{"title":"GDPR \u0026 Data Protection – Templates","description":"\u003cp\u003eDocument templates for the company's work with personal data: data processing agreements, record of processing activities, data protection impact assessment, balancing of interests, incident management, and data subject rights. Choose based on the processing or routine to be documented and adapt the template to your business.\u003c\/p\u003e\u003cp\u003e\u003ca href=\"\/en\/blogs\/foretag\/tagged\/it-dataskydd\"\u003eRead guides in the area\u003c\/a\u003e\u003c\/p\u003e","products":[{"product_id":"personuppgiftsbitradesavtal-pub-dpa-mall-2026-word-pdf","title":"Data Processing Agreement Template Package 2026 – DPA Word\/PDF","description":"\u003ch2\u003eData Processing Agreement 2026 – complete DPA according to GDPR Article 28\u003c\/h2\u003e\u003cp\u003eA data processing agreement is required when an external supplier processes personal data on an organization's behalf. This may apply to cloud services, IT operations, web agencies, payroll systems, CRM, customer support, email platforms, analytical tools, and other services where the supplier actually processes personal data on the instructions of the controller.\u003c\/p\u003e\u003cp\u003eThis template package is designed for Swedish companies and organizations that wish to properly document the processor relationship – not just write a short standard agreement. The package contains five separate documents in both Word and PDF formats, totaling 26 professionally designed A4 pages.\u003c\/p\u003e\u003ch3\u003eWhat is included\u003c\/h3\u003e\u003cul\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eData Processing Agreement \/ DPA 2026\u003c\/strong\u003e – master agreement with 22 clauses and four integrated contract annexes.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eProcessor Instruction \u0026amp; Processing Annex\u003c\/strong\u003e – worksheets for role assessment, processing activities, data flows, storage, instructions, and communication channels.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eSecurity Annex \/ TOM\u003c\/strong\u003e – detailed template for technical and organizational security measures.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eSub-processor \u0026amp; Third-Country Register\u003c\/strong\u003e – register, TIA screening, change notification, and approval\/objection process.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eSupplier Assessment, Incident \u0026amp; Erasure\u003c\/strong\u003e – due diligence, incident forms, support for data subject requests, erasure certificates, and annual follow-up.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\u003ch3\u003eDesigned for the minimum requirements in GDPR Article 28\u003c\/h3\u003e\u003cp\u003eThe master agreement regulates the core requirements that must exist in an agreement between a controller and a processor. This includes, among other things, the subject matter and duration of the processing, the nature and purpose of the processing, categories of data subjects and types of personal data, as well as the controller’s rights and obligations.\u003c\/p\u003e\u003cp\u003eThe agreement also contains provisions stating that processing may only take place according to documented instructions, confidentiality, appropriate security measures, sub-processors, assistance with data subject rights, support for obligations under GDPR Articles 32–36, erasure or return upon contract termination, and the controller’s right to information, audit, and inspection.\u003c\/p\u003e\u003ch3\u003eDocumented instructions\u003c\/h3\u003e\u003cp\u003eA common weakness in general DPAs is that the processing is described too vaguely. The package therefore contains a specific processing instruction where the parties can document exactly which service and processing are covered, why the processing takes place, which systems are used, which data subjects are affected, which personal data is processed, and how long the data is to be stored.\u003c\/p\u003e\u003cp\u003eThere is also a separate instruction table where each processing activity can be linked to a system, permitted action, and retention period. This makes it easier to demonstrate what the processor has actually been commissioned to do.\u003c\/p\u003e\u003ch3\u003eRole assessment – controller or processor?\u003c\/h3\u003e\u003cp\u003eIt is not enough for the parties to simply call the supplier a data processor. Roles under the GDPR are determined by the actual circumstances. The processing annex therefore contains a practical role assessment with questions regarding who determines the purpose, who determines the essential means, and whether the supplier uses data for its own independent purposes.\u003c\/p\u003e\u003cp\u003eThis helps the purchaser identify situations where a supplier may be an independent controller for a certain processing activity or where further regulation needs to be considered.\u003c\/p\u003e\u003ch3\u003eSub-processors\u003c\/h3\u003e\u003cp\u003eThe agreement contains two clear options for sub-processors: specific written authorization for each sub-processor or general written authorization with prior notice of planned additions and replacements.\u003c\/p\u003e\u003cp\u003eThe separate sub-processor register includes fields for the supplier, service, data, data subjects, country of processing, and approval. The package also includes a ready-made change notification that the processor can use when a new or changed sub-processor is to be introduced, as well as a structure for the controller’s approval or objective data protection objection.\u003c\/p\u003e\u003ch3\u003eThird-country transfers and SCCs\u003c\/h3\u003e\u003cp\u003eInternational cloud services and support chains may result in personal data being transferred or made accessible outside the EU\/EEA. The template therefore has a separate third-country register and a practical screening for international transfers.\u003c\/p\u003e\u003cp\u003eThe register can document the recipient, country, role, affected data, transfer mechanism under GDPR Chapter V, and any supplementary protective measures. The screening section helps the organization verify, among other things, adequacy decisions, SCCs, the correct module, supplementary protection, and onward transfers.\u003c\/p\u003e\u003cp\u003e\u003cstrong\u003eImportant:\u003c\/strong\u003e this template does not reproduce the European Commission's Standard Contractual Clauses (SCCs) verbatim and is not marketed as an unaltered SCC document. If official SCCs are used for a third-country transfer, the relevant original clauses must be used in accordance with the European Commission's instructions.\u003c\/p\u003e\u003ch3\u003eSecurity Annex \/ TOM\u003c\/h3\u003e\u003cp\u003eThe package's security annex makes it possible to document technical and organizational measures in a concrete manner. It covers, among other things, security governance, identity and access, MFA, encryption, key management, system and application security, patching, logging, backup, continuity, incident management, personnel, suppliers, physical security, data minimization, and erasure.\u003c\/p\u003e\u003cp\u003eEach security requirement can be marked as met, partially met, or not met and supplemented with a description or evidence. There are also fields for certifications, penetration tests, independent audits, open risks, and customer-specific supplementary requirements.\u003c\/p\u003e\u003ch3\u003ePersonal data breaches\u003c\/h3\u003e\u003cp\u003eThe processor must notify the controller without undue delay after becoming aware of a personal data breach. The master agreement therefore contains incident clauses and the possibility to agree on a shorter internal target deadline for the initial notification.\u003c\/p\u003e\u003cp\u003eThe operational document contains a specific incident form for the time, affected systems, categories of data subjects and personal data, approximate number of records, likely consequences, harm-mitigation measures, evidence\/logs, and the next update.\u003c\/p\u003e\u003ch3\u003eData subjects' rights and assistance\u003c\/h3\u003e\u003cp\u003eThe processor shall, taking into account the nature of the processing, assist the controller in fulfilling obligations toward data subjects. The package therefore contains a specific case template for, for example, access, rectification, erasure, restriction, portability, and objection, with tracking of receipt, forwarding, systems to be searched, and action taken.\u003c\/p\u003e\u003ch3\u003eSupplier assessment before contracting\u003c\/h3\u003e\u003cp\u003eThe controller shall only engage processors that provide sufficient guarantees that appropriate technical and organizational measures are implemented. The package therefore contains a concrete due diligence checklist for suppliers.\u003c\/p\u003e\u003cp\u003eThe checklist assesses, among other things, role, security, incident management, sub-processors, third countries, data subject rights, erasure, auditing, continuity, and personnel security. The result can be summarized as low, medium, or high risk and documented as approved, conditionally approved, or not approved.\u003c\/p\u003e\u003ch3\u003eErasure and return upon termination of the agreement\u003c\/h3\u003e\u003cp\u003eThe master agreement and the operational document contain support for the controller's choice between return and erasure. There are specific fields for active systems, sub-processors, backup cycles, remaining legal requirements, verification method, and final erasure date.\u003c\/p\u003e\u003cp\u003eThe separate erasure\/return certificate makes it possible to document that the decommissioning has actually been carried out – something that is often missing when a supplier agreement is terminated.\u003c\/p\u003e\u003ch3\u003eReview and audit\u003c\/h3\u003e\u003cp\u003eThe agreement regulates the processor’s obligation to provide information necessary to demonstrate compliance and to enable and contribute to audits and inspections. The template allows for the practical use of relevant audit reports, certifications, and other verifiable supporting documents, but without contracting away the controller's right under Article 28.\u003c\/p\u003e\u003ch3\u003eLegal status verified 2026\u003c\/h3\u003e\u003cp\u003eThe legal status has been verified on September 27, 2026. The package has been designed based on the GDPR, specifically Articles 5, 28, 30, 32–36, and 44–49, the Swedish Authority for Privacy Protection's (IMY) current guidance on data processing agreements and the roles of controller\/processor, as well as EDPB Guidelines 07\/2020. Consideration has also been given to the European Commission's Implementing Decisions (EU) 2021\/915 and (EU) 2021\/914 where these are relevant.\u003c\/p\u003e\u003ch3\u003eWord and PDF included\u003c\/h3\u003e\u003cp\u003eAll five documents are delivered both as fully editable Word files and as PDFs. In total, the customer receives 10 files and 26 A4 pages. The Word versions contain clear fill-in fields, checkboxes, tables, and selectable options.\u003c\/p\u003e\u003cp\u003e\u003cstrong\u003eDigital product for direct download. No physical product is sent.\u003c\/strong\u003e\u003c\/p\u003e\u003ch3\u003eImportant\u003c\/h3\u003e\u003cp\u003eThese are professional legal templates and working materials. The documents must always be adapted to the actual processing activities, the parties' true roles, information security risks, sub-processors, systems, and any international transfers. In cases of complex third-country transfers, sensitive processing, joint controllership, or high risk, individual data protection legal advice should be considered.\u003c\/p\u003e","brand":"Svenska Dokumentmallar","offers":[{"title":"Default Title","offer_id":55513794675030,"sku":"PUB-DPA-2026","price":99.0,"currency_code":"SEK","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0827\/2373\/3846\/files\/pub-avtal-dpa-2026-word-pdf.png?v=1790523521"},{"product_id":"gdpr-registerforteckning-ropa-mall-2026","title":"GDPR Record of Processing Activities (RoPA) Template Package 2026 – Word\/PDF\/Excel","description":"\n\u003ch2\u003eGDPR Record of Processing Activities \/ RoPA 2026 – complete template package in Word, PDF, and Excel\u003c\/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eA complete work tool for a record of personal data processing activities in accordance with Article 30 of the GDPR.\u003c\/strong\u003e The package is developed for Swedish companies and organizations that need to document, structure, and continuously follow up on their processing of personal data.\u003c\/p\u003e\n\n\u003cp\u003eYou will receive both a professional \u003cstrong\u003eWord\/PDF template\u003c\/strong\u003e and a practical \u003cstrong\u003eExcel register\u003c\/strong\u003e with separate sections for the data controller and data processor, retention schedule, legal basis, suppliers\/processors, and verification that mandatory information is included.\u003c\/p\u003e\n\n\u003ch3\u003eThis is included\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003eRecord of processing activities for the data controller\u003c\/li\u003e\n\n\u003cli\u003eRecord of processing activities for the data processor\u003c\/li\u003e\n\n\u003cli\u003eRetention schedule \/ storage limitation\u003c\/li\u003e\n\n\u003cli\u003eLegal basis matrix according to Article 6 of the GDPR\u003c\/li\u003e\n\n\u003cli\u003eCheck for sensitive personal data according to Article 9\u003c\/li\u003e\n\n\u003cli\u003eCheck for data regarding criminal convictions according to Article 10\u003c\/li\u003e\n\n\u003cli\u003eDocumentation of recipients and data processors\u003c\/li\u003e\n\n\u003cli\u003eDocumentation of third-country transfers and transfer mechanisms\u003c\/li\u003e\n\n\u003cli\u003eOverall technical and organizational security measures\u003c\/li\u003e\n\n\u003cli\u003eDPIA status and privacy information as practical control fields\u003c\/li\u003e\n\n\u003cli\u003eSupplier and processor register\u003c\/li\u003e\n\n\u003cli\u003eAnnual\/ongoing control checklist\u003c\/li\u003e\n\n\u003cli\u003eReview log\u003c\/li\u003e\n\n\u003cli\u003eExample entry for customer and order management\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eExcel tool with automatic quality control\u003c\/h3\u003e\n\u003cp\u003eThe Excel file is designed for actual, ongoing use. It includes, among other things:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003eoverview with key figures\u003c\/li\u003e\n\n\u003cli\u003e200 prepared rows for the data controller's processing activities\u003c\/li\u003e\n\n\u003cli\u003e200 prepared rows for data processor activities\u003c\/li\u003e\n\n\u003cli\u003eautomatic field that shows \u003cstrong\u003eComplete\u003c\/strong\u003e or \u003cstrong\u003eSupplement\u003c\/strong\u003e\n\n\u003c\/li\u003e\n\n\u003cli\u003ewarning flags for sensitive data and third-country transfers\u003c\/li\u003e\n\n\u003cli\u003edropdown menus for legal basis, DPIA status, and status\u003c\/li\u003e\n\n\u003cli\u003ereminder markers for when the next review date has passed\u003c\/li\u003e\n\n\u003cli\u003eseparate retention schedule\u003c\/li\u003e\n\n\u003cli\u003eseparate supplier\/processor list\u003c\/li\u003e\n\n\u003cli\u003elegal sources and links to IMY and EUR-Lex\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eWhat must be included according to Article 30?\u003c\/h3\u003e\n\u003cp\u003eFor a data controller, the register must include contact details, purposes, categories of data subjects and personal data, recipients, any third-country transfers, and – where possible – planned time limits for erasure, as well as a general description of security measures.\u003c\/p\u003e\n\n\u003cp\u003eData processors have a separate record-keeping requirement which includes, among other things, the data controllers for whom they process data, categories of processing, third-country transfers, and – where possible – security measures.\u003c\/p\u003e\n\n\u003ch3\u003eEven smaller companies may be covered\u003c\/h3\u003e\n\u003cp\u003eThere is a limited exemption for organizations with fewer than 250 employees, but the exemption does not apply if the processing is not occasional, is likely to result in a risk to the rights and freedoms of data subjects, or involves sensitive personal data or data relating to criminal convictions. Recurring processes such as payroll administration are therefore a clear example of processing that may need to be registered.\u003c\/p\u003e\n\n\u003ch3\u003eRetention schedule as a supplement\u003c\/h3\u003e\n\u003cp\u003eThe GDPR is based on the principle of storage limitation. Personal data shall not be kept longer than is necessary for the purpose, unless another law requires longer retention. The template package therefore contains a separate retention schedule where the business can document the start point, retention period or criterion, legal requirements, systems, and the responsible person.\u003c\/p\u003e\n\n\u003ch3\u003eLegal basis matrix\u003c\/h3\u003e\n\u003cp\u003eThe package provides support for the six legal bases under Article 6:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003econsent\u003c\/li\u003e\n\n\u003cli\u003econtract\u003c\/li\u003e\n\n\u003cli\u003elegal obligation\u003c\/li\u003e\n\n\u003cli\u003eprotection of vital interests\u003c\/li\u003e\n\n\u003cli\u003epublic interest \/ public authority\u003c\/li\u003e\n\n\u003cli\u003elegitimate interests\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003eThe template also serves as a reminder that the processing of sensitive personal data requires additional support under Article 9 and that data regarding criminal convictions is regulated separately in Article 10.\u003c\/p\u003e\n\n\u003ch3\u003eThird-country transfers\u003c\/h3\u003e\n\u003cp\u003eThe register contains specific fields for the country or international organization as well as the transfer mechanism, such as an adequacy decision or standard contractual clauses (SCC). This makes it easier to keep the register of processing activities, data processing agreements (DPA), sub-processor lists, and privacy information consistent.\u003c\/p\u003e\n\n\u003ch3\u003eSuitable for, among others\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003elimited companies and smaller businesses\u003c\/li\u003e\n\n\u003cli\u003ee-commerce companies\u003c\/li\u003e\n\n\u003cli\u003eSaaS and IT businesses\u003c\/li\u003e\n\n\u003cli\u003eemployers and HR functions\u003c\/li\u003e\n\n\u003cli\u003econsultancy and service firms\u003c\/li\u003e\n\n\u003cli\u003eorganizations that process personal data on behalf of clients\u003c\/li\u003e\n\n\u003cli\u003ebusinesses that need to structure or update their GDPR work\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eLegal basis\u003c\/h3\u003e\n\u003cp\u003eThe template was legally reviewed on \u003cstrong\u003eOctober 2, 2026\u003c\/strong\u003e, with particular consideration given to:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003eRegulation (EU) 2016\/679 of the European Parliament and of the Council (GDPR), especially Articles 5, 6, 9, 10, 13–14, 28, 30, and 32\u003c\/li\u003e\n\n\u003cli\u003eAct (2018:218) with supplementary provisions to the EU General Data Protection Regulation\u003c\/li\u003e\n\n\u003cli\u003ecurrent guidance from the Swedish Authority for Privacy Protection (IMY)\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eFrequently asked questions\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003eIs the record of processing activities the same thing as a privacy policy?\u003c\/strong\u003e\u003cbr\u003eNo. The record of processing activities is internal documentation according to Article 30. Privacy information according to Articles 13–14 is information provided to the data subjects.\u003c\/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eDoes a small company really need a processing register?\u003c\/strong\u003e\u003cbr\u003eIt depends on the processing activities. The exemption for fewer than 250 employees is limited. Regular processing, high-risk processing, and processing of special categories or criminal data may be subject to the registration obligation.\u003c\/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eCan I use the Excel file as my actual RoPA register?\u003c\/strong\u003e\u003cbr\u003eYes. It is structured for ongoing electronic record-keeping, but the content must be adapted to the organization's actual processing activities.\u003c\/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eDoes the template specify ready-made storage periods?\u003c\/strong\u003e\u003cbr\u003eNo. Retention periods must be assessed based on the purpose and any statutory retention requirements. The template helps you document the decision without claiming that a general time limit applies to all businesses.\u003c\/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eFormat:\u003c\/strong\u003e Word (DOCX) + PDF + Excel (XLSX)\u003cbr\u003e\n\u003cstrong\u003eLanguage:\u003c\/strong\u003e Swedish\u003cbr\u003e\n\u003cstrong\u003eJurisdiction:\u003c\/strong\u003e Sweden \/ EU GDPR\u003cbr\u003e\n\u003cstrong\u003eVersion:\u003c\/strong\u003e 1.0 – 2026-10-02\u003c\/p\u003e\n\n\u003cp\u003e\u003cem\u003eThe templates are general work documents and do not replace individual legal advice. Always adapt them to actual processing, sector, systems, agreements, and applicable special legislation.\u003c\/em\u003e\u003c\/p\u003e\n","brand":"Svenska Dokumentmallar","offers":[{"title":"Default Title","offer_id":55576879432022,"sku":"GDPR-ROPA-2026","price":199.0,"currency_code":"SEK","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0827\/2373\/3846\/files\/gdpr-registerforteckning-ropa-2026.png?v=1790944866"},{"product_id":"dpia-konsekvensbedomning-gdpr-mallpaket-2026","title":"DPIA \/ Data Protection Impact Assessment GDPR Template Package 2026 – Word\/PDF\/Excel","description":"\n\u003ch2\u003eDPIA \/ Data Protection Impact Assessment GDPR Template Package 2026 – Word, PDF \u0026amp; Excel\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003eComplete template package for Data Protection Impact Assessment (DPIA)\u003c\/strong\u003e according to Article 35 of the GDPR. The package is designed for Swedish companies, organizations, authorities, project managers, data protection officers, information security functions, and lawyers who need to document high-risk processing of personal data in a structured, auditable, and practical manner.\u003c\/p\u003e\n\n\u003cp\u003eThe package combines \u003cstrong\u003efour professional document templates in Word\/PDF\u003c\/strong\u003e with a comprehensive \u003cstrong\u003eExcel tool for screening, risk assessment, risk-mitigating measures, consultation, Article 36 assessment, and ongoing review\u003c\/strong\u003e. A total of 9 files are included.\u003c\/p\u003e\n\n\u003ch3\u003eWhat is included – 9 files\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003eDPIA \/ Data Protection Impact Assessment GDPR 2026 – Word (DOCX)\u003c\/li\u003e\n\n\u003cli\u003eDPIA \/ Data Protection Impact Assessment GDPR 2026 – PDF\u003c\/li\u003e\n\n\u003cli\u003eDPIA Screening \/ Need Assessment – Word\u003c\/li\u003e\n\n\u003cli\u003eDPIA Screening \/ Need Assessment – PDF\u003c\/li\u003e\n\n\u003cli\u003eConsultation, DPO Opinion \u0026amp; Prior Consultation – Word\u003c\/li\u003e\n\n\u003cli\u003eConsultation, DPO Opinion \u0026amp; Prior Consultation – PDF\u003c\/li\u003e\n\n\u003cli\u003eDPIA Review, Decision \u0026amp; Change Log – Word\u003c\/li\u003e\n\n\u003cli\u003eDPIA Review, Decision \u0026amp; Change Log – PDF\u003c\/li\u003e\n\n\u003cli\u003eDPIA Risk \u0026amp; Screening Work Tool – Excel (XLSX)\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eWhen is a DPIA required?\u003c\/h3\u003e\n\u003cp\u003eAccording to Article 35 of the GDPR, the controller must carry out a data protection impact assessment \u003cstrong\u003ebefore\u003c\/strong\u003e starting a type of processing if the processing is likely to result in a high risk to the rights and freedoms of natural persons. This applies particularly to, for example, extensive profiling or automated decision-making with significant effects, large-scale processing of sensitive personal data or data relating to criminal convictions, and large-scale systematic monitoring.\u003c\/p\u003e\n\n\u003cp\u003eFurthermore, the Swedish Authority for Privacy Protection (IMY) has a specific list according to Article 35.4 and uses the nine high-risk criteria developed in European data protection guidelines. As a general rule, at least two fulfilled criteria indicate that a DPIA should be carried out, but a single criterion may suffice in an individual case. The screening template and the Excel tool are built to document exactly this assessment.\u003c\/p\u003e\n\n\u003ch3\u003eScreening \/ need assessment\u003c\/h3\u003e\n\u003cp\u003eThe screening template helps you document, before project start, why a DPIA is required – or why it is not considered mandatory. It includes checks of:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003eArticle 35.3 of the GDPR\u003c\/li\u003e\n\n\u003cli\u003eIMY's Article 35.4 list\u003c\/li\u003e\n\n\u003cli\u003eevaluation and scoring\u003c\/li\u003e\n\n\u003cli\u003eautomated decision-making with significant effects\u003c\/li\u003e\n\n\u003cli\u003esystematic monitoring\u003c\/li\u003e\n\n\u003cli\u003esensitive or highly personal data\u003c\/li\u003e\n\n\u003cli\u003elarge-scale processing\u003c\/li\u003e\n\n\u003cli\u003emerging of datasets\u003c\/li\u003e\n\n\u003cli\u003evulnerable data subjects\u003c\/li\u003e\n\n\u003cli\u003einnovative use or new technology, including AI\u003c\/li\u003e\n\n\u003cli\u003eprocessing that prevents a person from exercising a right or gaining access to a service or contract\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eComplete DPIA according to Article 35\u003c\/h3\u003e\n\u003cp\u003eThe main template is designed to document the elements required by the GDPR and highlighted by IMY in its guidance. It includes, among other things:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003esystematic description of the processing and its purposes\u003c\/li\u003e\n\n\u003cli\u003edata subjects and personal data categories\u003c\/li\u003e\n\n\u003cli\u003esensitive personal data and Article 10 data\u003c\/li\u003e\n\n\u003cli\u003esystems, technology, AI, profiling, and automated decision-making\u003c\/li\u003e\n\n\u003cli\u003edata processors and recipients\u003c\/li\u003e\n\n\u003cli\u003ethird-country transfers\u003c\/li\u003e\n\n\u003cli\u003estorage and erasure\u003c\/li\u003e\n\n\u003cli\u003edata flow and lifecycle\u003c\/li\u003e\n\n\u003cli\u003elegal basis\u003c\/li\u003e\n\n\u003cli\u003eassessment of necessity and proportionality\u003c\/li\u003e\n\n\u003cli\u003eprivacy by design and privacy by default\u003c\/li\u003e\n\n\u003cli\u003erisks to the rights and freedoms of individuals\u003c\/li\u003e\n\n\u003cli\u003erisk-mitigating technical, organizational, and legal measures\u003c\/li\u003e\n\n\u003cli\u003eresidual risk\u003c\/li\u003e\n\n\u003cli\u003edecision on whether the processing can begin\u003c\/li\u003e\n\n\u003cli\u003eneed for prior consultation with IMY\u003c\/li\u003e\n\n\u003cli\u003eplan for ongoing review\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eThe risks concern people – not the company's business risk\u003c\/h3\u003e\n\u003cp\u003eA common weakness in DPIA work is that the risk analysis drifts into business risk. The template therefore explicitly distinguishes between these areas. The DPIA risk must concern how the processing could affect \u003cstrong\u003ethe rights and freedoms of natural persons\u003c\/strong\u003e, for example through discrimination, identity theft, financial loss, reputation damage, loss of confidentiality, improper surveillance, incorrect profiling, limited self-determination, or other physical, material, or non-material damage.\u003c\/p\u003e\n\n\u003ch3\u003eExcel tool with automatic risk classification\u003c\/h3\u003e\n\u003cp\u003eThe Excel file contains separate worksheets for:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003edashboard with key performance indicators\u003c\/li\u003e\n\n\u003cli\u003eDPIA screening\u003c\/li\u003e\n\n\u003cli\u003eprocessing description\u003c\/li\u003e\n\n\u003cli\u003enecessity and proportionality\u003c\/li\u003e\n\n\u003cli\u003erisk register\u003c\/li\u003e\n\n\u003cli\u003erisk measures\u003c\/li\u003e\n\n\u003cli\u003econsultation and DPO advice\u003c\/li\u003e\n\n\u003cli\u003ereview and change log\u003c\/li\u003e\n\n\u003cli\u003eArticle 36 – documentation for prior consultation\u003c\/li\u003e\n\n\u003cli\u003elegal sources and guidance\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003eThe risk register automatically calculates a risk value based on probability and impact and shows both \u003cstrong\u003einherent risk\u003c\/strong\u003e and \u003cstrong\u003eresidual risk after planned measures\u003c\/strong\u003e. This makes it easier to track how protective measures actually change the risk landscape.\u003c\/p\u003e\n\n\u003ch3\u003eThe role of the Data Protection Officer\u003c\/h3\u003e\n\u003cp\u003eIf the organization has a data protection officer (DPO), the DPO must be consulted during the implementation of the DPIA. The DPO can, among other things, provide advice on the need for a DPIA, methodology, risks, protective measures, and whether the assessment has been carried out correctly. However, it remains the controller's responsibility to ensure that the DPIA is carried out and for the decisions made.\u003c\/p\u003e\n\n\u003cp\u003eThe package therefore contains a separate template for \u003cstrong\u003eDPO opinion and consultation\u003c\/strong\u003e where advice, deviations, and follow-up can be documented clearly.\u003c\/p\u003e\n\n\u003ch3\u003eViews of data subjects\u003c\/h3\u003e\n\u003cp\u003eThe GDPR also implies that the views of data subjects or their representatives should be sought when appropriate. The consultation template therefore contains specific fields for methodology, participants, views, how the views have been considered, and – if consultation is not carried out – why it was not appropriate or possible.\u003c\/p\u003e\n\n\u003ch3\u003eArticle 36 – prior consultation with IMY\u003c\/h3\u003e\n\u003cp\u003eIf the DPIA shows that the processing would still entail \u003cstrong\u003ea high risk despite planned risk-mitigating measures\u003c\/strong\u003e, the controller must request prior consultation with IMY before starting the processing. The package includes both document fields and a specific Excel sheet to verify that the documentation is complete before such an assessment or request is made.\u003c\/p\u003e\n\n\u003ch3\u003eDPIA is an ongoing process\u003c\/h3\u003e\n\u003cp\u003eThe impact assessment should not be archived and forgotten after the project start. IMY describes the DPIA as an ongoing process. A new or updated assessment may be needed if, for example, purposes, data categories, number of data subjects, systems, AI functionality, suppliers, recipients, third-country transfers, or security risks change.\u003c\/p\u003e\n\n\u003cp\u003eThe separate template for \u003cstrong\u003ereview, decision, and change log\u003c\/strong\u003e makes it possible to document these changes and verify that the actual processing still matches the decided DPIA.\u003c\/p\u003e\n\n\u003ch3\u003eParticularly suitable for\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003enew IT systems and SaaS services\u003c\/li\u003e\n\n\u003cli\u003eAI and automated analysis\u003c\/li\u003e\n\n\u003cli\u003eprofiling and scoring\u003c\/li\u003e\n\n\u003cli\u003eHR and personnel systems\u003c\/li\u003e\n\n\u003cli\u003ecamera and sensor solutions\u003c\/li\u003e\n\n\u003cli\u003ehealth and other sensitive personal data\u003c\/li\u003e\n\n\u003cli\u003elarge-scale customer and user databases\u003c\/li\u003e\n\n\u003cli\u003emerging of various data sources\u003c\/li\u003e\n\n\u003cli\u003enew cloud providers or third-country transfers\u003c\/li\u003e\n\n\u003cli\u003eprocessing of data of children or other vulnerable groups\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eLegal basis\u003c\/h3\u003e\n\u003cp\u003eThe package is legally reviewed as of October 3, 2026, and is based, among other things, on:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003ethe General Data Protection Regulation (EU) 2016\/679, particularly Articles 5, 6, 9, 10, 25, 32, 35, 36, and 39\u003c\/li\u003e\n\n\u003cli\u003eIMY's guidance on impact assessment and practical guide\u003c\/li\u003e\n\n\u003cli\u003eIMY's list according to Article 35.4\u003c\/li\u003e\n\n\u003cli\u003eEDPB\/WP29 Guidelines on Data Protection Impact Assessment, WP248 rev.01\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003eIn 2026, the EDPB presented a new proposal for a common European DPIA template for public consultation. However, this product is not dependent on a draft consultation not yet finalized, but is based primarily on the current GDPR and IMY's current Swedish guidance.\u003c\/p\u003e\n\n\u003ch3\u003ePlease note\u003c\/h3\u003e\n\u003cp\u003eThe templates are general compliance documentation. They do not replace an actual analysis of the planned processing or individual legal advice. A correct DPIA must be based on actual systems, data flows, purposes, suppliers, data subjects, risks, and protective measures. Special sector rules may also need to be considered.\u003c\/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eFormat:\u003c\/strong\u003e Word (DOCX) + PDF + Excel (XLSX)\u003cbr\u003e\n\u003cstrong\u003eLanguage:\u003c\/strong\u003e Swedish\u003cbr\u003e\n\u003cstrong\u003eJurisdiction:\u003c\/strong\u003e Sweden \/ EU\u003cbr\u003e\n\u003cstrong\u003eNumber of files:\u003c\/strong\u003e 9\u003cbr\u003e\n\u003cstrong\u003eVersion:\u003c\/strong\u003e 1.0 – 2026-10-03\u003c\/p\u003e\n","brand":"Svenska Dokumentmallar","offers":[{"title":"Default Title","offer_id":55582656299350,"sku":"DPIA-GDPR-2026","price":249.0,"currency_code":"SEK","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0827\/2373\/3846\/files\/dpia-konsekvensbedomning-gdpr-mallpaket-2026.png?v=1790984985"},{"product_id":"intresseavvagning-lia-gdpr-mallpaket-2026","title":"Legitimate Interest Assessment \/ LIA GDPR Template Package 2026 – Word\/PDF\/Excel","description":"\n\u003ch2\u003eLegitimate Interest Assessment (LIA) \/ GDPR 2026 – complete template package\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003eA complete documentation package for Legitimate Interest Assessment (LIA) pursuant to Article 6(1)(f) GDPR.\u003c\/strong\u003e The package helps companies and organizations document the entire three-part test: legitimate interest, necessity, and the balancing against the interests, rights, and freedoms of the data subject. It also includes a separate Article 21 assessment for objections, ongoing review, and an Excel tool for registers and control.\u003c\/p\u003e\n\n\u003cp\u003eThe template package is legally reviewed as of \u003cstrong\u003eOctober 3, 2026\u003c\/strong\u003e, against the GDPR, the Swedish Authority for Privacy Protection's (IMY) current Swedish guidance, and EDPB Guidelines 1\/2024 on Article 6(1)(f).\u003c\/p\u003e\n\n\u003ch3\u003eIncluded – 9 files\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003eLegitimate Interest Assessment \/ LIA 2026 – Word (DOCX)\u003c\/li\u003e\n\n\u003cli\u003eLegitimate Interest Assessment \/ LIA 2026 – PDF\u003c\/li\u003e\n\n\u003cli\u003eObjection assessment pursuant to Article 21 – Word\u003c\/li\u003e\n\n\u003cli\u003eObjection assessment pursuant to Article 21 – PDF\u003c\/li\u003e\n\n\u003cli\u003eLIA Review \u0026amp; change log – Word\u003c\/li\u003e\n\n\u003cli\u003eLIA Review \u0026amp; change log – PDF\u003c\/li\u003e\n\n\u003cli\u003eGuide to Legitimate Interest Assessment – Word\u003c\/li\u003e\n\n\u003cli\u003eGuide to Legitimate Interest Assessment – PDF\u003c\/li\u003e\n\n\u003cli\u003eExcel tool for LIA register, balancing matrix, objections, and review\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eThe three-part test pursuant to Article 6(1)(f)\u003c\/h3\u003e\n\u003cp\u003eFor a legitimate interest assessment to be used, three cumulative conditions must be met:\u003c\/p\u003e\n\u003col\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eLegitimate interest:\u003c\/strong\u003e the interest must be lawful, sufficiently specific, real, and current.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eNecessity:\u003c\/strong\u003e the processing of personal data must be necessary to achieve the legitimate interest. If the same goal can reasonably be reached just as effectively with less privacy intrusion, it weighs against Article 6(1)(f).\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eBalancing:\u003c\/strong\u003e the interests, fundamental rights, and freedoms of the data subject may not override the legitimate interest.\u003c\/li\u003e\n\n\n\u003c\/ol\u003e\n\n\u003ch3\u003eReasonable expectations\u003c\/h3\u003e\n\u003cp\u003eThe template contains a specific balancing matrix regarding, among other things, the relationship with the data subject, how the data was collected, what the data subject can reasonably expect, the nature of the data, the scope of processing, storage period, profiling, children and other vulnerable individuals, power imbalance, and potential negative consequences.\u003c\/p\u003e\n\n\u003cp\u003eIMY emphasizes that an overall assessment must be made in each individual case. That processing is practical or commercially desirable is not in itself sufficient.\u003c\/p\u003e\n\n\u003ch3\u003eDocumentation and accountability\u003c\/h3\u003e\n\u003cp\u003eIMY recommends that the legitimate interest assessment be documented so that the controller can demonstrate how the assessment was performed. The package therefore provides separate fields for purpose, legitimate interest, alternative solutions, data minimization, reasonable expectations, safeguards, and final conclusion.\u003c\/p\u003e\n\n\u003ch3\u003eArticle 21 – when the data subject objects\u003c\/h3\u003e\n\u003cp\u003eA separate template helps the organization assess objections to processing based on Article 6(1)(f). For processing other than direct marketing, after an objection, the controller must be able to demonstrate \u003cstrong\u003ecompelling legitimate grounds\u003c\/strong\u003e that override the interests, rights, and freedoms of the data subject, or that the processing is necessary for the establishment, exercise, or defense of legal claims.\u003c\/p\u003e\n\n\u003ch3\u003eDirect marketing\u003c\/h3\u003e\n\u003cp\u003eRecital 47 of the GDPR states that processing for direct marketing may be regarded as a legitimate interest. However, this does not mean that all direct marketing is automatically permitted. Necessity, balancing, transparency, and other applicable marketing\/ePrivacy regulations must still be assessed. If the data subject objects to direct marketing, the processing for that purpose must cease.\u003c\/p\u003e\n\n\u003ch3\u003eChildren, employees, and other vulnerable groups\u003c\/h3\u003e\n\u003cp\u003eChildren have special protection under the GDPR. The template therefore contains specific checkpoints for children and other vulnerable data subjects. In the workplace, the power imbalance between employer and employee is also considered, as well as what the employee can reasonably expect in the current work environment.\u003c\/p\u003e\n\n\u003ch3\u003eAI and new technical use cases\u003c\/h3\u003e\n\u003cp\u003eLegitimate interest assessment may also need to be evaluated when developing or using AI. The package therefore contains checkpoints for data minimization, profiling, new technology, automation, and reasonable expectations. Commercial benefit can in some cases be a legitimate interest, but it does not determine the necessity or balancing step.\u003c\/p\u003e\n\n\u003ch3\u003ePublic authorities\u003c\/h3\u003e\n\u003cp\u003eArticle 6(1)(f) may not be used by public authorities when processing personal data in the performance of their public tasks. The template therefore contains a special check for this.\u003c\/p\u003e\n\n\u003ch3\u003eTransparency pursuant to Articles 13 and 14\u003c\/h3\u003e\n\u003cp\u003eWhen Article 6(1)(f) is used, the data subject must be informed about the legitimate interest. The package contains checkpoints to ensure that the privacy notice describes the legal basis, the legitimate interest, and the right to object.\u003c\/p\u003e\n\n\u003ch3\u003eExcel tool\u003c\/h3\u003e\n\u003cp\u003eThe Excel version contains a dashboard and separate sheets for:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003eLIA register and three-part test\u003c\/li\u003e\n\n\u003cli\u003ebalancing matrix from the data subject's perspective\u003c\/li\u003e\n\n\u003cli\u003eArticle 21 objections\u003c\/li\u003e\n\n\u003cli\u003ereview and change log\u003c\/li\u003e\n\n\u003cli\u003efinal checklist\u003c\/li\u003e\n\n\u003cli\u003elegal sources\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\u003cp\u003eThe tool automatically highlights incomplete assessments, open objections, and overdue reviews.\u003c\/p\u003e\n\n\u003ch3\u003eLegal basis\u003c\/h3\u003e\n\u003cp\u003eThe template package is based on, among other things:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003eThe General Data Protection Regulation (EU) 2016\/679, particularly Articles 5, 6(1)(f), 13, 14, and 21, as well as Recital 47\u003c\/li\u003e\n\n\u003cli\u003eIMY’s guidance on legitimate interest assessment\u003c\/li\u003e\n\n\u003cli\u003eEDPB Guidelines 1\/2024 on processing of personal data based on Article 6(1)(f) GDPR\u003c\/li\u003e\n\n\u003cli\u003eEDPB’s One-Stop-Shop Case Digest: Legitimate Interest 2026\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eWho is the package for?\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003ecompanies that use legitimate interest as a legal basis\u003c\/li\u003e\n\n\u003cli\u003edata protection officers, GDPR managers, and compliance functions\u003c\/li\u003e\n\n\u003cli\u003eHR, security, IT, and marketing\u003c\/li\u003e\n\n\u003cli\u003eorganizations that need to demonstrate accountability during audits\u003c\/li\u003e\n\n\u003cli\u003ebusinesses that need to handle objections pursuant to Article 21\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eNote\u003c\/h3\u003e\n\u003cp\u003eAn LIA is not a general permission for all future processing. The assessment must be linked to a specific purpose and a concrete processing activity and should be reconsidered when purpose, technology, data categories, recipients, scope, or the data subject’s reasonable expectations change. Sensitive personal data and data on criminal convictions additionally require separate legal support pursuant to Articles 9 and 10, respectively.\u003c\/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eFormat:\u003c\/strong\u003e Word (DOCX) + PDF + Excel (XLSX)\u003cbr\u003e\n\u003cstrong\u003eLanguage:\u003c\/strong\u003e Swedish\u003cbr\u003e\n\u003cstrong\u003eJurisdiction:\u003c\/strong\u003e Sweden \/ EU\u003cbr\u003e\n\u003cstrong\u003eNumber of files:\u003c\/strong\u003e 9\u003cbr\u003e\n\u003cstrong\u003eVersion:\u003c\/strong\u003e 1.0 – 2026-10-03\u003c\/p\u003e\n","brand":"Svenska Dokumentmallar","offers":[{"title":"Default Title","offer_id":55583511740758,"sku":"LIA-GDPR-2026","price":199.0,"currency_code":"SEK","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0827\/2373\/3846\/files\/intresseavvagning-lia-gdpr-mallpaket-2026.png?v=1791009044"},{"product_id":"personuppgiftsincident-gdpr-mallpaket-2026","title":"GDPR Personal Data Breach Template Package 2026 – Word\/PDF\/Excel","description":"\n\u003ch2\u003ePersonal Data Breach GDPR Template Package 2026 – incident report, IMY notification \u0026amp; 72-hour tool\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003eA complete template package for companies and organizations that need to detect, assess, document, and manage personal data breaches according to the GDPR.\u003c\/strong\u003e The package contains professional Word\/PDF templates as well as an Excel tool for incident registers, 72-hour deadlines, risk assessments, IMY (Swedish Authority for Privacy Protection) notifications, information to data subjects, processor reporting, and post-incident analysis.\u003c\/p\u003e\n\n\u003cp\u003eThe GDPR requires that \u003cstrong\u003eall personal data breaches be documented\u003c\/strong\u003e. A breach must be reported to the supervisory authority unless it is unlikely that it will result in a risk to the rights and freedoms of natural persons. If a notification is required, it must be made without undue delay and, where feasible, within \u003cstrong\u003e72 hours\u003c\/strong\u003e of the controller becoming aware of the breach.\u003c\/p\u003e\n\n\u003ch3\u003eIncluded – 9 files\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003ePersonal Data Breach – Incident Report \u0026amp; 72-hour assessment, Word + PDF\u003c\/li\u003e\n\n\u003cli\u003eNotification to IMY – preparation documentation, Word + PDF\u003c\/li\u003e\n\n\u003cli\u003eInformation to data subjects according to Article 34 GDPR, Word + PDF\u003c\/li\u003e\n\n\u003cli\u003eProcedure for personal data breaches \/ Incident Response Playbook, Word + PDF\u003c\/li\u003e\n\n\u003cli\u003eExcel tool with incident register, 72h status, risk classification, IMY log, data subjects, processor notices, measures, and post-incident analysis\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eIncident report with complete decision-making process\u003c\/h3\u003e\n\u003cp\u003eThe main template helps the organization document the entire incident from initial detection to closure:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003etime of incident, detection, and organization awareness\u003c\/li\u003e\n\n\u003cli\u003eautomatic\/clear 72-hour deadline\u003c\/li\u003e\n\n\u003cli\u003eclassification as a confidentiality, integrity, or availability breach\u003c\/li\u003e\n\n\u003cli\u003eaffected data subjects and personal data\u003c\/li\u003e\n\n\u003cli\u003esensitive data, Article 10 data, protected personal data, and children\/vulnerable individuals\u003c\/li\u003e\n\n\u003cli\u003eimmediate containment and recovery measures\u003c\/li\u003e\n\n\u003cli\u003erisk assessment for the rights and freedoms of data subjects\u003c\/li\u003e\n\n\u003cli\u003edecision regarding IMY notification\u003c\/li\u003e\n\n\u003cli\u003edecision regarding information to data subjects\u003c\/li\u003e\n\n\u003cli\u003eroot cause, corrective measures, and lessons learned\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eWhen should the breach be reported?\u003c\/h3\u003e\n\u003cp\u003eAs a data controller, you must report the breach if it is \u003cstrong\u003enot unlikely\u003c\/strong\u003e that it will result in a risk to the rights and freedoms of natural persons. If all information is not available within 72 hours, the information may be provided in phases without undue further delay. In the event of a late notification, the reasons for the delay must be documented.\u003c\/p\u003e\n\n\u003cp\u003eThe package therefore contains a separate \u003cstrong\u003eIMY preparation template\u003c\/strong\u003e with the central information that needs to be collected before or during the reporting. The actual notification is made via IMY's current e-service or other channel designated by the authority.\u003c\/p\u003e\n\n\u003ch3\u003eHigh risk – information to data subjects\u003c\/h3\u003e\n\u003cp\u003eIf the personal data breach is likely to result in a \u003cstrong\u003ehigh risk\u003c\/strong\u003e, the data subjects must, as a general rule, be informed without undue delay. The package contains a ready-to-use and editable communication template with:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003eclear description of what has happened\u003c\/li\u003e\n\n\u003cli\u003ewhat personal data is affected\u003c\/li\u003e\n\n\u003cli\u003elikely consequences\u003c\/li\u003e\n\n\u003cli\u003eimplemented and planned measures\u003c\/li\u003e\n\n\u003cli\u003epractical advice to the data subjects\u003c\/li\u003e\n\n\u003cli\u003econtact details for the Data Protection Officer or other point of contact\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003eThe template also includes a check against Article 34 exceptions, for example, if the data was effectively encrypted, if subsequent measures eliminated the high risk, or if individual notification involves disproportionate effort.\u003c\/p\u003e\n\n\u003ch3\u003eObligations of the processor\u003c\/h3\u003e\n\u003cp\u003eA processor must report a personal data breach to the controller \u003cstrong\u003ewithout undue delay\u003c\/strong\u003e. The processor does not need to determine whether the incident entails such a risk that it must be reported to IMY – the primary responsibility for the risk and notification assessment lies with the controller.\u003c\/p\u003e\n\n\u003cp\u003eThe Excel tool therefore contains a separate register for processor notices with awareness time, initial report, time difference, missing information, and next update.\u003c\/p\u003e\n\n\u003ch3\u003eExcel – incident register with 72-hour check\u003c\/h3\u003e\n\u003cp\u003eThe Excel file serves as a practical incident management tool and contains:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003edashboard with key performance indicators\u003c\/li\u003e\n\n\u003cli\u003eincident register\u003c\/li\u003e\n\n\u003cli\u003e72-hour deadline and status \u003cem\u003eOn time \/ Urgent \/ Overdue\u003c\/em\u003e\n\n\u003c\/li\u003e\n\n\u003cli\u003erisk classification based on probability and impact\u003c\/li\u003e\n\n\u003cli\u003eIMY notification register\u003c\/li\u003e\n\n\u003cli\u003ecommunication to data subjects\u003c\/li\u003e\n\n\u003cli\u003eprocessor reporting\u003c\/li\u003e\n\n\u003cli\u003emeasures register\u003c\/li\u003e\n\n\u003cli\u003ePost-Incident Review \/ root cause analysis\u003c\/li\u003e\n\n\u003cli\u003esources and legal references\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eAll breaches must be documented\u003c\/h3\u003e\n\u003cp\u003eEven breaches that do not need to be reported to IMY must be documented. The documentation should, among other things, make it possible to verify that the organization has followed the GDPR and should also include the reasons for the decision not to notify or not to inform data subjects.\u003c\/p\u003e\n\n\u003ch3\u003eCommon incidents for which the package can be used\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003emisdirected emails or documents\u003c\/li\u003e\n\n\u003cli\u003ephishing and compromised accounts\u003c\/li\u003e\n\n\u003cli\u003eransomware and data breaches\u003c\/li\u003e\n\n\u003cli\u003eincorrect access rights\u003c\/li\u003e\n\n\u003cli\u003elost computer, phone, or storage media\u003c\/li\u003e\n\n\u003cli\u003eaccidental publication\u003c\/li\u003e\n\n\u003cli\u003eincorrect sharing via cloud service or link\u003c\/li\u003e\n\n\u003cli\u003edeletion or loss of personal data\u003c\/li\u003e\n\n\u003cli\u003eincident at a processor or subcontractor\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eLegal basis\u003c\/h3\u003e\n\u003cp\u003eThe template package has been legally reviewed as of \u003cstrong\u003eOctober 3, 2026\u003c\/strong\u003e, based on:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003eGDPR Article 4(12)\u003c\/li\u003e\n\n\u003cli\u003eGDPR Article 33 – notification to the supervisory authority and documentation\u003c\/li\u003e\n\n\u003cli\u003eGDPR Article 34 – information to data subjects\u003c\/li\u003e\n\n\u003cli\u003eIMY's current guidance on personal data breaches and e-service\u003c\/li\u003e\n\n\u003cli\u003eEDPB Guidelines 01\/2021 on Examples regarding Personal Data Breach Notification\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003eDuring 2026, the EDPB also published a proposal for a common European breach-notification-template for public consultation. The legal accuracy of this package is not based on a consultation document that has not yet been fully implemented, but on current GDPR, IMY's current guidance, and adopted EDPB guidelines.\u003c\/p\u003e\n\n\u003ch3\u003ePlease note\u003c\/h3\u003e\n\u003cp\u003eThe package is a general compliance and documentation framework. An actual incident may simultaneously be covered by other reporting regulations, such as sector-specific requirements in finance, cybersecurity, healthcare, or public operations. Therefore, always check whether additional authorities, contracting parties, insurers, or other actors need to be informed.\u003c\/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eFormat:\u003c\/strong\u003e Word (DOCX) + PDF + Excel (XLSX)\u003cbr\u003e\n\u003cstrong\u003eLanguage:\u003c\/strong\u003e Swedish\u003cbr\u003e\n\u003cstrong\u003eJurisdiction:\u003c\/strong\u003e Sweden \/ EU\u003cbr\u003e\n\u003cstrong\u003eNumber of files:\u003c\/strong\u003e 9\u003cbr\u003e\n\u003cstrong\u003eVersion:\u003c\/strong\u003e 1.0 – 2026-10-03\u003c\/p\u003e\n","brand":"Svenska Dokumentmallar","offers":[{"title":"Default Title","offer_id":55590536610134,"sku":"GDPR-INCIDENT-2026","price":249.0,"currency_code":"SEK","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0827\/2373\/3846\/files\/personuppgiftsincident-gdpr-mallpaket-2026.png?v=1791040791"},{"product_id":"gdpr-registerutdrag-registrerades-rattigheter-mallpaket-2026","title":"GDPR Subject Access Request \u0026 Data Subject Rights Template Package 2026 – Word\/PDF\/Excel","description":"\n\u003ch2\u003eGDPR Data Subject Access Request \u0026amp; Data Subject Rights Template Package 2026\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003eComplete template package for companies and organizations that need to handle requests under Articles 15–22 of the GDPR.\u003c\/strong\u003e The package includes ready-to-use response templates for data subject access requests, rectification, erasure, restriction, data portability, objection, and automated decision-making, as well as an internal processing template, deadline\/refusal template, and an Excel tool for DSAR cases.\u003c\/p\u003e\n\n\u003cp\u003eThe template package was legally reviewed as of \u003cstrong\u003eOctober 3, 2026\u003c\/strong\u003e, and is based on the GDPR, the Swedish Authority for Privacy Protection’s (IMY) current guidance, and EDPB Guidelines 01\/2022 on the right of access.\u003c\/p\u003e\n\n\u003ch3\u003eIncluded – 15 files\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003eInternal processing template for data subject rights – Word + PDF\u003c\/li\u003e\n\n\u003cli\u003eData subject access request \/ right of access under Article 15 – Word + PDF\u003c\/li\u003e\n\n\u003cli\u003eRectification \u0026amp; completion under Articles 16 and 19 – Word + PDF\u003c\/li\u003e\n\n\u003cli\u003eErasure \u0026amp; restriction under Articles 17–19 – Word + PDF\u003c\/li\u003e\n\n\u003cli\u003eData portability under Article 20 – Word + PDF\u003c\/li\u003e\n\n\u003cli\u003eObjection \u0026amp; automated decision-making under Articles 21–22 – Word + PDF\u003c\/li\u003e\n\n\u003cli\u003eExtension, refusal, fees, and identity verification under Article 12 – Word + PDF\u003c\/li\u003e\n\n\u003cli\u003eExcel tool for cases, deadlines, system searches, recipients, objections, and decision logs\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eOne month – with proper handling of extensions\u003c\/h3\u003e\n\u003cp\u003eA request under Articles 15–22 must be handled without undue delay and normally \u003cstrong\u003ewithin one month of receipt\u003c\/strong\u003e. If the request is complex or many requests are handled simultaneously, the deadline can be extended by two further months if necessary. The data subject must then be informed of the extension and the reason within the first month.\u003c\/p\u003e\n\n\u003ch3\u003eData subject access request \/ Article 15\u003c\/h3\u003e\n\u003cp\u003eThe data subject access request template helps the organization document and provide the information required by Article 15, including:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003ewhether personal data is being processed\u003c\/li\u003e\n\n\u003cli\u003epurposes and categories of personal data\u003c\/li\u003e\n\n\u003cli\u003erecipients or categories of recipients\u003c\/li\u003e\n\n\u003cli\u003estorage period or criteria\u003c\/li\u003e\n\n\u003cli\u003erights and the right to lodge a complaint with the IMY\u003c\/li\u003e\n\n\u003cli\u003esource when data has not been collected from the person\u003c\/li\u003e\n\n\u003cli\u003eautomated decision-making\/profiling where applicable\u003c\/li\u003e\n\n\u003cli\u003ethird-country transfers and safeguards\u003c\/li\u003e\n\n\u003cli\u003ecopy of personal data in an appropriate format\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eRectification, erasure, and restriction\u003c\/h3\u003e\n\u003cp\u003eThe package includes separate response templates for Articles 16–19. The templates document not only the decision itself but also the obligation to, in relevant cases, inform recipients who previously received the data.\u003c\/p\u003e\n\u003cp\u003eThe erasure template includes both grounds for erasure and exceptions, so that the organization does not incorrectly treat the right to be forgotten as absolute. The restriction section covers, among other things, contested accuracy, unlawful processing, legal claims, and ongoing objection assessment.\u003c\/p\u003e\n\n\u003ch3\u003eData portability \/ Article 20\u003c\/h3\u003e\n\u003cp\u003eThe data portability template includes eligibility checks for specific conditions: processing must, among other things, be automated and based on consent or contract. The template also distinguishes between personal data provided by the data subject and data that falls outside of Article 20.\u003c\/p\u003e\n\n\u003ch3\u003eObjection \u0026amp; direct marketing\u003c\/h3\u003e\n\u003cp\u003eThe objection template distinguishes between regular processing under Article 21.1 and direct marketing. In the case of direct marketing, processing for that purpose must cease when the data subject objects. For other processing, a documented assessment of overriding legitimate grounds or legal claims is required.\u003c\/p\u003e\n\n\u003ch3\u003eAutomated decision-making \/ Article 22\u003c\/h3\u003e\n\u003cp\u003eThe package also includes verification of whether decisions are based solely on automated processing and have legal or similarly significant effects, as well as fields for exceptions, human intervention, the opportunity to express views, contest decisions, and provide meaningful information about the logic involved.\u003c\/p\u003e\n\n\u003ch3\u003eArticle 12 – extension, refusal, and fees\u003c\/h3\u003e\n\u003cp\u003eThe separate Article 12 template helps the organization manage situations where:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003ethe deadline needs to be extended\u003c\/li\u003e\n\n\u003cli\u003ethe request is only partially granted or is refused\u003c\/li\u003e\n\n\u003cli\u003ethe request is considered manifestly unfounded or excessive\u003c\/li\u003e\n\n\u003cli\u003eadditional identity information needs to be requested due to reasonable doubts\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eIdentity verification without over-collection\u003c\/h3\u003e\n\u003cp\u003eThe templates assume that the organization should facilitate the exercise of rights. Additional identification information should only be requested when there are reasonable doubts about the identity, and the verification must be proportionate.\u003c\/p\u003e\n\n\u003ch3\u003eExcel tool with deadline monitoring\u003c\/h3\u003e\n\u003cp\u003eThe Excel tool includes a dashboard and separate worksheets for:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003eall DSAR\/GDPR rights cases\u003c\/li\u003e\n\n\u003cli\u003eautomatic standard one-month deadline\u003c\/li\u003e\n\n\u003cli\u003eextended three-month deadline when extensions are used\u003c\/li\u003e\n\n\u003cli\u003edeadline status and overdue cases\u003c\/li\u003e\n\n\u003cli\u003esystem searches and data sources\u003c\/li\u003e\n\n\u003cli\u003eArticle 19 recipients\u003c\/li\u003e\n\n\u003cli\u003eArticle 21 objections\u003c\/li\u003e\n\n\u003cli\u003edecisions, fees, refusals, and extensions\u003c\/li\u003e\n\n\u003cli\u003elegal sources\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eEDPB guidelines on the right of access\u003c\/h3\u003e\n\u003cp\u003eThe data subject access request section considers the final version of the EDPB Guidelines 01\/2022 on the right of access. The guidelines address, among other things, how the organization should understand a request, search for relevant data, handle copies, electronic formats, and the rights of other individuals.\u003c\/p\u003e\n\n\u003ch3\u003eWho is this package for?\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003ecompanies and e-retailers\u003c\/li\u003e\n\n\u003cli\u003eSaaS and IT companies\u003c\/li\u003e\n\n\u003cli\u003eHR and personnel departments\u003c\/li\u003e\n\n\u003cli\u003ecustomer service and support\u003c\/li\u003e\n\n\u003cli\u003edata protection officers\u003c\/li\u003e\n\n\u003cli\u003ecompliance and legal departments\u003c\/li\u003e\n\n\u003cli\u003eorganizations that want a traceable and consistent process for data subject rights\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eLegal basis\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003eGeneral Data Protection Regulation (EU) 2016\/679, particularly Articles 12 and 15–22, and Article 19\u003c\/li\u003e\n\n\u003cli\u003eIMY’s current guidance on data subject rights and deadlines\u003c\/li\u003e\n\n\u003cli\u003eEDPB Guidelines 01\/2022 on data subject rights – Right of access, Version 2.1\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eFormat:\u003c\/strong\u003e Word (DOCX) + PDF + Excel (XLSX)\u003cbr\u003e\n\u003cstrong\u003eLanguage:\u003c\/strong\u003e Swedish\u003cbr\u003e\n\u003cstrong\u003eJurisdiction:\u003c\/strong\u003e Sweden \/ EU\u003cbr\u003e\n\u003cstrong\u003eNumber of files:\u003c\/strong\u003e 15\u003cbr\u003e\n\u003cstrong\u003eVersion:\u003c\/strong\u003e 1.0 – 2026-10-03\u003c\/p\u003e\n\n\u003cp\u003e\u003cem\u003eThe templates are general document materials. Sector-specific regulations, confidentiality, archiving rules, accounting requirements, and other legal obligations may affect how a specific request should be handled.\u003c\/em\u003e\u003c\/p\u003e\n","brand":"Svenska Dokumentmallar","offers":[{"title":"Default Title","offer_id":55591101464918,"sku":"GDPR-RATTIGHETER-2026","price":199.0,"currency_code":"SEK","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0827\/2373\/3846\/files\/gdpr-registrerades-rattigheter-mallpaket-2026.png?v=1791043090"}],"url":"https:\/\/mallbutiken.se\/en\/collections\/gdpr-dataskydd-mallar.oembed","provider":"Mallbutiken","version":"1.0","type":"link"}