
Setterwalls Advokatbyrå
INPLP member firm · Gothenburg, Sweden
Setterwalls is one of Sweden’s leading full-service business law firms and one of the largest, with some 190 lawyers advising clients from its offices in Stockholm and Gothenburg. Established in 1874, Setterwalls is Sweden’s oldest law firm and remains fully independent, supported by an extensive and well-established international network. In 2026, Setterwalls was named “Law Firm of the Year – Sweden” by Chambers & Partners. Setterwalls’ Data Privacy and Data Protection team provides strategic advice and specialist expertise across the full range of data privacy, data protection and cybersecurity matters. Recognised as one of Sweden’s leading teams in this field, the team combines a strong standalone data privacy and data protection practice with the broader capabilities of a full-service business law firm. Scandinavia is one of the world’s most globalised business environments, and Setterwalls regularly works in multinational contexts and across linguistic and cultural boundaries. Approximately half of the firm’s client assignments originate from outside Sweden, including work for international companies, banks and other financial institutions. To support clients with international legal and business needs, Setterwalls has established foreign desks covering China, France and Germany, bringing together lawyers with relevant legal expertise, language skills and an understanding of the respective business cultures and legal systems. Fredrik Roos is a partner at Setterwalls and heads the firm’s IP7Tech team. He has advised companies on technology, intellectual property, commercial contracts, data and privacy since 2003. Fredrik advises Swedish and international companies on technology and IP-intensive projects, including partnerships, transactions, licensing, services and sourcing. He regularly advises on complex matters relating to the introduction of new technologies and digital services, with particular experience in projects involving data, AI, automation, IoT and Open Source Software. Combining his experience in privacy and intellectual property law with a technology background, Fredrik has developed a distinct niche in negotiating complex transactions and contracts concerning the ownership and commercial exploitation of data. He has more than 20 years of experience of regulatory matters relating to privacy and data protection. Emily Svedberg-Possfelt is Counsel at Setterwalls, specialising in IT law, data protection and commercial contracts. She advises Swedish and international companies in some of the most technology-intensive and innovative industries. Emily has particular expertise in technology-related regulation and data protection, including cybersecurity, GDPR compliance, cross-border data transfers and personal data breaches. She also advises on a broad range of IT and software-related matters, including intellectual property, e-commerce, electronic signatures and social media, with particular expertise in open source software regulation. Her practice also includes drafting and negotiating commercial and technology agreements, dispute resolution, transactions and regulatory matters. Emily takes a practical and commercially grounded approach and has advised some of Sweden’s largest companies as well as international clients on data privacy and commercial contract matters.
Representatives

Fredrik Roos
partner

Emily Svedberg-Possfelt
member
Contact
Publications
- Controversial Swedish Freedom of Press Exemption challenged by the GDPRThe GDPR, designed to safeguard personal data, sometimes conflicts with rights like freedom of expression. In Sweden, online publishers can get a certificate of publication, exempting them from GDPR. This exemption, rooted in principles dated back to the second world war of free speech and transparency, is now exploited by websites to share personal data that GDPR would typically protect, such as addresses, incomes, and even criminal records, by offering them to any paying user. Traditional media criticize these practices, and despite lawsuits, such as for defamation, the sites have largely prevailed. However, recent court rulings have started to prioritize GDPR over these exemptions, creating legal uncertainty for any online publishers dependent on the exempti on. This article will clarify what these certificates are, their function in Sweden, and the impact of new court rulings that threaten this constitutional safeguard as well as the repercussions for online publishers.26 September 2024
- Insurance company fined SEK 35 million for security failures and putting data subjects’ data at risk.The Swedish Authority for Privacy Protection issued an administrative fine of SEK 35 million (3MEUR+) against the insurance company Trygg-Hansa due to severe security flaws that enabled unauthorized access to information via the internet and put 650 000 customers’ data at risk for a period of over two years . The case also provides guidance on IMY’s view for calculating the amount of fines in large groups of companies with autonomous business areas and separate IT systems.6 December 2023
- Sweden: The EU implements the Travel Rule for transfers of crypto-assetsThe so-called “Travel Rule” will soon be extended to cover transfers of crypto-assets following the approval of the revised Transfer of Funds Regulation. Crypto Asset Service Providers and intermediaries registered in the European Union will be obligated to collect, verify, store and exchange personal data of persons involved in a transaction – including when transfers are made to so-called un-hosted wallets. Crypto Asset Service Providers now need to establish procedures to adhere to the regulation as well as update and evaluate their processing of personal data.14 June 2023
- Multiple online pharmacies under investigation for the use of Facebook PixelThe Swedish Authority for Privacy Protection (“the Swedish DPA”) is currently investigating four online pharmacies in Sweden for their use of Facebook Pixels on their websites which has resulted in the transfer of personal data to Facebook. The investigations were initiated this summer when the pharmacies reported themselves to the authority for personal data incidents.22 December 2022
- Klarna Bank AB - the importance of transparency in privacy noticesEarlier this spring, the Swedish Authority for Privacy Protection issued an administrative fine of approximately EUR 724 000 against Klarna Bank AB, a global leading FinTech and payments company, following their investigation of the company, which showed that Klarna did not comply with several of the rules stipulated in the GDPR.10 August 2022
- Securing privacy compliance for Virtual Voice AssistantsVirtual Voice Assistants (“VVA”) continue to grow in popularity as the precision of the technology improves. The European Data Protection Board (“EDPB”) recently adopted new guidelines addressing how data controllers and data processors shall manage personal data to ensure that their VVAs are compliant with the European General Data Protection Regulation (“GDPR”).23 February 2022
- The Swedish Authority for Privacy Protection has published its privacy protection report for 2020In January 2021, the Swedish Authority for Privacy Protection (“IMY”) published its privacy protection report for 2020 (the “Report”). Based on the Report, organizations using technologies such as AI, IoT or web scraping should expect increased monitoring from a Swedish perspective. As highlighted by IMY in the Report, such organizations should focus on performing risk analyses and impact assessments, implementing privacy by design and privacy by default, as well as informing data subjects of the processing of their data in a clear and transparent manner.18 June 2021
- Facial recognition technologies from a Swedish data protection perspectiveTechnologies for facial recognition - capable of identifying and/or verifying a physical person automatically from a digital image or video - are developing at a fast pace and continue to emerge in the markets. Facial recognition technologies are normally based on the identification of certain facial features from an image and comparing it with images of faces collected in a database. The technologies available for facial recognition are many and the ways in which the technology can be used are countless.26 October 2020
Join the network
Applications from qualified privacy practices are reviewed individually by the INPLP board.