aivalet.nu, a Swedish guide
🆕 New guide Winningtemp price 2026: how much it costs Read →

Home › Data protection & EU laws

Data protection, sovereignty and EU laws

Which AI tool you may use depends not only on price, but on where the data ends up and who can access it. Here we explain the rules briefly, and why we highlight Swedish and European tools.

This is an overview for information purposes, not legal advice. Always check current requirements with the relevant authority and vendor.

How we classify tools

Every tool in the catalogue gets an origin label based on where the vendor is based:

Swedish

Swedish company under Swedish and EU law.

EU/EEA

EU/EEA company under EU law (GDPR).

EU-approved third country

Company in a country outside the EU/EEA with an EU adequacy decision (GDPR Art. 45) – data may be transferred without additional safeguards.

Outside EU

Non-EU company – may be subject to laws such as the US CLOUD Act even with EU data storage.

CLOUD Act: why "EU data storage" is not enough

The US CLOUD Act (2018) allows US authorities to request data from US companies, even when the data is stored on servers in the EU. That means an American tool with an "EU datacenter" can still be exposed. It is the reason we rank by where the vendor is based, not just where the server is. For sensitive personal data, a Swedish or European company is usually the safer choice.

One more thing to watch: many American tools offer EU data storage, but often only on expensive Enterprise or Business plans, with processing that may still happen in the US. A free account or cheap subscription rarely gets the same protection. We therefore label those tools "EU data: Enterprise only" instead of a green ✓.

The regulations in brief

GDPR (General Data Protection Regulation)
The EU's foundation for personal data. Regulates how you may collect and process data about individuals. Supervision in Sweden: IMY (Swedish Authority for Privacy Protection). You usually need a data processing agreement (DPA) with the tool.
EU AI Act
Risk-based regulation of AI systems phased in gradually: prohibited systems and AI literacy requirements have applied since February 2025, rules for general-purpose AI (GPAI) since August 2025. High-risk requirements have been postponed to 2027–2028 following the EU Digital Omnibus 2026. In Sweden PTS is the coordinating market surveillance authority, together with IMY and Finansinspektionen in their respective areas.
NIS2
EU directive on cybersecurity for essential and important entities. Implemented in Swedish law through the Cybersecurity Act (2025:1506), in force since January 2026. Supervision is sectoral and shared between several authorities; MSB, and from 2026 the Swedish Civil Contingencies Agency (MCF), has a coordinating role. It covers more organisations than the previous NIS law.
DORA
EU regulation on digital operational resilience for the financial sector, in force since January 2025. Sets requirements on IT service providers among others. Supervision in Sweden: Finansinspektionen.
Cyber Resilience Act (CRA)
EU regulation with cybersecurity requirements for products with digital elements. Adopted in 2024 with requirements phased in until around 2027. Mainly concerns manufacturers and those placing digital products on the market.

Who supervises in Sweden?

RegulationSwedish authority
GDPRIMY (Integritetsskyddsmyndigheten)
NIS2 / cybersecurityMSB/MCF (coordinating) + sector authorities, e.g. PTS
DORA (financial sector)Finansinspektionen
AI ActPTS (coordinating), IMY and Finansinspektionen
Marketing / affiliate linksKonsumentverket (Swedish Consumer Agency)

Checklist: 5 questions before choosing an AI tool

  1. Where is data stored? Within the EU/EEA, or in the US? Look for "EU data storage", and remember that "Enterprise only" does not help on a free account.
  2. Where is the vendor based? A US company can be covered by the CLOUD Act even with EU servers. Swedish or EU company is safer for sensitive data.
  3. Is a data processing agreement (DPA) available? Required under GDPR if the tool processes personal data on your behalf.
  4. Which sub-processors are used? Many EU tools still forward data to American AI models. Ask, or read their sub-processor list.
  5. How do you get your data out if you leave? Check export and deletion before you start, not afterwards.

For municipalities and regions

The public sector has extra-strict requirements on where data may end up, and several municipalities and regions have flagged risks with American cloud services linked to the CLOUD Act. If you procure AI for a municipality or region, Swedish or European vendor and clear EU data storage is often a precondition, not just a preference. Use the origin labels as a first filter, and always verify against your own procurement and information-security requirements.

CLOUD Act status for all reviewed tools →
🧭 Run the tool compass and filter for Swedish/EU →