GDPR — The Data Protection Regulation that Protects Personal Privacy
Personal privacy deserves protection in society. That is the background to the data protection regulation that has applied throughout the EU since 2018.
The regulation is known as the General Data Protection Regulation (GDPR). In Sweden, it replaced the Personal Data Act (Personuppgiftslagen). The regulation governs how personal data may be processed, that is, collected, handled and stored. Its purpose is to protect the personal data and privacy of all EU citizens. The EU also wants to make it easier for companies and organisations to operate across multiple EU countries.
It is important to meet the requirements of the GDPR, not least to avoid the risk of fines. Every organisation that processes personal data bears responsibility for doing so correctly. In Sweden, the Swedish Authority for Privacy Protection (IMY) is responsible for supervision and reviews whether the rules are being applied correctly. IMY is also tasked with providing guidance and support on GDPR-related matters.
What is personal data?
Personal data is any information that can be linked to a living person. A person's name is personal data, but so are a photograph or an audio recording (even if the name is not mentioned).
It is important to classify the personal data being processed, since different classes require different levels of protection. The GDPR defines three classes, but in Sweden there is also a fourth for national identity numbers (personnummer).
- Sensitive personal data, for example ethnic origin, health, trade union membership and sexual orientation. Processing sensitive personal data is, in principle, prohibited unless there are specific grounds for doing so. In such cases, it must be given extra protection.
- Privacy-sensitive personal data, for example salary information, criminal offenses and social circumstances. This data may only be processed where there is a legal basis or consent. Here too, an enhanced level of protection must be applied.
- National identity numbers (personnummer), the general rule is that the data subject must give their consent for their national identity number to be processed.
- Non-sensitive personal data, for example name, address, employer and email address.
Fundamental principles
There is a great deal to keep track of when an organisation needs to ensure that its processing of personal data meets the requirements of the GDPR. To begin with, the seven fundamental principles must be complied with.
- There must be support under one of the legal bases, described below.
- There must be a clear purpose for processing the personal data.
- Data minimisation means that only necessary data should be collected.
- Personal data that proves to be inaccurate must be corrected or deleted.
- Personal data must be erased as soon as it is no longer needed.
- There must be adequate technical and organizational protection in place to prevent unauthorised access.
- In addition to complying with these fundamental principles, an organisation must also document HOW it complies with them.
Roles and responsibilities under the GDPR
The GDPR describes three roles and their respective areas of responsibility. The first role, the Data Controller, is always relevant. The other two roles, the Data Processor and the Data Protection Officer, are relevant in certain cases. These roles are described below.
- Data Controller, the party that intends to process personal data for a specific purpose. This can be a natural or legal person. Within a company, it is never an individual employee or the CEO who bears the responsibility, but the company as a legal entity.
- Data Processor, the data controller may appoint a data processor to carry out the processing of personal data on the controller's behalf. The parties must enter into a data processing agreement setting out how the processor is permitted to process the personal data.
- Data Protection Officer, an expanded role compared with the "personal data representative" under the previous Swedish law (PUL). Appointing a Data Protection Officer is not mandatory, but should be seen as a mark of quality. The role includes advising the organisation on matters relating to the processing of personal data and acting as the point of contact with IMY.
Legal basis — the purpose that makes it lawful to process personal data
One of the fundamental principles of the GDPR, described above, is that there must be a purpose for processing personal data in order for the processing to be lawful. This purpose is known as the legal basis.
There are six legal bases on which personal data processing can rest:
- Consent, obtained from the data subject.
- Performance of a contract, a contract entered into between the data subject and the data controller.
- Legitimate interest, meaning that the data controller weighs the interest in processing the data against the data subject's interest in personal privacy — a balancing of interests.
- Legal obligation, sometimes personal data must be processed in order to comply with laws and regulations.
- Exercise of official authority and tasks carried out in the public interest, government and municipal bodies may process personal data on the basis of EU or Swedish law. Private actors may also rely on this legal basis, for example a private school.
- Protection of vital interests, can only be relied on when the data subject is unconscious and it is a matter of saving a life.
Data subjects have eight rights
The GDPR gives data subjects enhanced protection whenever their personal data is processed. Data subjects have eight rights that the data controller must respect.
- Right to information, the data subject has the right to know when personal data is being collected, and, on request, to receive an extract of what personal data is stored.
- Right of access, the data controller must, no later than one month after a request from a data subject, disclose what personal data about the data subject is being processed, along with information on where the data came from, the purpose of the processing, and to whom it is disclosed.
- Right to rectification, the data subject has the right to have inaccurate data corrected or completed.
- Right to erasure, under certain conditions the data subject has the right to have their data erased, for example if the legal basis was consent and the data subject wishes to withdraw that consent. There are also cases where erasure cannot be carried out due to legal requirements.
- Right to restriction of processing, under certain circumstances the data subject can request that processing of their personal data be restricted. This may apply, for example, if the data subject has pointed out that the data is inaccurate, meaning processing must be restricted until it has been corrected.
- Data portability, the data subject has the right to obtain their personal data if it is the data subject themselves who provided it, for example on a social media service.
- Right to object, this right applies to personal data processed on the basis of legitimate interest, exercise of official authority, or tasks carried out in the public interest. If the data subject objects, the data controller must demonstrate grounds that override the data subject's interests.
- Automated decision-making and profiling, the data subject has the right to be informed when automated decision-making is used, for example if a credit application is submitted and the response is generated automatically without human involvement. Profiling means the automated collection of personal data to assess personal characteristics.
Obligations of the data controller
The data controller must have a legal basis and follow the fundamental principles when processing personal data. There are also several additional obligations.
- It is important to have sound procedures for verifying the identity of a data subject who requests access to their data, to ensure that it is disclosed to the correct person. However, this identity verification must not involve collecting additional unnecessary personal data.
- It must be easy for data subjects to check their personal data, and the data controller may only refuse a request if the data subject cannot be identified. The reason for any refusal must be recorded.
- A data subject may lodge a complaint with IMY if they believe their personal data is being processed in breach of the GDPR. In certain cases, the data controller may be liable for damages if IMY finds that the processing has not complied with the GDPR.
- If a personal data breach occurs, it must in certain cases be reported to IMY. A personal data breach means that the personal data of one or more data subjects has ended up in the wrong hands, been lost, or been destroyed, which may result in a violation of the data subject's rights and freedoms or cause them financial harm.
Special protection when processing children's personal data
The GDPR states that children deserve special protection in an increasingly digitalised world, as they are less aware of the risks of disclosing personal data. This, combined with the fact that the UN Convention on the Rights of the Child has been Swedish law since 1 January 2020, means that children now have stronger legal protection.
The most common legal basis for collecting children's personal data is consent. In Sweden, the age limit for giving consent is 13. The GDPR sets the age at 16, but each member state may decide to lower it. For children younger than 13, consent should be given by a guardian.
The most common situations in which children's personal data is collected are:
- Social media
- Logs
- Internet forums
- Video-sharing platforms
- Chat applications
- Online games
- Apps with games or other content
- Connected toys.