Is Google Analytics Legal in Sweden? Cookie Consent, the IMY Fine, and What the Court Said

A dark editorial hero. On the right, a dimmed, skeletal recreation of the Google Analytics 4 interface (a 'Google Analytics 4' wordmark, a Home/Reports/Explore/Advertising/Admin menu, and a 'Reports snapshot' panel) sits behind a soft wash of the Swedish flag: a blue field crossed by a gold Nordic cross offset toward the hoist. Two lines glow through the ghost panel: a red line reading '2023: IMY fined a Google Analytics user, court upheld it' and an amber line reading 'No analytics exemption: every cookie needs consent.' On the left, the Clickport wordmark and the kicker 'GA4 in Sweden' sit above four labelled rows: 'Sweden put a price on Google Analytics,' 'A court of appeal upheld the fine,' 'Every analytics cookie needs consent,' and 'Cookieless analytics needs no banner.'
Legal status re-verified against primary sources in July 2026. Every ruling and figure below links to the original decision or report.

Seven EU countries declared Google Analytics illegal. Only one put a price tag on it. Sweden fined Tele2 SEK 12 million, fined CDON SEK 300,000, and ordered two more companies to stop. The Administrative Court of Appeal in Stockholm (Kammarratten) upheld the fine in October 2025. Then IMY fined two pharmacies SEK 45 million for Meta Pixel transfers. If you use cookie-based tracking on a Swedish website, the enforcement precedent isn't theoretical. It's case law.

Key Takeaways
  • Sweden is the only EU country that fined companies for using Google Analytics. IMY fined Tele2 SEK 12 million (~EUR 1M) and CDON SEK 300,000 in June 2023. The Administrative Court of Appeal in Stockholm upheld the Tele2 fine in October 2025.
  • Sweden has zero consent exemptions for analytics cookies. Under LEK Chapter 9 Section 28, every analytics cookie requires prior opt-in consent. Unlike France, which still offers an analytics exemption, Sweden has none.
  • IMY has fined tracking tools over SEK 72 million total: Google Analytics (SEK 12.3M), Meta Pixel pharmacies (SEK 45M), Avanza Bank Meta Pixel (SEK 15M). In April 2025, three more companies were reprimanded for dark pattern cookie banners.
  • Only 14% of Swedish cookie banners are minimally compliant (CHI 2025 study). Combined with 41% ad blocker adoption and Safari's 22% browser share, cookie-based analytics on Swedish websites see roughly a third of actual traffic.
  • The EU Digital Omnibus (proposed November 2025) would create an analytics consent exemption for aggregated audience measurement. Google Analytics would not qualify. Cookieless, first-party analytics would.

The rules you're actually subject to

Cookie consent in Sweden is governed by two laws, enforced by two separate authorities.

The first is LEK (Lag 2022:482 om elektronisk kommunikation), Sweden's Electronic Communications Act. The cookie provisions are in Chapter 9, Section 28. Consent is required before any non-essential data is stored on or accessed from a visitor's device. Supervised by PTS (Post- och telestyrelsen, the Swedish Post and Telecom Authority).

The second is the GDPR, enforced by IMY (Integritetsskyddsmyndigheten, Sweden's Authority for Privacy Protection). Once cookies collect personal data, the processing needs a lawful basis under GDPR Article 6. If consent was invalid, the processing is unlawful.

The 2022 version of LEK explicitly aligned the consent standard with GDPR Article 4(11): freely given, specific, informed, and unambiguous. No ambiguity.

Only two exemptions exist. A cookie is exempt if its sole purpose is transmitting a communication over a network, or if it's necessary to provide a service the user explicitly requested. Session management, shopping carts, login state. That's it.

Analytics cookies aren't exempt. PTS itself asks for consent for its own statistics cookie on pts.se. When the cookie enforcement authority asks permission for its own analytics, that tells you everything about the legal standard.

This is the same position as Denmark and Austria. Unlike France, which still offers a consent exemption for audience measurement (providers now self-assess against CNIL's published criteria), Sweden has no exemption framework, no approved list, and no carve-out for first-party analytics.

Sweden vs. France vs. Denmark: analytics consent
Sweden (LEK)
No consent exemption
No approved tools list
First to fine for GA use
Two enforcers: PTS + IMY
Denmark
No consent exemption
No approved tools list
Cannot issue fines directly
Two enforcers: DIGST + Datatilsynet
France (CNIL)
Formal consent exemption
Provider self-assessment (2026)
No fine for GA (formal notice)
Single enforcer: CNIL
Cookieless analytics that don't store data on the visitor's device fall outside LEK Chapter 9 Section 28 entirely.

PTS has established concrete design requirements. Both "Accept" and "Reject" must be visible on the same layer. Pre-ticked boxes are prohibited. Continued browsing isn't consent. "I understand" isn't consent. Colors can't emphasize acceptance over refusal. And withdrawing consent must be as easy as giving it.

In October 2022, PTS investigated four websites for the first time: Swedbank, Tele2, the Public Health Agency, and the Consumer Agency. None were compliant. Not the bank. Not the telecom. Not even the government agencies whose job is consumer protection.

IMY: first in Europe to fine for Google Analytics

IMY has approximately 160 employees and a budget of roughly SEK 220 million (~EUR 20 million). In 2024, they handled over 18,000 cases, initiated 421 supervisory matters, and imposed SEK 60.6 million in fines across 6 cases. In 2025, they received 12,276 data breach notifications, an 89% increase over 2024 and the highest since GDPR took effect. In practice, enforcement here is accelerating fast.

Unlike Denmark, where Datatilsynet can't issue fines directly (GDPR Recital 151 requires court prosecution), IMY issues administrative fines directly. No police referral. No court delay. When IMY decides, the fine is real.

IMY's largest GDPR fines
Spotify
Failed to clearly inform users exercising data access rights
SEK 58M
Apoteket (pharmacy)
Meta Pixel transferred medication purchase data to Meta. 930,000 affected.
SEK 37M
Trygg-Hansa (insurance)
URL change exposed 650,000 customers' health and financial data for 2 years
SEK 35M
Avanza Bank
Meta Pixel sent securities holdings and loan amounts to Meta. Up to 1M customers.
SEK 15M
Tele2 (Google Analytics)
First GA fine in Europe. Unlawful US data transfers. Court-upheld October 2025.
SEK 12M
Apohem (pharmacy)
Meta Pixel transferred health data to Meta. 15,000 affected.
SEK 8M
Klarna
Inadequate privacy notice. Missing info on transfers, recipients, data subject rights.
SEK 7.5M

Spotify. Klarna. Tele2. Apoteket. Avanza. Sweden's own unicorns and household names aren't exempt. The same country that produces more tech companies per capita than almost anywhere on earth also fines them for privacy violations.

Google Analytics: fined, appealed, upheld

On June 30, 2023, IMY issued decisions against four companies for using Google Analytics. This was the first time any EU data protection authority imposed financial penalties for GA use. Austria, France, Italy, Denmark, Finland, and Norway had all found violations earlier. None fined.

Tele2 Sverige AB received the heaviest penalty: SEK 12 million (~EUR 1 million). In plain English: about EUR 1 million for one analytics tool. Tele2 relied on Google Analytics' built-in IP anonymization, Standard Contractual Clauses, and Google's encryption and ISO 27001 certification. IMY found all of these insufficient: Google holds the encryption keys, US intelligence agencies can compel access under FISA Section 702, and it was unclear whether IP truncation even happened before data reached US servers.

CDON AB was fined SEK 300,000 (~EUR 25,000). Similar lack of supplementary measures.

Coop Sverige AB and Dagens Industri were ordered to stop using GA but received no fine. The difference: both had implemented server-side proxy servers that prevented visitors' IP addresses from reaching Google directly. Dagens Industri also hashed cookie identifiers with a salt. These measures showed good-faith effort, even though IMY still found them legally insufficient. The lesson: a proxy server is the difference between a million-euro fine and a compliance order.

IMY's legal advisor Sandra Arvidsson stated: "These decisions have implications not only for these four companies, but can also provide guidance for other organisations that use Google Analytics."

noyb's Marco Blocher called it "a pleasant change compared to other DPAs simply holding that there has been a violation but creating no incentive to comply in the future."

First to fine: Sweden's Google Analytics enforcement timeline
Aug 2020
noyb files 101 complaints across 30 EU/EEA states, including 6 targeting Swedish companies.
Jan 2022
Austria rules first: GA illegal. No fine.
Feb 2022
France orders websites to stop using GA. No fine.
Jun 2022
Italy declares GA unlawful. 90-day compliance order. No fine.
Sep 2022
Denmark declares GA non-compliant. No fine (can't issue fines under constitution).
Jun 2023
Sweden fines Tele2 SEK 12M and CDON SEK 300K. First financial penalty in Europe for GA use.
Jul 2023
EU-US Data Privacy Framework adopted. 10 days after Sweden's fines. No retroactive effect.
Oct 2025
Administrative Court of Appeal in Stockholm upholds the SEK 12M fine. The precedent is now case law.

The timing is remarkable. IMY published the fines on July 3, 2023. The European Commission adopted the EU-US Data Privacy Framework on July 10, 2023. Ten days later. In other words, the fix arrived 10 days too late. The DPF had no retroactive effect. The fines stood. And in October 2025, the Administrative Court of Appeal in Stockholm confirmed every krona, while acknowledging the DPF has since changed the legal landscape for future transfers.

Tele2 had already stopped using Google Analytics voluntarily before the decision. They were still fined for the period of violation. Stopping early doesn't erase past non-compliance.

Beyond Google Analytics: Meta Pixel and dark patterns

The GA fines weren't an isolated event. IMY has been systematically targeting tracking tools.

In August 2024, IMY fined two Swedish pharmacy chains for Meta Pixel data transfers. Apoteket AB received SEK 37 million. Apohem AB received SEK 8 million. That means SEK 45 million for two pharmacies. The Meta Pixel had been sending customers' medication purchases, STI testing kit orders, and health-condition-related browsing to Meta. Up to 930,000 people affected at Apoteket alone. IMY's legal advisor Shirin Daneshgari Nejad stated: "The companies were obligated to take appropriate measures to safeguard the data from, for example, being shared with unauthorized parties."

Avanza Bank was fined SEK 15 million in June 2024 for accidentally activating Meta Pixel features that transmitted customers' securities holdings, loan amounts, and account numbers to Meta. Up to 1 million customers affected over 18 months.

A screenshot of a Swedish online pharmacy product page with Chrome DevTools docked below showing the Network panel during page load. The site's header brand area is cropped out of frame. The product page shows a generic medicine box, the title 'Smärtstillande 500 mg, 30 tabletter', a 'Receptbelagt läkemedel' (prescription medicine) badge, the price '89 kr', and a green 'Lägg i varukorgen' button. The DevTools Network panel lists requests including gtm.js, analytics.js, fbevents.js, and three Meta Pixel beacons (PageView, ViewContent, AddToCart) all tinted pale red. The selected ViewContent beacon shows its Request URL with the parameters cd[content_name]=Smartstillande+500+mg, cd[content_category]=Receptbelagt+lakemedel, cd[content_ids]=PROD-58271, cd[value]=89, cd[currency]=SEK transmitted to www.facebook.com. Three red annotations point at the friction. One reads 'Meta Pixel loaded on initial page load. PageView beacon fired before any consent prompt was shown.' Another reads 'Product name, category Receptbelagt lakemedel (prescription medicine), price, and the page path all transmitted to Meta servers.' A third reads 'SEK 37 million IMY fine on Apoteket for exactly this pattern (August 2024). SEK 8 million on Apohem. SEK 15 million on Avanza Bank for the same Pixel sending account data. All three settled out of court.'
What the IMY fines were really for. The Meta Pixel beacon's URL parameters carry the product name, the prescription category, the price, and the page path to Meta servers on every product view. Apoteket paid SEK 37 million for exactly this pattern.

Then in April 2025, IMY reprimanded three companies over their cookie practices: ATG (a prominent green accept button next to a grey, buried reject link), Aller Media (processing personal data on the basis of legitimate interest without documenting the interest or a balancing test), and Warner Music Sweden (failing to give clear information about the right to withdraw consent). IMY's legal counsel Michaela Prieto Ceric stated: "A cookie banner must provide clear information to the visitor and it should be equally easy to give consent as to later withdraw it."

A recreated generic Swedish online store with a cookie banner titled 'Vi vardesatter din integritet.' Three categories are pre-checked (Funktionella; Statistik, including Google Analytics; Marknadsforing, including Meta Pixel), the 'Anpassa installningar' settings link is buried, and a prominent green 'Acceptera alla' button dominates. No 'Avvisa alla' reject button appears on the first layer. Editorial annotations flag the pre-checked boxes, the buried settings link, and the missing reject button.
Recreated for illustration. The pre-checked, no-reject pattern IMY and PTS keep flagging. One correction to the baked-in labels: the appeal court is an administrative Kammarratt, not a Hovratt, and IMY's Aller Media reprimand concerned relying on legitimate interest without a documented balancing test, not a multi-step rejection flow.
The pattern
IMY is not targeting one tool. It's targeting the practice: Google Analytics (SEK 12.3M in fines), Meta Pixel (SEK 60M in fines), dark pattern cookie banners (reprimands in 2025). Total tracking-related enforcement: over SEK 72 million. If your website sends visitor data to a third party's servers, or if your cookie banner makes rejection harder than acceptance, IMY has established the precedent.

What you actually lose when visitors click "Reject"

Even with a perfect cookie banner, you lose most of your data. I've watched this play out on the Swedish sites we measure, and the reject rate here is very real.

A 2025 study from Aarhus University (CHI 2025, 254,148 websites across 31 countries) found that only 14% of Swedish cookie banners are minimally compliant. Only 49% of Swedish consent interfaces even offer a reject option. Accept buttons score 1.83 on visual prominence while reject buttons score 1.29. In plain English: the banners are built to get a yes. They're designed to get clicks, not informed consent.

Internetstiftelsen's 2024 report found that 1 in 4 Swedish internet users actively declines cookies, up 12 percentage points over the measurement period. And 83% accept terms of service without reading them. Put another way, the ones who read the banner are the ones who say no. The people who click "Accept" aren't making an informed choice. The people who click "Reject" are. Your analytics are seeing the uninformed segment and missing the deliberate one.

Sweden has 41% ad blocker adoption, the highest in the Nordics. Safari holds 22.1% of Swedish browser traffic (39% on mobile) with Intelligent Tracking Prevention blocking third-party cookies. Firefox holds 3.5% with Enhanced Tracking Protection. In practice, a big slice of traffic never loads GA at all.

If Clickport tracks your Swedish traffic, you see the visitors GA4 loses, close to all of them. No consent needed for analytics, no scripts blocked, no data lost to rejection.

Your analytics blind spot in Sweden
Estimate how much of your Swedish traffic is invisible to cookie-based analytics.
35,375
Invisible visitors
14,625
Visible to GA4
Your Swedish analytics show just 29% of your actual traffic.

Europe's unicorn factory vs its own privacy regulator

Sweden produces more tech unicorns per capita than any country outside the United States, from a country of 10 million. Stockholm has the highest concentration of billion-dollar startups of any city outside Silicon Valley. Spotify, Klarna, King, Mojang, Skype. Sweden's R&D spending is 3.57% of GDP, the highest in Europe. In other words, the most research-intensive economy on the continent.

And 99.9% of Swedish adults use BankID, the national digital identity system. 7.6 billion authentications in 2024. Swedes voluntarily identify themselves online 240 times per second. That means a population completely at ease online. This is a country that lives digitally.

That digital sophistication is precisely why cookie-based analytics fail here. These aren't passive internet users. Only 16% have ever exercised their GDPR rights, and most say GDPR made little difference to how safe they feel online. They're not looking at cookie banners and thinking about regulation. They're looking at them and thinking: I don't want to be tracked.

Key insight
Sweden passed the world's first data protection law in 1973 (Datalagen), 45 years before GDPR. It also built Spotify, Klarna, Minecraft, and Skype. Then its privacy regulator fined its own telecom company for using the world's most popular analytics tool. Sweden creates the tech and regulates it. That's the environment your website operates in.

There's a deeper Swedish paradox worth understanding. Sweden has had the Offentlighetsprincipen (principle of public access) since 1766: your neighbor's salary, tax returns, and court judgments are public record. Anyone can request them. But your website needs explicit consent before it can set a single analytics cookie. Sweden is simultaneously the most transparent country in the world and one of the strictest on digital tracking.

What's coming: Digital Omnibus and the DPF's uncertain future

Sweden's own Kommerskollegium (National Board of Trade) found GDPR is "often cited among the most burdensome EU regulations" for digital sectors, finding it has "hindered EU companies' productivity and thereby their competitiveness." Svenskt Naringsliv (Confederation of Swedish Enterprise) published "What's Still Wrong with GDPR?" calling for reform. IMY Director General Eric Leijonram called the Digital Omnibus "substantial GDPR modifications, larger alterations than we anticipated."

The Digital Omnibus would create a consent exemption for aggregated audience measurement. The DPF is also under active legal challenge. Sweden has the EU's strongest GA enforcement precedent. If the DPF is invalidated, every Swedish website using GA4 faces the same legal situation as June 2023, with the Tele2 case law already on the books.

Until the Omnibus passes (realistically 2027-2028), Sweden's current rules remain in full force. Every analytics cookie requires consent.

Check your own site
See what your site loads before consent.
Paste your URL into the free GDPR checker. It reads your page source, identifies every tracking script, and checks whether each one is gated behind consent, which is where IMY's guidance starts. No signup, about thirty seconds.
Scan your site for trackers →

What this means for your website

If you run a website serving Swedish visitors, here's your risk assessment.

If you're using Google Analytics with a cookie banner: Your US data transfers are covered by the DPF (for now), but you need valid cookie consent under LEK. That means equal-prominence accept and reject buttons, no pre-loaded cookies, granular purpose selection, and easy withdrawal. IMY fined Tele2 SEK 12 million and the court upheld it. The dark patterns crackdown (April 2025) targets exactly the banner designs that inflate consent rates.

If your cookie banner isn't compliant: You're in the 86%. Only 14% of Swedish banners are minimally compliant. IMY and PTS are both enforcing. A non-compliant banner can trigger action from either authority: PTS for LEK violations, IMY for GDPR violations. The Aller Media and ATG cases show IMY will act on dark patterns. Our cookie banner decision flowchart maps out the checks, and our free GDPR checker scans your site for trackers that fire before consent.

If you want accurate data without the compliance risk: Cookieless analytics avoid LEK entirely. In a country where the courts have already upheld a SEK 12 million fine for GA, eliminating the consent trigger is the most defensible position. Our privacy-friendly analytics guide walks through how this model works across the Nordics, and our GA alternatives comparison ranks the leading tools that meet LEK requirements.

Cookie-based vs. cookieless analytics under Swedish law
Cookie-based analytics
Requires consent banner (LEK Ch. 9 Sec. 28)
55%+ of visitors invisible after rejection
Ad blockers block GA: ~41%
Court-confirmed fine precedent (Tele2)
DPF dependency for US data transfers
Cookieless analytics
Falls outside LEK Ch. 9 Sec. 28 entirely
No exposure to the Tele2 precedent
Unaffected by IMY's dark pattern enforcement
Reaches the 41% of Swedes using ad blockers
No dependency on the DPF staying valid
LEK targets device access. IMY fined Tele2 for device access. The pattern is clear: remove the device access, and Sweden's entire enforcement framework becomes irrelevant to your analytics.

Sweden ranks number one in Europe on the Innovation Scoreboard. Its citizens use BankID 7.6 billion times a year and barely carry cash. These are people who live online and know what tracking means. The visitors your analytics miss are the ones who read the banner, understood it, and clicked reject. In Sweden, that's the majority.

A screenshot of the same generic Swedish online store from the hero, this time in a post-cleanup state with no cookie banner. The site's header brand area is cropped out of frame. The hero image of seasonal autumn items shows the headline 'Höstens favoriter' and 'Fri frakt över 500 kr' with a 'Handla nu' button. Below the hero, three product cards: Stickad pläd ull 599 kr, Keramikmugg handgjord 149 kr, Doftljus ceder och bergamott 199 kr, each with a 'Lägg i varukorgen' button. A newsletter form at the bottom shows 'Din e-postadress' and a 'Prenumerera' button. No banner, no chat widget, no reCAPTCHA. A centered green-bordered badge on a dark navy background reads in two lines: '2 cookies på sidan.' and 'session_id och csrf_token. Båda strikt nödvändiga. Inget samtycke krävs under LEK Kapitel 9 paragraf 28.'
The same site, no banner needed. Two cookies, both strictly necessary, both exempt under LEK Chapter 9 Section 28. No consent prompt, no SEK 12 million risk, no compliance overhead.

One more thing, because this is a legal topic: I'm not a lawyer and this article isn't legal advice. It's a founder's map of the terrain, with every claim linked to the ruling or the source it came from. If your setup is complicated, show this to your DPO or lawyer.

And if you're staring at an IMY decision right now and something here doesn't match what you're seeing, email me.

Frequently asked questions

IMY fined four companies for using Google Analytics in June 2023: Tele2 (SEK 12M) and CDON (SEK 300K) received fines, while Coop and Dagens Industri were ordered to stop. The Administrative Court of Appeal in Stockholm upheld the Tele2 fine in October 2025. The EU-US Data Privacy Framework (July 2023) resolved the specific transfer issue, but you still need valid cookie consent under LEK and compliance with all other GDPR requirements. IMY hasn't issued post-DPF guidance on GA4.

How much was Sweden's Google Analytics fine?

Tele2 was fined SEK 12 million (~EUR 1 million) and CDON was fined SEK 300,000 (~EUR 25,000). Coop and Dagens Industri were ordered to stop using GA but received no fine because they had implemented server-side proxy servers as supplementary measures. Total GA-related fines: SEK 12.3 million. The Tele2 fine was upheld by the Administrative Court of Appeal in Stockholm in October 2025.

Yes. LEK Chapter 9 Section 28 requires consent for all non-essential cookies, including analytics. Sweden has no consent exemption for analytics (unlike France, which still exempts qualifying audience-measurement tools). PTS itself asks for consent for its own statistics cookie. Cookieless analytics that don't store data on the visitor's device fall outside LEK's scope.

Both, with different jurisdictions. PTS enforces LEK (the ePrivacy cookie rule): was consent obtained before cookies were placed? Was information adequate? IMY enforces GDPR: does the data processing have a valid legal basis? Is the consent valid under GDPR standards? A non-compliant cookie banner can trigger enforcement from either authority.

Analytics tools that don't set cookies, don't fingerprint visitors, and don't track across sites avoid LEK Chapter 9 Section 28's consent trigger. The law applies to "storage of or access to information on terminal equipment." If the tool also processes no personal data (anonymous aggregation only), the GDPR consent requirement doesn't apply either. This is why cookieless, privacy-first analytics can operate without a consent banner in Sweden.

The DPF (adopted July 2023) resolved the specific US data transfer issue from IMY's June 2023 rulings. Google is DPF-certified. But you still need valid cookie consent under LEK, a data processing agreement with Google, and compliance with all GDPR requirements. IMY has issued no post-DPF guidance on GA4. And the DPF's durability is uncertain: the PCLOB has been gutted, and the framework is being challenged at the CJEU. If it falls, Sweden has the strongest enforcement precedent in the EU.

David Karpik

David Karpik

Founder of Clickport Analytics
Building privacy-focused analytics for website owners who respect their visitors.

Comments

Loading comments...

Leave a comment