
Setterwalls Advokatbyrå Göteborg AB
INPLP member firm · Gothenburg, Sweden
Setterwalls is one of Sweden’s leading full-service business law firms, as well as one of Sweden’s largest law firms, with some 190 lawyers servicing clients from its three offices in Sweden’s largest cities – Stockholm, Gothenburg (Göteborg) and Malmoe (Malmö). Setterwalls is an independent law firm with an extensive, well-established international network. Established in 1874, it is also Sweden’s oldest law firm. Our Data Privacy and Data Protection legal team provides top-class expertise and strategic advice on all issues surrounding data privacy and data protection law as well as cyber-security. We are one of the leading data privacy and data protection teams in Sweden with a strong stand-alone business combined with the benefit of being part of a full-service firm. Since Scandinavia is one of the world’s most globalised business environments, Set-terwalls is accustomed to working in multinational contexts — across linguistic and cultural boundaries. All in all, about half of Setterwalls’ client assignments originate from countries outside of Sweden, including many of the world’s leading companies and banks and other financial institutions. Setterwalls has established a number of foreign desks — the China desk, the French desk, and the German desk — to meet clients’ demand for truly international exper-tise and legal advice. Each desk consists of a group of lawyers combining legal spe-cialist expertise with linguistic skills. They also have a deep understanding of the business culture and legal system of China, France, and Germany respectively. P.O. Box 11235, 404 25 Gothenburg Sankt Eriksgatan 5, 411 05 GothenburgT: +46 31 701 17 00E: gothenburg@setterwalls.seW: www.setterwalls.se fredrik.roos@setterwalls.seFredrik Roos is a partner at Setterwalls since 2010 and the leader of the firm’s IP/Tech team. He is a technology lawyer and assists Swedish and international companies with technology and IP intensive projects including partnerships, procurement, transactions, licensing, e-commerce, social media, telecommunications and intellectual property rights. He regularly advices on complex matters in relation to the introduction of new technologies and digital services. Based on his experience in both privacy and intellectual property law, and his technology background, Fredrik has found a niche in assisting clients with the negotiation of complex transactions and contracts relating to information ownership and the exploitation of data. He has a particular interest and experience in projects relating to data, machine learning, AI, Internet of Things (IoT) and Open Source Software. Fredrik also has more than 15 years’ experience of working with regulatory issues relating to privacy and data protection. emily.svedberg-possfelt@setterwalls.seEmily Svedberg-Possfelt is a senior associate specialized in information technology and commercial contract law. Emily has assisted some of Sweden’s largest corporations as well as international clients with their data privacy matters and commercial contract law.
Representatives

Fredrik Roos
partner

Emily Svedberg-Possfelt
member
Contact
Publications
- Controversial Swedish Freedom of Press Exemption challenged by the GDPRThe GDPR, designed to safeguard personal data, sometimes conflicts with rights like freedom of expression. In Sweden, online publishers can get a certificate of publication, exempting them from GDPR. This exemption, rooted in principles dated back to the second world war of free speech and transparency, is now exploited by websites to share personal data that GDPR would typically protect, such as addresses, incomes, and even criminal records, by offering them to any paying user. Traditional media criticize these practices, and despite lawsuits, such as for defamation, the sites have largely prevailed. However, recent court rulings have started to prioritize GDPR over these exemptions, creating legal uncertainty for any online publishers dependent on the exempti on. This article will clarify what these certificates are, their function in Sweden, and the impact of new court rulings that threaten this constitutional safeguard as well as the repercussions for online publishers.26 September 2024
- Insurance company fined SEK 35 million for security failures and putting data subjects’ data at risk.The Swedish Authority for Privacy Protection issued an administrative fine of SEK 35 million (3MEUR+) against the insurance company Trygg-Hansa due to severe security flaws that enabled unauthorized access to information via the internet and put 650 000 customers’ data at risk for a period of over two years . The case also provides guidance on IMY’s view for calculating the amount of fines in large groups of companies with autonomous business areas and separate IT systems.6 December 2023
- Sweden: The EU implements the Travel Rule for transfers of crypto-assetsThe so-called “Travel Rule” will soon be extended to cover transfers of crypto-assets following the approval of the revised Transfer of Funds Regulation. Crypto Asset Service Providers and intermediaries registered in the European Union will be obligated to collect, verify, store and exchange personal data of persons involved in a transaction – including when transfers are made to so-called un-hosted wallets. Crypto Asset Service Providers now need to establish procedures to adhere to the regulation as well as update and evaluate their processing of personal data.14 June 2023
- Multiple online pharmacies under investigation for the use of Facebook PixelThe Swedish Authority for Privacy Protection (“the Swedish DPA”) is currently investigating four online pharmacies in Sweden for their use of Facebook Pixels on their websites which has resulted in the transfer of personal data to Facebook. The investigations were initiated this summer when the pharmacies reported themselves to the authority for personal data incidents.22 December 2022
- Klarna Bank AB - the importance of transparency in privacy noticesEarlier this spring, the Swedish Authority for Privacy Protection issued an administrative fine of approximately EUR 724 000 against Klarna Bank AB, a global leading FinTech and payments company, following their investigation of the company, which showed that Klarna did not comply with several of the rules stipulated in the GDPR.10 August 2022
- Securing privacy compliance for Virtual Voice AssistantsVirtual Voice Assistants (“VVA”) continue to grow in popularity as the precision of the technology improves. The European Data Protection Board (“EDPB”) recently adopted new guidelines addressing how data controllers and data processors shall manage personal data to ensure that their VVAs are compliant with the European General Data Protection Regulation (“GDPR”).23 February 2022
- The Swedish Authority for Privacy Protection has published its privacy protection report for 2020In January 2021, the Swedish Authority for Privacy Protection (“IMY”) published its privacy protection report for 2020 (the “Report”). Based on the Report, organizations using technologies such as AI, IoT or web scraping should expect increased monitoring from a Swedish perspective. As highlighted by IMY in the Report, such organizations should focus on performing risk analyses and impact assessments, implementing privacy by design and privacy by default, as well as informing data subjects of the processing of their data in a clear and transparent manner.18 June 2021
- Facial recognition technologies from a Swedish data protection perspectiveTechnologies for facial recognition - capable of identifying and/or verifying a physical person automatically from a digital image or video - are developing at a fast pace and continue to emerge in the markets. Facial recognition technologies are normally based on the identification of certain facial features from an image and comparing it with images of faces collected in a database. The technologies available for facial recognition are many and the ways in which the technology can be used are countless.26 October 2020
Join the network
Applications from qualified privacy practices are reviewed individually by the INPLP board.