LODLINE
EN / SV

compliance-sanctions-cyber

Data protection supervision and how an inspection runs: step by step

Data protection supervision and how an inspection runs: step by step comes down to six stages: notice, an information request, document review, interviews, a preliminary findings letter with a right of reply, and a final decision that may include a corrective order or a fine. Each stage carries its own deadline; missing one narrows what happens next.

Who this concerns

The company under review is usually a controller or a processor already known to the supervisory authority: through a complaint from a data subject, a breach notification filed earlier, a sector-wide sweep, or a follow-up to a finding closed in a previous cycle. Inspections are not reserved for large multinationals. A regional retailer running a loyalty programme, a payroll processor handling several clients' employee data, or a healthcare provider outsourcing patient records to a cloud vendor all fall within scope on the same footing as a listed group.

Where the entity under review sits inside a group with an establishment elsewhere in the EU, the first practical question is which supervisory authority actually leads the matter. Lead authority status follows the location of the main establishment, meaning where decisions on the purposes and means of processing are actually taken, not where the Swedish entity happens to be registered or where the servers sit. A Swedish subsidiary that only executes instructions from a parent established in another member state may find the inspection is coordinated by that other authority, with the Swedish authority acting as a concerned party rather than as the lead.

That distinction matters for timing as much as for substance. A finding reached locally can remain provisional pending the lead authority's own view, and a company that treats a Swedish letter as the final word can be surprised when the position is reopened once the cross-border process concludes.

What the law says

The power to open an inspection, request information, enter premises and issue a corrective order rests on the general data protection framework applicable in Sweden, under Swedish law as it currently stands. That framework gives the supervisory authority a graduated set of tools: a written request for information, an on-site inspection, a formal warning, an order to bring processing into compliance within a set timeframe, a temporary or permanent ban on a specific processing activity, and an administrative fine. Which tool is used first, and how far the matter escalates, depends on the seriousness of the issue as the authority assesses it at intake, not on the size of the company or the sector it operates in.

How it works in practice

Notice and scope

The inspection typically opens with a written notice identifying the processing activity under review and the basis the authority intends to examine. The notice sets out the scope in specific terms: which processing operations, which data categories, which systems or contracts are in play. A vague or unusually broad notice is worth querying immediately, in writing, before any documents are produced, because the scope defined at this stage frames what the company can later argue was outside the inspection's remit.

The information request

Alongside or shortly after the notice comes a formal request for information: records of processing activities, data protection impact assessments if any were carried out, the register of processors and sub-processors, incident logs, and internal policies covering retention, access control and breach response. The request states a deadline for the response. That deadline is fixed case by case, based on the volume of material sought and the complexity of the processing under review, and it is stated in the request itself rather than following a fixed default that applies across every matter.

Document and system review

The authority reviews what has been produced against what the notice describes. Where records are incomplete, inconsistent with what the company's own privacy notice says, or silent on a processing activity the authority already knows about from another source, a supplementary request usually follows. This is the stage where a mismatch between what a data protection impact assessment describes on paper and what a system actually does in production becomes visible, and it is the single most common source of an inspection expanding beyond its original scope. A register of processing activities that was drafted once and never updated as systems changed is the recurring cause of that mismatch.

Interviews with staff and management

Some inspections include interviews with the data protection officer, the IT lead responsible for the system in question, or the business owner who commissioned the processing. Interviews are not adversarial by design, but answers are recorded and can be referred back to later in the process. A company that sends whoever happens to be available, rather than the person who actually knows how the system works day to day, tends to generate answers that contradict the documentation already submitted, and that contradiction becomes the next question.

On-site inspection

An on-site visit is not automatic; many inspections are conducted entirely on paper. Where a visit does take place, the authority's representatives can inspect systems, request live demonstrations of how access controls actually operate, and review physical security measures at the premises named in the notice. The company is entitled to have its own legal and technical staff present throughout, and to keep a parallel written record of what was shown and what was asked.

Preliminary findings and the right of reply

Before any formal decision, the authority sets out its preliminary findings and gives the company an opportunity to respond. This is the point at which factual errors, missing context, or a mischaracterised system should be corrected in writing, with supporting documents attached rather than merely asserted. A reply that repeats the original submission without addressing the specific points raised in the preliminary findings rarely changes the outcome, because it gives the authority nothing new to weigh.

The final decision

The final decision confirms, narrows or drops the preliminary findings and states what happens next: no further action, a formal reprimand, an order to bring the processing into compliance by a stated date, a ban on a specific processing activity, or an administrative fine. The decision states the deadline for any corrective action it orders; that deadline, again, is set case by case rather than following a uniform rule that could be quoted in advance.

Appeal

A decision can be challenged before the competent court. Challenging a finding of fact requires the evidential record built during the inspection itself, which is why the quality of what was submitted at the information request and reply stages matters more, in practice, than what is argued once the matter reaches appeal.

What to check

  • Whether the notice's stated scope matches every system, contract and data category the company believes is actually involved, before anything is produced.
  • Whether the register of processing activities, the sub-processor list and the actual data flows agree with one another, rather than describing three slightly different versions of the same process.
  • Whether the person put forward for an interview is the person who operationally understands the system under review, not the most senior person available.
  • Whether a previous finding on the same or a related processing activity has already been closed, and what it required the company to change.
  • Whether the deadline stated in the request is realistic given the volume sought, and whether an extension needs to be requested in writing before it lapses rather than after.

How long does the response window for an information request usually last?

The window is set out in the request itself and varies with the volume and complexity of what is being asked for; there is no default period that applies across all matters. A company that needs more time should ask before the stated deadline lapses, in writing, rather than assume an extension will be granted after the fact.

Can a company limit what it hands over during an inspection?

A company can and should push back on a request that goes beyond the scope stated in the notice, but it cannot lawfully withhold material that falls squarely within that scope. The more useful lever is precision: producing exactly what was asked for, checked for internal consistency first, rather than either withholding material or over-producing it.

Does the company need legal representation present at an on-site inspection?

There is no requirement to have legal counsel present, but a company is entitled to have its own legal and technical staff attend throughout, and most companies that have been through the process before choose to exercise that right rather than leave technical staff to answer questions alone.

The numbers

No two inspections run to the same clock. The deadline for responding to an information request, the deadline for replying to preliminary findings and the deadline for completing an ordered corrective action are each set out in the relevant letter, not fixed by a general rule applied uniformly across all matters. What is calculable in advance is the categories of exposure the final decision can carry, not the figures themselves: a reprimand that carries no financial consequence but sits on the company's compliance record; an order to bring processing into compliance by a stated date, non-compliance with which becomes a separate and more serious matter; a ban on a specific processing activity, which can stop a product or service outright; and an administrative fine, calculated by reference to the framework in force and to the seriousness, duration and scale of the infringement rather than a flat tariff. None of these can be sensibly estimated before the scope and the findings are known, and a company that budgets compliance work around a guessed fine risks preparing for the wrong problem entirely.

Where it usually goes wrong

The most common failure is treating the information request as a document dump rather than a curated response. Sending everything that might conceivably be relevant, without checking it against the register of processing activities first, routinely surfaces an inconsistency the authority would not otherwise have found on its own.

The second is missing the internal deadline for requesting an extension. An extension asked for before the stated deadline lapses is a routine administrative matter; the same request made after the deadline has passed is treated as a separate compliance failure layered on top of the original inquiry.

The third is assuming the inspection is confined to the processing activity named in the original notice. Once the authority has access to a company's systems and policies, a second processing activity that surfaces incidentally, and that looks non-compliant on its face, is fair game for a supplementary request even though it was never mentioned at the outset.

The fourth, and the one with the widest reach for a group with cross-border operations, is assuming the Swedish authority's decision is the only one that matters. Where the lead authority sits in another member state, a Swedish finding can be provisional pending that authority's own view, and a company that settles matters locally without checking who actually leads can find the position reopened once the cross-border process concludes.

None of this makes the process unwinnable. A company that produces exactly what the notice asks for, on time, with an internally consistent account of its own processing, closes a large share of inspections at the preliminary findings stage without ever reaching a formal decision.

What to do next

This is the point where reading stops being enough. Working out whether a given processing activity is defensible under the framework in force requires looking at the actual data protection impact assessment, the actual contracts with processors, and the actual system configuration, not a general description of how the rules are supposed to work. Where the entity under review also runs systems that fall under network and information security obligations, the questions raised by an inspection often overlap with what the entities the Cyber Security Act covers already need addressed, and that overlap is worth checking before responding to the authority rather than after.

Lodline's compliance, sanctions and cyber practice reviews the notice, the register of processing activities and the draft response before anything goes to the authority, and takes the assessment call from there.

Request a preliminary assessment