Continue reading on DataGuidance with:
Free Member
Limited ArticlesCreate an account to continue accessing select articles, resources, and guidance notes.
Already have an account? Log in
Sweden: IMY establishes requirements for accreditation of certification bodies
On August 14, 2024, the Swedish Authority for Privacy Protection (IMY) announced its decision for the establishment of requirements for accreditation of certification bodies. IMY noted that the requirements must be applied by the Board for Accreditation and Technical Control (Swedac) when accrediting certification bodies that issue certifications according to the General Data Protection Regulation (GDPR).
According to IMY, these requirements are in addition to the requirements under existing Swedac regulations, which certification bodies must fulfill. IMY stated that the certification makes it possible for certification bodies that want to issue certificates in Sweden to start their business. This may apply to certificates for personal data processing within the entire EEA, EU data protection seals, or certificates for personal data processing that mainly take place in Sweden.
Finally, IMY noted that those who wish to apply for the certification scheme approval must make an application to IMY.
You can read the press release here and the decision here, both only available in Swedish.