What is IMY?
Sweden's data protection authority — the regulator for GDPR. Handles complaints and can issue fines.
IMY stands for Integritetsskyddsmyndigheten (the Swedish Authority for Privacy Protection). It is Sweden's regulator for personal data rules, especially GDPR. Think of IMY as a kind of traffic police for data: they are not there to chase you endlessly, but they watch that everyone plays by the rules — and they can fine those who handle people's data carelessly.
IMY was formerly called Datainspektionen (the Data Inspection Board) and changed its name in 2021. As well as investigating and deciding on penalties, the authority accepts complaints from individuals who believe a business has mishandled their data. It also publishes guidance and advice, so it acts as much teacher as enforcer.
If someone feels your organisation has misused their data, they can turn to IMY. The authority can then request documentation, ask questions, and in the worst case decide on a fine. That is why it pays to have your paperwork in order before it ever becomes relevant.
Why is IMY important for your business?
IMY is the body that can actually penalise your business if you break data protection rules. Understanding what they require helps you avoid both costly fines and the trust hit that follows when a data incident becomes public.
At the same time, IMY is a resource. Their guides and checklists are free and written so ordinary businesses can understand them. Reading up before you build something new saves both time and headaches.
IMY in practice
Say a former customer asks to have all their data deleted, but your business never responds. The customer reports you to IMY. The authority contacts you, asks for an explanation, and checks how you handle data subject rights. If you have proper procedures and can show them, it is usually a reminder rather than a fine.
At ZORC, we build systems where routines like deletion and data export are built in, so you can respond quickly and confidently if IMY ever asks.
Common questions about IMY
What does IMY mean?
IMY means Integritetsskyddsmyndigheten — Sweden's authority that supervises GDPR. It accepts complaints, investigates breaches, and can decide on penalties.
What was IMY called before?
IMY was called Datainspektionen until 2021, when it was renamed Integritetsskyddsmyndigheten. The core mission is the same: protecting individuals' privacy and ensuring data protection rules are followed.
Can IMY issue fines?
Yes. IMY can decide on penalties against businesses and organisations that breach GDPR. The amount depends on how serious the breach is and whether you cooperated and took remedial action.
Related terms
Consent Mode
Google's standard for passing consent to its services. Consent Mode v2 has been required since March 2024.
GDPR
The EU's data protection regulation. Governs how businesses may process personal data. Break it and fines can reach millions.
DPA
Data Processing Agreement. Required when someone else processes personal data on your behalf — e.g. cloud providers.
DPF
EU-US Data Privacy Framework. The replacement for Privacy Shield. Allows data transfers to certified US companies.
DPIA
Data Protection Impact Assessment. A required impact assessment for high-risk processing under GDPR Article 35.
Data Processing Agreement
A written agreement for everyone who handles your customers' data on your behalf. Complicated name, simple idea: you decide, they promise to behave.