Changeflow GovPing Privacy Enforcement GDPR Breach Fines for SL Group Companies
Priority review Enforcement Amended Final

GDPR Breach Fines for SL Group Companies

Favicon for www.imy.se IMY News (Sweden DPA)
Filed July 3rd, 2025
Detected February 11th, 2026
Email

Summary

The Swedish Authority for Privacy Protection (IMY) has issued administrative fines of SEK 75,000 each to Aktiebolaget Storstockholms Lokaltrafik (SL) and Waxholms Ångfartygs AB (WÅAB). The fines were imposed for processing personal data related to employee sobriety tests in breach of the GDPR, specifically regarding excessive data storage and handling of potentially sensitive health data.

What changed

The Swedish Authority for Privacy Protection (IMY) has fined two companies within the SL Group, Aktiebolaget Storstockholms Lokaltrafik (SL) and Waxholms Ångfartygs AB (WÅAB), SEK 75,000 each for violations of the General Data Protection Regulation (GDPR). The violations stem from the processing of personal data related to sobriety tests conducted on employees, specifically ship captains. IMY found that the companies stored this data for longer than necessary and failed to implement sufficient routines, thereby exceeding legitimate interests and potentially mishandling sensitive health data.

Companies that conduct sobriety tests on employees must ensure that data processing is lawful under the GDPR and that data is not stored for longer than necessary. Employers must be aware that sobriety test results can indicate alcohol dependency, classifying this information as health data which requires strong legal protection. Failure to comply with GDPR requirements regarding data minimization, purpose limitation, and data security can result in significant administrative fines.

What to do next

  1. Review data retention policies for employee sobriety test results to ensure compliance with GDPR.
  2. Assess the necessity and proportionality of collecting and storing employee sobriety test data.
  3. Ensure robust data protection routines are in place for handling sensitive personal data, including health data.

Penalties

Administrative fines of SEK 75,000 each for the two companies.

Source document (simplified)

Svensk version Listen

Administrative fines against two companies in the SL Group

Published: 3 July 2025 The Swedish Authority for Privacy Protection (IMY) has fined Aktiebolaget Storstockholms Lokaltrafik (SL) and Waxholms Ångfartygs AB (WÅAB) for processing personal data relating to sobriety tests conducted by employees in breach fo the GDPR. IMY issues an administrative fine of SEK 75, 000 against each companies. IMY has reviewed two complaints from employees that has conducted sobriety tests during their employments as ship captains of public transports. An employer could have a legitimate interest of letting their employees do sobriety tests to ensure security in, for example, public transports.

– Our review shows that it is not necessary to collect and store employee’s sobriety tests to the extent SL and WÅAB have done. Due to insufficient routines the data has been stored for months even though that was not necessary to achieve the purpose of the processing, says Maja Welander, department lawyer at IMY.

IMY concludes that it is important to take into account an employee’s position of dependency. The employer must ensure that the processing of personal data is lawful under the GDPR and that it does not interfere with the individuals privacy more than necessary. An employer who considers sobriety tests for their employees must also be aware that the results from the tests can indicate that a person is alcohol dependent. Such information is classified as health data which is subject to a strong legal protection under the GDPR.

IMY concludes that SL and WÅAB has violated the GDPR. IMY issues an administrative fine of SEK 75, 000 against each of the companies.

For further information, contact

Maja Welander, avdelningsjurist, 08-515 154 39
Presstjänsten, 08-515 154 15

Latest update: 3 July 2025 Print Page labels Data protection, Arbetsliv, Tillsyn

More news on this topic

28 January 2026
- ### Administrative fine against the Equality Ombudsman when personal data was collected via a web form

12 May 2025
- ### The Hospital Board has failed in its security measures when handling e-mail

12 May 2025
- ### Administrative fines against Apoteket and Apohem for transferring personal data to Meta

3 July 2025
See more news

More news on this topic

28 January 2026
- ### Administrative fine against the Equality Ombudsman when personal data was collected via a web form

12 May 2025
- ### The Hospital Board has failed in its security measures when handling e-mail

12 May 2025
- ### Administrative fines against Apoteket and Apohem for transferring personal data to Meta

3 July 2025
See more news Latest update: 3 July 2025 Print Page labels Data protection, Arbetsliv, Tillsyn

Source

Analysis generated by AI. Source diff and links are from the original.

Classification

Agency
Various
Filed
July 3rd, 2025
Instrument
Enforcement
Legal weight
Binding
Stage
Final
Change scope
Substantive

Who this affects

Applies to
Employers Employees
Geographic scope
Sweden

Taxonomy

Primary area
Data Privacy
Operational domain
Compliance
Topics
Employment Law GDPR

Get Privacy Enforcement alerts

Weekly digest. AI-summarized, no noise.

Free. Unsubscribe anytime.

Get alerts for this source

We'll email you when IMY News (Sweden DPA) publishes new changes.

Free. Unsubscribe anytime.