Kammarrätten - 7125-24
| Kammarrätten - 7125-24 | |
|---|---|
| Court: | Kammarrätten (Sweden) |
| Jurisdiction: | Sweden |
| Relevant Law: | Article 44 GDPR Article 46 GDPR |
| Decided: | |
| Published: | 15.10.2025 |
| Parties: | Tele2 IMY |
| National Case Number/Name: | 7125-24 |
| European Case Law Identifier: | |
| Appeal from: | |
| Appeal to: | Not appealed |
| Original Language(s): | Swedish |
| Original Source: | The Administrative Court of Appeal in Stockholm (in Swedish) |
| Initial Contributor: | xz |
A court held that Tele2 violated Chapter V of the GDPR by failing to implement adequate safeguards when transferring personal data to the U.S. through the use of Google Analytics
English Summary
Facts
The Swedish Authority for Privacy Protection (IMY) conducted an investigation into Tele2 between August 2020 and May 2023. The investigation focused on Tele2’s use of Google Analytics on its website and whether this resulted in the transfer of personal data to the United States.
IMY concluded that Tele2 had violated Chapter V of the General Data Protection Regulation (GDPR), which regulates the transfer of personal data to countries outside the EU/EEA. According to IMY, the company failed to implement adequate safeguards when transferring personal data to the U.S. through Google Analytics.
As a result, IMY imposed a sanction fee of SEK 12,000,000 (€1,020,000) on Tele2 in June 2023. Tele2 appealed the decision to the Administrative Court, which rejected the appeal.
Tele2 then appealed to the Administrative Court of Appeal.
Holding
The Administrative Court of Appeal rejected Tele2’s appeal and upheld IMY’s decision.
The court confirmed that Tele2 had violated the General Data Protection Regulation (GDPR) by transferring personal data to the United States without adequate protection through its use of Google Analytics. The data in question was considered personal data because it could be combined with other information held by Google to identify individuals. The court also found that the safeguard measures implemented by Tele2 were insufficient to ensure a level of protection essentially equivalent to that guaranteed within the EU/EEA. As a result, the administrative fine imposed by IMY was deemed lawful and proportionate.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the Swedish original. Please refer to the Swedish original for more details.
The Court of Appeal finds that Tele2 has transferred personal data to the USA in violation of the EU Data Protection Regulation. The Swedish Data Protection Authority decided after supervising Tele2 that the company should pay a penalty fee. This is because the company, by using the Google Analytics tool on its website, transferred personal data to a country outside the EU. The Court of Appeal finds that Tele2 has violated the Data Protection Regulation. This is because the processed data constitutes personal data and that the company did not take sufficient protective measures. Tele2 must therefore pay a penalty fee of SEK 12 million. – The Court of Appeal finds that Tele2 has violated the EU Data Protection Regulation by transferring personal data to the USA and must therefore pay a penalty fee, says Court of Appeal lawyer Peder Liljeqvist.




