Data protection supervision and how an inspection runs: what to do in the first hours after the notice arrives decides much of what follows. The controller must acknowledge the enquiry, identify one internal point of contact, and hold every document requested without editing it, while resisting the instinct to explain, apologise, or volunteer information the notice did not ask for.
Who this concerns
This concerns any controller or processor operating in Sweden that receives a formal enquiry, a request for information, or an announcement of an on-site review from the supervisory authority. It reaches organisations of every size: a small consultancy asked to explain a data breach notification, a payment processor whose vendor questionnaire triggered a wider look at subprocessor contracts, or a group entity where the compliance function sits in another country and has to be briefed before the local unit can respond. The broader mechanics of regulatory contact across compliance, sanctions and cyber work follow the same logic even when the specific trigger differs.
Supervision is not limited to organisations that have made an obvious mistake. Reviews open from complaints, from breach notifications the controller itself filed, from sector sweeps that touch every operator in a segment, and from information the authority already holds from an earlier, unrelated matter. Whether the trigger was a complaint or a routine sweep changes the tone of the first letter, not the obligation to respond fully and on time. Commercial organisations that treat the notice as an administrative formality, to be handled whenever someone finds time, are the ones most likely to still be in the review six months later.
What the law says
Supervisory powers over personal data processing in Sweden rest on the data protection framework as implemented and supplemented at national level. Under Swedish law as it currently stands, the supervisory authority can request access to premises, documents, and processing systems, and can issue binding orders once a review is concluded. The framework does not require the authority to disclose in advance the full scope of an enquiry, and a request framed narrowly at the outset is not a commitment that it will stay narrow.
The controller's own obligations, to document processing activities, to be able to demonstrate a lawful basis for each activity, and to cooperate with the authority in good faith, do not pause because a review is under way. A controller that cannot produce a record it is legally required to hold faces a materially different conversation with the authority than one that produces the record late but complete. The distinction the authority draws is between an organisation that is behind and one that is missing documentation it was always required to keep, and the second is treated as a substantive finding in itself, independent of whatever the review was originally opened to look at.
How it works in practice
How the first contact typically arrives
Contact usually comes as a written notice, by letter or through a secure channel, naming the processing activity or activities under review and setting a date by which the controller must respond. Occasionally the first contact is a phone call asking for a document informally before the formal notice follows; treating that call as the start of the deadline, even if the letter arrives a day later, avoids losing time that cannot be recovered.
Who inside the organisation should take the call
One person should coordinate the response, not necessarily the data protection officer and not necessarily legal, but whoever has the authority to instruct different departments to produce documents on a shared timeline and to sign off on what goes out. Splitting coordination between two people, one for the technical answer and one for the legal framing, is workable, but only if one of them is clearly in charge of the deadline and can say no to a department that wants to send its own version.
What gets requested in the first round of documents
The first request is usually narrower than the review will eventually become: the record of processing for the activity named, the lawful basis relied on, and any data processing agreement with a relevant external party. What it signals is which processing activity the authority is looking at, not necessarily why. Answering only the letter of the first request, while flagging internally that the same processing activity touches other systems the request did not name, keeps the response accurate without volunteering more than was asked.
Desk-based review versus a visit to the premises
Most reviews are conducted on paper: documents go back and forth by post or secure channel, and the matter closes or escalates without anyone from the authority setting foot on site. A visit changes the calculus, because staff who are not part of the coordinated response may be asked questions directly, and an answer given informally during a visit carries the same weight as one submitted in writing. Preparing the staff most likely to be approached, not just the coordinator, is the difference between a visit that stays contained and one that generates new lines of enquiry.
Cross-border processing and the lead authority mechanism
Where the controller has a main establishment outside Sweden, or where the same processing activity is supervised in more than one member state, the Swedish authority is not necessarily the one that leads the review. The lead authority mechanism assigns primary responsibility to the authority where the main establishment sits, with other authorities, including the Swedish one, participating as concerned authorities. A group that assumes the Swedish entity can respond and close the matter locally, when the lead in fact sits elsewhere, ends up producing two inconsistent responses instead of one coordinated one, which is worse than either response alone would have been.
When a supplier or subcontractor becomes part of the enquiry
A review that starts with the controller often does not stay there. If a processing activity depends on an external processor, the authority can ask for the contract terms that govern that arrangement, and a controller that cannot produce a data processing agreement with the required content faces the same exposure as if it had failed to document the activity itself. This is the same territory covered by supplier security obligations across contracts, and a controller preparing for supervision benefits from checking that document set before, not during, the review.
What happens after the first response
Closure is not automatic once documents go out. The authority can come back with follow-up questions on the same processing activity, widen the enquiry to a related activity that the first response mentioned only in passing, or move to a formal decision without further contact. A controller that assumes silence means the matter is closed, and stops tracking the file internally, is often the one caught unprepared when a follow-up letter arrives asking why an earlier gap has not been remedied.
What to check before anything is sent
- Whether the record of processing activities named in the request is current, not the version from the last internal audit
- Whether the lawful basis relied on for each activity is the one actually recorded, not one added retrospectively to answer the question
- Whether any data processing agreement referenced in the response matches what the processor is actually doing today
- Whether the person named as internal contact has authority to commit the organisation, or only to relay messages
- Whether a parallel breach notification, complaint, or earlier enquiry touches the same processing activity, and whether the current review is aware of it
- Whether documents sent in response to the first request are internally consistent with each other before they leave the building
Does a data protection review ever turn into a bookkeeping or accounting enquiry?
Not directly, but the two can converge. If documents produced during a data protection review reveal that transaction records were altered or destroyed rather than merely mishandled from a privacy standpoint, the supervisory authority can refer that finding onward, and a separate process decides whether it amounts to a bookkeeping offence rather than a data protection failure. Who decides in that separate process is a distinct question from who decides the data protection outcome itself.
Can a data protection review expose issues with capital maintenance or shareholder transactions?
It can, though this is not its purpose. Documents produced to answer a processing-activity question sometimes show, incidentally, that value moved out of the company in a way that has nothing to do with personal data. When that happens, the rules on unlawful value transfers apply on their own terms, assessed separately from whatever the data protection authority concludes about the processing itself.
What does olovlig värdeöverföring mean and why would it come up here?
Olovlig värdeöverföring is the Swedish term for an unlawful value transfer out of a company, a company-law concept unrelated to data protection as such. It surfaces in this context only because document sets produced for one review are sometimes read for more than their original purpose; the full definition of the term sits in company law, not in the data protection framework.
The numbers
There is no single statutory day-count that applies to every notice; the deadline for a first response is set in the notice itself and varies with the scope of the request and the authority's own caseload. What is worth tracking numerically is different: how many separate document requests the review generates, how many processing activities they touch, and how many of those activities the controller can map without asking a third party for help. A review that stays inside two or three processing activities usually resolves faster than one that fans out across the whole record of processing, and the fan-out is driven by what the first response reveals, not by anything fixed in advance.
Cost follows the same pattern. What drives it up is not the initial letter but the volume of documents to review before they go out, the number of internal witnesses who need briefing, and whether a cross-border element pulls in a second authority under the coordination that applies to group processing. An organisation with one processing activity, a clean record, and a single point of contact spends a fraction of what an organisation with the opposite profile spends, and the difference is set months before the notice arrives, not during the response to it.
Where it usually goes wrong
The review stops being manageable at a specific point, not gradually. The most common one: someone inside the organisation answers a question from the authority informally, by phone or in a hallway conversation during an on-site visit, without it being recorded or cleared through the person coordinating the response. What was meant as a helpful clarification becomes part of the file, and it cannot be withdrawn.
A second point: documents get sent in batches as they are found, rather than as a set that has been checked for consistency first. Two departments describing the same processing activity in incompatible terms reads to the authority as concealment, even when it is only inconsistent internal terminology.
A third: the organisation treats a request from the authority as adversarial from the outset and routes everything through outside counsel before establishing what is actually being asked. This is sometimes right, but treating every enquiry that way slows down the parts of the review that would have resolved themselves with a cooperative, factual answer, and it signals a defensiveness the authority reads as substantive rather than procedural.
Where a foreign parent or a subprocessor is involved, the point at which control is lost is usually earlier: the local entity does not have a mandate to speak for the group, and by the time head office authorises a coordinated answer, the deadline in the notice has already passed. None of this is unique to data protection reviews, but the deadline discipline in this area is less forgiving than in most adjacent supervisory contexts, because the authority treats a missed deadline itself as a separate and independently assessable failure, apart from whatever the underlying processing activity turns out to have been.
What to do next
Everything above is work a controller can do without outside help: acknowledging the notice, assigning one coordinator, checking that the record of processing matches reality, and sending a first response that is accurate and no wider than the question asked. Where self-directed work reaches its limit is earlier than most organisations expect, usually at the point where the first response reveals a gap between the documented lawful basis and what the processing activity actually does, or where a subprocessor's contract does not say what the organisation assumed it said.
That is the point to bring in an outside assessment of the position, rather than to keep managing the review with people who also have to explain, internally, why the gap exists. The ICT risk management framework for supervised entities sets out adjacent obligations that a data protection review often surfaces alongside its own findings, and is worth reading before the next document goes out. For a read on the specific position, book an assessment of the current review.