IMY (Sweden) - IMY-2024-1521

From GDPRhub
IMY - IMY-2024-1521
Authority: IMY (Sweden)
Jurisdiction: Sweden
Relevant Law: Article 4 GDPR
Article 6 GDPR
Article 9 GDPR
The Ship Safety Act (och fartygssäkerhetslagen - 2003:365)
The Swedish Maritime Code (säkerhetskrav som framgår i sjölagen - 1994:1004)
Type: Complaint
Outcome: Upheld
Started:
Decided: 18.06.2025
Published:
Fine: 75000 SEK
Parties: Data Subject versus Storstockholms Lokaltrafik (SL)
National Case Number/Name: IMY-2024-1521
European Case Law Identifier: n/a
Appeal: Unknown
Original Language(s): Swedish
Original Source: IMY (in SV)
Initial Contributor: Shravan

The DPA fined the Stockholm public transportation authority SEK 75,000 (about €6,700) for unlawfully processing ferry captains’ health data via alcohol tests, in breach of Articles 6 and 9 GDPR.

English Summary

Facts

Storstockholms Lokaltrafik (the controller) is the public transport authority in the Stockholm region. The controller engaged a subcontractor to operate commuter ferry services.

Between October 2021 and August 2022, ferry captains were required to perform breath alcohol tests prior to each departure. The tests were administered via alcohol meters installed on the vessels. While the results did not include names, they contained timestamps and vessel identifiers, which could be matched with duty rosters to identify crew members. The results were automatically stored both locally and on a server accessible to the controller and the subcontractor.

A data subject, who was employed as a ferry captain, submitted a complaint to the Swedish DPA (IMY). He caimed that the breath alcohol test results constituted sensitive health data and that the processing of such data was not allowed under Article 9 GDPR. The data subject also argued that no valid ground under Article 6 GDPR justified the collection and storage of the data, and that the routine and systematic storage of test results prior to each departure was disproportionate and not necessary to ensure transport safety. Finally, the data subject complained about the lack of a clear time limit for storing the data.

Storstockholms Lokaltrafik claimed that the processing was lawful under Article 6(1)(f) GDPR (legitimate interest), as well as Article 6(1)(e) and Article 9(2)(g) GDPR (public interest in the exercise of official authority). In support of its position, the controller cited provisions of national Swedish law, including the Swedish Maritime Code[1] and the Ship Safety Act[2]. The controller asserted that the processing was necessary to ensure public safety and to meet its maritime safety obligations under Swedish legislation

Holding

The Swedish DPA (IMY) held that the controller violated Article 6 GDPR and Article 9 GDPR by unlawfully processing the personal data and health data of ferry captains. On this basis, the DPA issued an administrative fine of SEK 75,000.

The breath alcohol test results, although not directly linked to names, constituted personal data within the meaning of Article 4(1) GDPR, as individual crew members could be indirectly identified using timestamps and work schedules.

Furthermore, the test results qualified as health data under Article 4(15) GDPR. In this regard, the DPA clarified that it did not matter that all of the data subject's test results were negative.

The controller could not rely on Article 6(1)(f) GDPR (legitimate interest), as the processing was not strictly necessary and disproportionately interfered with the rights of data subjects. In this regard, the DPA pointed out that less intrusive alternatives (e.g. non-recorded testing or alcohol locks) could have served the same purpose.

The controller also failed to meet the requirements of Article 6(1)(e) GDPR (public interest) in conjunction with Article 9(2)(g) GDPR. In this regard, the DPA found that Swedish law did not provide a sufficiently clear and specific legal basis for such such systematic data collection and retention.

Finally, the storage of test results for several months violated the principles of data minimisation and storage limitations under Articles 5(1)(c) and (e) GDPR. In particular, the controller only implemented a precise data retention policy in August 2022.

The DPA held that the breach was not severe, as it was limited to a single data subject, and no actual harm was identified. The DPA also considered that the controller implemented corrective measures, including implementing deletion routines and ending the storage of test results. For these reasons, the DPA imposed a fine of SEK 75,000 (about €6,7000)

Comment

The investigation also led to a SEK 75,000 against Waxholms Ångfartygs AB, the publicly owned company operating the ferry boats. The decision is available on the DPA's website and is very similar to the one against Storstockholms Lokaltrafik.

In recent years, IMY has begun issuing significantly higher fines—such as SEK 16 million on SL for unlawfully deploying body-worn cameras (Mål nr 1552-22) and SEK 12 million on Medhelp AB (DI-2019-3375) for insecure processing of health data. The SEK 75,000 fine in this case, while modest, continues that enforcement trend, particularly concerning the processing of special categories of data.

The decision underscores several GDPR principles. It affirms that indirectly identifiable data, such as timestamps combined with work schedules, can constitute personal data under Article 4(1) GDPR. It also classifies breath alcohol test results as health data, consistent with the DPA’s view that physiological readings fall under Article 4(15) GDPR. Importantly, it reiterates that public authorities cannot rely on general safety duties to bypass the specific legal requirements under Article 9 GDPR. While other national DPAs, such as the Polish UODO, have accepted limited workplace alcohol testing under narrow conditions, IMY’s position makes clear that routine testing programmes without explicit legal basis are unlikely to satisfy GDPR requirements. This decision aligns with a broader EU trend: workplace health monitoring must meet strict standards of necessity, proportionality, and legal certainty.

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Swedish original. Please refer to the Swedish original for more details.

1(16)

COMPLAINT
See attachment

OBJECT OF SUPERVISION
Aktiebolaget Storstockholms Lokaltrafik

Registration number:
IMY-2024-1521 Decision after supervision according to

Date: Data Protection Regulation –
2025-06-18
Aktiebolaget Storstockholms

Lokaltrafik

Decision of the Swedish Data Protection Authority

The Swedish Data Protection Authority finds that Aktiebolaget Storstockholms Lokaltrafik,

with corporate registration number 556013-0683, during the period October 2021–August 2022
has processed the complainant's personal data in violation of

1
• Article 6 of the Data Protection Regulation by processing the complainant's
personal data without a legal basis and
• Article 9 of the Data Protection Regulation by processing sensitive
personal data about the complainant without any of the exceptions from the prohibition on

processing such data being applicable.

IMY decides, based on Articles 58(2) and 83 of the Data Protection Regulation, that

Aktiebolaget Storstockholms Lokaltrafik shall pay an administrative penalty of
75,000 (seventy-five thousand) SEK for the violations.

Statement of the supervisory case

The Swedish Data Protection Authority (IMY) has initiated supervision against Aktiebolaget Storstockholms
Lokaltrafik (SL or the company) due to a complaint.

IMY is investigating whether the current processing of the complainant's personal data has
been supported by a legal basis in Article 6 of the Data Protection Regulation, whether the processing has
included sensitive personal data about the complainant pursuant to Article 9 of the Data Protection Regulation and, if so, whether any of the exceptions to the prohibition on processing
such sensitive data have been applicable.

Postal address:
Box 8114 Background
104 20 Stockholm

Website: IMY initiated supervision against the Stockholm Region Transport Administration due to
www.imy.se the complaint in January 2023 in case number IMY-2023-696. The case
E-mail:
imy@imy.se
1Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to
Telephone: the processing of personal data and on the free movement of such data, and repealing
08-657 61 00 Directive 95/46/EC (General Data Protection Regulation).

Page 1 of 16Integrity Protection Authority Case number: IMY-2024-1521 2(16)
Date: 2025-06-18

was closed due to the fact that the Stockholm Region Transport Authority was not deemed
to be the controller of personal data for the processing to which the complaint relates. IMY has added
relevant documents from the previous supervisory case to case IMY-2024-1521.

The complaint

The complainant has essentially stated the following. The complainant is a commander and employee of
a transport operator that carries out procured public transport on water for SL. The commanders of
the transport operator take a breath test in an alcohol meter before each ferry departure.
The result is registered and stored in a system. The system of alcohol testing of
employees with registration and storage of the results of the tests has not occurred
before. The transport operator has not been able to answer on what legal basis the processing of
sensitive data is based. The only stated purpose of alcohol testing is
to
ensure that the master is not under the influence of alcohol when operating the vessel, but
the transport operator cannot explain what the legal basis, purpose and interest of registering test results for
storage is. The probable reason why the transport operator
cannot clearly and distinctly answer the complainant's questions is that the transport operator
has not received sufficient information and supporting documents in its agreement with the Stockholm Regional Transport Administration. The transport operator shall report the results of the alcohol tests to SL.

The information on the breath test results is stored in the permanently installed alcohol meter on board the vessels for one year. The same information is transferred via digital
connection to a server that the transport operator and SL have access to. Since both the operator and SL can link the log information from the breathalyzer with the duty schedules, this means that it is a matter of personal data processing. According to law, the operator and SL must know who is on board and be recorded in the ship's logbook, which SL also has access to. The information in the ship's logbook is saved for three years. The master who is required to blow into the breathalyzer can therefore be linked to the breathalyzer that has been taken. Statements from SL SL's statements are presented in the relevant sections under the heading "Motivation of the decision". Below is a summary of what has mainly emerged regarding the personal data processing in question. The breathalyzer records information about the current breathalyzer connected to the ship, the time and result of the master's breathalyzer. Information about who a breathalyzer relates to is not recorded. The registered data is stored in the alcohol meter, the control box on board the ship and in SL's computer system for seven days according to current screening procedures. For results up to the legal limit, 0.2 per mille, only a green result is displayed. It is only when the result has passed the legal limit that a result expressed in per mille is visible and the breathalyzer shows red. Only a few authorized persons at the transport operator have been able to identify the master's breathalyzer result through access to the results from the alcohol meter as a ship's logbook. This has been necessary to achieve the purpose of using the alcohol meter, which was to prevent ships from operating under the influence of alcohol. When the breathalyzers were put into use in October 2021, screening procedures were lacking because SL did not consider that the results of the breathalyzers constituted personal data for the company. A proposal for a thinning decision was presented to the Regional Archives on 2 April 2022.
Thinning of all data in the system was carried out on 2 May 2022. A formal

thinning decision was approved by the Regional Archives on 3 October 2022. After the formal

Page 2 of 16Integrity Protection Authority Case number: IMY-2024-1521 3(16)
Date: 2025-06-18

thinning decision, automatic thinning shall take place after seven days from the breath test. A
storage period of seven days is necessary to ensure that the transport operator has time to follow up
and take action in the event of a possible positive result. It has not been deemed to be
any interest in keeping breath tests and logs for a longer period of time as

the data is of no significance in other respects. SL estimates that the complainant has
performed approximately two breath tests per working day. The data about the complainant is no longer
saved. Breathalyzer tests have been paused since August 26, 2022 due to IMY's supervision. SL wishes to resume the tests as soon as possible.

Statements from the complainant

The complainant has been given the opportunity to comment on SL's statements and has stated, among other things, the following. SL considers itself responsible for safety on board. The shipping company, in this case
the operator, together with the master, are responsible for safety and
the working environment on board. SL further refers to the alcohol and drug policy, which is
the industry standard regardless of whether SL is the principal or not. This policy includes
among other things zero tolerance for alcohol and drugs in the workplace, alcohol and
drug tests upon new employment, suspicion and accident and random tests. The complainant

questions whether SL has established, based on a proportionality assessment, that
these measures have not worked and whether SL has established problems with alcohol and
drugs among its contractor's personnel that justify further measures.

Reasoning for the decision

IMY shall initially examine whether the results from the breath tests have constituted
personal data about the complainant. If so, the IMY shall then decide whether SL

has been supported by Articles 6 and 9 of the Data Protection Regulation to process the complainant's
personal data in connection with the breath tests carried out during the period
October 2021–August 2022.

The processing covers personal data

Legal regulation
The concept of personal data is defined in Article 4(1) of the Data Protection Regulation as any
information relating to an identified or identifiable natural person, whereby an

identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, a
location data or online identifiers or to one or more factors specific to the
physical, physiological, genetic, mental,

economic, cultural or social identity of that natural person.

Recital 26 of the Data Protection Regulation states, among other things, the following. Personal data

that have been pseudonymised and which could be attributed to a natural person by the use of
supplementary information should be considered as data relating to an identifiable
natural person. In order to determine whether a natural person is identifiable, account should be taken of all
means, such as filtering, which, either by the controller or

by another person, could reasonably be used to directly or indirectly
identify the natural person. In order to determine whether means could reasonably be used to identify the natural person, all objective factors, such as the costs and time required for identification,
taking into account both the technology available at the time of the processing and the
technological development, should be taken into account.

Page 3 of 16Integrity Protection Authority Case number: IMY-2024-1521 4(16)

Date: 2025-06-18

According to case law, the term “personal data” should be given a broad meaning. The European Court of Justice

has ruled that information relates to an identifiable natural person when, by reason of
its content, purpose or effect, it is linked to an identifiable person. The European Court of Justice

has further stated that it is not necessary for the information itself to make it possible
to identify the natural person for the information to constitute personal data.
It follows from Article 4(1) in conjunction with recital 26 that personal data which, by

using supplementary information, could be attributed to a natural person are to be considered
as data relating to an identifiable natural person. It is not required that a single person

possesses all the information necessary to identify the data subject for
a piece of information to be considered to constitute personal data within the meaning of
Article 4(1) of
5
the Data Protection Regulation.

What SL has stated
SL's statements include the following. Information on who a breath sample

relates to is not recorded in the system. The system registers information about the current breathalyzer unit connected to the ship, the time and results of the breathalyzer test. Two employees of the transport operator have access to the results of the breathalyzer tests in the system. These authorized persons can in turn link the results of the breathalyzer test with who has been the master of the ship on which the breathalyzer test in question has been carried out. SL does not have access to this information. SL has decided that only personnel of the transport operator shall have access to the results of the breathalyzer test. Before the breathalyzer tests were introduced, SL assessed that the results did not constitute personal data for the company, since the company did not perceive that the means to identify which master had taken which breathalyzer test could reasonably or likely be accessed by SL. SL has had some opportunity to obtain access to data stored in the breathalyzer unit through measures taken by the supplier, but has primarily perceived that the opportunity was not within the scope of what is considered to constitute a reasonable measure. After dialogue with, among others, the captain regarding the breath tests
in the spring of 2022, SL made a renewed assessment of the issue, whereby the company considered that
the processing can probably be considered to constitute personal data processing for the company.

IMY's assessment
In light of the investigation into the matter, IMY assesses that the results of the breath tests
can be linked to the natural person who has performed the breath test through
supplementary information, which is available from the transport operator. According to IMY
it is sufficient that the results of the breath tests with the supplementary information in the ship's logbook can be linked to an identifiable natural person. The fact
6
that SL has not had direct access to the results of the breath tests or that no information has been registered about who has performed a breath test in the system where the results
have been stored is, according to IMY, irrelevant in this context. The results of the breath tests thus constitute personal data pursuant to Article 4(1) of the General Data Protection Regulation.

SL is the data controller

Legal regulation
According to Article 4(7) of the General Data Protection Regulation, a controller is a

natural or legal person, public authority, institution or other body which

2
See, for example, the judgment of the Court of Justice of the European Union in Österreichische Datenschutzbehörde, C-487/21, EU:C:2023:369, p. 23 and the case law
3cited therein.
Judgment of the Court of Justice of the European Union in Case C-487/21, p. 24.
4 Judgment of the Court of Justice of the European Union in Nacionalinis visiones sveikatos centras, C-683/21, EU:C:2023:949, p. 58.
5 Judgment of the Court of Justice of the European Union in IAB Europe, C-604/22, EU:C:2024:214, p. 40.
6Cf. recital 26 and the judgment of the Court of Justice of the European Union in case IAB Europe, C-604/22, p. 40.

Page 4 of 16Integrity Protection Authority Case number: IMY-2024-1521 5(16)
Date: 2025-06-18

alone or jointly with others determines the purposes and means of
the processing of personal data.

What SL has stated
SL has stated, among other things, the following. SL has determined the purposes of the current

personal data processing and decided how the processing will be carried out. SL has
decided on the installation of the meters on the ships. SL has decided on how the
results of the breath tests will be stored and on the storage period. SL has further decided that

only personnel at the transport operator shall have access to the results of the breath tests.

The transport operator is a personal data processor for SL in the part in which the transport operator handles

personal data on SL's behalf. SL has entered into a personal data processor agreement with
the transport operator.

IMY's assessment
IMY assesses that the investigation shows that SL has determined the purposes and means of the

current personal data processing. SL is therefore the personal data controller for it.

Legal basis for the processing of personal data

Article 6 of the General Data Protection Regulation states that the processing of personal data is only

lawful if at least one of the conditions in Article 6(1) is met. In other words, there must
be a legal basis for the processing of personal data.

SL has stated that the company has carried out a documented balancing of interests and
has concluded that the processing in question can be based on Article 6(1)(f) of the General Data Protection Regulation. SL has also stated that if IMY does not consider that a legal basis according to Article 6(1)(f) exists, the processing has been supported by the legal basis
of public interest according to Article 6(1)(e) of the General Data Protection Regulation.

Legal regulation

Article 6(1)(e) of the General Data Protection Regulation states that the processing of personal data is lawful
if it is necessary for the performance of a task carried out in the public interest or in the exercise of the authority of the
controller. According to Article 6(3) of the GDPR, the basis for the processing referred to in Article 6(1)(e) shall be determined in accordance with Union law or the national law of a Member State to which the controller is subject.

Article 6(1)(f) of the GDPR states that processing of personal data is lawful if it is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, unless the interests or fundamental rights and freedoms of the data subject are overridden and require the protection of personal data.

The provision thus lays down three cumulative conditions that must be met for the processing of personal data to be permissible. The first condition is that the interests which the processing is intended to protect must constitute legitimate interests of the controller or of a third party. The legitimate interest must be lawful, which means that it must not conflict with Union or national law.

Furthermore, the interest must be clearly and distinctly formulated and relate to a genuine interest that

7Cf. judgment of the Court of Justice of the European Union in M.I.C.M., C-597/19, EU:C:2021:492, p. 106 and EDPB guidelines Guidelines 1/2024 on
processing of personal data based on Article 6(1)(f) GDPR (version 1.0 adopted on 8 October 2024 for public
consultation), p. 6. Please note that the guidelines have not been finally adopted by the EDPB at the time of this decision.
8Cf. judgment of the Court of Justice of the European Union in Koninklijke Nederlandse Lawn Tennisbond, C-621/22, EU:C:2024:857, p. 49.

Page 5 of 16Integritetsskyddsmyndigheten Case number: IMY-2024-1521 6(16)

Date: 2025-06-18

exists at the time of the processing and is not hypothetical. If a

controller is acting not only in its own legitimate interest (e.g. its

business interest), but also in the interests of society as a whole, this interest will generally

weigh 10
more heavily than otherwise.

The second condition is that the processing is necessary for a purpose relating to

the legitimate interest. This means that the legitimate interest cannot reasonably be achieved in an equally effective manner by other means which infringe less on the fundamental rights and freedoms of the data subjects, in particular the right to privacy and the right to the protection of personal data under Articles 7 and 8 of the Charter of Fundamental Rights of the European Union (the EU Charter of Rights). It also follows from practice that the requirement of necessity must be examined in conjunction with the principle of data minimisation under Article 5(1)(c) of the GDPR, which requires that the personal data collected must be adequate, relevant 12 and not excessive in relation to the purposes for which they are processed. The third condition is that the fundamental rights and freedoms of the data subjects (the interest in privacy) do not outweigh the legitimate interest that the processing is intended to protect. The assessment must be made on the basis of the specific circumstances of the individual case. The controller shall, among other things, identify and take into account
the interests and rights and freedoms of the data subject, the impact of the processing on
the data subject and whether the data subject could reasonably expect the processing
for the purpose in question. 13

In accordance with the principle of accountability in Article 5(2) of the Data Protection Regulation,

the controller is responsible for and able to demonstrate that the rules in
the Data Protection Regulation are complied with, including that the processing is lawful.

What SL has stated
SL believes that the company has a legitimate interest in processing personal data in the

way that it does. The legitimate interest in the processing is to ensure
the safety of passengers in public transport. The Stockholm Region operates public transport
on water based on decisions on public service obligations and a number of traffic agreements. Public transport
on water is operated by SL and Waxholms Ångfartygs Aktiebolag (WÅAB). SL is

responsible for ensuring that public transport within the company's area of responsibility is operated in a safe
manner. SL's intention in sobriety testing captains has been to guarantee the safety

of passengers, employees and road users in public transport. SL has considered the
privacy concerns that this may entail for captains in connection with the performance of sobriety tests. SL has assessed that the interest in sober captains outweighs the
privacy concerns that may arise for the captains concerned. SL has assessed that it is
necessary to process personal data to achieve the purpose. It is not
possible to achieve the purpose without the personal data in question being processed. SL has carried out
a documented impact assessment with the result that the processing can take place.

The Stockholm Region Traffic Administration has established in its Traffic Safety Policy for Maritime Traffic

that vessels within the traffic administration shall be gradually equipped with reliable
alcohol interlocks and that uniform procedures shall be in place for how these shall be used. The

traffic administration's safety regulations SSA SÄB 0478 further state that all
vehicles, including ships, in public transport must have alcohol interlocks and that work is underway

9
10U Court judgment Asociaţia de Proprietari bloc M5A-ScaraA, C-708/18, EU:C:2019:1064, p. 44.
Judgment of the Court of Justice of the EU in case C-708/18, p. 44.
11 Judgment of the Court of Justice of the EU in case C-708/18, p. 47.
12 Judgment of the Court of Justice of the EU in case C-708/18, p. 48.
13 See EDPB Guidelines 1/2024, p. 32–34.

Page 6 of 16 Swedish Data Protection Authority Case number: IMY-2024-1521 7(16)
Date: 2025-06-18

introduction of alcohol interlocks for the fleet. SL's requirement that alcohol meters be used and
the requirement that masters carry out breath tests and store the results at
the transport operator means that the processing may be considered necessary.

SL has minimized the number of personal data processed to fulfill the purposes of
the processing. When employed by the transport operator, prospective personnel are informed of

zero tolerance regarding alcohol and drugs and employees have access to the current
alcohol and drug policy.

SL has taken and considered other measures to achieve the purpose of the processing.

None of the measures have been deemed to ensure the overall need for drivers
in public transport never to operate vessels under the influence of alcohol. SL sets out requirements regarding

maritime safety related to alcohol and drugs in public transport procurements.

The latest procurement requires that transport operators must have a defined policy
for preventive work against alcohol and drugs. Transport operators have an obligation to

exercise supervision and carry out checks to meet SL's requirements for safety and

security. The checks carried out are reported annually with the aim that SL, together with

the transport operator, can evaluate and take measures for safe maritime traffic. The operator shall carry out alcohol and drug tests on the personnel working with the operation of the vessels through so-called random tests twice a year. In addition to random checks, requirements are set for alcohol and drug tests in connection with accidents and incidents. It should be emphasized that the only way to ensure that a master of a vessel is sober when operating the vessel is to carry out a sobriety test immediately before the vessel's departure. It is not sufficient to use random sobriety tests and provide information about the applicable alcohol and drug policy in connection with employment. A theoretically different way to achieve the purpose of the processing would be to install alcohol locks on vessels. SL believes that processing in connection with such a mechanism would entail equivalent infringements of the privacy of the data subjects, since the necessary follow-up of why a certain vessel cannot be operated due to an alcohol lock at a certain time would give rise to a corresponding type of personal data processing.

When introducing sobriety tests, SL has found that previously implemented measures

do not ensure SL's needs. SL has not been able to identify any less privacy-infringing measures than those introduced in connection with the sobriety tests and in the way the results of the checks are handled. SL further believes that the company's legitimate

interest in carrying out the processing outweighs the interests of the data subjects.

With regard to the legal basis of public interest, SL has stated that the activities

that Region Stockholm, as a public transport authority, conducts constitute a public

interest. SL, which is responsible for public transport, has a statutory obligation to
operate public transport in a safe manner for both passengers and employees.

IMY's assessment of the legal basis balancing of interests

Legitimate interest

SL has stated that the company has a legitimate interest in processing the complainant's

personal data to ensure the safety of public transport and that ships are not
operated under the influence of alcohol. IMY finds that SL's interest in processing
personal data for the purpose of ensuring the safety of public transport is an important

public interest that constitutes a legitimate interest within the meaning of the Data Protection Regulation.

Page 7 of 16Integrity Protection Authority Case number: IMY-2024-1521 8(16)
Date: 2025-06-18

Necessity

IMY shall further examine whether the processing in question has been necessary to achieve

the purpose of the personal data processing.

In this part, SL has stated that the company has investigated other appropriate and less

privacy-sensitive measures to achieve the purpose of the processing and that the company has not
been able to identify any less privacy-intrusive measures to achieve the purpose
of the current processing. SL has identified the installation of alcohol locks in ships as

a theoretical alternative way to achieve the purpose of the processing. However, SL has assessed that
necessary follow-up of why a certain ship cannot be operated due to alcohol locks
at a certain time is to be considered a corresponding type of personal data processing

as the processing to which the complaint applies.

The necessity requirement shall, as mentioned, be tested together with the principle of

data minimization. IMY notes that from the time the breath tests were introduced in
October 2021 until they were stopped in August 2022, SL has lacked formal screening procedures for
these. This has meant that the complainant's test results, from the average of two breath tests per shift that he carried out during the period, have been registered and stored in SL's system for a long time of several months. SL has stated that a longer storage period than seven days has not been justified either for follow-up of the results or for any other reasons. IMY believes that it can thus be considered clear that the purpose of safe public transport and preventing ships from being operated under the influence of alcohol has been achieved without such extensive processing of the complainant's personal data as carried out during the period. Against this background, IMY assesses, also taking into account that at one point during the period, a thinning of all data in the system has been carried out, that the processing has not been necessary to achieve the legitimate interest. Furthermore, SL has identified alcohol interlocks as an alternative way of achieving the purpose of the processing. IMY does not share SL's assessment that the personal data processing

that the use of an alcolock would entail, as described by the company, would

entail an equivalent infringement of the complainant's privacy in relation to that which

was carried out. IMY believes that personal data processing in the form of an investigation when necessary and

only when an alcolock has prevented the movement of a vessel would restrict the complainant's
privacy protection to a lesser extent compared to the current processing of
personal data, where each breath test result, regardless of the result, has been registered

and, during the period covered by the supervision, stored for an indefinite period of time, in any case for several
months. IMY therefore considers that even taking this circumstance into account

it can be concluded that the current processing could have been achieved with less

intrusive measures.

In summary, IMY assesses that the processing of the complainant's personal data

has not been necessary to achieve SL's legitimate interest and that all conditions
for the processing to be based on Article 6(1)(f) are not met.
The processing of the complainant's personal data has therefore not been supported by the legal

basis of balancing of interests.

IMY's assessment of the legal basis of public interest

IMY has assessed that SL has not been able to support the processing of the complainant's personal data on Article 6(1)(f) of the Data Protection Regulation because it has not been
necessary to achieve the purpose of the processing. IMY notes that in order for a

processing to be able to be supported by Article 6(1)(e) of the Data Protection Regulation, it is required that

the processing is necessary taking into account an important public interest arising from

Union or national law. The provision thus contains a requirement for
the same necessity as in Article 6(1)(f) of the Regulation. IMY has assessed that the processing of

the complainant's personal data has not been necessary to achieve the purpose of safe
public transport since the processing could have been achieved in an equally effective manner through
less intrusive personal data processing. Given that the requirement of

necessity has not been met, the processing of the complainant's personal data
could not therefore be carried out on the basis of the legal basis of public interest.

IMY concludes in summary that SL has not had a legal basis for the processing
of the complainant's personal data in connection with breath tests carried out during

the period October 2021–August 2022. SL has thus processed the complainant's
personal data in violation of Article 6 of the Data Protection Regulation.

Processing of sensitive data

Legal regulation
Health data constitute special categories of personal data, so-called
sensitive personal data, which are given particularly strong protection under the Data Protection

Regulation. It is generally prohibited to process such personal data
under Article 9(1) of the Data Protection Regulation, unless the processing falls under one of the
exceptions in Article 9(2) of the Regulation.

It follows from Article 9(2)(g) that the prohibition on processing sensitive personal data does not apply

where the processing is necessary for reasons of important public interest, on the basis of
Union law or the national law of the Member States, which shall be proportionate to

the purpose pursued, be compatible with the essence of the right to data protection
and provide for suitable and specific measures to safeguard the fundamental rights and interests of
the data subject.

According to practice, the concept of sensitive personal data is to be interpreted broadly and also includes
data that indirectly reveal such information. 14

Data concerning health are defined in Article 4(15) of the Data Protection Regulation as personal

data relating to the physical or mental health of a natural person which provide information
about his or her health status. Recital 35 of the GDPR states that personal data concerning health should include all data relating to the health of a data subject which provide information on the past, present or future physical or mental state of the data subject, including, inter alia, data resulting from tests or examinations of a body part or substance.

It follows from the wording of Article 4(15) of the GDPR, as specified in recital 35 of the GDPR, that the decisive factor in determining whether certain personal data constitute data concerning health is whether it is possible to draw conclusions from the data in question concerning the health of the data subject. 15

The European Data Protection Board (EDPB) has stated in its Guidelines on Automated Individual Decision-Making and Profiling that profiling can create sensitive personal data by drawing conclusions from and combining non-sensitive data. According to the EDPB, it may be possible, for example, to draw a conclusion about someone’s

14CJEU judgments Lindqvist, C-101/01, EU:C:2003:596, p. 50, Vyriausioji tarnybinės etikos komisija, C-184/20,
EU:C:2022:601, p. 125–127 and Lindenapotheke, C-21/23, EU:C:2024:846, p. 84, 89–91 and 94.
15See Opinion of the Advocate General in CJEU case NADA C-115/22, EU:C_2023:676, p. 97.

Page 9 of 16Privacy Protection Authority Case number: IMY-2024-1521 10(16)
Date: 2025-06-18

health status from information about their food purchases together with information about the food
quality and energy content.16

What SL has stated

The possible processing of sensitive personal data is supported by Article 9.2 g of
the Data Protection Regulation. SL has assessed that it has been necessary to process
personal data in order to achieve safe public transport. SL performs work where people
lives may be in direct danger if captains on board are under the influence of alcohol in connection with
work on the ships. Traffic safety constitutes an important public interest and requires SL
to sobriety test captains in order to ensure safe public transport for staff, passengers and

fellow passengers. In a combined assessment of the
safety requirements set out in the Maritime Act (1994:1004) and the Ship Safety Act
(2003:365), SL has found that the processing is necessary. SL has considered that the sobriety tests are a mandatory measure to ensure safety on board and the obligations arising from the law. The method used in the tests has been carefully considered and deemed to be the least privacy-infringing for the purpose.

SL has further stated that no positive result has ever been found when performing sobriety tests. SL cannot therefore be considered to have processed sensitive personal data.

The lack of a positive result cannot be considered to constitute processing of sensitive personal data about health. Furthermore, the technical equipment used to carry out sobriety tests is designed in such a way that the blood alcohol level is only
displayed when the result has exceeded the legal limit. The result is only stored for seven
days, which means that it is not possible to notice any patterns or

risk behaviors over time that could in some cases entail the processing of sensitive personal data. SL is therefore of the opinion that sensitive personal data
has neither actually been, nor potentially could be, processed through the sobriety test system that SL has introduced.

IMY's assessment

It is clear from the investigation into the case that data from all breath tests carried out by the
complainant have been stored during the period October 2021–May 2022 and were deleted in May
2022. IMY further notes that it is clear that the processing has continued thereafter and

that, although SL in April 2022 submitted a proposal for a decision on deletion after seven
days, there was no formal decision that enabled the deletion of the data also

during the period May 2022–August 2022. It is thus a matter of extensive and
regular processing of data on the results of the complainant's breath tests over
a longer period of time. No positive results regarding the complainant have been registered.

In assessing whether the processing has included sensitive personal data, IMY
takes into account in particular that the concept of “health data” should be interpreted broadly and that it is possible

to create sensitive data by collecting non-sensitive data. It is also taken into account that health data can have different degrees of sensitivity. However, the sensitivity of a particular
piece of data is not of importance for whether a piece of data constitutes health data within the meaning of

the Data Protection Regulation. It can also be stated that even data that
makes it possible to conclude that someone does not suffer from a certain medical condition can
be data about that person’s health.

The current case concerns the processing of a large amount of personal data in the form of results from breath alcohol tests over a period of several months. In light of

the scope of the processing in the individual case, IMY assesses that, based on the

16Guidelines on automated individual decision-making and profiling under Regulation (EU) 2016/679
WP251rev.01, p.16.

Page 10 of 16Integrity Protection Authority Case number: IMY-2024-1521 11(16)
Date: 2025-06-18

collected data, it has been possible to draw conclusions about the complainant's

health status. SL has thus processed data about the complainant's health in the
sense referred to in Article 4(15) of the Data Protection Regulation.

In order for the processing of sensitive personal data about health to be lawful, it must
be covered by one of the exceptions in Article 9(2) of the Data Protection Regulation. SL has

stated that the processing in question was supported by Article 9(2)(g).

IMY notes that a prerequisite for the processing of sensitive personal data to be

lawful under any of the points in Article 9(2) is that the processing is supported by a
legal basis. Since IMY has assessed above that SL lacked a legal basis for

the processing, it can already be concluded for that reason that the processing is not
permitted under Article 9 of the Data Protection Regulation either.

Furthermore, IMY has assessed that SL has not been able to support the processing of the complainant's
personal data on Article 6(1)(f) of the Data Protection Regulation because it was not

necessary to achieve the purpose of the processing. IMY notes that the exception in

Article 9(2)(g) applies to processing that is necessary for an important
public interest arising from Union or national law. This

provision also contains a requirement of necessity equivalent to that in

Article 6(1)(f). Since IMY has assessed that this requirement is not met in relation to the public interest in safe public transport invoked by

SL, the processing of sensitive

personal data could not be based on Article 9(2)(g) of the Data Protection Regulation.

In summary, IMY assesses that SL lacked support in any of the exceptions in Article

9(2) from the prohibition on processing sensitive personal data. SL has thus processed

the complainant's personal data in violation of Article 9 of the Data Protection Regulation.

Choice of intervention

Legal regulation
In the event of violations of the Data Protection Regulation, IMY has a number of corrective

powers available to it under the Data Protection Regulation. Article 58(2) of the GDPR provides that the IMY shall, in accordance with Article 83, impose administrative fines in addition to or instead of other corrective measures referred to in Article 58(2), depending on the circumstances of each case. Each supervisory authority shall ensure that the imposition of administrative fines is effective, proportionate and dissuasive in each case. This is stated in Article 83(1) of the GDPR. Article 83(2) sets out the factors to be taken into account in determining whether an administrative fine should be imposed, as well as the factors that should influence the amount of the fine. The nature, severity and duration of the infringement are relevant for the assessment of the seriousness of the infringement. The EDPB has adopted guidelines on the calculation of administrative fines under the GDPR, which aim to create a harmonised methodology and principles for calculating fines. 18

According to Article 83(5), infringements of, among others, Articles 6 and 9 shall be subject to
administrative fines of up to EUR 20,000,000 or, in the case of an

17CJEU judgment of 21 December 2023, Krankenversicherung Nordrhein, case C-667/21, p. 79.
18Guidelines 04/2022 on the calculation of administrative fines under the GDPR.

Page 11 of 16Integrity Protection Authority Case number: IMY-2024-1521 12(16)
Date: 2025-06-18

4 percent of the total worldwide annual turnover in the preceding
financial year, whichever is the higher.

Article 83(3) states that if a controller infringes several of the provisions of the Regulation in relation to the same or connected processing operations, the administrative fine shall not exceed the amount set for the most serious infringement.

If the infringement is minor, the IMY may, as stated in recital 148, issue a reprimand in accordance with Article 58(2)(b) of the Regulation instead of imposing a fine.

What SL has stated
SL has stated that in the event that the IMY considers that the company has processed personal data without legal basis, a reprimand should be imposed in the first place instead of a fine.

SL's sole purpose with the sobriety tests is to ensure the safety of passengers and employees in public transport. SL has taken far-reaching measures to ensure that

the invasion of privacy for the data subject is as minimal as possible. SL has limited
the number of people who have been subject to sobriety tests and has minimized the storage time,
the number of data stored and people who have had the opportunity to read the results
in order to be able to take action in the event of a positive result. In addition, there has been continuous dialogue
between the transport operator and SL to ensure that sobriety tests are carried out in an
appropriate manner. As a result of the dialogue, SL has on several occasions paused
the use of sobriety tests to address and investigate issues that have arisen
during the time. No sensitive personal data has actually or potentially been
processed. Nor has there been any security incident that posed risks to
the complainant. A sanction fee would, taking into account the situation as a whole and the
circumstances presented by SL, entail a disproportionate measure that is
counterproductive. A reprimand with an order on how the processing should be adjusted in
to make it legal appears to be more appropriate.
If IMY decides to impose a penalty fee, it must be taken into account that the processing has been
proportionate and necessary in relation to the purpose of the processing. The equipment
used when performing sobriety tests has, after investigation, been deemed to be the
least infringing on privacy for the established purpose. The sobriety tests have been
interrupted on several occasions for technical reasons and to investigate views.
The actual time for using sobriety tests has therefore been very limited and
the number of tests performed has thus been relatively few. Since IMY decided to
initiate supervision, SL has cooperated and provided information upon request. SL has also been
careful to submit corrections in the event that incorrect information has been provided.

SL is 100 percent owned by the Stockholm Region. The region exercises active ownership in SL

and has significant legal influence in decision-making over how the company shall conduct
its operations and fulfil the authority's mission. SL is thus a publicly owned
company where the majority is financed with tax-financed funds and the company should therefore

not be imposed a higher sanction fee than what can be imposed on an authority. SL is
a limited liability company but, in light of the current structure, should be essentially equated with an
authority when fulfilling the Stockholm Region's mission as a public transport

authority. Any sanction fee should be significantly lower than for a
commercial company with a profit objective and should only be assessed based on the circumstances of
the case in question. It should also be noted that the provision of public transport on

water constitutes a small part of SL's overall operations. SL further notes that
the processing of previous supervisory matters and current supervision has been ongoing for just over two years.

IMY's assessment

A penalty fee shall be imposed

IMY has found that SL has processed the complainant's personal data in violation of Articles 6
and 9 of the Data Protection Regulation. This means that SL, even taking into account that

the processing has been periodically paused, has collected and stored sensitive
personal data about the complainant in his capacity as an employee for a long time without legal support. Against this background, IMY considers that these are not such minor

violations that could result in a reprimand being issued instead of a
penalty fee.

The EU Court of Justice has clarified that it is required that the data controller has committed an
infringement intentionally or negligently in order for administrative penalty fees

to be imposed under the Data Protection Regulation. The EU Court of Justice has stated in this regard that
data controllers can be imposed penalty fees for actions if they cannot

be considered to have been unaware that the action constituted an infringement, regardless of whether they
were aware that they were infringing the provisions of the Data Protection Regulation. 19

SL is, in its capacity as data controller, responsible for the personal data processing that
takes place within the company and for it to be carried out in accordance with the applicable regulations. SL has

processed the complainant's personal data in violation of the Data Protection Regulation by
processing the personal data without a legal basis in Article 6 and without any of

the exceptions to the prohibition on processing sensitive personal data in Article 9 having
been applicable. IMY considers that the company cannot be considered to have been unaware that the action
entailed a violation of the Regulation. Against this background, IMY considers that the company

has been negligent in relation to the violations of the Data Protection Regulation that
have been established. There are therefore grounds for imposing an administrative

penalty on the company.

Basis for calculating the penalty

The maximum penalty that applies to companies in case of violations of Articles 6

and 9 is the higher of EUR 20,000,000 and 4 percent of
the total global annual turnover in the previous financial year. There is no support for
instead applying the lower maximum amounts for penalty fees that apply to
authorities according to Chapter 6, Section 2, second paragraph of the Act (2018:218) with supplementary
provisions to the EU Data Protection Regulation, since SL is not an authority but a
20
private law body.

When determining the maximum amount of a penalty fee to be imposed on an undertaking,
the definition of the term undertaking used by the Court of Justice of the European Union in
the application of Articles 101 and 102 of the TFEU shall be used. The calculation of the maximum amount for

a controller constituting such an undertaking or forming part of such an undertaking
shall be based on a percentage of the total global

turnover of the undertaking concerned

19CJEU judgments Nacionalinis visuemines sveikatos centras, C-683/21, paragraph 81 and Deutsche Wohnen, C-
807/21, p. 76.
20It is the terminology of the instrument of government that is the starting point for interpreting the concept of authority under
the Data Protection Regulation. According to this terminology, bodies organised in private law forms, such as
state and municipal companies, do not constitute authorities, even if they exercise public authority. See Bill No. 2017/18:105, p. 46 and
139.

Page 13 of 16Integrity Protection Authority Case number: IMY-2024-1521 14(16)
Date: 2025-06-18

21
the annual turnover in the previous financial year. The concept of undertaking shall also
be taken into account in order to assess the actual or material economic capacity of the
person on whom the penalty payment is imposed and thereby to verify whether the penalty payment
is effective, proportionate and dissuasive. 22

It is clear from the case-law of the Court that the concept covers any entity that carries out
an economic activity, regardless of the legal form of the entity and the way in which it is financed

and even if the entity in legal terms consists of several natural or legal persons.
Different companies within the same group can thus form an economic unit and thus an undertaking within the meaning of Articles 101 and 102 TFEU. 23

A parent company and a subsidiary are considered to be part of the same economic unit when the parent company exercises a decisive influence over the subsidiary. The decisive influence (i.e. control) can be achieved either through ownership or by agreement. It is clear from case-law that a 100% or almost 100% ownership gives rise to a presumption that control is to be considered to exist (the so-called Akzo principle). However, the presumption can be rebutted if the company provides sufficient
24
evidence to prove that the subsidiary acts independently on the market.

SL is the parent company of a group in which SL is the sole owner of the companies SL Nya
Tunnelbanan AB, AB SL Finans and WÅAB. Against this background, IMY assesses that

the SL Group, in accordance with the Akzo principle, which is not considered to have been refuted, is
an economic entity that constitutes an undertaking within the meaning of the provisions of

the TFEU.

When determining the maximum amount of the penalty, IMY will base the assessment on SL's annual and
consolidated accounts for 2023 (since the annual accounts for 2024 have not been adopted at

the time of the decision). IMY assesses that it is the SL Group's annual turnover for

2023 of SEK 24,512,000,000 that should be used as the basis for calculating

the penalty. This means that the maximum amount that can be determined in the case
is SEK 980,480,000, which corresponds to four percent of the annual turnover.

The seriousness of the infringements

The EDPB guidelines state that the supervisory authority shall assess whether the infringements
are of low, medium or high seriousness in accordance with Article 83(2)(a), (b) and (g) of the GDPR.

26

The processing to which the infringements relate has been extensive, taking into account that it has been carried out over a long period of a total of just over 9 months and that the complainant has been tested

approximately twice per work shift. The processing has also included sensitive
personal data about the complainant collected in the context of his employment, a

situation where he was in a position of dependence in relation to his employer.

In assessing the seriousness, IMY also attaches great importance to
that the processing was carried out for the purpose of maintaining safety in public transport and that the supervision

only covers the processing of personal data of an individual complainant. Furthermore,
the complainant has not been directly identifiable and as a result of measures taken by SL,

21See recital 150 of the Data Protection Regulation and the judgment of the Court of Justice of the EU in Deutsche Wohnen, C-807/21, p. 57.
22See the judgment of the Court of Justice of the EU in ILVA, C-383/23, EU:C:2025:84, p. 36.
23The judgment of the Court of Justice of the EU in Akzo Nobel, C-516/15 P, EU:C:2017:314, p. 48.
24
25CJEU judgment Akzo Nobel and Others, C-97/08, EU:C:2009:536, p. 59–61
EDPB Guidelines 04/2022 on the calculation of administrative fines under the GDPR, paragraph 130 and
26CJEU judgment Groupe Gascogne SA v European Commission, C-58/12P,ECLI:EU:C:2013:770, paragraphs 54–56.
EDPB Guidelines 04/2022, p. 60.

Page 14 of 16Integrity Protection Authority Case number: IMY-2024-1521 15(16)
Date: 2025-06-18

only a few persons had access to all the information required to identify
the complainant.

In light of the above circumstances, IMY assesses that these are all violations of Articles 6 and 9 of the General Data Protection Regulation of low

seriousness.

In its assessment of the size of the penalty fee, IMY shall also take into account such aggravating and mitigating factors as listed in Article 83(2) of the General Data Protection Regulation. SL has now taken measures to limit the storage period and has

also highlighted that the company has paused the alcohol tests on several occasions to address and
investigate issues that have arisen during the processing. IMY does not believe that the measures taken

go beyond what is expected of the company in the current case and that they
therefore do not constitute factors that should affect the assessment of the size of the penalty fee in a mitigating direction. IMY further notes that SL has had an obligation to

cooperate with IMY within the framework of supervision and this is a circumstance that
should be considered neutral when determining the penalty fee. IMY assesses that

there have been no other aggravating or mitigating circumstances, in addition to
those taken into account when assessing the seriousness, that affect

the size of the penalty fee. In light of the complexity of the case, IMY assesses that

the length of time the case is being processed should not lead to a lower penalty fee.28

The administrative penalty fee shall be effective, proportionate and
dissuasive. This means that the amount shall be determined so that the administrative

penalty fee leads to correction, that it has a preventive effect and that it
is also proportionate in relation to both the current violation and the ability to pay of the supervised entity.

IMY decides based on an overall assessment that SL shall pay an administrative

sanction fee of SEK 75,000. IMY considers that this amount is effective, proportionate
and dissuasive.

__________________________

This decision has been made by the Head of Unit Nidia Nordenström after a presentation by
the Departmental Lawyer Maja Welander.

Nidia Nordenström

Appendices

1. The complainant's personal data
2. Information on how to pay a sanction fee

Copy to
the Data Protection Officer

27EDPB guidelines 04/2022, p. 95–98.
28The Stockholm Administrative Court has in two complicated supervisory cases assessed that there was no reason to reduce
the sanction fee due to the processing time of the cases, which amounted to two years and seven months and three years respectively.
See the Stockholm Administrative Court judgments of 26 January 2023 in case no. 1552-22 and 11 March 2024 in case no. 2829-23.

Page 15 of 16Integrity Protection Agency Case number: IMY-2024-1521 16(16)
Date: 2025-06-18

How to appeal

If you wish to appeal the decision, you should write to IMY. Indicate in the letter which decision you are
appealing and the change you are requesting. The appeal must have been received by IMY

within three weeks from the day you received the decision. If you are a party representing
the public, however, the appeal must have been received within three weeks from the day the
decision was announced. If the appeal has been received in good time, IMY will forward it
to the Stockholm Administrative Court for review.

You can email the appeal to IMY if it does not contain any privacy-sensitive personal data or information that may be subject to confidentiality. The authority's

contact details are provided on the first page of the decision.

Page 16 of 16
  1. Säkerhetskrav som framgår i sjölagen - 1994:1004.
  2. Och fartygssäkerhetslagen - 2003:365.