Compliance & frameworks

What is GDPR?

A plain-English guide to GDPR for security teams: what the law requires, how breaches are reported and penalised in Sweden and what it means for AI and data transfers.

Key takeaways
  • GDPR Article 32 makes appropriate security a legal duty, so a data breach becomes a compliance event as well as an IT problem.
  • Report a personal data breach to IMY, the Swedish authority, within 72 hours of becoming aware of it (Article 33).
  • Fines reach 20 million euros or 4 percent of global turnover. The largest to date is 1.2 billion euros, against Meta in 2023.
  • Swedish enforcement is real. IMY imposed 60.6 million kronor in fines in 2024.
  • The biggest breach fines follow security failures. British Airways paid 20 million pounds and Marriott 18.4 million pounds after attacks exposed customer data.
  • Processors are liable too. IMY fined SportAdmin 6 million kronor after a 2025 SQL injection exposed 2.1 million people, many of them children.
  • Appoint a data protection officer if you are a public body, monitor people at scale or handle sensitive data at scale.
  • Run a konsekvensbedömning (a data protection impact assessment) before high-risk processing begins (Article 35).
  • Where data can be legally reached matters as much as where it is stored. Schrems II and the US CLOUD Act shape transfer risk alongside the physical location of the server.
  • AI brings new duties. Personal data used to train or run AI still needs a lawful basis, data minimisation and, for automated decisions, Article 22 safeguards.

GDPR Defined in Plain Terms

The General Data Protection Regulation (GDPR) is the European Union law that governs how organisations collect, use and protect personal data. In force since 25 May 2018 as Regulation (EU) 2016/679, it applies to any organisation that handles the data of people in the EU wherever that organisation is based.

For security teams, one article matters most. GDPR Article 32 requires appropriate technical and organisational measures to keep personal data safe. That turns a data breach into a legal event not only an IT one and it is why the largest GDPR penalties so often follow a security failure.

Personal data means any information that relates to an identified or identifiable person from a name or email address to an IP address or location record. The regulation reaches beyond Europe under Article 3 so a Swedish supplier and a US cloud vendor can both fall in scope. The full consolidated text is published on EUR-Lex.

What GDPR Requires for Security

GDPR does not hand you a checklist of tools. It sets duties and expects you to choose measures that match the risk. Six of them shape day-to-day security work.

  • Security of processing (Article 32): Appropriate technical and organisational measures from encryption and pseudonymisation to access control, backups and regular testing.
  • Data protection by design and by default (Article 25): Build privacy and security into systems from the start rather than adding them later.
  • Breach notification (Article 33): Report a personal data breach to the supervisory authority within 72 hours of becoming aware of it.
  • Telling the people affected (Article 34): Inform data subjects without undue delay when a breach is likely to put them at high risk.
  • Impact assessments (Article 35): Run a data protection impact assessment, known in Swedish as a konsekvensbedömning, before high-risk processing begins.
  • The accountability principle (Article 5(2)): Keep records that show you meet these duties, because you have to be able to prove it.
What GDPR Requires for Security

In Sweden the supervisory authority is IMY, the Swedish Authority for Privacy Protection. A breach report goes to IMY and the 72-hour clock starts when you become aware of the breach well before you finish investigating it.

A konsekvensbedömning is required when processing is likely to be high risk, for example large-scale monitoring or handling sensitive data. IMY publishes a list of the processing that always needs one and running it early makes it a design tool rather than a late paperwork exercise.

Controllers, Processors and the DPO

GDPR splits responsibility between two roles and knowing which one you are decides what you owe.

A controller decides why and how personal data is processed. A processor acts on the controller’s instructions for example a payroll provider or a cloud host. Both carry security duties under Article 32 and a controller must put a written contract in place with every processor under Article 28.

The split does not let either side off the hook. A Swedish case in 2025 saw IMY fine a software supplier acting purely as a processor which shows the duty follows the data rather than the job title.

GDPR also gives people rights over their data. They can ask to see it, correct it, delete it under the right to erasure, move it to another provider under Article 20 and object to certain uses. They can also refuse a purely automated decision that has a significant effect on them under Article 22.

A data protection officer (DPO) is the person who oversees GDPR compliance and acts as the contact point for IMY. You must appoint one if you are a public authority, if your core activity is large-scale monitoring of people or if you process special category data at scale. Many organisations outside those triggers appoint one anyway to hold the duty in one place.

What GDPR Failures Cost

GDPR fines come in two tiers. Lower-tier breaches can reach 10 million euros or 2 percent of global annual turnover whichever is higher. Serious breaches such as ignoring the core principles or people’s rights, can reach 20 million euros or 4 percent.

The numbers are real. The largest GDPR fine to date is 1.2 billion euros issued to Meta by Ireland’s Data Protection Commission in May 2023 over unlawful data transfers to the United States.

Sweden is not a soft touch. IMY imposed 60.6 million kronor in fines during 2024 and its recent cases have turned on weak security rather than paperwork alone.

The fine is rarely the whole bill. A breach also brings incident response, notification to regulators and customers, legal costs, lost business and civil claims from the people whose data leaked. For most organisations those costs add up to far more than the fine.

Real-World Cases

British Airways

In 2018 an attacker broke into British Airways systems and quietly redirected customer payment details to a fraudulent site. Around 429,000 people were affected before the skimming was found.

The UK Information Commissioner’s Office found that BA had failed to secure the data as Article 32 requires. It first proposed 183 million pounds and issued a final fine of 20 million pounds in October 2020, the largest the ICO had issued under GDPR at the time.

The attacker got in through the credentials of a third-party supplier with remote access. Multi-factor authentication on that access together with tighter monitoring of outbound traffic would have closed the door the attack walked through.

Marriott

Marriott discovered in 2018 that attackers had been inside the Starwood reservation system since 2014, four years before anyone noticed. Around 339 million guest records were exposed worldwide.

The breach was inherited. Marriott bought Starwood in 2016 and took on the compromised systems without spotting the intruder. The ICO issued a final fine of 18.4 million pounds in October 2020 for insufficient security and weak due diligence.

Basic detection would have surfaced four years of unauthorised access long before it did. So would a proper security review of the systems Marriott acquired since a merger inherits the seller’s risks along with its assets.

SportAdmin

In January 2025 attackers used an SQL injection to break into SportAdmin, a Swedish platform used by sports clubs. The personal data of more than 2.1 million people leaked, most of them children and young players.

SportAdmin was a processor, handling data on behalf of the clubs. IMY still fined it 6 million kronor finding it had failed to put appropriate security measures in place under Article 32.

SQL injection is one of the oldest web weaknesses and is well understood. Parameterised queries and input validation are standard secure-coding practice and they shut down injection attacks like this one.

GDPR, AI and the Wider Rulebook

GDPR does not sit on its own. Its security duties overlap with other EU rules and for many Swedish organisations several apply at once.

The security measures in NIS2 Article 21 and GDPR Article 32 cover much of the same ground from encryption and access control to breach detection and staff training. GDPR then adds duties NIS2 does not such as data subject rights, a DPO and impact assessments. For the Swedish transposition, see our guide to NIS2 compliance.

GDPR, AI and the Wider Rulebook

Reporting can double up. A ransomware attack that exposes personal data is both a GDPR breach and for essential and important entities, a reportable cyber incident under Cybersäkerhetslagen. The personal data breach goes to IMY within 72 hours. Since 1 July 2026 the cyber incident goes to the national cyber security centre at FRA which took over that role from MCF (formerly MSB).

Financial firms answer to more. Under DORA, Swedish financial entities report major ICT incidents to Finansinspektionen and must show operational resilience. Where DORA applies it takes precedence over NIS2. Our guide to DORA compliance covers the overlap.

AI raises fresh GDPR questions. Training a model on personal data still needs a lawful basis and data minimisation and using AI to make decisions about people brings Article 22 into play. The EU AI Act adds its own obligations on top so an AI system can owe duties under both laws at once.

An ISO 27001 management system is a practical way to evidence much of what Article 32 expects.

Data Transfers and Where Your Data Lives

Where your data physically sits is only half the question. GDPR restricts sending personal data outside the EU and who can legally reach the data matters as much as the location of the server.

In 2020 the Court of Justice of the EU struck down the Privacy Shield transfer deal in its Schrems II ruling. It kept standard contractual clauses alive but said organisations must check whether foreign law undermines them before relying on them.

The replacement, the EU-US Data Privacy Framework, took effect in 2023 and remains valid in 2026. It survived a first legal challenge when the EU General Court upheld it in September 2025 though that ruling is under appeal at the Court of Justice, so its future is not settled.

This is where the US CLOUD Act bites. A provider under US jurisdiction can be compelled to hand over data even when the servers sit in Europe which is why serious buyers weigh who controls a service and which laws bind it alongside the country on the data centre map.

How to Build GDPR-Ready Security

GDPR compliance is mostly good security done deliberately and written down. Start with these.

  • Map your personal data. You cannot protect or minimise what you have not located so record what you hold, where it lives and who can reach it.
  • Collect less and keep it for less time. Data you do not hold cannot leak.
  • Encrypt personal data at rest and in transit and manage the keys properly.
  • Lock down access with multi-factor authentication and least privilege, the gap the British Airways attackers walked through.
  • Patch and test your applications including for injection flaws like the one behind the SportAdmin breach.
  • Monitor for intrusions so a breach is caught in hours rather than the years Marriott lost.
  • Test your backups by restoring them because availability is part of Article 32.
  • Run a konsekvensbedömning before any high-risk processing.
  • Vet your processors and put an Article 28 contract in place with each one.
  • Rehearse the 72-hour breach drill so the report to IMY is ready before you need it.
  • Review your data transfers and know which safeguard each one relies on.

None of this is exotic. It is the same security hygiene that stops most attacks applied with GDPR’s duties in mind and documented so you can prove it. To see how these controls map to the regulation, our GDPR compliance page lays it out.

Myths & Facts

Myth

GDPR is just a legal or paperwork problem.

Only huge companies get fined.

If we use a processor, a breach is their problem.

GDPR only applies to companies based in the EU.

Storing data in the EU means the transfer rules do not apply.

We can decide later whether to report a breach.

Fact

GDPR Article 32 makes security a legal duty, and several major fines, including British Airways and Marriott, followed a security failure rather than a filing error.

IMY fined SportAdmin, a mid-sized supplier, 6 million kronor. Small and mid-sized organisations are firmly in scope.

Processors carry direct security duties, and SportAdmin was fined as a processor. Controllers must also vet and contract them under Article 28.

Article 3 extends GDPR to any organisation offering goods or services to, or monitoring, people in the EU, wherever it is based.

A provider under US jurisdiction can be compelled to hand over EU-stored data, so control and applicable law matter as much as location.

Article 33 gives you 72 hours from becoming aware. Missing that window is itself a breach of GDPR, even if you handled the incident well.

Test Yourself

Four real-world scenarios, then six knowledge questions. See how prepared you would be under pressure.

Scenario Simulation

  1. Your team confirms on Friday afternoon that a database of customer records was accessed by an attacker.

    What is the priority?

    • Start the clock on the 72-hour breach report to IMY and begin your assessment
    • Wait until Monday when the full team is back before doing anything
    • Only tell customers, since regulators do not need to know
  2. You run a small software platform that processes personal data for your clients. Attackers exploit an SQL injection flaw and steal user records.

    Where does responsibility sit?

    • With you as well, because a processor carries its own Article 32 security duties
    • Only with your clients, since they are the controllers
    • With the attacker only, so no fine can reach your company
  3. A vendor offers to store your customer data in a data centre inside the EU, but the vendor is a US-headquartered company.

    What should you check before signing?

    • Whether US law could compel the vendor to hand over the data, and which transfer safeguard applies
    • Nothing, because EU servers automatically satisfy GDPR
    • Only the price, since data location is not a GDPR concern
  4. A third-party supplier needs remote access to part of your network to do their job.

    What is the safest way to grant it?

    • Multi-factor authentication and least-privilege access, limited to what they need
    • A shared password the whole supplier team can use
    • Full administrator access so they never get blocked

Knowledge Test

  1. Which GDPR article sets the requirement to secure personal data with appropriate measures?

    • Article 6
    • Article 32
    • Article 17
    • Article 82

    Article 32 requires appropriate technical and organisational measures to secure personal data.

  2. How long do you have to report a personal data breach to the supervisory authority?

    • 24 hours
    • 72 hours
    • One week
    • One month

    Article 33 requires notification within 72 hours of becoming aware of the breach.

  3. What is the maximum GDPR fine for the most serious breaches?

    • 10 million euros or 2 percent of global turnover
    • 20 million euros or 4 percent of global turnover
    • 5 million euros
    • 1 percent of national turnover

    Serious breaches can reach 20 million euros or 4 percent of global annual turnover, whichever is higher.

  4. Who is the supervisory authority for GDPR in Sweden?

    • MCF
    • Finansinspektionen
    • IMY
    • FRA

    IMY, the Swedish Authority for Privacy Protection, enforces GDPR in Sweden.

  5. In the SportAdmin case, why was the company fined even though it was a processor?

    • Processors have no GDPR duties
    • Processors carry their own Article 32 security duties
    • Only controllers can be fined
    • The fine was a mistake

    Processors are directly liable for their own security measures under Article 32, as the SportAdmin fine showed.

  6. What is a konsekvensbedömning?

    • A breach report
    • A data protection impact assessment
    • A cookie banner
    • A type of encryption

    A konsekvensbedömning is the Swedish term for a data protection impact assessment under Article 35.

Take It with You

Share the Summary PDF with Your Team

A short distilled brief in PDF: key findings, red flags and action steps.

Download summary PDF

Why Training Matters

Most breaches start with a person rather than a firewall. The British Airways attack began with stolen supplier credentials, and phishing remains the most common way attackers get their first foothold. GDPR recognises this, and Article 32 counts staff awareness as part of appropriate security. Training that teaches your people to spot suspicious requests, handle personal data carefully and report incidents quickly turns your biggest risk into a working line of defence.

Frequently Asked Questions

What is GDPR?

GDPR, the General Data Protection Regulation, is the EU law governing how organisations handle personal data. In force since 25 May 2018, it sets principles for lawful, secure and transparent processing, gives people rights over their data and applies to any organisation handling the data of people in the EU, wherever it is based.

What does GDPR require for cybersecurity?

GDPR Article 32 requires appropriate technical and organisational measures to keep personal data secure, judged against the risk. In practice that means encryption, access control, monitoring, tested backups and staff awareness. It also requires you to report a personal data breach to the supervisory authority within 72 hours under Article 33.

Who enforces GDPR in Sweden?

IMY, the Swedish Authority for Privacy Protection, enforces GDPR in Sweden. It investigates complaints and breaches, issues fines and publishes guidance, including on impact assessments. Personal data breaches under Article 33 are reported to IMY. In 2024 IMY imposed 60.6 million kronor in administrative fines.

How big are GDPR fines?

GDPR fines run in two tiers. Lower-tier breaches reach 10 million euros or 2 percent of global annual turnover, and serious breaches reach 20 million euros or 4 percent, whichever is higher. The largest fine so far is 1.2 billion euros, issued to Meta in 2023 over unlawful data transfers.

When must you report a data breach under GDPR?

You must notify the supervisory authority, IMY in Sweden, within 72 hours of becoming aware of a personal data breach, under Article 33. If the breach is likely to put people at high risk, you must also tell them without undue delay under Article 34. Missing the deadline is itself a violation.

What is a data protection officer and do we need one?

A data protection officer (DPO) oversees GDPR compliance and is the contact point for IMY and data subjects. You must appoint one if you are a public authority, if your core activity is large-scale monitoring of people or if you process special category data at scale. Others appoint one voluntarily.

What is a konsekvensbedömning?

A konsekvensbedömning is the Swedish term for a data protection impact assessment (DPIA) under GDPR Article 35. It is a structured review of the privacy and security risks of a processing activity, required before high-risk processing begins. IMY publishes a list of the processing that always needs one.

Does GDPR apply to artificial intelligence?

Yes. Whenever an AI system uses personal data, GDPR applies. Training or running a model on personal data needs a lawful basis and data minimisation, and Article 22 limits purely automated decisions that significantly affect people. The EU AI Act adds further obligations, so both laws can apply to the same system.

You Understand the Risk.
Now See Where You Stand.

Book a 30-minute briefing with one of our analysts, or run the free breach check first to find out what attackers already know about your organisation.

Book a 30-Min Briefing
No sales pitch, just a straight assessment

How eBuilder Security Can Help

Awareness is the first layer. These are the services that turn it into measurable protection.