Polismyndigheten – Violation Found (Sweden, 2026)

Violation Found
Integritetsskyddsmyndigheten3 July 2026Sweden
final
Violation Found

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Sweden's privacy authority found that Polismyndigheten, the national police authority, did not provide enough information to travelers about how their personal data was processed at the airport. This matters because travelers need to know how their data is collected and used, especially during border control. Companies handling personal data must ensure clear communication about data practices.

What happened

The authority reprimanded Polismyndigheten for failing to inform travelers about the processing of their personal data during border checks.

Who was affected

Travelers arriving from third countries at Arlanda Airport were affected by the lack of information.

What the authority found

The authority ruled that Polismyndigheten did not provide sufficient information under Article 13 of GDPR, violating the requirement for transparency.

Why this matters

This finding emphasizes the need for clear communication about data processing practices, especially in public services. It serves as a reminder for all organizations to prioritize transparency in their data handling.

GDPR Articles Cited

AI-verified

Art. 13(GDPR)
View original scraped data
Art. 13(GDPR)

Original data from scraper before AI verification against source document.

Source verified 9 July 2026
verified correct
Full Legal Summary
Detailed

The supervisory authority launched an investigation into the border control unit of the national police authority (the controller) at Arlanda Airport concerning the processing of the personal data of travellers arriving from third countries (the data subjects). During border control, the controller scanned the data subjects’ passports, and some travellers were required to provide fingerprints. The data collected was then possibly checked against various border control systems, such as the Schengen Information System (SIS) and the Visa Information System (VIS). There were no signs, brochures, or other written information on the processing of personal data available directly in the arrival hall. The only information available could be found on the controller’s website. The DPA issued the controller a reprimand for the infringement of Article 13 GDPR. It held that the controller had not provided the data subjects sufficient information about the processing of personal data during border controls. According to the DPA, the data subjects had not been able to easily access information regarding, among other things, what personal data is collected, how it is processed, and what rights data subjects have. The DPA took into account that not all travellers arriving from third countries could be expected to know which national authority is responsible for border controls, let alone be able to find and understand the information on the controller’s website without any guidance in the arrivals hall. It concluded that the lack of easily accessible information on this matter constituted a significant shortcoming: the border control operations included the processing of sensitive data, including biometric data, of a large number of travellers on a daily basis. On the other hand, the investigation was limited to one arrivals hall. The controller had also obtained signs with tailored information regarding the processing of personal data during border control since the beginning

Outcome

Violation Found

The DPA found a violation but did not impose a fine.

Details

Decision Date

3 July 2026

Authority

Integritetsskyddsmyndigheten

GDPRhub ID

gdprhub-10115

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Polismyndigheten - Sweden (2026). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: