Support Centre

You have out of 5 free articles left for the month

Signup for a trial to access unlimited content.

Start Trial

Continue reading on DataGuidance with:

Free Member

Limited Articles

Create an account to continue accessing select articles, resources, and guidance notes.

Free Trial

Unlimited Access

Start your free trial to access unlimited articles, resources, guidance notes, and workspaces.

Sweden: IMY establishes requirements for accreditation of certification bodies

On August 14, 2024, the Swedish Authority for Privacy Protection (IMY) announced its decision for the establishment of requirements for accreditation of certification bodies. IMY noted that the requirements must be applied by the Board for Accreditation and Technical Control (Swedac) when accrediting certification bodies that issue certifications according to the General Data Protection Regulation (GDPR).

According to IMY, these requirements are in addition to the requirements under existing Swedac regulations, which certification bodies must fulfill. IMY stated that the certification makes it possible for certification bodies that want to issue certificates in Sweden to start their business. This may apply to certificates for personal data processing within the entire EEA, EU data protection seals, or certificates for personal data processing that mainly take place in Sweden. 

Finally, IMY noted that those who wish to apply for the certification scheme approval must make an application to IMY.

You can read the press release here and the decision here, both only available in Swedish.