Polismyndigheten – Violation Found (Sweden, 2026)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Sweden's privacy authority found that Polismyndigheten, the national police authority, did not provide enough information to travelers about how their personal data was processed at the airport. This matters because travelers need to know how their data is collected and used, especially during border control. Companies handling personal data must ensure clear communication about data practices.
What happened
The authority reprimanded Polismyndigheten for failing to inform travelers about the processing of their personal data during border checks.
Who was affected
Travelers arriving from third countries at Arlanda Airport were affected by the lack of information.
What the authority found
The authority ruled that Polismyndigheten did not provide sufficient information under Article 13 of GDPR, violating the requirement for transparency.
Why this matters
This finding emphasizes the need for clear communication about data processing practices, especially in public services. It serves as a reminder for all organizations to prioritize transparency in their data handling.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
The supervisory authority launched an investigation into the border control unit of the national police authority (the controller) at Arlanda Airport concerning the processing of the personal data of travellers arriving from third countries (the data subjects). During border control, the controller scanned the data subjects’ passports, and some travellers were required to provide fingerprints. The data collected was then possibly checked against various border control systems, such as the Schengen Information System (SIS) and the Visa Information System (VIS). There were no signs, brochures, or other written information on the processing of personal data available directly in the arrival hall. The only information available could be found on the controller’s website. The DPA issued the controller a reprimand for the infringement of Article 13 GDPR. It held that the controller had not provided the data subjects sufficient information about the processing of personal data during border controls. According to the DPA, the data subjects had not been able to easily access information regarding, among other things, what personal data is collected, how it is processed, and what rights data subjects have. The DPA took into account that not all travellers arriving from third countries could be expected to know which national authority is responsible for border controls, let alone be able to find and understand the information on the controller’s website without any guidance in the arrivals hall. It concluded that the lack of easily accessible information on this matter constituted a significant shortcoming: the border control operations included the processing of sensitive data, including biometric data, of a large number of travellers on a daily basis. On the other hand, the investigation was limited to one arrivals hall. The controller had also obtained signs with tailored information regarding the processing of personal data during border control since the beginning
Outcome
Violation Found
The DPA found a violation but did not impose a fine.
Related Enforcement Actions (2)
Other enforcement actions involving Polismyndigheten in SE
Violation Found
Details
About this data
Cite as: Cookie Fines. Polismyndigheten - Sweden (2026). Retrieved from cookiefines.eu
Last updated: