Questions around privacy and the handling of personal data are becoming increasingly important for businesses, driven by stricter regulations and the need for effective, business-oriented solutions.

Affärsadvokaterna has long-standing experience in providing practical and strategic advice in data protection – from drafting information and contractual texts to privacy policies and data protection impact assessments. We ensure not only legal compliance but also cost-efficiency and real-world applicability. We conduct clear internal trainings and work methodically with an understanding of industry-specific requirements and regulatory expectations. We also maintain regular contact with supervisory authorities and have extensive experience acting as Data Protection Officers (DPOs).

Our broad experience across diverse client projects has given us deep expertise in implementing guidelines and procedures for the processing of personal data (including sensitive data), and in developing clear plans for how companies should handle security incidents caused by cyberattacks, including regulatory response.

Our advice covers both strategic and legal considerations throughout all phases of a data breach – from investigation to legal proceedings – including action plans and the establishment of incident response routines. We also provide guidance during subsequent authority proceedings and propose improvements to information and cybersecurity protocols.

Examples of assignments:

  • Advised a digital health services platform on all legal aspects related to Sweden’s largest data breach. Managed all interactions with authorities (mainly the Police and the Swedish Authority for Privacy Protection) and communications with affected individuals.
  • Advised a leading Nordic optics and eye health company on group-wide data protection governance strategy, including conducting integrity analysis’ of the group’s handling of personal data for the purpose of implementing guidelines and routines
  • Supported an electric vehicle company entering the European market in developing privacy documentation and user terms for connected car services and websites, including coordination of data protection advice across multiple EU jurisdictions.
  • Provided legal and strategic advice (including EU and non-EU legal assessments) to an international e-commerce company following a cyberattack on its IT systems.
  • Assisted a leading Nordic optics company in negotiating data processing agreements with customers and suppliers concerning patient and sensitive data transfers.
  • Advised an international IT company in a healthcare procurement process, including all contract negotiations and GDPR-related matters.
  • Assisted a Swedish-based global company in drafting a data processing agreement to be used across jurisdictions. The project was complex due to the need to comply with GDPR and other international data protection laws.
  • Supported a major pharmaceutical company in its role as external DPO, including handling of data subject access requests, review of international policies, and providing practical advice on consent and direct marketing.
  • Conducted data protection compliance audits for a Nordic health data company.
  • Advised a Swedish digital healthcare provider on data protection compliance related to their IT platform for digital care and consultations, including negotiating a complex agreement with an EHR system provider.
  • Supported a leading Swedish vehicle inspection company in all GDPR-related matters, including cybersecurity incidents. Our advice covered all phases – from investigation to litigation – along with incident response strategies and improvements to cybersecurity protocols.
  • Advised the same company on legal assessment of repurposing existing personal data, including metadata from previously unused, unstructured systems in an employment context.
  • Assisted one of the world’s largest management and IT consulting firms in developing a background check policy, including placement of consultants in critical infrastructure and financial institutions.
  • Supported a mid-sized Swedish company in reviewing and negotiating multiple data processing and data sharing agreements across several industries.
  • Advised one of the world’s largest building materials manufacturers in incident response discussions and negotiations, including cybersecurity policy development, incident handling plans, and internal/external communication strategies. Also developed playbooks for realistic breach scenarios.
  • Advised a Swedish real estate and construction management company on the use of biometric identification on construction sites. The advice included technical assessments (e.g., fingerprint-to-hash conversion) and legal analysis under Swedish data protection law, particularly in relation to employee privacy concerns.