Almost all Swedish websites have a cookie banner today. The problem is that most of them aren't legal — and the vast majority of the people running the sites don't know it.
When we at ZORC went through hundreds of Swedish business websites, we saw the same pattern over and over again. The banner appears, looks clean, has a nice "Approve" button — and meanwhile the site has already loaded Google Analytics and the Meta pixel, before the visitor has time to take a stand. That is exactly what is not allowed. And that's why we start right here. Swedish Cybersecurity is a broader investment in cyber security for Swedish companies — but we chose to start with cookies, because it is a requirement that affects almost everyone, and that almost everyone is wrong about.
What the law actually requires
Two regulations govern cookies in Sweden. The Electronic Communications Act (2022:482) states that cookies that are not strictly necessary may not be placed before the visitor has received information and actively consented. In turn, the GDPR governs how the consent itself must look: it must be voluntary, specific, informed and unambiguous. If a single one of those requirements is missing, the consent is invalid — even if the visitor has pressed "Approve".
In practice, this means three things. No cookies that require consent may be set before the visitor has chosen. Denying should be as easy as approving. And you must be able to demonstrate that, and how, consent has been obtained.
It sounds simple. But this is exactly where most people fall.
What we saw when we looked
The most common flaws are surprisingly similar. Tracking that loads already on page load, long before anyone clicks. A big, colorful "Approve All" next to a pale "Deny" as a text link — or no No button at all in the first view. Checked boxes for statistics and marketing. And almost no one actually records the consents, which means that you cannot prove anything if the question is asked.
Any of these things can invalidate consent. And the strange thing is that the violation is fully visible to anyone. A visitor, a competitor or a reviewing authority can open the site in an incognito window and see in the developer tools that the tracking cookies are already there. Here, supervision is divided: The Post and Telecommunications Authority (PTS) monitors the requirement for consent before cookies are placed, while the Privacy Protection Agency (IMY) reviews how the personal data is then handled. Both can require correction, and in serious cases it can lead to a penalty fee — IMY directed criticism against several Swedish companies' cake banners as recently as 2025.
Equally important, although more difficult to put a number on, is trust. A banner that clearly tries to trick the visitor into clicking "yes" says something about how the company views its customers' privacy.
Our first service: a cookie banner that complies with the law
Our idea was simple: make it easier to do right than to do wrong. The first service in Swedish Cybersecurity is a tool that allows you to create, customize and publish a cookie banner that complies with the law — in a few minutes, even without technical or legal experience.
This includes:
Three equivalent choices.Deny, customize and approve are given equal weight — no button is highlighted. The configurator warns you if a design change risks becoming a dark pattern.
Consent register.Each consent is saved with the time and the choices made, so you can show how it was obtained in the event of an audit.
Automatic scanning.The tool recognizes common tracking tools such as Google Analytics and Meta Pixel and suggests the right categories — you complete manually.
Simple installation.One line of code in the head of the page, with step-by-step guides for WordPress, Webflow, Shopify, Squarespace and Next.js.
Data within the EU.All data is stored on servers within the EU, and IP addresses are never saved in clear text but only in pseudonymised form.
It starts at SEK 39/month per domain, with a 14-day free trial period and no commitment period. The legality itself is included in all plans.
One thing we want to be clear about
A tool can make it easy to do the right thing, but it can't take over your responsibility. As the website owner, you are the person in charge of personal data and are responsible for how cookies are used on your site. What we do is provide you with a banner that meets the requirements and a document that documents the consents for you — the rest of the compliance is still up to you. We think it's more important to say it straight than to promise more than we can keep.
Test where your own site stands
Before you do anything else: find out where you actually are. Our free cookie checker scans your website, shows which tracking tools are running and if you risk breaking the rules — the result is emailed to you. It takes a couple of minutes and costs nothing.
And if the check shows flaws, it's easy to correct them.
Cookies are just the beginning. Swedish Cybersecurity is being expanded with more services in cyber security and regulatory compliance in the future — but everything we release will be based on the same principle: make it easy for Swedish companies to do the right thing.
Swedish Cyber Security is live now — test your site atsvenskcybersakerhet.se.