LODLINE
EN / SV

compliance-sanctions-cyber

Incident reporting and its deadlines: what to do in the first ten days

Incident reporting and its deadlines: what to do in the first ten days is answered by a fixed sequence, not by waiting for full clarity. The first internal notification, the first regulatory contact and the first written record of the decision trail all need to happen inside that window, in that order, regardless of how uncertain the facts still are.

Who this concerns

This concerns any Swedish entity, or any entity operating in Sweden, that holds a duty to notify a supervisory authority when something goes wrong with personal data, network and information systems, financial crime controls or sanctions screening. The trigger is rarely a single clean event. It is usually a message from an IT provider, a flag from a monitoring tool, or a phone call from a customer, arriving at a moment when nobody in the building yet knows whether what happened meets the threshold for a formal report.

The person who picks this up is almost never the person who should own it for the following ten days. A technical lead escalates because something looks wrong. General counsel or the compliance officer then has to decide, often within hours, whether a reportable incident exists at all, before any forensic work has confirmed scope or cause. That decision, taken on partial information, sets the tone for everything that follows in this area of the compliance, sanctions and cyber practice.

Groups with more than one regulated entity face a second layer. A single incident inside a shared IT environment can trigger separate duties for separate legal entities, each running its own clock, each potentially reporting to a different authority for a different reason.

What the law says

The relevant Swedish framework does not treat "we are still investigating" as a reason to delay the first contact with the competent authority. The obligation attaches at the point an entity becomes aware, or ought reasonably to have become aware, that a reportable incident has occurred, not at the point the investigation is complete. Under Swedish law as it currently stands, the precise wording of the threshold, the identity of the competent authority and the exact form of the first notification depend on which regime is engaged, and more than one regime can be engaged by the same event.

What can be said without reference to a specific provision is the shape of the obligation: an early notification made on incomplete information, followed by supplementation as facts firm up, is the structure the regime is built around. Entities that try to produce one complete, final report instead of an early provisional one are working against that structure rather than with it.

Where sanctions exposure or suspicious-transaction indicators sit alongside a cyber or data incident, the reporting duties do not merge into one filing. Each duty is assessed and discharged on its own terms, even where the underlying facts overlap substantially.

How it works in practice

Day zero: confirming that something reportable may exist

The first task is not classification. It is a narrow factual question: is there a plausible basis to believe a reportable incident has occurred. This decision should be recorded in writing, with the name of the person who made it and the information available at the time, even if the conclusion is later revised.

Day one: first internal notification and ownership

Ownership moves to a single named person, usually general counsel, compliance, or an appointed data protection lead. IT keeps working the technical problem; that person now owns the reporting problem. Splitting this ownership later, once the pressure is on, almost always produces gaps in the record.

Days one to three: the first regulatory contact

Where a statutory notification duty exists, the first contact with the authority is typically due on a short clock measured in hours rather than days. This is not the moment for a finished analysis. It is the moment for a factual statement of what is known, what is not yet known, and when a fuller update will follow.

Days two to four: containment and evidence preservation

Containment decisions and evidence preservation run in parallel with, not after, the first notification. Logs, access records and communications from the relevant period need to be secured before normal retention or overwrite cycles remove them. A containment step taken without a contemporaneous note of why it was taken is difficult to defend later.

Days three to six: scoping who and what is affected

This is usually the longest single task inside the window: which systems, which categories of data or transactions, which counterparties, and how many individuals or entities are affected. Scoping conclusions reached this early should be phrased as provisional, because the number nearly always moves before the fuller report is due.

Days five to eight: assessing whether direct notification to affected parties is also required

A duty to notify a regulator does not automatically discharge a separate duty to notify affected individuals or counterparties directly. These two assessments use different thresholds and can point in different directions on the same facts.

Foreign parent companies and group escalation

Where the entity handling the incident sits under a foreign parent, or shares infrastructure with group companies outside Sweden, two clocks run at once: the Swedish statutory clock, and the group's internal escalation clock, which is often contractual rather than statutory and can be shorter. A parent company outside Sweden has no standing to instruct the Swedish entity to delay a statutory notification, and instructions from head office to that effect should be put in writing and challenged, not simply followed.

Days seven to ten: drafting the fuller report

The fuller report consolidates what has been confirmed, states clearly what remains open, and sets out the remediation steps taken so far. It should read as a continuation of the first notification, not as a replacement for it. Authorities that see a fuller report contradicting an earlier provisional one, without an explanation of why the position changed, tend to ask more questions, not fewer.

Documenting the decision trail

Every material decision in this window, who made it, on what information, and why, should exist in writing before the ten days close. This record is what separates a defensible late correction from an indefensible one if a regulator later asks why an earlier assessment turned out to be wrong.

What drives cost inside the window

Cost in this period is driven less by the notification itself and more by scoping. Forensic support to establish what actually happened, legal review hours to assess overlapping duties, and translation or coordination work where a foreign parent or counterparty is involved are the main variables. A narrowly scoped, well-documented incident with a single regulator is materially cheaper to handle than one where scope keeps expanding and more than one authority becomes involved.

What to check in the first ten days

  • Whether the incident meets the reporting threshold under each regime potentially engaged, not only the most obvious one
  • Which authority has competence for this specific type of incident, and whether that changes if scope expands
  • Whether a direct notification duty to affected individuals or counterparties exists separately from the regulatory one
  • Whether a service provider's incident also triggers the client entity's own independent reporting duty
  • Whether a foreign parent's internal escalation timeline is being allowed to override the Swedish statutory clock
  • Whether the first notification and any later supplement are consistent, and where they are not, whether that is explained

FAQ

#### Does the reporting window start from detection or from confirmation?

It starts from the point an entity becomes aware, or ought reasonably to have become aware, that a reportable incident may exist, not from the point an investigation confirms it. Waiting for confirmation before making the first contact is one of the most common ways this window is lost, because confirmation can take considerably longer than the clock allows.

#### What happens if the initial report turns out to be incomplete?

An initial report is expected to be provisional. Supplementing it as facts firm up is the normal process, not a failure. What creates exposure is a later report that contradicts the earlier one without a documented explanation of why the assessment changed, or a gap where no update was sent at all despite new material facts emerging.

#### Can a single incident be reportable to more than one authority?

Yes. A cyber incident that also exposes personal data, or that coincides with a suspicious transaction pattern, can trigger separate duties under separate regimes at the same time. Each duty is assessed and discharged on its own terms; treating one filing as covering all of them is a frequent and consequential mistake.

The numbers

No verified deadline figures, thresholds or fee amounts are available for this note. Exact clocks for the first contact and for the fuller report differ by regime, and more than one regime can apply to the same event with different timing. Before relying on any specific figure, the current wording of the regime actually engaged in the incident at hand needs to be checked directly, because the framing used in this note, a ten-day working window, is a practical convention for organising the response, not a statutory period in itself.

Where it usually goes wrong

The most common failure is treating the first ten days as a fact-finding period during which nothing needs to be sent externally. Regimes built around early provisional notification assume the opposite: that the entity will contact the authority before it has full clarity, and will supplement afterwards.

A second failure is an internal conclusion of "not reportable" reached quickly, recorded nowhere, and revisited only once new facts surface days later, by which point the window for the first contact has already closed. A documented "not reportable" decision, wrong in good faith on the facts available at the time, is defensible. An undocumented one rarely is.

A third failure sits at group level: a foreign parent's instruction to hold off on notification until head office has reviewed the matter. Swedish statutory reporting duties attach to the Swedish entity and do not pause for a parent company's internal sign-off process, wherever that parent is based.

A fourth failure is assuming that once one authority has been notified, the matter is closed for reporting purposes. Where sanctions, data protection and cyber security elements overlap in the same incident, each duty needs its own assessment, even where the same underlying facts are being described each time.

What to do next

Self-service work inside this window covers factual scoping, containment, documentation and the first provisional contact with the authority concerned. It stops being self-service work at the point the assessment turns into a judgement call about which regimes are actually engaged, how they interact, and what a fuller report should and should not concede. That is a legal assessment, not a documentation exercise, and it is where an outside review earns its place.

For entities that want to see what a Swedish supervisory process looks like once it has moved past the notification stage, how a supervisory inspection actually runs sets out the timeline and cost drivers for that later phase. Where the ten-day window is already running and the classification question is unresolved, the next step is to book an assessment call before the fuller report is drafted, not after.

Request a preliminary assessment