Data protection supervision and how an inspection runs: timeline and cost depend on what triggered the case, the authority's caseload and how fast the organisation answers document requests. Under Swedish law as it currently stands, the process runs from a written request through a review period to a decision, with cost driven mainly by document volume and correspondence rounds.
Who this concerns
Any organisation that processes personal data as a controller or a processor with an establishment, employees or customers in Sweden can receive a notice opening a supervisory file. In practice this reaches far beyond obvious data-heavy businesses: a mid-sized distributor with an HR system, a group entity that shares a customer database with a foreign parent, or a service provider running marketing analytics can all be the subject of the first letter.
The trigger is rarely a routine audit. Most files open after a complaint from a data subject, a self-reported personal data breach, or a targeted review of a sector where the authority has flagged systemic risk, such as health data processors, financial services or adtech. Group entities operating in Sweden also feel this alongside separate information-security duties that sit under the compliance, sanctions and cyber framework this material belongs to, a related but distinct regime with its own procedure.
What is actually at stake is broader than a fine. A supervisory file can end in a binding order to stop a processing activity, a requirement to notify affected individuals directly, or a corrective plan with its own deadlines. The management time spent producing documents and coordinating a response is, in most cases, the largest real cost before any sanction is even discussed, and it falls on the same people who run day-to-day operations.
What the law says
Under Swedish law as it currently stands, the competent supervisory authority for data protection matters in Sweden, Integritetsskyddsmyndigheten (IMY, the Swedish Authority for Privacy Protection), derives its investigatory and corrective powers directly from the data protection framework applicable across the EU and from the national provisions that implement and supplement it domestically. Those powers include the right to request information and documents, to access premises where processing takes place, to order that processing stop or be brought into compliance, and, where warranted, to impose an administrative fine.
The organisation under review has a corresponding duty to cooperate: providing accurate information on request, granting access where lawfully required, and not obstructing the review. Failure to cooperate is treated as a separate matter from the underlying processing question and tends to harden the authority's eventual findings rather than soften them, regardless of how the substantive point is ultimately resolved.
Where the facts of a case touch more than one member state, the authority also operates within a cooperation mechanism that allows it to exchange information with, or hand lead responsibility to, another EU supervisory authority. That mechanism matters most for group structures where the decision-making entity sits outside Sweden, a point developed further below.
Because the specific procedural timetable and the applicable thresholds are set out in instruments outside the scope of this material, no fixed statutory deadline or figure is quoted here; what follows describes the mechanics as they run in practice, not a numbered checklist tied to a particular clause.
How it works in practice
What actually triggers a case file
A complaint from an individual, a breach notification the organisation submitted itself, a request from another EU supervisory authority under the cooperation mechanism, or a proactive sweep of a sector are the four common openings. The trigger shapes the scope: a complaint-driven file is usually narrow and tied to one processing activity, while a sector sweep can start broad and later narrow once the authority sees what is actually in place across the organisation.
The competent authority and what it can do
IMY handles the file from opening to decision. It can request documents in writing, hold meetings, conduct an on-site or remote inspection, and issue a findings letter before any final decision. It does not need to prove intent to issue a corrective order; a processing gap found during review is enough to trigger a requirement to fix it, independent of whether a fine follows.
Step one: the opening notice
The file usually opens with a written notice describing, in general terms, what prompted the review and what information is requested first. This is not yet an accusation of a breach: it is a request for the organisation's own account and records. How this first response is framed tends to set the tone for everything that follows, including how many further rounds of questions the authority feels it needs to ask.
Step two: document requests and the review window
The authority then works through the documents supplied, often followed by one or more rounds of clarifying questions. Typical requests cover the record of processing activities, data processing agreements with vendors, the legal basis relied on for the processing in question, retention schedules, and any prior data protection impact assessment. Each round of questions restarts a response window, so the number of rounds, not any single deadline, is what determines how long this stage runs.
Step three: inspection, remote or on site
Some files are resolved on paper. Others include an inspection, which today is as often conducted remotely as on site. An on-site visit typically covers interviews with the staff responsible for the processing, a walk-through of the systems involved, and spot checks against the documents already supplied. Refusing reasonable access at this stage is treated as non-cooperation, and it rarely helps the eventual outcome.
Step four: the findings letter and the right of reply
Before a final decision, the authority ordinarily sets out its preliminary findings and gives the organisation an opportunity to respond. This is the last point at which factual corrections, additional context or missing documents can change the outcome: a decision issued after this stage is difficult to unwind other than through a formal challenge, which is a separate and slower process in itself.
Step five: decision and corrective measures
The decision can range from closing the file with no action, through a reprimand or an order to bring processing into compliance by a set date, to an administrative fine calculated on the basis of the specific facts, including the nature of the processing, the degree of cooperation shown and whether the same issue has arisen before. Orders to change or stop a processing activity are, in commercial terms, usually more disruptive than the fine itself, because they can require rebuilding a data flow the business depends on for its ordinary operations.
What good cooperation looks like in practice
Cooperation is not the same as agreeing with every preliminary view the authority forms. It means answering what was actually asked, on time or with a reasoned request for more time before the deadline passes, and flagging early where a document does not exist rather than letting the authority discover the gap itself. Organisations that treat each request as an opportunity to narrow the scope with facts, rather than to argue the underlying law, generally move through the process faster.
Documents the authority typically asks for
- the record of processing activities covering the processing under review
- data processing agreements with any processor or sub-processor involved
- internal policies on retention, access control and breach handling
- the legal basis analysis for the specific processing activity
- any data protection impact assessment carried out for that activity
- correspondence with the data subject where the file started as a complaint
When the controller or a group company sits outside Sweden
Where the entity that actually decides how data is processed is a parent company abroad, or where data flows to a group affiliate outside the EU, the review does not stop at the Swedish subsidiary's door. The Swedish authority can request the same documents from the local entity regardless of where decisions are made, and a transfer mechanism that looks adequate on paper is checked against how it operates in fact, not against how it reads in a group policy manual. A foreign parent's assumption that its own compliance programme automatically covers the Swedish entity is one of the most common reasons a file that started narrow ends up broad, and one of the hardest positions to correct once the findings letter has already gone out.
What to check before you send the first response
- who inside the organisation actually controls the processing described in the notice, not who is named as the formal controller on paper
- whether the record of processing activities matches what the systems actually do today, not what it said a year ago
- whether any processor involved has its own obligations that need to be pulled into the response
- whether a breach notification was filed on time for the same facts, if that is relevant to the file
- whether responding without legal input risks conceding a point that is still genuinely arguable
How long does a data protection inspection typically take from opening notice to decision?
There is no single statutory clock that applies to every case. A file resolved on paper with one round of document requests moves faster than one that includes an inspection and a findings letter with a right of reply. The authority's own caseload at the time also affects how quickly each stage moves, which is why two similar files can run on very different timelines.
What happens if the deadline to respond to a document request is missed?
Missing a response window does not close the file in the organisation's favour. It is treated as a cooperation issue in its own right, separate from the underlying processing question, and tends to result in a firmer tone in subsequent correspondence rather than in the request being dropped or forgotten.
Does a supervisory inspection always end in a fine?
No. Outcomes range from closing the file with no action, through a reprimand or a compliance order with its own deadline, to an administrative fine. In commercial terms, a compliance order that requires rebuilding a data flow is often more disruptive than a fine would have been on its own.
The numbers
No fixed statutory clock is quoted here because the applicable deadlines depend on the specific notice received and the instrument it is issued under, which sits outside the scope of this material. What can be said with confidence is how the timeline and the cost are actually built, and which factors move them in either direction.
| Factor | Effect on timeline and cost |
|---|---|
| Number of correspondence rounds | Each round restarts a response window and adds review time on both sides |
| Whether an inspection takes place | Adds a scheduling and preparation stage not present in paper-only files |
| Completeness of the first response | Fewer follow-up questions if the record of processing activities is current |
| Involvement of a processor or sub-processor | Adds a party whose documents also need to be gathered and checked |
| Whether the entity's parent sits outside Sweden | Can widen the scope of documents requested and the time needed to assemble them |
The timeline is set by the authority's own caseload and by how complete the organisation's response is at each stage, not by a single published number. A file that answers every document request in one round, with nothing missing, moves faster than one that triggers three rounds of follow-up questions because the first response was incomplete.
Cost follows the same logic. It is driven by the volume of documents that must be reviewed and assembled, the number of correspondence rounds, whether an inspection takes place, and whether the organisation needs legal input to draft the response to the findings letter rather than only to the opening notice. None of this is quoted in kronor here, because it depends on facts specific to the file, not on a rate card.
Where it usually goes wrong
A file that opens narrow, tied to one complaint, regularly expands once the authority reviews the record of processing activities and finds gaps unrelated to the original complaint. Treating the first document request as the full scope of the review, rather than as an opening position, is the most common planning mistake.
A second failure is assuming that no fine means no consequence. A corrective order with a compliance deadline can require rebuilding a data flow the business depends on, which is often more expensive in management time than any fine that might have been imposed instead.
A third is responding to the opening notice as an administrative task rather than as the start of a legal proceeding. Once the findings letter arrives, factual gaps in the earlier response are harder to correct, and a position conceded early cannot always be walked back later in the same file.
A fourth, specific to groups with a presence outside Sweden, is assuming that a parent company's own data protection programme automatically covers the Swedish entity. The authority tests what actually happens locally, not what a group policy says should happen on paper.
A fifth is delegating the entire response to IT or compliance staff without legal review, on the assumption that this is purely a technical exercise. Some of the questions asked in a findings letter carry legal consequences well beyond the specific processing activity under review, and answering them without checking that broader exposure is a frequent source of avoidable damage.
What to do next
Reading the notice correctly and answering the first document request well is work an organisation can do on its own, provided the record of processing activities is current and the people who actually run the processing are in the room. Self-directed work stops being enough once the findings letter arrives, or once the notice touches a processing activity that overlaps with obligations under the Cyber Security Act's scope and cost for entities within that regime, where two reviews can move in parallel and pull the organisation in different directions.
At that point, the practical question is no longer what the notice says but what the underlying documents actually show, and that reading needs to happen before the response is drafted, not after. For a short assessment of where a specific file stands and what the realistic exposure looks like, arrange a short assessment call.