IMY (Sweden) - IMY-2024-1521
| IMY - IMY-2024-1521 | |
|---|---|
| Authority: | IMY (Sweden) |
| Jurisdiction: | Sweden |
| Relevant Law: | Article 4 GDPR Article 6 GDPR Article 9 GDPR The Ship Safety Act (och fartygssäkerhetslagen - 2003:365) The Swedish Maritime Code (säkerhetskrav som framgår i sjölagen - 1994:1004) |
| Type: | Complaint |
| Outcome: | Upheld |
| Started: | |
| Decided: | 18.06.2025 |
| Published: | |
| Fine: | 75000 SEK |
| Parties: | Data Subject versus Storstockholms Lokaltrafik (SL) |
| National Case Number/Name: | IMY-2024-1521 |
| European Case Law Identifier: | n/a |
| Appeal: | Unknown |
| Original Language(s): | Swedish |
| Original Source: | IMY (in SV) |
| Initial Contributor: | Shravan |
The DPA fined the Stockholm public transportation authority SEK 75,000 (about €6,700) for unlawfully processing ferry captains’ health data via alcohol tests, in breach of Articles 6 and 9 GDPR.
English Summary
Facts
Storstockholms Lokaltrafik (the controller) is the public transport authority in the Stockholm region. The controller engaged a subcontractor to operate commuter ferry services.
Between October 2021 and August 2022, ferry captains were required to perform breath alcohol tests prior to each departure. The tests were administered via alcohol meters installed on the vessels. While the results did not include names, they contained timestamps and vessel identifiers, which could be matched with duty rosters to identify crew members. The results were automatically stored both locally and on a server accessible to the controller and the subcontractor.
A data subject, who was employed as a ferry captain, submitted a complaint to the Swedish DPA (IMY). He caimed that the breath alcohol test results constituted sensitive health data and that the processing of such data was not allowed under Article 9 GDPR. The data subject also argued that no valid ground under Article 6 GDPR justified the collection and storage of the data, and that the routine and systematic storage of test results prior to each departure was disproportionate and not necessary to ensure transport safety. Finally, the data subject complained about the lack of a clear time limit for storing the data.
Storstockholms Lokaltrafik claimed that the processing was lawful under Article 6(1)(f) GDPR (legitimate interest), as well as Article 6(1)(e) and Article 9(2)(g) GDPR (public interest in the exercise of official authority). In support of its position, the controller cited provisions of national Swedish law, including the Swedish Maritime Code[1] and the Ship Safety Act[2]. The controller asserted that the processing was necessary to ensure public safety and to meet its maritime safety obligations under Swedish legislation
Holding
The Swedish DPA (IMY) held that the controller violated Article 6 GDPR and Article 9 GDPR by unlawfully processing the personal data and health data of ferry captains. On this basis, the DPA issued an administrative fine of SEK 75,000.
The breath alcohol test results, although not directly linked to names, constituted personal data within the meaning of Article 4(1) GDPR, as individual crew members could be indirectly identified using timestamps and work schedules.
Furthermore, the test results qualified as health data under Article 4(15) GDPR. In this regard, the DPA clarified that it did not matter that all of the data subject's test results were negative.
The controller could not rely on Article 6(1)(f) GDPR (legitimate interest), as the processing was not strictly necessary and disproportionately interfered with the rights of data subjects. In this regard, the DPA pointed out that less intrusive alternatives (e.g. non-recorded testing or alcohol locks) could have served the same purpose.
The controller also failed to meet the requirements of Article 6(1)(e) GDPR (public interest) in conjunction with Article 9(2)(g) GDPR. In this regard, the DPA found that Swedish law did not provide a sufficiently clear and specific legal basis for such such systematic data collection and retention.
Finally, the storage of test results for several months violated the principles of data minimisation and storage limitations under Articles 5(1)(c) and (e) GDPR. In particular, the controller only implemented a precise data retention policy in August 2022.
The DPA held that the breach was not severe, as it was limited to a single data subject, and no actual harm was identified. The DPA also considered that the controller implemented corrective measures, including implementing deletion routines and ending the storage of test results. For these reasons, the DPA imposed a fine of SEK 75,000 (about €6,7000)
Comment
The investigation also led to a SEK 75,000 against Waxholms Ångfartygs AB, the publicly owned company operating the ferry boats. The decision is available on the DPA's website and is very similar to the one against Storstockholms Lokaltrafik.
In recent years, IMY has begun issuing significantly higher fines—such as SEK 16 million on SL for unlawfully deploying body-worn cameras (Mål nr 1552-22) and SEK 12 million on Medhelp AB (DI-2019-3375) for insecure processing of health data. The SEK 75,000 fine in this case, while modest, continues that enforcement trend, particularly concerning the processing of special categories of data.
The decision underscores several GDPR principles. It affirms that indirectly identifiable data, such as timestamps combined with work schedules, can constitute personal data under Article 4(1) GDPR. It also classifies breath alcohol test results as health data, consistent with the DPA’s view that physiological readings fall under Article 4(15) GDPR. Importantly, it reiterates that public authorities cannot rely on general safety duties to bypass the specific legal requirements under Article 9 GDPR. While other national DPAs, such as the Polish UODO, have accepted limited workplace alcohol testing under narrow conditions, IMY’s position makes clear that routine testing programmes without explicit legal basis are unlikely to satisfy GDPR requirements. This decision aligns with a broader EU trend: workplace health monitoring must meet strict standards of necessity, proportionality, and legal certainty.
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the Swedish original. Please refer to the Swedish original for more details.
1(16) COMPLAINT See attachment OBJECT OF SUPERVISION Aktiebolaget Storstockholms Lokaltrafik Registration number: IMY-2024-1521 Decision after supervision according to Date: Data Protection Regulation – 2025-06-18 Aktiebolaget Storstockholms Lokaltrafik Decision of the Swedish Data Protection Authority The Swedish Data Protection Authority finds that Aktiebolaget Storstockholms Lokaltrafik, with corporate registration number 556013-0683, during the period October 2021–August 2022 has processed the complainant's personal data in violation of 1 • Article 6 of the Data Protection Regulation by processing the complainant's personal data without a legal basis and • Article 9 of the Data Protection Regulation by processing sensitive personal data about the complainant without any of the exceptions from the prohibition on processing such data being applicable. IMY decides, based on Articles 58(2) and 83 of the Data Protection Regulation, that Aktiebolaget Storstockholms Lokaltrafik shall pay an administrative penalty of 75,000 (seventy-five thousand) SEK for the violations. Statement of the supervisory case The Swedish Data Protection Authority (IMY) has initiated supervision against Aktiebolaget Storstockholms Lokaltrafik (SL or the company) due to a complaint. IMY is investigating whether the current processing of the complainant's personal data has been supported by a legal basis in Article 6 of the Data Protection Regulation, whether the processing has included sensitive personal data about the complainant pursuant to Article 9 of the Data Protection Regulation and, if so, whether any of the exceptions to the prohibition on processing such sensitive data have been applicable. Postal address: Box 8114 Background 104 20 Stockholm Website: IMY initiated supervision against the Stockholm Region Transport Administration due to www.imy.se the complaint in January 2023 in case number IMY-2023-696. The case E-mail: imy@imy.se 1Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to Telephone: the processing of personal data and on the free movement of such data, and repealing 08-657 61 00 Directive 95/46/EC (General Data Protection Regulation). Page 1 of 16Integrity Protection Authority Case number: IMY-2024-1521 2(16) Date: 2025-06-18 was closed due to the fact that the Stockholm Region Transport Authority was not deemed to be the controller of personal data for the processing to which the complaint relates. IMY has added relevant documents from the previous supervisory case to case IMY-2024-1521. The complaint The complainant has essentially stated the following. The complainant is a commander and employee of a transport operator that carries out procured public transport on water for SL. The commanders of the transport operator take a breath test in an alcohol meter before each ferry departure. The result is registered and stored in a system. The system of alcohol testing of employees with registration and storage of the results of the tests has not occurred before. The transport operator has not been able to answer on what legal basis the processing of sensitive data is based. The only stated purpose of alcohol testing is to ensure that the master is not under the influence of alcohol when operating the vessel, but the transport operator cannot explain what the legal basis, purpose and interest of registering test results for storage is. The probable reason why the transport operator cannot clearly and distinctly answer the complainant's questions is that the transport operator has not received sufficient information and supporting documents in its agreement with the Stockholm Regional Transport Administration. The transport operator shall report the results of the alcohol tests to SL. The information on the breath test results is stored in the permanently installed alcohol meter on board the vessels for one year. The same information is transferred via digital connection to a server that the transport operator and SL have access to. Since both the operator and SL can link the log information from the breathalyzer with the duty schedules, this means that it is a matter of personal data processing. According to law, the operator and SL must know who is on board and be recorded in the ship's logbook, which SL also has access to. The information in the ship's logbook is saved for three years. The master who is required to blow into the breathalyzer can therefore be linked to the breathalyzer that has been taken. Statements from SL SL's statements are presented in the relevant sections under the heading "Motivation of the decision". Below is a summary of what has mainly emerged regarding the personal data processing in question. The breathalyzer records information about the current breathalyzer connected to the ship, the time and result of the master's breathalyzer. Information about who a breathalyzer relates to is not recorded. The registered data is stored in the alcohol meter, the control box on board the ship and in SL's computer system for seven days according to current screening procedures. For results up to the legal limit, 0.2 per mille, only a green result is displayed. It is only when the result has passed the legal limit that a result expressed in per mille is visible and the breathalyzer shows red. Only a few authorized persons at the transport operator have been able to identify the master's breathalyzer result through access to the results from the alcohol meter as a ship's logbook. This has been necessary to achieve the purpose of using the alcohol meter, which was to prevent ships from operating under the influence of alcohol. When the breathalyzers were put into use in October 2021, screening procedures were lacking because SL did not consider that the results of the breathalyzers constituted personal data for the company. A proposal for a thinning decision was presented to the Regional Archives on 2 April 2022. Thinning of all data in the system was carried out on 2 May 2022. A formal thinning decision was approved by the Regional Archives on 3 October 2022. After the formal Page 2 of 16Integrity Protection Authority Case number: IMY-2024-1521 3(16) Date: 2025-06-18 thinning decision, automatic thinning shall take place after seven days from the breath test. A storage period of seven days is necessary to ensure that the transport operator has time to follow up and take action in the event of a possible positive result. It has not been deemed to be any interest in keeping breath tests and logs for a longer period of time as the data is of no significance in other respects. SL estimates that the complainant has performed approximately two breath tests per working day. The data about the complainant is no longer saved. Breathalyzer tests have been paused since August 26, 2022 due to IMY's supervision. SL wishes to resume the tests as soon as possible. Statements from the complainant The complainant has been given the opportunity to comment on SL's statements and has stated, among other things, the following. SL considers itself responsible for safety on board. The shipping company, in this case the operator, together with the master, are responsible for safety and the working environment on board. SL further refers to the alcohol and drug policy, which is the industry standard regardless of whether SL is the principal or not. This policy includes among other things zero tolerance for alcohol and drugs in the workplace, alcohol and drug tests upon new employment, suspicion and accident and random tests. The complainant questions whether SL has established, based on a proportionality assessment, that these measures have not worked and whether SL has established problems with alcohol and drugs among its contractor's personnel that justify further measures. Reasoning for the decision IMY shall initially examine whether the results from the breath tests have constituted personal data about the complainant. If so, the IMY shall then decide whether SL has been supported by Articles 6 and 9 of the Data Protection Regulation to process the complainant's personal data in connection with the breath tests carried out during the period October 2021–August 2022. The processing covers personal data Legal regulation The concept of personal data is defined in Article 4(1) of the Data Protection Regulation as any information relating to an identified or identifiable natural person, whereby an identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, a location data or online identifiers or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. Recital 26 of the Data Protection Regulation states, among other things, the following. Personal data that have been pseudonymised and which could be attributed to a natural person by the use of supplementary information should be considered as data relating to an identifiable natural person. In order to determine whether a natural person is identifiable, account should be taken of all means, such as filtering, which, either by the controller or by another person, could reasonably be used to directly or indirectly identify the natural person. In order to determine whether means could reasonably be used to identify the natural person, all objective factors, such as the costs and time required for identification, taking into account both the technology available at the time of the processing and the technological development, should be taken into account. Page 3 of 16Integrity Protection Authority Case number: IMY-2024-1521 4(16) Date: 2025-06-18 According to case law, the term “personal data” should be given a broad meaning. The European Court of Justice has ruled that information relates to an identifiable natural person when, by reason of its content, purpose or effect, it is linked to an identifiable person. The European Court of Justice has further stated that it is not necessary for the information itself to make it possible to identify the natural person for the information to constitute personal data. It follows from Article 4(1) in conjunction with recital 26 that personal data which, by using supplementary information, could be attributed to a natural person are to be considered as data relating to an identifiable natural person. It is not required that a single person possesses all the information necessary to identify the data subject for a piece of information to be considered to constitute personal data within the meaning of Article 4(1) of 5 the Data Protection Regulation. What SL has stated SL's statements include the following. Information on who a breath sample relates to is not recorded in the system. The system registers information about the current breathalyzer unit connected to the ship, the time and results of the breathalyzer test. Two employees of the transport operator have access to the results of the breathalyzer tests in the system. These authorized persons can in turn link the results of the breathalyzer test with who has been the master of the ship on which the breathalyzer test in question has been carried out. SL does not have access to this information. SL has decided that only personnel of the transport operator shall have access to the results of the breathalyzer test. Before the breathalyzer tests were introduced, SL assessed that the results did not constitute personal data for the company, since the company did not perceive that the means to identify which master had taken which breathalyzer test could reasonably or likely be accessed by SL. SL has had some opportunity to obtain access to data stored in the breathalyzer unit through measures taken by the supplier, but has primarily perceived that the opportunity was not within the scope of what is considered to constitute a reasonable measure. After dialogue with, among others, the captain regarding the breath tests in the spring of 2022, SL made a renewed assessment of the issue, whereby the company considered that the processing can probably be considered to constitute personal data processing for the company. IMY's assessment In light of the investigation into the matter, IMY assesses that the results of the breath tests can be linked to the natural person who has performed the breath test through supplementary information, which is available from the transport operator. According to IMY it is sufficient that the results of the breath tests with the supplementary information in the ship's logbook can be linked to an identifiable natural person. The fact 6 that SL has not had direct access to the results of the breath tests or that no information has been registered about who has performed a breath test in the system where the results have been stored is, according to IMY, irrelevant in this context. The results of the breath tests thus constitute personal data pursuant to Article 4(1) of the General Data Protection Regulation. SL is the data controller Legal regulation According to Article 4(7) of the General Data Protection Regulation, a controller is a natural or legal person, public authority, institution or other body which 2 See, for example, the judgment of the Court of Justice of the European Union in Österreichische Datenschutzbehörde, C-487/21, EU:C:2023:369, p. 23 and the case law 3cited therein. Judgment of the Court of Justice of the European Union in Case C-487/21, p. 24. 4 Judgment of the Court of Justice of the European Union in Nacionalinis visiones sveikatos centras, C-683/21, EU:C:2023:949, p. 58. 5 Judgment of the Court of Justice of the European Union in IAB Europe, C-604/22, EU:C:2024:214, p. 40. 6Cf. recital 26 and the judgment of the Court of Justice of the European Union in case IAB Europe, C-604/22, p. 40. Page 4 of 16Integrity Protection Authority Case number: IMY-2024-1521 5(16) Date: 2025-06-18 alone or jointly with others determines the purposes and means of the processing of personal data. What SL has stated SL has stated, among other things, the following. SL has determined the purposes of the current personal data processing and decided how the processing will be carried out. SL has decided on the installation of the meters on the ships. SL has decided on how the results of the breath tests will be stored and on the storage period. SL has further decided that only personnel at the transport operator shall have access to the results of the breath tests. The transport operator is a personal data processor for SL in the part in which the transport operator handles personal data on SL's behalf. SL has entered into a personal data processor agreement with the transport operator. IMY's assessment IMY assesses that the investigation shows that SL has determined the purposes and means of the current personal data processing. SL is therefore the personal data controller for it. Legal basis for the processing of personal data Article 6 of the General Data Protection Regulation states that the processing of personal data is only lawful if at least one of the conditions in Article 6(1) is met. In other words, there must be a legal basis for the processing of personal data. SL has stated that the company has carried out a documented balancing of interests and has concluded that the processing in question can be based on Article 6(1)(f) of the General Data Protection Regulation. SL has also stated that if IMY does not consider that a legal basis according to Article 6(1)(f) exists, the processing has been supported by the legal basis of public interest according to Article 6(1)(e) of the General Data Protection Regulation. Legal regulation Article 6(1)(e) of the General Data Protection Regulation states that the processing of personal data is lawful if it is necessary for the performance of a task carried out in the public interest or in the exercise of the authority of the controller. According to Article 6(3) of the GDPR, the basis for the processing referred to in Article 6(1)(e) shall be determined in accordance with Union law or the national law of a Member State to which the controller is subject. Article 6(1)(f) of the GDPR states that processing of personal data is lawful if it is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, unless the interests or fundamental rights and freedoms of the data subject are overridden and require the protection of personal data. The provision thus lays down three cumulative conditions that must be met for the processing of personal data to be permissible. The first condition is that the interests which the processing is intended to protect must constitute legitimate interests of the controller or of a third party. The legitimate interest must be lawful, which means that it must not conflict with Union or national law. Furthermore, the interest must be clearly and distinctly formulated and relate to a genuine interest that 7Cf. judgment of the Court of Justice of the European Union in M.I.C.M., C-597/19, EU:C:2021:492, p. 106 and EDPB guidelines Guidelines 1/2024 on processing of personal data based on Article 6(1)(f) GDPR (version 1.0 adopted on 8 October 2024 for public consultation), p. 6. Please note that the guidelines have not been finally adopted by the EDPB at the time of this decision. 8Cf. judgment of the Court of Justice of the European Union in Koninklijke Nederlandse Lawn Tennisbond, C-621/22, EU:C:2024:857, p. 49. Page 5 of 16Integritetsskyddsmyndigheten Case number: IMY-2024-1521 6(16) Date: 2025-06-18 exists at the time of the processing and is not hypothetical. If a controller is acting not only in its own legitimate interest (e.g. its business interest), but also in the interests of society as a whole, this interest will generally weigh 10 more heavily than otherwise. The second condition is that the processing is necessary for a purpose relating to the legitimate interest. This means that the legitimate interest cannot reasonably be achieved in an equally effective manner by other means which infringe less on the fundamental rights and freedoms of the data subjects, in particular the right to privacy and the right to the protection of personal data under Articles 7 and 8 of the Charter of Fundamental Rights of the European Union (the EU Charter of Rights). It also follows from practice that the requirement of necessity must be examined in conjunction with the principle of data minimisation under Article 5(1)(c) of the GDPR, which requires that the personal data collected must be adequate, relevant 12 and not excessive in relation to the purposes for which they are processed. The third condition is that the fundamental rights and freedoms of the data subjects (the interest in privacy) do not outweigh the legitimate interest that the processing is intended to protect. The assessment must be made on the basis of the specific circumstances of the individual case. The controller shall, among other things, identify and take into account the interests and rights and freedoms of the data subject, the impact of the processing on the data subject and whether the data subject could reasonably expect the processing for the purpose in question. 13 In accordance with the principle of accountability in Article 5(2) of the Data Protection Regulation, the controller is responsible for and able to demonstrate that the rules in the Data Protection Regulation are complied with, including that the processing is lawful. What SL has stated SL believes that the company has a legitimate interest in processing personal data in the way that it does. The legitimate interest in the processing is to ensure the safety of passengers in public transport. The Stockholm Region operates public transport on water based on decisions on public service obligations and a number of traffic agreements. Public transport on water is operated by SL and Waxholms Ångfartygs Aktiebolag (WÅAB). SL is responsible for ensuring that public transport within the company's area of responsibility is operated in a safe manner. SL's intention in sobriety testing captains has been to guarantee the safety of passengers, employees and road users in public transport. SL has considered the privacy concerns that this may entail for captains in connection with the performance of sobriety tests. SL has assessed that the interest in sober captains outweighs the privacy concerns that may arise for the captains concerned. SL has assessed that it is necessary to process personal data to achieve the purpose. It is not possible to achieve the purpose without the personal data in question being processed. SL has carried out a documented impact assessment with the result that the processing can take place. The Stockholm Region Traffic Administration has established in its Traffic Safety Policy for Maritime Traffic that vessels within the traffic administration shall be gradually equipped with reliable alcohol interlocks and that uniform procedures shall be in place for how these shall be used. The traffic administration's safety regulations SSA SÄB 0478 further state that all vehicles, including ships, in public transport must have alcohol interlocks and that work is underway 9 10U Court judgment Asociaţia de Proprietari bloc M5A-ScaraA, C-708/18, EU:C:2019:1064, p. 44. Judgment of the Court of Justice of the EU in case C-708/18, p. 44. 11 Judgment of the Court of Justice of the EU in case C-708/18, p. 47. 12 Judgment of the Court of Justice of the EU in case C-708/18, p. 48. 13 See EDPB Guidelines 1/2024, p. 32–34. Page 6 of 16 Swedish Data Protection Authority Case number: IMY-2024-1521 7(16) Date: 2025-06-18 introduction of alcohol interlocks for the fleet. SL's requirement that alcohol meters be used and the requirement that masters carry out breath tests and store the results at the transport operator means that the processing may be considered necessary. SL has minimized the number of personal data processed to fulfill the purposes of the processing. When employed by the transport operator, prospective personnel are informed of zero tolerance regarding alcohol and drugs and employees have access to the current alcohol and drug policy. SL has taken and considered other measures to achieve the purpose of the processing. None of the measures have been deemed to ensure the overall need for drivers in public transport never to operate vessels under the influence of alcohol. SL sets out requirements regarding maritime safety related to alcohol and drugs in public transport procurements. The latest procurement requires that transport operators must have a defined policy for preventive work against alcohol and drugs. Transport operators have an obligation to exercise supervision and carry out checks to meet SL's requirements for safety and security. The checks carried out are reported annually with the aim that SL, together with the transport operator, can evaluate and take measures for safe maritime traffic. The operator shall carry out alcohol and drug tests on the personnel working with the operation of the vessels through so-called random tests twice a year. In addition to random checks, requirements are set for alcohol and drug tests in connection with accidents and incidents. It should be emphasized that the only way to ensure that a master of a vessel is sober when operating the vessel is to carry out a sobriety test immediately before the vessel's departure. It is not sufficient to use random sobriety tests and provide information about the applicable alcohol and drug policy in connection with employment. A theoretically different way to achieve the purpose of the processing would be to install alcohol locks on vessels. SL believes that processing in connection with such a mechanism would entail equivalent infringements of the privacy of the data subjects, since the necessary follow-up of why a certain vessel cannot be operated due to an alcohol lock at a certain time would give rise to a corresponding type of personal data processing. When introducing sobriety tests, SL has found that previously implemented measures do not ensure SL's needs. SL has not been able to identify any less privacy-infringing measures than those introduced in connection with the sobriety tests and in the way the results of the checks are handled. SL further believes that the company's legitimate interest in carrying out the processing outweighs the interests of the data subjects. With regard to the legal basis of public interest, SL has stated that the activities that Region Stockholm, as a public transport authority, conducts constitute a public interest. SL, which is responsible for public transport, has a statutory obligation to operate public transport in a safe manner for both passengers and employees. IMY's assessment of the legal basis balancing of interests Legitimate interest SL has stated that the company has a legitimate interest in processing the complainant's personal data to ensure the safety of public transport and that ships are not operated under the influence of alcohol. IMY finds that SL's interest in processing personal data for the purpose of ensuring the safety of public transport is an important public interest that constitutes a legitimate interest within the meaning of the Data Protection Regulation. Page 7 of 16Integrity Protection Authority Case number: IMY-2024-1521 8(16) Date: 2025-06-18 Necessity IMY shall further examine whether the processing in question has been necessary to achieve the purpose of the personal data processing. In this part, SL has stated that the company has investigated other appropriate and less privacy-sensitive measures to achieve the purpose of the processing and that the company has not been able to identify any less privacy-intrusive measures to achieve the purpose of the current processing. SL has identified the installation of alcohol locks in ships as a theoretical alternative way to achieve the purpose of the processing. However, SL has assessed that necessary follow-up of why a certain ship cannot be operated due to alcohol locks at a certain time is to be considered a corresponding type of personal data processing as the processing to which the complaint applies. The necessity requirement shall, as mentioned, be tested together with the principle of data minimization. IMY notes that from the time the breath tests were introduced in October 2021 until they were stopped in August 2022, SL has lacked formal screening procedures for these. This has meant that the complainant's test results, from the average of two breath tests per shift that he carried out during the period, have been registered and stored in SL's system for a long time of several months. SL has stated that a longer storage period than seven days has not been justified either for follow-up of the results or for any other reasons. IMY believes that it can thus be considered clear that the purpose of safe public transport and preventing ships from being operated under the influence of alcohol has been achieved without such extensive processing of the complainant's personal data as carried out during the period. Against this background, IMY assesses, also taking into account that at one point during the period, a thinning of all data in the system has been carried out, that the processing has not been necessary to achieve the legitimate interest. Furthermore, SL has identified alcohol interlocks as an alternative way of achieving the purpose of the processing. IMY does not share SL's assessment that the personal data processing that the use of an alcolock would entail, as described by the company, would entail an equivalent infringement of the complainant's privacy in relation to that which was carried out. IMY believes that personal data processing in the form of an investigation when necessary and only when an alcolock has prevented the movement of a vessel would restrict the complainant's privacy protection to a lesser extent compared to the current processing of personal data, where each breath test result, regardless of the result, has been registered and, during the period covered by the supervision, stored for an indefinite period of time, in any case for several months. IMY therefore considers that even taking this circumstance into account it can be concluded that the current processing could have been achieved with less intrusive measures. In summary, IMY assesses that the processing of the complainant's personal data has not been necessary to achieve SL's legitimate interest and that all conditions for the processing to be based on Article 6(1)(f) are not met. The processing of the complainant's personal data has therefore not been supported by the legal basis of balancing of interests. IMY's assessment of the legal basis of public interest IMY has assessed that SL has not been able to support the processing of the complainant's personal data on Article 6(1)(f) of the Data Protection Regulation because it has not been necessary to achieve the purpose of the processing. IMY notes that in order for a processing to be able to be supported by Article 6(1)(e) of the Data Protection Regulation, it is required that the processing is necessary taking into account an important public interest arising from Union or national law. The provision thus contains a requirement for the same necessity as in Article 6(1)(f) of the Regulation. IMY has assessed that the processing of the complainant's personal data has not been necessary to achieve the purpose of safe public transport since the processing could have been achieved in an equally effective manner through less intrusive personal data processing. Given that the requirement of necessity has not been met, the processing of the complainant's personal data could not therefore be carried out on the basis of the legal basis of public interest. IMY concludes in summary that SL has not had a legal basis for the processing of the complainant's personal data in connection with breath tests carried out during the period October 2021–August 2022. SL has thus processed the complainant's personal data in violation of Article 6 of the Data Protection Regulation. Processing of sensitive data Legal regulation Health data constitute special categories of personal data, so-called sensitive personal data, which are given particularly strong protection under the Data Protection Regulation. It is generally prohibited to process such personal data under Article 9(1) of the Data Protection Regulation, unless the processing falls under one of the exceptions in Article 9(2) of the Regulation. It follows from Article 9(2)(g) that the prohibition on processing sensitive personal data does not apply where the processing is necessary for reasons of important public interest, on the basis of Union law or the national law of the Member States, which shall be proportionate to the purpose pursued, be compatible with the essence of the right to data protection and provide for suitable and specific measures to safeguard the fundamental rights and interests of the data subject. According to practice, the concept of sensitive personal data is to be interpreted broadly and also includes data that indirectly reveal such information. 14 Data concerning health are defined in Article 4(15) of the Data Protection Regulation as personal data relating to the physical or mental health of a natural person which provide information about his or her health status. Recital 35 of the GDPR states that personal data concerning health should include all data relating to the health of a data subject which provide information on the past, present or future physical or mental state of the data subject, including, inter alia, data resulting from tests or examinations of a body part or substance. It follows from the wording of Article 4(15) of the GDPR, as specified in recital 35 of the GDPR, that the decisive factor in determining whether certain personal data constitute data concerning health is whether it is possible to draw conclusions from the data in question concerning the health of the data subject. 15 The European Data Protection Board (EDPB) has stated in its Guidelines on Automated Individual Decision-Making and Profiling that profiling can create sensitive personal data by drawing conclusions from and combining non-sensitive data. According to the EDPB, it may be possible, for example, to draw a conclusion about someone’s 14CJEU judgments Lindqvist, C-101/01, EU:C:2003:596, p. 50, Vyriausioji tarnybinės etikos komisija, C-184/20, EU:C:2022:601, p. 125–127 and Lindenapotheke, C-21/23, EU:C:2024:846, p. 84, 89–91 and 94. 15See Opinion of the Advocate General in CJEU case NADA C-115/22, EU:C_2023:676, p. 97. Page 9 of 16Privacy Protection Authority Case number: IMY-2024-1521 10(16) Date: 2025-06-18 health status from information about their food purchases together with information about the food quality and energy content.16 What SL has stated The possible processing of sensitive personal data is supported by Article 9.2 g of the Data Protection Regulation. SL has assessed that it has been necessary to process personal data in order to achieve safe public transport. SL performs work where people lives may be in direct danger if captains on board are under the influence of alcohol in connection with work on the ships. Traffic safety constitutes an important public interest and requires SL to sobriety test captains in order to ensure safe public transport for staff, passengers and fellow passengers. In a combined assessment of the safety requirements set out in the Maritime Act (1994:1004) and the Ship Safety Act (2003:365), SL has found that the processing is necessary. SL has considered that the sobriety tests are a mandatory measure to ensure safety on board and the obligations arising from the law. The method used in the tests has been carefully considered and deemed to be the least privacy-infringing for the purpose. SL has further stated that no positive result has ever been found when performing sobriety tests. SL cannot therefore be considered to have processed sensitive personal data. The lack of a positive result cannot be considered to constitute processing of sensitive personal data about health. Furthermore, the technical equipment used to carry out sobriety tests is designed in such a way that the blood alcohol level is only displayed when the result has exceeded the legal limit. The result is only stored for seven days, which means that it is not possible to notice any patterns or risk behaviors over time that could in some cases entail the processing of sensitive personal data. SL is therefore of the opinion that sensitive personal data has neither actually been, nor potentially could be, processed through the sobriety test system that SL has introduced. IMY's assessment It is clear from the investigation into the case that data from all breath tests carried out by the complainant have been stored during the period October 2021–May 2022 and were deleted in May 2022. IMY further notes that it is clear that the processing has continued thereafter and that, although SL in April 2022 submitted a proposal for a decision on deletion after seven days, there was no formal decision that enabled the deletion of the data also during the period May 2022–August 2022. It is thus a matter of extensive and regular processing of data on the results of the complainant's breath tests over a longer period of time. No positive results regarding the complainant have been registered. In assessing whether the processing has included sensitive personal data, IMY takes into account in particular that the concept of “health data” should be interpreted broadly and that it is possible to create sensitive data by collecting non-sensitive data. It is also taken into account that health data can have different degrees of sensitivity. However, the sensitivity of a particular piece of data is not of importance for whether a piece of data constitutes health data within the meaning of the Data Protection Regulation. It can also be stated that even data that makes it possible to conclude that someone does not suffer from a certain medical condition can be data about that person’s health. The current case concerns the processing of a large amount of personal data in the form of results from breath alcohol tests over a period of several months. In light of the scope of the processing in the individual case, IMY assesses that, based on the 16Guidelines on automated individual decision-making and profiling under Regulation (EU) 2016/679 WP251rev.01, p.16. Page 10 of 16Integrity Protection Authority Case number: IMY-2024-1521 11(16) Date: 2025-06-18 collected data, it has been possible to draw conclusions about the complainant's health status. SL has thus processed data about the complainant's health in the sense referred to in Article 4(15) of the Data Protection Regulation. In order for the processing of sensitive personal data about health to be lawful, it must be covered by one of the exceptions in Article 9(2) of the Data Protection Regulation. SL has stated that the processing in question was supported by Article 9(2)(g). IMY notes that a prerequisite for the processing of sensitive personal data to be lawful under any of the points in Article 9(2) is that the processing is supported by a legal basis. Since IMY has assessed above that SL lacked a legal basis for the processing, it can already be concluded for that reason that the processing is not permitted under Article 9 of the Data Protection Regulation either. Furthermore, IMY has assessed that SL has not been able to support the processing of the complainant's personal data on Article 6(1)(f) of the Data Protection Regulation because it was not necessary to achieve the purpose of the processing. IMY notes that the exception in Article 9(2)(g) applies to processing that is necessary for an important public interest arising from Union or national law. This provision also contains a requirement of necessity equivalent to that in Article 6(1)(f). Since IMY has assessed that this requirement is not met in relation to the public interest in safe public transport invoked by SL, the processing of sensitive personal data could not be based on Article 9(2)(g) of the Data Protection Regulation. In summary, IMY assesses that SL lacked support in any of the exceptions in Article 9(2) from the prohibition on processing sensitive personal data. SL has thus processed the complainant's personal data in violation of Article 9 of the Data Protection Regulation. Choice of intervention Legal regulation In the event of violations of the Data Protection Regulation, IMY has a number of corrective powers available to it under the Data Protection Regulation. Article 58(2) of the GDPR provides that the IMY shall, in accordance with Article 83, impose administrative fines in addition to or instead of other corrective measures referred to in Article 58(2), depending on the circumstances of each case. Each supervisory authority shall ensure that the imposition of administrative fines is effective, proportionate and dissuasive in each case. This is stated in Article 83(1) of the GDPR. Article 83(2) sets out the factors to be taken into account in determining whether an administrative fine should be imposed, as well as the factors that should influence the amount of the fine. The nature, severity and duration of the infringement are relevant for the assessment of the seriousness of the infringement. The EDPB has adopted guidelines on the calculation of administrative fines under the GDPR, which aim to create a harmonised methodology and principles for calculating fines. 18 According to Article 83(5), infringements of, among others, Articles 6 and 9 shall be subject to administrative fines of up to EUR 20,000,000 or, in the case of an 17CJEU judgment of 21 December 2023, Krankenversicherung Nordrhein, case C-667/21, p. 79. 18Guidelines 04/2022 on the calculation of administrative fines under the GDPR. Page 11 of 16Integrity Protection Authority Case number: IMY-2024-1521 12(16) Date: 2025-06-18 4 percent of the total worldwide annual turnover in the preceding financial year, whichever is the higher. Article 83(3) states that if a controller infringes several of the provisions of the Regulation in relation to the same or connected processing operations, the administrative fine shall not exceed the amount set for the most serious infringement. If the infringement is minor, the IMY may, as stated in recital 148, issue a reprimand in accordance with Article 58(2)(b) of the Regulation instead of imposing a fine. What SL has stated SL has stated that in the event that the IMY considers that the company has processed personal data without legal basis, a reprimand should be imposed in the first place instead of a fine. SL's sole purpose with the sobriety tests is to ensure the safety of passengers and employees in public transport. SL has taken far-reaching measures to ensure that the invasion of privacy for the data subject is as minimal as possible. SL has limited the number of people who have been subject to sobriety tests and has minimized the storage time, the number of data stored and people who have had the opportunity to read the results in order to be able to take action in the event of a positive result. In addition, there has been continuous dialogue between the transport operator and SL to ensure that sobriety tests are carried out in an appropriate manner. As a result of the dialogue, SL has on several occasions paused the use of sobriety tests to address and investigate issues that have arisen during the time. No sensitive personal data has actually or potentially been processed. Nor has there been any security incident that posed risks to the complainant. A sanction fee would, taking into account the situation as a whole and the circumstances presented by SL, entail a disproportionate measure that is counterproductive. A reprimand with an order on how the processing should be adjusted in to make it legal appears to be more appropriate. If IMY decides to impose a penalty fee, it must be taken into account that the processing has been proportionate and necessary in relation to the purpose of the processing. The equipment used when performing sobriety tests has, after investigation, been deemed to be the least infringing on privacy for the established purpose. The sobriety tests have been interrupted on several occasions for technical reasons and to investigate views. The actual time for using sobriety tests has therefore been very limited and the number of tests performed has thus been relatively few. Since IMY decided to initiate supervision, SL has cooperated and provided information upon request. SL has also been careful to submit corrections in the event that incorrect information has been provided. SL is 100 percent owned by the Stockholm Region. The region exercises active ownership in SL and has significant legal influence in decision-making over how the company shall conduct its operations and fulfil the authority's mission. SL is thus a publicly owned company where the majority is financed with tax-financed funds and the company should therefore not be imposed a higher sanction fee than what can be imposed on an authority. SL is a limited liability company but, in light of the current structure, should be essentially equated with an authority when fulfilling the Stockholm Region's mission as a public transport authority. Any sanction fee should be significantly lower than for a commercial company with a profit objective and should only be assessed based on the circumstances of the case in question. It should also be noted that the provision of public transport on water constitutes a small part of SL's overall operations. SL further notes that the processing of previous supervisory matters and current supervision has been ongoing for just over two years. IMY's assessment A penalty fee shall be imposed IMY has found that SL has processed the complainant's personal data in violation of Articles 6 and 9 of the Data Protection Regulation. This means that SL, even taking into account that the processing has been periodically paused, has collected and stored sensitive personal data about the complainant in his capacity as an employee for a long time without legal support. Against this background, IMY considers that these are not such minor violations that could result in a reprimand being issued instead of a penalty fee. The EU Court of Justice has clarified that it is required that the data controller has committed an infringement intentionally or negligently in order for administrative penalty fees to be imposed under the Data Protection Regulation. The EU Court of Justice has stated in this regard that data controllers can be imposed penalty fees for actions if they cannot be considered to have been unaware that the action constituted an infringement, regardless of whether they were aware that they were infringing the provisions of the Data Protection Regulation. 19 SL is, in its capacity as data controller, responsible for the personal data processing that takes place within the company and for it to be carried out in accordance with the applicable regulations. SL has processed the complainant's personal data in violation of the Data Protection Regulation by processing the personal data without a legal basis in Article 6 and without any of the exceptions to the prohibition on processing sensitive personal data in Article 9 having been applicable. IMY considers that the company cannot be considered to have been unaware that the action entailed a violation of the Regulation. Against this background, IMY considers that the company has been negligent in relation to the violations of the Data Protection Regulation that have been established. There are therefore grounds for imposing an administrative penalty on the company. Basis for calculating the penalty The maximum penalty that applies to companies in case of violations of Articles 6 and 9 is the higher of EUR 20,000,000 and 4 percent of the total global annual turnover in the previous financial year. There is no support for instead applying the lower maximum amounts for penalty fees that apply to authorities according to Chapter 6, Section 2, second paragraph of the Act (2018:218) with supplementary provisions to the EU Data Protection Regulation, since SL is not an authority but a 20 private law body. When determining the maximum amount of a penalty fee to be imposed on an undertaking, the definition of the term undertaking used by the Court of Justice of the European Union in the application of Articles 101 and 102 of the TFEU shall be used. The calculation of the maximum amount for a controller constituting such an undertaking or forming part of such an undertaking shall be based on a percentage of the total global turnover of the undertaking concerned 19CJEU judgments Nacionalinis visuemines sveikatos centras, C-683/21, paragraph 81 and Deutsche Wohnen, C- 807/21, p. 76. 20It is the terminology of the instrument of government that is the starting point for interpreting the concept of authority under the Data Protection Regulation. According to this terminology, bodies organised in private law forms, such as state and municipal companies, do not constitute authorities, even if they exercise public authority. See Bill No. 2017/18:105, p. 46 and 139. Page 13 of 16Integrity Protection Authority Case number: IMY-2024-1521 14(16) Date: 2025-06-18 21 the annual turnover in the previous financial year. The concept of undertaking shall also be taken into account in order to assess the actual or material economic capacity of the person on whom the penalty payment is imposed and thereby to verify whether the penalty payment is effective, proportionate and dissuasive. 22 It is clear from the case-law of the Court that the concept covers any entity that carries out an economic activity, regardless of the legal form of the entity and the way in which it is financed and even if the entity in legal terms consists of several natural or legal persons. Different companies within the same group can thus form an economic unit and thus an undertaking within the meaning of Articles 101 and 102 TFEU. 23 A parent company and a subsidiary are considered to be part of the same economic unit when the parent company exercises a decisive influence over the subsidiary. The decisive influence (i.e. control) can be achieved either through ownership or by agreement. It is clear from case-law that a 100% or almost 100% ownership gives rise to a presumption that control is to be considered to exist (the so-called Akzo principle). However, the presumption can be rebutted if the company provides sufficient 24 evidence to prove that the subsidiary acts independently on the market. SL is the parent company of a group in which SL is the sole owner of the companies SL Nya Tunnelbanan AB, AB SL Finans and WÅAB. Against this background, IMY assesses that the SL Group, in accordance with the Akzo principle, which is not considered to have been refuted, is an economic entity that constitutes an undertaking within the meaning of the provisions of the TFEU. When determining the maximum amount of the penalty, IMY will base the assessment on SL's annual and consolidated accounts for 2023 (since the annual accounts for 2024 have not been adopted at the time of the decision). IMY assesses that it is the SL Group's annual turnover for 2023 of SEK 24,512,000,000 that should be used as the basis for calculating the penalty. This means that the maximum amount that can be determined in the case is SEK 980,480,000, which corresponds to four percent of the annual turnover. The seriousness of the infringements The EDPB guidelines state that the supervisory authority shall assess whether the infringements are of low, medium or high seriousness in accordance with Article 83(2)(a), (b) and (g) of the GDPR. 26 The processing to which the infringements relate has been extensive, taking into account that it has been carried out over a long period of a total of just over 9 months and that the complainant has been tested approximately twice per work shift. The processing has also included sensitive personal data about the complainant collected in the context of his employment, a situation where he was in a position of dependence in relation to his employer. In assessing the seriousness, IMY also attaches great importance to that the processing was carried out for the purpose of maintaining safety in public transport and that the supervision only covers the processing of personal data of an individual complainant. Furthermore, the complainant has not been directly identifiable and as a result of measures taken by SL, 21See recital 150 of the Data Protection Regulation and the judgment of the Court of Justice of the EU in Deutsche Wohnen, C-807/21, p. 57. 22See the judgment of the Court of Justice of the EU in ILVA, C-383/23, EU:C:2025:84, p. 36. 23The judgment of the Court of Justice of the EU in Akzo Nobel, C-516/15 P, EU:C:2017:314, p. 48. 24 25CJEU judgment Akzo Nobel and Others, C-97/08, EU:C:2009:536, p. 59–61 EDPB Guidelines 04/2022 on the calculation of administrative fines under the GDPR, paragraph 130 and 26CJEU judgment Groupe Gascogne SA v European Commission, C-58/12P,ECLI:EU:C:2013:770, paragraphs 54–56. EDPB Guidelines 04/2022, p. 60. Page 14 of 16Integrity Protection Authority Case number: IMY-2024-1521 15(16) Date: 2025-06-18 only a few persons had access to all the information required to identify the complainant. In light of the above circumstances, IMY assesses that these are all violations of Articles 6 and 9 of the General Data Protection Regulation of low seriousness. In its assessment of the size of the penalty fee, IMY shall also take into account such aggravating and mitigating factors as listed in Article 83(2) of the General Data Protection Regulation. SL has now taken measures to limit the storage period and has also highlighted that the company has paused the alcohol tests on several occasions to address and investigate issues that have arisen during the processing. IMY does not believe that the measures taken go beyond what is expected of the company in the current case and that they therefore do not constitute factors that should affect the assessment of the size of the penalty fee in a mitigating direction. IMY further notes that SL has had an obligation to cooperate with IMY within the framework of supervision and this is a circumstance that should be considered neutral when determining the penalty fee. IMY assesses that there have been no other aggravating or mitigating circumstances, in addition to those taken into account when assessing the seriousness, that affect the size of the penalty fee. In light of the complexity of the case, IMY assesses that the length of time the case is being processed should not lead to a lower penalty fee.28 The administrative penalty fee shall be effective, proportionate and dissuasive. This means that the amount shall be determined so that the administrative penalty fee leads to correction, that it has a preventive effect and that it is also proportionate in relation to both the current violation and the ability to pay of the supervised entity. IMY decides based on an overall assessment that SL shall pay an administrative sanction fee of SEK 75,000. IMY considers that this amount is effective, proportionate and dissuasive. __________________________ This decision has been made by the Head of Unit Nidia Nordenström after a presentation by the Departmental Lawyer Maja Welander. Nidia Nordenström Appendices 1. The complainant's personal data 2. Information on how to pay a sanction fee Copy to the Data Protection Officer 27EDPB guidelines 04/2022, p. 95–98. 28The Stockholm Administrative Court has in two complicated supervisory cases assessed that there was no reason to reduce the sanction fee due to the processing time of the cases, which amounted to two years and seven months and three years respectively. See the Stockholm Administrative Court judgments of 26 January 2023 in case no. 1552-22 and 11 March 2024 in case no. 2829-23. Page 15 of 16Integrity Protection Agency Case number: IMY-2024-1521 16(16) Date: 2025-06-18 How to appeal If you wish to appeal the decision, you should write to IMY. Indicate in the letter which decision you are appealing and the change you are requesting. The appeal must have been received by IMY within three weeks from the day you received the decision. If you are a party representing the public, however, the appeal must have been received within three weeks from the day the decision was announced. If the appeal has been received in good time, IMY will forward it to the Stockholm Administrative Court for review. You can email the appeal to IMY if it does not contain any privacy-sensitive personal data or information that may be subject to confidentiality. The authority's contact details are provided on the first page of the decision. Page 16 of 16




