IMY (Sweden) - IMY-2024-2904

From GDPRhub
IMY - IMY-2024-2904
Authority: IMY (Sweden)
Jurisdiction: Sweden
Relevant Law: Article 13 GDPR
Type: Investigation
Outcome: Violation Found
Started:
Decided: 03.07.2026
Published: 08.07.2026
Fine: n/a
Parties: Polismyndigheten
National Case Number/Name: IMY-2024-2904
European Case Law Identifier: n/a
Appeal: Unknown
Original Language(s): Swedish
Original Source: IMY (in SV)
Initial Contributor: av

The DPA reprimanded the national police authority for not providing arriving travellers sufficient information regarding the processing of personal data that takes place during border control at an airport.

English Summary

Facts

The supervisory authority launched an investigation into the border control unit of the national police authority (the controller) at Arlanda Airport concerning the processing of the personal data of travellers arriving from third countries (the data subjects).

During border control, the controller scanned the data subjects’ passports, and some travellers were required to provide fingerprints. The data collected was then possibly checked against various border control systems, such as the Schengen Information System (SIS) and the Visa Information System (VIS). There were no signs, brochures, or other written information on the processing of personal data available directly in the arrival hall. The only information available could be found on the controller’s website.

Holding

The DPA issued the controller a reprimand for the infringement of Article 13 GDPR. It held that the controller had not provided the data subjects sufficient information about the processing of personal data during border controls. According to the DPA, the data subjects had not been able to easily access information regarding, among other things, what personal data is collected, how it is processed, and what rights data subjects have.

The DPA took into account that not all travellers arriving from third countries could be expected to know which national authority is responsible for border controls, let alone be able to find and understand the information on the controller’s website without any guidance in the arrivals hall. It concluded that the lack of easily accessible information on this matter constituted a significant shortcoming: the border control operations included the processing of sensitive data, including biometric data, of a large number of travellers on a daily basis.

On the other hand, the investigation was limited to one arrivals hall. The controller had also obtained signs with tailored information regarding the processing of personal data during border control since the beginning of the investigation. Based on an overall assessment, the DPA held that the lack of information required by Article 13 in the arrivals hall constituted a minor GDPR violation.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Swedish original. Please refer to the Swedish original for more details.

1(5)

Police Authority

Registration number:
IMY-2024-2904 Decision after supervision according to, among others, VIS-

Your registration number: the regulation and the border regulation

A276.737/2024
– Police Authority
Date:
2026-07-03

Decision of the Swedish Data Protection Authority

The Swedish Data Protection Authority finds that the Police Authority (202100-0076) has
processed personal data in violation of Article 13 of the Data Protection Regulation by
not providing sufficient information to data subjects about
the personal data processing that takes place at the border control at Arlanda Airport.

IMY decides, based on Article 58(2)(b) of the Data Protection Regulation, to give
the Police Authority a reprimand for the violation of Article 13.

Statement of the inspection case

Purpose of the inspection

The Swedish Data Protection Authority (IMY) has initiated an inspection of the Police Authority's
border section at Arlanda Airport. The purpose of the inspection has been to check whether the
2
personal data processing carried out in the border control (in accordance with the Borders Code) when
using the Schengen Information System (SIS) and the Visa Information System (VIS)
3 4
is in compliance with the Border Regulation, the VIS Regulation
and the Data Protection Regulation.

Method and scope of the inspection

The inspection was carried out through an inspection at Arlanda Airport, which was then followed up
with supplementary questions. The inspection was limited in that it only
covered the border control in one of the arrival halls at Arlanda Airport where travellers

arrive from third countries. IMY has specifically reviewed which information on

Postal address:
1Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing
104 20 Stockholm Directive 95/46/EC (General Data Protection Regulation).
Website: 2Regulation (EU) 2016/399 of the European Parliament and of the Council of 9 March 2016 on a Union Code on the rules on the movement of persons across borders (Schengen Borders Code).
www.imy.se 3Regulation (EU) 2018/1861 of the European Parliament and of the Council of 28 November 2018 on the establishment, operation and
Email: use of the Schengen Information System (SIS) in the field of entry and exit checks, amending the Convention
imy@imy.se implementing the Schengen Agreement and amending and repealing Regulation (EC) No 1987/2006.
4Regulation (EC) No 767/2008 of the European Parliament and of the Council of 9 July 2008 on the Visa Information System (VIS) and the exchange of data between Member States on short-stay visas (VIS-
08-657 61 00 Regulation).Privacy Protection Authority Case number: IMY-2024-2904 2(5)
Date: 2026-07-03

data subjects' rights available on site, what training regarding

data protection those working in border control receive and what personal data is
processed in border control. IMY has also examined the authorisations of employees and how

the use of the systems is logged. In addition, IMY has examined the handling of
personal data incidents linked to the processing of personal data at the police

border control and what security measures the Police Authority has taken regarding
the processing.

Reasons for the decision

Applicable provisions, etc.

What regulations apply to the processing?
It follows from both the VIS Regulation and the Border Regulation that

the Data Protection Regulation also applies when competent authorities process

personal data in accordance with the respective regulation. The police authority's processing of

personal data in connection with border control in accordance with the Border Code therefore needs to be
in accordance with the above-mentioned regulations.

IMY's corrective powers follow from the Data Protection Regulation.

Information to data subjects

Article 13 of the Data Protection Regulation states that the controller shall
provide the data subject with certain information about the processing of

personal data collected from a data subject in connection with the receipt of these.

This information shall include, among other things, who is the controller, the purpose

and legal basis for the processing and contact details for the data protection officer.

Furthermore, according to Article 12 of the Data Protection Regulation, this information shall, as a basic rule, be provided in writing in an easily accessible and understandable manner.

Recital 39 of the Data Protection Regulation states that it should be clear and obvious to

natural persons how personal data relating to them are collected, used, consulted
or otherwise processed and to what extent the personal data are

or will be processed.

When providing information about the processing of personal data,

the specific circumstances and context of the personal data processing shall

be taken into account.

A controller may use a tiered approach to

provide the information set out in Article 13. The tiered approach

means that the information that is of most importance to the data subject should be presented
even before the data subject has his or her personal data processed, for example on a sign.

The sign should contain information on the purpose of the processing and the
identity of the controller and a description of the data subject

5Cf. recital 17 of the VIS Regulation. Now also regulated in Article 36a(2) which is introduced by Regulation (EU) 2021/1134 of the European Parliament and of the Council of 7 July 2021 amending Regulations (EC) No 767/2008, (EC) No 810/2009, (EU) 2016/399, (EU) 2017/2226, (EU) 2018/1240, (EU) 2018/1860, (EU) 2018/1861,
(EU) 2019/817 and (EU) 2019/1896 of the European Parliament and of the Council and repealing Council Decisions 2004/512/EC and 2008/633/JHA, with a view to

6reforming the Visa Information System.
7See Article 51(2) of the Borders Regulation.
8See Article 94 of the Data Protection Regulation.
See also Article 29 Working Party Guideline WP260rev.01 on transparency and information to data subjects.
9See recital 60 of the Data Protection Regulation.Integrity Protection Authority Case number: IMY-2024-2904 3(5)
Date: 2026-07-03

rights. Other information can be provided in other ways, e.g. on a website or in a
10
complete information sheet or a brochure.

IMY's assessment

During the inspection, it became clear that the Police Authority at the border control for entry from
third countries processes personal data from all travellers by scanning
the passport document. Some travellers also need to provide their fingerprints. The data
that is collected is, depending on the situation, run against different border control systems, e.g. VIS

and SIS.

During the inspection, IMY noted that there was a lack of written information about

the processing of personal data to arriving travellers in connection with their
providing fingerprints and other information at the border control. There were neither signs,
brochures nor other written information to be consulted directly in the

arrival hall in question. The only information available was that which was
published on the Police Authority's website, but there was no

reference to this information in the arrival hall.

Even if information regarding the current processing was published on

the Police Authority's website, it needs to be taken into account that not all travellers can
be assumed to have the opportunity to find and utilize the information on the website during
the time they are in the arrivals hall. Travellers from third countries cannot
be expected to know that it is the Police Authority that is responsible for border controls in Sweden,
since it looks different in the member states, and therefore, without special information, understand
that they should turn to the Police Authority's website for information about

the processing of personal data.

The Police Authority has stated that one month after the inspection, in connection with a
test prior to the implementation of a new system (the EEA entry and exit system), they put up
signs at the border controls at Arlanda Airport with information about the authority's

processing of personal data. However, IMY notes that the sign mainly contained
information about the testing activities themselves and only very brief and general
information about the authority's personal data processing, thus no adapted
information about the processing that takes place at the border control.

Against this background, IMY finds that there was no opportunity for those who would pass
the border control to access information about the
personal data processing that the Police Authority carries out at the border control in an easily accessible manner.

The Police Authority, as the personal data controller for the processing, has thus failed
in its information obligation according to Article 13 of the Data Protection Regulation.

What has otherwise emerged in the review does not give IMY reason to establish
any further shortcomings.

Choice of intervention

In the event of violations of the Data Protection Regulation, IMY has a number of corrective
powers available according to Article 58(2)(a)-
j of the Regulation, including reprimand,
injunction and penalty payment. It further follows from Chapter 6. 2 § of the Data Protection Act that11

1Cf. recital 39 of the Data Protection Regulation and the Article 29 Working Party guideline WP260rev.01 on transparency and
information to data subjects.
1Act (2018:218) with supplementary provisions to the EU Data Protection Regulation.Integrity Protection Authority Case number: IMY-2024-2904 4(5)
Date: 2026-07-03

The IMY may levy penalty fees on authorities for violations of, among others, Article 13 of
the Data Protection Regulation. It is clear from Article 83(2) of the Regulation that the IMY shall impose
administrative penalty fees in addition to or instead of the other measures referred to in

Article 58(2) depending on the circumstances of the individual case. If it is a minor violation, the IMY may, as stated in recital 148 of the Data Protection Regulation, issue a reprimand in accordance with Article 58(2)(b) of the Data Protection Regulation instead of imposing a penalty fee. Consideration shall be given to aggravating and mitigating circumstances in the case, such as the nature, severity and duration of the violation, as well as previous violations of relevance. The IMY has assessed that the Police Authority has failed to fulfil its information obligation in accordance with Article 13 of the Data Protection Regulation because there has been a lack of opportunity for those who have crossed the border to obtain information in an easily accessible manner about, among other things, what personal data is collected, how it is processed and what rights the data subjects have. When assessing the choice of intervention, the IMY takes into account that at the current border control at Arlanda Airport, sensitive data such as biometric data from a large number of travellers, including children, is processed every day. It is of great
importance that the individual understands why his or her personal data is being processed and what

rights are associated with it. According to IMY, it is therefore a significant shortcoming that there has been a
lack of easily accessible information about this at the border control.

In this case, however, the supervision is limited in that the inspection only covered an
arrival hall at Arlanda Airport, which constitutes a limited part of the Police Authority's
border control operations in Sweden. IMY also shares the Police Authority's assessment that

it may be considered common knowledge among the majority of travellers that their personal data will be processed to some extent in connection with a border control. It is also
taken into account that IMY has been informed that, during the handling of the
supervision, the Police Authority has, among other things, produced signs with adapted information regarding

the personal data processing that takes place at the border control. Furthermore, no previous relevant violations have emerged on the part of the Police Authority.

In an overall assessment, IMY therefore considers that this is a minor
infringement as referred to in recital 148 of the Data Protection Regulation and that a reprimand is
a sufficient and proportionate measure to highlight the infringement and ensure
compliance with the Data Protection Regulation.

Against this background, IMY considers that the Police Authority should be given a reprimand in accordance with

Article 58(2)(b) of the Data Protection Regulation for the infringement.

__________________________

This decision has been made by Head of Unit Jonas Agnvall following a presentation by the lawyer
Linda Markus. In the final handling of the case, the departmental lawyer

Lisa Zettervall and the IT and information security specialist Mats Juhlén have also participated.

Jonas Agnvall

Copy to
Data Protection OfficerIntegrity Protection Authority Filing number: IMY-2024-2904 5(5)
Date: 2026-07-03

How to appeal

If you wish to appeal the decision, you should write to IMY. Indicate in the letter which decision you
are appealing and the change you are requesting. The appeal must have been received by IMY

within three weeks of the day you received the decision. If you are a party representing
the public, however, the appeal must have been received within three weeks of the day on which
the decision was notified. If the appeal has been received in good time, IMY will forward it
to the Administrative Court in Stockholm for review.

You can e-mail the appeal to IMY if it does not contain any privacy-sensitive
personal data or information that may be subject to confidentiality. The authority

contact details are stated on the first page of the decision.