# IMY reprimands Swedish Police for inadequate GDPR Article 13 info at Arlanda border

- Type: Enforcement
- Source: IMY (Sweden)
- Date: 2026-07-03
- Original: https://gdprhub.eu/index.php?title=IMY_(Sweden)_-_IMY-2024-2904
- Canonical: https://overview.legal/posts/57263
- Topics: Personal Data, Controllers, Information Provision Modalities and Communication Methods, Supervisory Authorities, Processing, Special Categories of Data, International Transfer, Data Controller, Types of Special Categories of Personal Data, Biometric Data

## Summary

Facts — The supervisory authority launched an investigation into the border control unit of the national police authority (the controller) at Arlanda Airport concerning the processing of the personal data of travellers arriving from third countries (the data subjects). During border control, the controller scanned the data subjects’ passports, and some travellers were required to provide fingerprints. The data collected was then possibly checked against various border control systems, such as the Schengen Information System (SIS) and the Visa Information System (VIS). There were no signs, brochures, or other written information on the processing of personal data available directly in the arrival hall. The only information available could be found on the controller’s website. Holding — The DPA issued the controller a reprimand for the infringement of Article 13 GDPR. It held that the controller had not provided the data subjects sufficient information about the processing of personal data during border controls. According to the DPA, the data subjects had not been able to easily access information regarding, among other things, what personal data is collected, how it is processed, and what rights data subjects have. The DPA took into account that not all travellers arriving from third countries could be expected to know which national authority is responsible for border controls, let alone be able to find and understand the information on the controller’s website without any guidance in the arrivals hall. It concluded that the lack of easily accessible information on this matter constituted a significant shortcoming: the border control operations included the processing of sensitive data, including biometric data, of a large number of travellers on a daily basis. On the other hand, the investigation was limited to one arrivals hall. The controller had also obtained signs with tailored information regarding the processing of personal data during border control since the beginning of the investigation. Based on an overall assessment, the DPA held that the lack of information required by Article 13 in the arrivals hall constituted a minor GDPR violation.

## Full text

1(5) Police Authority Registration number: IMY-2024-2904 Decision after supervision according to, among others, VIS- Your registration number: the regulation and the border regulation A276.737/2024 – Police Authority Date: 2026-07-03 Decision of the Swedish Data Protection Authority The Swedish Data Protection Authority finds that the Police Authority (202100-0076) has processed personal data in violation of Article 13 of the Data Protection Regulation by not providing sufficient information to data subjects about the personal data processing that takes place at the border control at Arlanda Airport. IMY decides, based on Article 58(2)(b) of the Data Protection Regulation, to give the Police Authority a reprimand for the violation of Article 13. Statement of the inspection case Purpose of the inspection The Swedish Data Protection Authority (IMY) has initiated an inspection of the Police Authority's border section at Arlanda Airport. The purpose of the inspection has been to check whether the 2 personal data processing carried out in the border control (in accordance with the Borders Code) when using the Schengen Information System (SIS) and the Visa Information System (VIS) 3 4 is in compliance with the Border Regulation, the VIS Regulation and the Data Protection Regulation. Method and scope of the inspection The inspection was carried out through an inspection at Arlanda Airport, which was then followed up with supplementary questions. The inspection was limited in that it only covered the border control in one of the arrival halls at Arlanda Airport where travellers arrive from third countries. IMY has specifically reviewed which information on Postal address: 1Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing 104 20 Stockholm Directive 95/46/EC (General Data Protection Regulation). Website: 2Regulation (EU) 2016/399 of the European Parliament and of the Council of 9 March 2016 on a Union Code on the rules on the movement of persons across borders (Schengen Borders Code). www.imy.se 3Regulation (EU) 2018/1861 of the European Parliament and of the Council of 28 November 2018 on the establishment, operation and Email: use of the Schengen Information System (SIS) in the field of entry and exit checks, amending the Convention imy@imy.se implementing the Schengen Agreement and amending and repealing Regulation (EC) No 1987/2006. 4Regulation (EC) No 767/2008 of the European Parliament and of the Council of 9 July 2008 on the Visa Information System (VIS) and the exchange of data between Member States on short-stay visas (VIS- 08-657 61 00 Regulation).Privacy Protection Authority Case number: IMY-2024-2904 2(5) Date: 2026-07-03 data subjects' rights available on site, what training regarding data protection those working in border control receive and what personal data is processed in border control. IMY has also examined the authorisations of employees and how the use of the systems is logged. In addition, IMY has examined the handling of personal data incidents linked to the processing of personal data at the police border control and what security measures the Police Authority has taken regarding the processing. Reasons for the decision Applicable provisions, etc. What regulations apply to the processing? It follows from both the VIS Regulation and the Border Regulation that the Data Protection Regulation also applies when competent authorities process personal data in accordance with the respective regulation. The police authority's processing of personal data in connection with border control in accordance with the Border Code therefore needs to be in accordance with the above-mentioned regulations. IMY's corrective powers follow from the Data Protection Regulation. Information to data subjects Article 13 of the Data Protection Regulation states that the controller shall provide the data subject with certain information about the processing of personal data collected from a data subject in connection with the receipt of these. This information shall include, among other things, who is the controller, the purpose and legal basis for the processing and contact details for the data protection officer. Furthermore, according to Article 12 of the Data Protection Regulation, this information shall, as a basic rule, be provided in writing in an easily accessible and understandable manner. Recital 39 of the Data Protection Regulation states that it should be clear and obvious to natural persons how personal data relating to them are collected, used, consulted or otherwise processed and to what extent the personal data are or will be processed. When providing information about the processing of personal data, the specific circumstances and context of the personal data processing shall be taken into account. A controller may use a tiered approach to provide the information set out in Article 13. The tiered approach means that the information that is of most importance to the data subject should be presented even before the data subject has his or her personal data processed, for example on a sign. The sign should contain information on the purpose of the processing and the identity of the controller and a description of the data subject 5Cf. recital 17 of the VIS Regulation. Now also regulated in Article 36a(2) which is introduced by Regulation (EU) 2021/1134 of the European Parliament and of the Council of 7 July 2021 amending Regulations (EC) No 767/2008, (EC) No 810/2009, (EU) 2016/399, (EU) 2017/2226, (EU) 2018/1240, (EU) 2018/1860, (EU) 2018/1861, (EU) 2019/817 and (EU) 2019/1896 of the European Parliament and of the Council and repealing Council Decisions 2004/512/EC and 2008/633/JHA, with a view to 6reforming the Visa Information System. 7See Article 51(2) of the Borders Regulation. 8See Article 94 of the Data Protection Regulation. See also Article 29 Working Party Guideline WP260rev.01 on transparency and information to data subjects. 9See recital 60 of the Data Protection Regulation.Integrity Protection Authority Case number: IMY-2024-2904 3(5) Date: 2026-07-03 rights. Other information can be provided in other ways, e.g. on a website or in a 10 complete information sheet or a brochure. IMY's assessment During the inspection, it became clear that the Police Authority at the border control for entry from third countries processes personal data from all travellers by scanning the passport document. Some travellers also need to provide their fingerprints. The data that is collected is, depending on the situation, run against different border control systems, e.g. VIS and SIS. During the inspection, IMY noted that there was a lack of written information about the processing of personal data to arriving travellers in connection with their providing fingerprints and other information at the border control. There were neither signs, brochures nor other written information to be consulted directly in the arrival hall in question. The only information available was that which was published on the Police Authority's website, but there was no reference to this information in the arrival hall. Even if information regarding the current processing was published on the Police Authority's website, it needs to be taken into account that not all travellers can be assumed to have the opportunity to find and utilize the information on the website during the time they are in the arrivals hall. Travellers from third countries cannot be expected to know that it is the Police Authority that is responsible for border controls in Sweden, since it looks different in the member states, and therefore, without special information, understand that they should turn to the Police Authority's website for information about the processing of personal data. The Police Authority has stated that one month after the inspection, in connection with a test prior to the implementation of a new system (the EEA entry and exit system), they put up signs at the border controls at Arlanda Airport with information about the authority's processing of personal data. However, IMY notes that the sign mainly contained information about the testing activities themselves and only very brief and general information about the authority's personal data processing, thus no adapted information about the processing that takes place at the border control. Against this background, IMY finds that there was no opportunity for those who would pass the border control to access information about the personal data processing that the Police Authority carries out at the border control in an easily accessible manner. The Police Authority, as the personal data controller for the processing, has thus failed in its information obligation according to Article 13 of the Data Protection Regulation. What has otherwise emerged in the review does not give IMY reason to establish any further shortcomings. Choice of intervention In the event of violations of the Data Protection Regulation, IMY has a number of corrective powers available according to Article 58(2)(a)- j of the Regulation, including reprimand, injunction and penalty payment. It further follows from Chapter 6. 2 § of the Data Protection Act that11 1Cf. recital 39 of the Data Protection Regulation and the Article 29 Working Party guideline WP260rev.01 on transparency and information to data subjects. 1Act (2018:218) with supplementary provisions to the EU Data Protection Regulation.Integrity Protection Authority Case number: IMY-2024-2904 4(5) Date: 2026-07-03 The IMY may levy penalty fees on authorities for violations of, among others, Article 13 of the Data Protection Regulation. It is clear from Article 83(2) of the Regulation that the IMY shall impose administrative penalty fees in addition to or instead of the other measures referred to in Article 58(2) depending on the circumstances of the individual case. If it is a minor violation, the IMY may, as stated in recital 148 of the Data Protection Regulation, issue a reprimand in accordance with Article 58(2)(b) of the Data Protection Regulation instead of imposing a penalty fee. Consideration shall be given to aggravating and mitigating circumstances in the case, such as the nature, severity and duration of the violation, as well as previous violations of relevance. The IMY has assessed that the Police Authority has failed to fulfil its information obligation in accordance with Article 13 of the Data Protection Regulation because there has been a lack of opportunity for those who have crossed the border to obtain information in an easily accessible manner about, among other things, what personal data is collected, how it is processed and what rights the data subjects have. When assessing the choice of intervention, the IMY takes into account that at the current border control at Arlanda Airport, sensitive data such as biometric data from a large number of travellers, including children, is processed every day. It is of great importance that the individual understands why his or her personal data is being processed and what rights are associated with it. According to IMY, it is therefore a significant shortcoming that there has been a lack of easily accessible information about this at the border control. In this case, however, the supervision is limited in that the inspection only covered an arrival hall at Arlanda Airport, which constitutes a limited part of the Police Authority's border control operations in Sweden. IMY also shares the Police Authority's assessment that it may be considered common knowledge among the majority of travellers that their personal data will be processed to some extent in connection with a border control. It is also taken into account that IMY has been informed that, during the handling of the supervision, the Police Authority has, among other things, produced signs with adapted information regarding the personal data processing that takes place at the border control. Furthermore, no previous relevant violations have emerged on the part of the Police Authority. In an overall assessment, IMY therefore considers that this is a minor infringement as referred to in recital 148 of the Data Protection Regulation and that a reprimand is a sufficient and proportionate measure to highlight the infringement and ensure compliance with the Data Protection Regulation. Against this background, IMY considers that the Police Authority should be given a reprimand in accordance with Article 58(2)(b) of the Data Protection Regulation for the infringement. __________________________ This decision has been made by Head of Unit Jonas Agnvall following a presentation by the lawyer Linda Markus. In the final handling of the case, the departmental lawyer Lisa Zettervall and the IT and information security specialist Mats Juhlén have also participated. Jonas Agnvall Copy to Data Protection OfficerIntegrity Protection Authority Filing number: IMY-2024-2904 5(5) Date: 2026-07-03 How to appeal If you wish to appeal the decision, you should write to IMY. Indicate in the letter which decision you are appealing and the change you are requesting. The appeal must have been received by IMY within three weeks of the day you received the decision. If you are a party representing the public, however, the appeal must have been received within three weeks of the day on which the decision was notified. If the appeal has been received in good time, IMY will forward it to the Administrative Court in Stockholm for review. You can e-mail the appeal to IMY if it does not contain any privacy-sensitive personal data or information that may be subject to confidentiality. The authority contact details are stated on the first page of the decision.

## Cited law provisions (1)

### GDPR — gdpr-art-13-en

Information to be provided where personal data are collected from the data subject

---
Generated by overview.legal · https://overview.legal/posts/57263 · 2026-08-23
