime Authority sets out who actually decides what once a matter moves into that track.

Is a data protection inspection the same thing as a besiktning?

No. Besiktning is a Swedish term for a physical or technical inspection, typically of property or equipment, carried out by an appointed inspector against defined criteria. A data protection inspection is an administrative review of documentation and controls, not a physical inspection, though the two are sometimes confused because both are described in everyday speech as an "inspection". What besiktning means sets out the term properly.

Do security requirements imposed on suppliers and subcontractors get reviewed during an inspection?

Frequently, yes. Where personal data is processed by a supplier or subcontractor, the authority routinely asks for the underlying data processing agreement and evidence that the security requirements in it are actually enforced, not just documented. Security requirements on suppliers and subcontractors sets out where those obligations stop.

The numbers

Cost is not driven by the size of the organisation under review; it is driven by the volume of processing activity in scope and the state of the documentation before the request lands. An organisation with an up-to-date record of processing, current impact assessments and processor agreements on file spends far less time and far less money responding than one that has to reconstruct that documentation from scratch under a deadline.

The bulk of the cost sits in three places: the hours spent assembling and checking documentation against what the authority has asked for, the hours spent on legal review of the response before it goes out, and, in the smaller number of cases that reach that stage, the cost of addressing a corrective order once issued. Forensic or technical review adds materially to cost and is usually only needed where the documentation itself cannot answer the authority's question, for example where access logs are incomplete.

Duration is set by the completeness of what is submitted and by the authority's own caseload at the time, not by a fixed statutory clock that applies uniformly to every file. A complete, well-organised initial response tends to shorten the process; an incomplete one that generates follow-up requests lengthens it, often by more than the time saved by rushing the first submission.

Exposure to a fine, where it exists at all, tracks the severity of the underlying failure, whether the same failure has been raised with the organisation before, and how the organisation engaged once contacted, rather than a fixed percentage applied mechanically to every case that reaches a decision.

Where it usually goes wrong

The framework above holds for a single-entity inspection with no criminal element and no cross-border complication. It stops holding in several identifiable situations.

Where the facts under review also look like they involve deliberate concealment or a knowing breach of an obligation elsewhere in the regulatory perimeter, for example around reporting obligations to a sector regulator, the file can move outside a purely administrative track and into contact with a body such as the Economic Crime Authority. At that point the questions asked, and the standard applied to the answers, change materially.

Where the group has operations, or a parent, outside Sweden, and the processing decisions are genuinely made elsewhere, the lead authority mechanism can shift the entire matter to a different supervisory authority mid-process. An organisation that has already prepared a response on the assumption that the Swedish authority will decide the matter can find that assumption wrong partway through.

Where the organisation operates in a regulated sector with its own supervisor, such as financial services, a data protection finding can trigger a parallel enquiry from the sector regulator on overlapping facts. The two processes are not run by the same body and do not necessarily reach the same conclusion on the same evidence.

Where an inspection that starts on one processing activity uncovers a systemic gap, for example a supplier security failure that runs across multiple activities rather than the one under review, the scope of the inspection itself can expand. What began as a narrow enquiry into a single complaint can end as a review of an entire supplier relationship.

What to do next

Everything above can be assessed and largely prepared without outside involvement: pulling the record of processing, checking it against what is actually done, and gathering the processor agreements that cover the activity in question. Where self-directed work stops is at the point of judging how a specific set of facts is likely to be read by the authority, and whether a gap uncovered during preparation, such as an unenforced supplier security clause, creates exposure beyond the inspection itself.

That second question is where an assessment of the specific position, rather than a general description of how inspections run, becomes the relevant next step. Get in touch to have the current position reviewed before the next deadline in an active file.

Supplier and counterparty gaps surfaced during a data protection inspection are frequently the same gaps that show up in sanctions and beneficial-ownership screening, because both rest on the same underlying due diligence. Sanctions screening for counterparties sets out what a working screening process actually covers and where the first ten counterparties checked usually reveal the gap.

For the wider set of materials on supervision, sanctions exposure and cyber-related compliance obligations, see the compliance, sanctions and cyber practice.

Request a preliminary assessment