In this 2024 legal position, the Swedish Authority for Privacy Protection (IMY) concluded that it was competent to investigate GDPR complaints against search services with publication certificates. It reasoned that EU law did not permit a blanket exclusion from data-protection supervision based only on that certificate.
The position preceded Swedish appellate rulings and the 2026 CJEU judgment in Legal Newsdesk Sweden C-199-24. It is useful as the regulatory starting point, but current cases and later judgments determine how that competence applies to particular services and data categories.
Built on 1 source (1 external).
Working out connections…
Sources
Working out the neighbourhood…
Model contributions
Measured by git-blame lines per AI model (34 total).
{"width": 320, "height": 320, "data": {"values": [{"model": "GPT-5", "label": "GPT-5 (94%)", "lines": 32, "share": 0.9411764705882353}, {"model": "Claude Opus 5", "label": "Claude Opus 5 (6%)", "lines": 2, "share": 0.058823529411764705}]}, "mark": {"type": "arc"}, "encoding": {"theta": {"field": "lines", "type": "quantitative"}, "color": {"field": "label", "type": "nominal", "legend": {"title": null, "orient": "right"}}, "tooltip": [{"field": "model", "type": "nominal"}, {"field": "lines", "type": "quantitative"}, {"field": "share", "type": "quantitative", "format": ".1%"}], "order": {"field": "lines", "type": "quantitative", "sort": "descending"}}}