{"title":"IT Agreements \u0026 Digital Services – Templates","description":"\u003cp\u003eTemplates cover SaaS, SLAs, IT services, licences, data, customer and supplier relationships and digital compliance.\u003c\/p\u003e\u003cp\u003eCompare the options below. The product title shows the document type; open the product for full contents, formats and intended use.\u003c\/p\u003e","products":[{"product_id":"saas-avtal-mall-svensk-ratt-word-pdf","title":"SaaS Agreement Template 2026 – Swedish Law Word\/PDF | SLA \u0026 GDPR","description":"\u003ch2\u003eSaaS Agreement under Swedish Law – complete B2B template in Word and PDF\u003c\/h2\u003e\u003cp\u003eA professional and comprehensive \u003cstrong\u003eSaaS agreement for Swedish companies\u003c\/strong\u003e that sell or buy cloud-based software, subscription services, and other Software as a Service solutions. The template is structured as a complete contractual framework and regulates not only the right to use the software itself but also service levels, support, personal data, information security, subcontractors, intellectual property rights, liability, termination, and exit.\u003c\/p\u003e\u003cp\u003e\u003cstrong\u003eYou receive both an editable Word file (DOCX) and a ready-to-use PDF version.\u003c\/strong\u003e The document is designed for B2B relationships and can be used by both SaaS providers and corporate clients who want a structured and clear agreement.\u003c\/p\u003e\u003ch2\u003e15 professional pages – main agreement + 6 annexes\u003c\/h2\u003e\u003cp\u003eThe SaaS template consists of a main agreement with \u003cstrong\u003e32 contract areas\u003c\/strong\u003e and six practical annexes. In total, the document comprises 15 professionally designed A4 pages with ready-to-use clauses, alternatives, tables, fillable fields, and checklists.\u003c\/p\u003e\u003ch3\u003eThe main agreement covers, among other things\u003c\/h3\u003e\u003cul\u003e\n\n\u003cli\u003eparties, background, and definitions,\u003c\/li\u003e\n\n\u003cli\u003eorder of priority of contract documents,\u003c\/li\u003e\n\n\u003cli\u003escope of service and implementation,\u003c\/li\u003e\n\n\u003cli\u003elicense and right of use,\u003c\/li\u003e\n\n\u003cli\u003euser accounts and permissions,\u003c\/li\u003e\n\n\u003cli\u003eobligations of the provider and the customer,\u003c\/li\u003e\n\n\u003cli\u003eavailability, maintenance, and SLA,\u003c\/li\u003e\n\n\u003cli\u003esupport and incident prioritization,\u003c\/li\u003e\n\n\u003cli\u003echanges to the SaaS service,\u003c\/li\u003e\n\n\u003cli\u003ecustomer data and data rights,\u003c\/li\u003e\n\n\u003cli\u003eGDPR and personal data processing,\u003c\/li\u003e\n\n\u003cli\u003esubcontractors and sub-processors,\u003c\/li\u003e\n\n\u003cli\u003ethird-country transfers,\u003c\/li\u003e\n\n\u003cli\u003einformation and cybersecurity,\u003c\/li\u003e\n\n\u003cli\u003ebackup and restoration,\u003c\/li\u003e\n\n\u003cli\u003eintellectual property rights and customizations,\u003c\/li\u003e\n\n\u003cli\u003einfringement claims,\u003c\/li\u003e\n\n\u003cli\u003econfidentiality,\u003c\/li\u003e\n\n\u003cli\u003efees, invoicing, and price adjustments,\u003c\/li\u003e\n\n\u003cli\u003edefects, warranties, and remediation,\u003c\/li\u003e\n\n\u003cli\u003elimitation of liability and liability caps,\u003c\/li\u003e\n\n\u003cli\u003eforce majeure,\u003c\/li\u003e\n\n\u003cli\u003econtract term and termination,\u003c\/li\u003e\n\n\u003cli\u003esuspension of the service,\u003c\/li\u003e\n\n\u003cli\u003eexit and data return,\u003c\/li\u003e\n\n\u003cli\u003eaudit and verification,\u003c\/li\u003e\n\n\u003cli\u003eassignment, notices, Swedish law, and dispute resolution.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\u003ch2\u003eAnnex 1 – Service Specification and Order Form\u003c\/h2\u003e\u003cp\u003eThis defines what the customer is actually purchasing. The annex contains fields for service name, business purpose, included modules and features, number of users, data volume, operating region, implementation, integrations, documentation, and explicit exclusions.\u003c\/p\u003e\u003cp\u003eFurthermore, there are ready-to-use tables for functional requirements, acceptance criteria, milestones, and technical dependencies. This reduces the risk of disputes over what is actually included in the subscription.\u003c\/p\u003e\u003ch2\u003eAnnex 2 – Service Level Agreement (SLA)\u003c\/h2\u003e\u003cp\u003eA separate SLA is included and can be customized according to the service level of the offering. The annex includes, among other things:\u003c\/p\u003e\u003cul\u003e\n\n\u003cli\u003emonthly availability targets,\u003c\/li\u003e\n\n\u003cli\u003eplanned maintenance windows,\u003c\/li\u003e\n\n\u003cli\u003eRPO and RTO,\u003c\/li\u003e\n\n\u003cli\u003eincident classes P1–P4,\u003c\/li\u003e\n\n\u003cli\u003einitial response time,\u003c\/li\u003e\n\n\u003cli\u003erestoration targets,\u003c\/li\u003e\n\n\u003cli\u003estatus updates,\u003c\/li\u003e\n\n\u003cli\u003eservice credits for lack of availability,\u003c\/li\u003e\n\n\u003cli\u003eexcluded time and emergency security measures.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\u003ch2\u003eAnnex 3 – Data Processing Agreement (DPA) according to Article 28 GDPR\u003c\/h2\u003e\u003cp\u003eFor many SaaS services, the provider processes personal data on behalf of the customer. In such cases, Article 28 of the GDPR requires a binding agreement between the controller and the processor. Therefore, the template contains a complete \u003cstrong\u003eDPA\/data processing annex\u003c\/strong\u003e.\u003c\/p\u003e\u003cp\u003eThe annex includes, among other things, the subject matter and duration of the processing, purpose, categories of data subjects, types of personal data, special categories, instructions, confidentiality, technical and organizational security measures, sub-processors, data subject rights, personal data breaches, DPIA, third-country transfers, audit, and deletion and return.\u003c\/p\u003e\u003ch2\u003eAnnex 4 – Information and Cybersecurity Requirements\u003c\/h2\u003e\u003cp\u003eA practical security annex makes it possible to agree on concrete security requirements instead of a vague formulation regarding \"appropriate security.\" The checklists cover, among other things:\u003c\/p\u003e\u003cul\u003e\n\n\u003cli\u003esecurity governance and risk management,\u003c\/li\u003e\n\n\u003cli\u003erole-based access and MFA,\u003c\/li\u003e\n\n\u003cli\u003eencryption,\u003c\/li\u003e\n\n\u003cli\u003esecurity logging and retention,\u003c\/li\u003e\n\n\u003cli\u003evulnerability and patch management,\u003c\/li\u003e\n\n\u003cli\u003esecure development lifecycle,\u003c\/li\u003e\n\n\u003cli\u003ebackup and restoration,\u003c\/li\u003e\n\n\u003cli\u003eincident management,\u003c\/li\u003e\n\n\u003cli\u003eBCP and disaster recovery,\u003c\/li\u003e\n\n\u003cli\u003esupply chain security,\u003c\/li\u003e\n\n\u003cli\u003epersonnel security,\u003c\/li\u003e\n\n\u003cli\u003ephysical security,\u003c\/li\u003e\n\n\u003cli\u003epenetration tests,\u003c\/li\u003e\n\n\u003cli\u003eISO 27001, SOC 2, or other agreed verification.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\u003cp\u003eThe annex is designed so that further requirements can be added for customers subject to, for example, the \u003cstrong\u003eCybersecurity Act\/NIS2\u003c\/strong\u003e. The Swedish Cybersecurity Act (2025:1506), which has been in effect since January 15, 2026, contains, among other things, requirements for supply chain security for businesses subject to the act.\u003c\/p\u003e\u003ch2\u003eAnnex 5 – Exit, data export, and deletion certificate\u003c\/h2\u003e\u003cp\u003eThe issue of exit is often forgotten when a SaaS agreement is signed. This template regulates from the start how the customer will be able to leave the service.\u003c\/p\u003e\u003cp\u003eThe annex contains fields for export period, export format, metadata, API export, secure transfer, costs, migration support, and deletion. Additionally, there is a specific \u003cstrong\u003edeletion certificate\u003c\/strong\u003e for production environments, test environments, support copies, and backups.\u003c\/p\u003e\u003ch2\u003eAnnex 6 – Pricing Annex and Change Log\u003c\/h2\u003e\u003cp\u003eReady-to-use pricing annex for basic fees, users, implementation, premium support, over-usage, consulting time, and exit support. A version and change log makes it easier to document future changes to the agreement.\u003c\/p\u003e\u003ch2\u003eLegally updated for 2026\u003c\/h2\u003e\u003cp\u003eVersion 1.0 was legally reviewed on \u003cstrong\u003eSeptember 27, 2026\u003c\/strong\u003e. The template has been designed with consideration given to, among other things:\u003c\/p\u003e\u003cul\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eThe Contracts Act (1915:218)\u003c\/strong\u003e – including contract formation and Section 36 regarding unfair contract terms,\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eThe Copyright Act (1960:729)\u003c\/strong\u003e – including rules concerning computer programs and licensing,\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eGDPR (EU) 2016\/679\u003c\/strong\u003e – specifically Article 28 on data processors, Article 32 on security, and rules regarding third-country transfers,\u003c\/li\u003e\n\n\u003cli\u003eSwedish supplementary data protection legislation,\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eThe Cybersecurity Act (2025:1506)\u003c\/strong\u003e – relevant for agreements with businesses subject to NIS2 rules.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\u003cp\u003eThe Swedish Authority for Privacy Protection's guidance on data processing agreements and third-country transfers has also been taken into account.\u003c\/p\u003e\u003ch2\u003eLiability caps and risk allocation – not an arbitrary standard value\u003c\/h2\u003e\u003cp\u003eThe template contains options for liability caps but leaves the specific percentage open for customization. An appropriate liability cap depends on, among other things, contract value, data sensitivity, the customer's operations, cyber risk, insurance coverage, and potential damage. The document therefore reminds the user to specifically assess exceptions for, for example, confidentiality, personal data breaches, intellectual property claims, as well as intent and gross negligence.\u003c\/p\u003e\u003ch2\u003eWho is the SaaS agreement suitable for?\u003c\/h2\u003e\u003cp\u003eThe template is suitable for, among others:\u003c\/p\u003e\u003cul\u003e\n\n\u003cli\u003eSaaS companies and software firms,\u003c\/li\u003e\n\n\u003cli\u003estartups and scaleups,\u003c\/li\u003e\n\n\u003cli\u003eIT consulting firms selling their own cloud services,\u003c\/li\u003e\n\n\u003cli\u003ecompanies buying business systems and web-based services,\u003c\/li\u003e\n\n\u003cli\u003eproviders of CRM, HR, finance, analysis, and automation systems,\u003c\/li\u003e\n\n\u003cli\u003ecompanies needing a standard agreement for corporate clients or procurements.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\u003ch2\u003eWord and PDF\u003c\/h2\u003e\u003cul\u003e\n\n\u003cli\u003e15 professionally designed A4 pages\u003c\/li\u003e\n\n\u003cli\u003eEditable Word file (DOCX)\u003c\/li\u003e\n\n\u003cli\u003ePDF version\u003c\/li\u003e\n\n\u003cli\u003e32 contract areas\u003c\/li\u003e\n\n\u003cli\u003e6 integrated annexes\u003c\/li\u003e\n\n\u003cli\u003eReady-to-use tables and fillable fields\u003c\/li\u003e\n\n\u003cli\u003eAlternative clauses where risk allocation needs to be selected\u003c\/li\u003e\n\n\u003cli\u003eSignature section\u003c\/li\u003e\n\n\u003cli\u003eLegal checklist before signing\u003c\/li\u003e\n\n\u003cli\u003eSources of law and version information\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\u003ch2\u003eImportant regarding customization\u003c\/h2\u003e\u003cp\u003eSaaS agreements are heavily influenced by the concrete service and the parties' operations. A simple project platform and a business-critical cloud service for healthcare, finance, or socially important services should not have identical contractual terms.\u003c\/p\u003e\u003cp\u003eThe template must therefore be adapted based on actual functionality, information classification, customer data, SLA, subcontractors, operating region, liability, insurance, and any sector-specific requirements. It is a professional contractual foundation but does not replace individual legal advice in particularly complex or high-risk business deals.\u003c\/p\u003e\u003ch2\u003eDigital delivery\u003c\/h2\u003e\u003cp\u003eAfter purchase, the customer receives:\u003c\/p\u003e\u003cul\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eSaaS_agreement_Swedish_law_2026.docx\u003c\/strong\u003e – fully editable Word template\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eSaaS_agreement_Swedish_law_2026.pdf\u003c\/strong\u003e – ready-to-use PDF version\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\u003cp\u003eThe product is delivered digitally. No physical product is sent.\u003c\/p\u003e\u003ch2\u003eFrequently Asked Questions\u003c\/h2\u003e\u003ch3\u003eIs this just a license agreement?\u003c\/h3\u003e\u003cp\u003eNo. It is a complete SaaS agreement with service specification, SLA, GDPR\/DPA, security, exit, and commercial terms.\u003c\/p\u003e\u003ch3\u003eIs a data processing agreement included?\u003c\/h3\u003e\u003cp\u003eYes. Annex 3 is an integrated DPA annex adapted to Article 28 of the GDPR.\u003c\/p\u003e\u003ch3\u003eCan the agreement be used by both provider and customer?\u003c\/h3\u003e\u003cp\u003eYes. The clauses are designed as a balanced B2B foundation and several commercial risk points contain selectable options.\u003c\/p\u003e\u003ch3\u003eIs the agreement adapted for NIS2?\u003c\/h3\u003e\u003cp\u003eThe agreement contains a security annex and supply chain requirements that can be used as a basis for NIS2-related customer requirements. However, a business subject to the Cybersecurity Act must always adapt the agreement to its own risk analysis and any applicable regulations.\u003c\/p\u003e\u003ch3\u003eCan I edit everything?\u003c\/h3\u003e\u003cp\u003eYes. The Word version is fully editable and contains clear brackets and tables for content that needs to be customized.\u003c\/p\u003e","brand":"Svenska Dokumentmallar","offers":[{"title":"Default Title","offer_id":55511376560470,"sku":"SAAS-AVTAL-2026","price":149.0,"currency_code":"SEK","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0827\/2373\/3846\/files\/saas-avtal-svensk-ratt-2026-word-pdf.png?v=1790501479"},{"product_id":"allmanna-villkor-mall-e-handel-foretag-2026","title":"Terms and Conditions Template Package 2026 – E-commerce \u0026 Business Word\/PDF","description":"\n\u003ch2\u003eGeneral Terms and Conditions template 2026 for e-commerce and business\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003eA complete and editable template package in Word and PDF\u003c\/strong\u003e for Swedish companies selling goods, services, or digital content via a website, app, or other distance channel. The template is structured for both \u003cstrong\u003eB2C and B2B\u003c\/strong\u003e and contains clear, selectable sections so you can adapt the terms to your specific business.\u003c\/p\u003e\n\n\u003cp\u003eGeneral terms and conditions are a central part of a company's contractual structure. They regulate, among other things, how orders are placed, when an agreement is formed, prices and payment, delivery, the right of withdrawal, complaints, digital content, liability, intellectual property rights, and dispute resolution. This template is designed for Swedish law and updated for the regulations applicable in \u003cstrong\u003e2026\u003c\/strong\u003e.\u003c\/p\u003e\n\n\u003ch3\u003eImportant 2026: new withdrawal function for distance contracts\u003c\/h3\u003e\n\u003cp\u003eThe template package takes into account the new rules that entered into force on \u003cstrong\u003eJune 19, 2026\u003c\/strong\u003e. When an agreement with a statutory right of withdrawal is entered into via a website or app, the company must, where relevant, provide a specific withdrawal function on the same website or in the same app. The template contains both the terms text and an implementation checklist for this.\u003c\/p\u003e\n\n\u003ch3\u003eWhat is included\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003eGeneral Terms and Conditions 2026 – complete editable template\u003c\/li\u003e\n\n\u003cli\u003eModule for sales to consumers (B2C)\u003c\/li\u003e\n\n\u003cli\u003eModule for sales between companies (B2B)\u003c\/li\u003e\n\n\u003cli\u003eTerms for physical goods\u003c\/li\u003e\n\n\u003cli\u003eTerms for digital content and digital services\u003c\/li\u003e\n\n\u003cli\u003eTerms for services\u003c\/li\u003e\n\n\u003cli\u003eRight of withdrawal and return policy\u003c\/li\u003e\n\n\u003cli\u003e2026 requirements for a specific withdrawal function\u003c\/li\u003e\n\n\u003cli\u003eComplaints and liability for defects\u003c\/li\u003e\n\n\u003cli\u003ePayment and delivery terms\u003c\/li\u003e\n\n\u003cli\u003eIntellectual property rights and license terms\u003c\/li\u003e\n\n\u003cli\u003eLimitation of liability for B2B\u003c\/li\u003e\n\n\u003cli\u003eForce majeure\u003c\/li\u003e\n\n\u003cli\u003ePersonal data and reference to privacy policy\u003c\/li\u003e\n\n\u003cli\u003eARN (National Board for Consumer Disputes) and alternative dispute resolution\u003c\/li\u003e\n\n\u003cli\u003eStandard form for right of withdrawal\u003c\/li\u003e\n\n\u003cli\u003eRecommended checkout texts for digital content and services\u003c\/li\u003e\n\n\u003cli\u003eImplementation checklist for Swedish e-commerce 2026\u003c\/li\u003e\n\n\u003cli\u003eB2B clauses to consider\u003c\/li\u003e\n\n\u003cli\u003eLegal basis and version history\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eFor digital products and downloadable content\u003c\/h3\u003e\n\u003cp\u003eThe template contains a specific section for digital content. This covers, among other things, the delivery of downloadable files, technical requirements, functionality, compatibility, liability for defects, and how explicit consent can be formulated when delivery is to begin immediately and the right of withdrawal is to cease in accordance with statutory conditions.\u003c\/p\u003e\n\n\u003ch3\u003eFor companies selling to consumers\u003c\/h3\u003e\n\u003cp\u003eThe B2C section is designed with consideration for central Swedish consumer rules, including the Act on Distance Contracts and Contracts Off-Premises, the Consumer Sales Act, the E-Commerce Act, the Price Information Act, and rules on alternative dispute resolution. The template clearly reminds the user that mandatory consumer rights may not be contracted away to the detriment of the consumer.\u003c\/p\u003e\n\n\u003ch3\u003eFor B2B sales\u003c\/h3\u003e\n\u003cp\u003eFor corporate customers, there are separate clauses regarding, among other things, complaints, default interest, liability caps, indirect damages, and the use of digital material. These parts are clearly marked so that they are not confused with consumer terms.\u003c\/p\u003e\n\n\u003ch3\u003eProfessionally designed and easy to adapt\u003c\/h3\u003e\n\u003cp\u003eThe document uses clear headings, a professional layout, and marked fields where the company's own information should be filled in. Sections that do not fit the business can be removed, and the template contains instructions on which parts normally need to be adapted.\u003c\/p\u003e\n\n\u003ch3\u003eDelivered in Word and PDF\u003c\/h3\u003e\n\u003cp\u003eYou receive both \u003cstrong\u003eDOCX\u003c\/strong\u003e and \u003cstrong\u003ePDF\u003c\/strong\u003e. The Word file is fully editable and can be customized with the company's name, corporate identity number, contact details, payment terms, delivery terms, return procedures, license terms, and other business-specific information. The PDF version serves as a reference and can also be used as a basis for publication after adaptation.\u003c\/p\u003e\n\n\u003ch3\u003eLegal basis\u003c\/h3\u003e\n\u003cp\u003eThe template has been reviewed against central rules applicable as of October 2, 2026, including:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003eAct (2005:59) on Distance Contracts and Contracts Off-Premises\u003c\/li\u003e\n\n\u003cli\u003eConsumer Sales Act (2022:260)\u003c\/li\u003e\n\n\u003cli\u003eAct (2002:562) on Electronic Commerce and Other Information Society Services\u003c\/li\u003e\n\n\u003cli\u003ePrice Information Act (2004:347)\u003c\/li\u003e\n\n\u003cli\u003eAct (2015:671) on Alternative Dispute Resolution in Consumer Relations\u003c\/li\u003e\n\n\u003cli\u003eThe Contracts Act, the Sale of Goods Act, and the Interest Act where applicable\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eSuitable for, among others\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003eweb shops and e-commerce companies\u003c\/li\u003e\n\n\u003cli\u003ecompanies selling digital products\u003c\/li\u003e\n\n\u003cli\u003eSaaS and IT companies\u003c\/li\u003e\n\n\u003cli\u003econsultants and service companies\u003c\/li\u003e\n\n\u003cli\u003ecompanies selling to both private individuals and other companies\u003c\/li\u003e\n\n\u003cli\u003esmall and medium-sized enterprises that need a clear contractual basis\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eFrequently Asked Questions\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003eCan the template be used for both B2C and B2B?\u003c\/strong\u003e\u003cbr\u003eYes. It contains separate and clearly marked sections for consumers and corporate customers, respectively.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eDoes the template include terms for digital products?\u003c\/strong\u003e\u003cbr\u003eYes. Digital content and digital services have their own sections, including recommended checkout text for explicit consent upon immediate delivery.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eIs it adapted for the new rules in 2026?\u003c\/strong\u003e\u003cbr\u003eYes. Version 1.0 was legally reviewed on October 2, 2026, and specifically includes the new withdrawal function that has been in effect since June 19, 2026.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eCan I use the document directly without changes?\u003c\/strong\u003e\u003cbr\u003eNo. General terms and conditions must always be adapted to the company's actual operations, products, payment solutions, delivery methods, and customer groups. The template is a professional foundation and does not replace individual legal advice in complex or unusual situations.\u003c\/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eFormat:\u003c\/strong\u003e Word (DOCX) + PDF\u003cbr\u003e\n\u003cstrong\u003eLanguage:\u003c\/strong\u003e Swedish\u003cbr\u003e\n\u003cstrong\u003eJurisdiction:\u003c\/strong\u003e Sweden\u003cbr\u003e\n\u003cstrong\u003eVersion:\u003c\/strong\u003e 2026-10-02\u003c\/p\u003e\n","brand":"Svenska Dokumentmallar","offers":[{"title":"Default Title","offer_id":55575115301206,"sku":"ALLM-VILLKOR-2026","price":79.0,"currency_code":"SEK","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0827\/2373\/3846\/files\/allmanna-villkor-mallpaket-2026.png?v=1790938039"},{"product_id":"gdpr-registerforteckning-ropa-mall-2026","title":"GDPR Record of Processing Activities (RoPA) Template Package 2026 – Word\/PDF\/Excel","description":"\n\u003ch2\u003eGDPR Record of Processing Activities \/ RoPA 2026 – complete template package in Word, PDF, and Excel\u003c\/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eA complete work tool for a record of personal data processing activities in accordance with Article 30 of the GDPR.\u003c\/strong\u003e The package is developed for Swedish companies and organizations that need to document, structure, and continuously follow up on their processing of personal data.\u003c\/p\u003e\n\n\u003cp\u003eYou will receive both a professional \u003cstrong\u003eWord\/PDF template\u003c\/strong\u003e and a practical \u003cstrong\u003eExcel register\u003c\/strong\u003e with separate sections for the data controller and data processor, retention schedule, legal basis, suppliers\/processors, and verification that mandatory information is included.\u003c\/p\u003e\n\n\u003ch3\u003eThis is included\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003eRecord of processing activities for the data controller\u003c\/li\u003e\n\n\u003cli\u003eRecord of processing activities for the data processor\u003c\/li\u003e\n\n\u003cli\u003eRetention schedule \/ storage limitation\u003c\/li\u003e\n\n\u003cli\u003eLegal basis matrix according to Article 6 of the GDPR\u003c\/li\u003e\n\n\u003cli\u003eCheck for sensitive personal data according to Article 9\u003c\/li\u003e\n\n\u003cli\u003eCheck for data regarding criminal convictions according to Article 10\u003c\/li\u003e\n\n\u003cli\u003eDocumentation of recipients and data processors\u003c\/li\u003e\n\n\u003cli\u003eDocumentation of third-country transfers and transfer mechanisms\u003c\/li\u003e\n\n\u003cli\u003eOverall technical and organizational security measures\u003c\/li\u003e\n\n\u003cli\u003eDPIA status and privacy information as practical control fields\u003c\/li\u003e\n\n\u003cli\u003eSupplier and processor register\u003c\/li\u003e\n\n\u003cli\u003eAnnual\/ongoing control checklist\u003c\/li\u003e\n\n\u003cli\u003eReview log\u003c\/li\u003e\n\n\u003cli\u003eExample entry for customer and order management\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eExcel tool with automatic quality control\u003c\/h3\u003e\n\u003cp\u003eThe Excel file is designed for actual, ongoing use. It includes, among other things:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003eoverview with key figures\u003c\/li\u003e\n\n\u003cli\u003e200 prepared rows for the data controller's processing activities\u003c\/li\u003e\n\n\u003cli\u003e200 prepared rows for data processor activities\u003c\/li\u003e\n\n\u003cli\u003eautomatic field that shows \u003cstrong\u003eComplete\u003c\/strong\u003e or \u003cstrong\u003eSupplement\u003c\/strong\u003e\n\n\u003c\/li\u003e\n\n\u003cli\u003ewarning flags for sensitive data and third-country transfers\u003c\/li\u003e\n\n\u003cli\u003edropdown menus for legal basis, DPIA status, and status\u003c\/li\u003e\n\n\u003cli\u003ereminder markers for when the next review date has passed\u003c\/li\u003e\n\n\u003cli\u003eseparate retention schedule\u003c\/li\u003e\n\n\u003cli\u003eseparate supplier\/processor list\u003c\/li\u003e\n\n\u003cli\u003elegal sources and links to IMY and EUR-Lex\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eWhat must be included according to Article 30?\u003c\/h3\u003e\n\u003cp\u003eFor a data controller, the register must include contact details, purposes, categories of data subjects and personal data, recipients, any third-country transfers, and – where possible – planned time limits for erasure, as well as a general description of security measures.\u003c\/p\u003e\n\n\u003cp\u003eData processors have a separate record-keeping requirement which includes, among other things, the data controllers for whom they process data, categories of processing, third-country transfers, and – where possible – security measures.\u003c\/p\u003e\n\n\u003ch3\u003eEven smaller companies may be covered\u003c\/h3\u003e\n\u003cp\u003eThere is a limited exemption for organizations with fewer than 250 employees, but the exemption does not apply if the processing is not occasional, is likely to result in a risk to the rights and freedoms of data subjects, or involves sensitive personal data or data relating to criminal convictions. Recurring processes such as payroll administration are therefore a clear example of processing that may need to be registered.\u003c\/p\u003e\n\n\u003ch3\u003eRetention schedule as a supplement\u003c\/h3\u003e\n\u003cp\u003eThe GDPR is based on the principle of storage limitation. Personal data shall not be kept longer than is necessary for the purpose, unless another law requires longer retention. The template package therefore contains a separate retention schedule where the business can document the start point, retention period or criterion, legal requirements, systems, and the responsible person.\u003c\/p\u003e\n\n\u003ch3\u003eLegal basis matrix\u003c\/h3\u003e\n\u003cp\u003eThe package provides support for the six legal bases under Article 6:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003econsent\u003c\/li\u003e\n\n\u003cli\u003econtract\u003c\/li\u003e\n\n\u003cli\u003elegal obligation\u003c\/li\u003e\n\n\u003cli\u003eprotection of vital interests\u003c\/li\u003e\n\n\u003cli\u003epublic interest \/ public authority\u003c\/li\u003e\n\n\u003cli\u003elegitimate interests\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003eThe template also serves as a reminder that the processing of sensitive personal data requires additional support under Article 9 and that data regarding criminal convictions is regulated separately in Article 10.\u003c\/p\u003e\n\n\u003ch3\u003eThird-country transfers\u003c\/h3\u003e\n\u003cp\u003eThe register contains specific fields for the country or international organization as well as the transfer mechanism, such as an adequacy decision or standard contractual clauses (SCC). This makes it easier to keep the register of processing activities, data processing agreements (DPA), sub-processor lists, and privacy information consistent.\u003c\/p\u003e\n\n\u003ch3\u003eSuitable for, among others\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003elimited companies and smaller businesses\u003c\/li\u003e\n\n\u003cli\u003ee-commerce companies\u003c\/li\u003e\n\n\u003cli\u003eSaaS and IT businesses\u003c\/li\u003e\n\n\u003cli\u003eemployers and HR functions\u003c\/li\u003e\n\n\u003cli\u003econsultancy and service firms\u003c\/li\u003e\n\n\u003cli\u003eorganizations that process personal data on behalf of clients\u003c\/li\u003e\n\n\u003cli\u003ebusinesses that need to structure or update their GDPR work\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eLegal basis\u003c\/h3\u003e\n\u003cp\u003eThe template was legally reviewed on \u003cstrong\u003eOctober 2, 2026\u003c\/strong\u003e, with particular consideration given to:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003eRegulation (EU) 2016\/679 of the European Parliament and of the Council (GDPR), especially Articles 5, 6, 9, 10, 13–14, 28, 30, and 32\u003c\/li\u003e\n\n\u003cli\u003eAct (2018:218) with supplementary provisions to the EU General Data Protection Regulation\u003c\/li\u003e\n\n\u003cli\u003ecurrent guidance from the Swedish Authority for Privacy Protection (IMY)\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eFrequently asked questions\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003eIs the record of processing activities the same thing as a privacy policy?\u003c\/strong\u003e\u003cbr\u003eNo. The record of processing activities is internal documentation according to Article 30. Privacy information according to Articles 13–14 is information provided to the data subjects.\u003c\/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eDoes a small company really need a processing register?\u003c\/strong\u003e\u003cbr\u003eIt depends on the processing activities. The exemption for fewer than 250 employees is limited. Regular processing, high-risk processing, and processing of special categories or criminal data may be subject to the registration obligation.\u003c\/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eCan I use the Excel file as my actual RoPA register?\u003c\/strong\u003e\u003cbr\u003eYes. It is structured for ongoing electronic record-keeping, but the content must be adapted to the organization's actual processing activities.\u003c\/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eDoes the template specify ready-made storage periods?\u003c\/strong\u003e\u003cbr\u003eNo. Retention periods must be assessed based on the purpose and any statutory retention requirements. The template helps you document the decision without claiming that a general time limit applies to all businesses.\u003c\/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eFormat:\u003c\/strong\u003e Word (DOCX) + PDF + Excel (XLSX)\u003cbr\u003e\n\u003cstrong\u003eLanguage:\u003c\/strong\u003e Swedish\u003cbr\u003e\n\u003cstrong\u003eJurisdiction:\u003c\/strong\u003e Sweden \/ EU GDPR\u003cbr\u003e\n\u003cstrong\u003eVersion:\u003c\/strong\u003e 1.0 – 2026-10-02\u003c\/p\u003e\n\n\u003cp\u003e\u003cem\u003eThe templates are general work documents and do not replace individual legal advice. Always adapt them to actual processing, sector, systems, agreements, and applicable special legislation.\u003c\/em\u003e\u003c\/p\u003e\n","brand":"Svenska Dokumentmallar","offers":[{"title":"Default Title","offer_id":55576879432022,"sku":"GDPR-ROPA-2026","price":199.0,"currency_code":"SEK","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0827\/2373\/3846\/files\/gdpr-registerforteckning-ropa-2026.png?v=1790944866"},{"product_id":"data-act-mallpaket-2026","title":"Data Act Template Package 2026 – Agreements \u0026 Compliance Word\/PDF\/Excel","description":"\n\u003ch2\u003eData Act Template Package 2026 – agreements, data sharing and cloud switching\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003eA complete compliance package for companies affected by the EU Data Act (Regulation (EU) 2023\/2854)\u003c\/strong\u003e. The package is designed for Swedish companies working with connected products, related digital services, data sharing, third-party access, or data processing services such as cloud, SaaS, PaaS, and IaaS.\u003c\/p\u003e\n\n\u003cp\u003eThe Data Act began to apply on \u003cstrong\u003eSeptember 12, 2025\u003c\/strong\u003e. As of \u003cstrong\u003eSeptember 12, 2026\u003c\/strong\u003e, Article 3(1)’s specific design requirements also apply to connected products and related services placed on the market after this date. The package is updated and legally reviewed as of \u003cstrong\u003eOctober 2, 2026\u003c\/strong\u003e.\u003c\/p\u003e\n\n\u003ch3\u003eIncluded – 9 files\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eData Holder – User\u003c\/strong\u003e, agreement template in Word (DOCX)\u003c\/li\u003e\n\n\u003cli\u003eData Holder – User, PDF\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eData Holder – Data Recipient\u003c\/strong\u003e, agreement template in Word (DOCX)\u003c\/li\u003e\n\n\u003cli\u003eData Holder – Data Recipient, PDF\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eCloud Switching \u0026amp; Exit Addendum\u003c\/strong\u003e, Word (DOCX)\u003c\/li\u003e\n\n\u003cli\u003eCloud Switching \u0026amp; Exit Addendum, PDF\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eData Act Compliance Guide \u0026amp; Checklist 2026\u003c\/strong\u003e, Word (DOCX)\u003c\/li\u003e\n\n\u003cli\u003eData Act Compliance Guide \u0026amp; Checklist 2026, PDF\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eData Act Compliance 2026 – Excel tool\u003c\/strong\u003e with registers, monitoring, and control\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003e1. Agreement between Data Holder and User\u003c\/h3\u003e\n\u003cp\u003eThe first agreement template is intended for the relationship between the entity holding readily available data from a connected product or related service and the user who has rights under the Data Act. The template regulates, among other things:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003eproduct data and related service data\u003c\/li\u003e\n\n\u003cli\u003edata catalogs, metadata, and technical formats\u003c\/li\u003e\n\n\u003cli\u003edirect and indirect access\u003c\/li\u003e\n\n\u003cli\u003eAPIs, export functions, and other interfaces\u003c\/li\u003e\n\n\u003cli\u003efree access for the user where required by the Data Act\u003c\/li\u003e\n\n\u003cli\u003ethe data holder’s use of non-personal data\u003c\/li\u003e\n\n\u003cli\u003ethe user’s right to request sharing with third parties\u003c\/li\u003e\n\n\u003cli\u003epersonal data and the relationship to the GDPR\u003c\/li\u003e\n\n\u003cli\u003etrade secrets and protective measures\u003c\/li\u003e\n\n\u003cli\u003esecurity limitations\u003c\/li\u003e\n\n\u003cli\u003eprohibited competitive use of data\u003c\/li\u003e\n\n\u003cli\u003eincidents, amendments, and termination\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003e2. Agreement between Data Holder and Data Recipient\u003c\/h3\u003e\n\u003cp\u003eThe second agreement template is used when a user requests that a data holder makes data available to an external third party. It is particularly relevant for companies building services on top of IoT, automotive, machine, energy, industrial, or other product data.\u003c\/p\u003e\n\n\u003cp\u003eThe template includes provisions regarding the user’s instruction, data quality, technical delivery, permitted use, further sharing, compensation, trade secrets, personal data, security, and non-discriminatory terms.\u003c\/p\u003e\n\n\u003ch3\u003eReasonable compensation and the SME rule\u003c\/h3\u003e\n\u003cp\u003eWhen Article 9 of the Data Act is applicable, compensation for making data available between businesses must be \u003cstrong\u003enon-discriminatory and reasonable\u003c\/strong\u003e. The package contains a specific compensation annex where costs for, among other things, formats, electronic transfer, and storage can be documented.\u003c\/p\u003e\n\n\u003cp\u003eIf the data recipient is an SME or a qualified non-profit research organization, the compensation may be specifically limited under Article 9(4). The template therefore contains specific fields for SME status and cost documentation.\u003c\/p\u003e\n\n\u003ch3\u003e3. Cloud Switching \u0026amp; Exit Addendum\u003c\/h3\u003e\n\u003cp\u003eThe cloud section is designed for data processing service agreements where the Data Act's rules on provider switching are applicable. It can be used as an addendum to, for example, SaaS, PaaS, or IaaS agreements and regulates, among other things:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003eswitching to another provider\u003c\/li\u003e\n\n\u003cli\u003eporting to local ICT infrastructure\u003c\/li\u003e\n\n\u003cli\u003eexportable data and digital assets\u003c\/li\u003e\n\n\u003cli\u003enotice period for initiating a switch\u003c\/li\u003e\n\n\u003cli\u003etransition period\u003c\/li\u003e\n\n\u003cli\u003ereasonable technical assistance\u003c\/li\u003e\n\n\u003cli\u003eoperational continuity\u003c\/li\u003e\n\n\u003cli\u003esecurity during transfer\u003c\/li\u003e\n\n\u003cli\u003eAPIs and export formats\u003c\/li\u003e\n\n\u003cli\u003edata retrieval period\u003c\/li\u003e\n\n\u003cli\u003efinal deletion\u003c\/li\u003e\n\n\u003cli\u003eswitching fees and the transition to 2027\u003c\/li\u003e\n\n\u003cli\u003einformation on international governmental access to non-personal data\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eImportant cloud dates\u003c\/h3\u003e\n\u003cp\u003eThe Data Act requires, among other things, that relevant cloud agreements clearly describe the switching process. The maximum notice period to initiate the switching process may generally not exceed \u003cstrong\u003etwo months\u003c\/strong\u003e, and the mandatory maximum transition period is generally \u003cstrong\u003e30 calendar days\u003c\/strong\u003e. Furthermore, the customer must have at least a \u003cstrong\u003e30-calendar-day data retrieval period\u003c\/strong\u003e after the transition period where the rules are applicable.\u003c\/p\u003e\n\n\u003cp\u003eFrom \u003cstrong\u003eJanuary 12, 2027\u003c\/strong\u003e, switching charges under Article 29 must be fully abolished. Until then, only reduced switching charges may be levied within the limits specified by the Data Act.\u003c\/p\u003e\n\n\u003ch3\u003e4. Compliance Guide 2026\u003c\/h3\u003e\n\u003cp\u003eThe guide helps the business determine where the Data Act affects the organization and how implementation can be structured. It includes, among other things:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003escope test for roles and operations\u003c\/li\u003e\n\n\u003cli\u003eimportant dates\u003c\/li\u003e\n\n\u003cli\u003eproduct and service mapping\u003c\/li\u003e\n\n\u003cli\u003edata mapping\u003c\/li\u003e\n\n\u003cli\u003eArticle 3 design requirements\u003c\/li\u003e\n\n\u003cli\u003euser access and third-party sharing\u003c\/li\u003e\n\n\u003cli\u003etrade secrets\u003c\/li\u003e\n\n\u003cli\u003eB2B compensation\u003c\/li\u003e\n\n\u003cli\u003eunfair unilaterally imposed data terms\u003c\/li\u003e\n\n\u003cli\u003ecloud switching\u003c\/li\u003e\n\n\u003cli\u003eSwedish supplementary legislation and current status\u003c\/li\u003e\n\n\u003cli\u003eimplementation checklist\u003c\/li\u003e\n\n\u003cli\u003elegal sources and EU Commission guidance\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003e5. Excel tool for practical implementation\u003c\/h3\u003e\n\u003cp\u003eThe Excel file is built as a working tool, not just an empty table. It contains separate sheets for:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eScope\u003c\/strong\u003e – role assessment and applicability\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eProducts\u003c\/strong\u003e – connected products and related services\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eData Catalog\u003c\/strong\u003e – product data, service data, formats, metadata, and access\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eRequests\u003c\/strong\u003e – register of user and third-party requests\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eRecipients\u003c\/strong\u003e – data recipients, compensation, and protective measures\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eCloud Switching\u003c\/strong\u003e – control of notice period, transition, export, and deletion\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eAgreement Review\u003c\/strong\u003e – risk control for unfair terms under Article 13\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eActions\u003c\/strong\u003e – compliance plan with person responsible, priority, and deadline\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eSources\u003c\/strong\u003e – primary EU sources and Swedish legislative status\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003eThe dashboard automatically calculates, among other things, the number of mapped products, open access requests, active data recipients, cloud services needing action, and open compliance actions.\u003c\/p\u003e\n\n\u003ch3\u003eFor connected products after September 12, 2026\u003c\/h3\u003e\n\u003cp\u003eArticle 3(1) implies that relevant connected products and related services placed on the market after September 12, 2026, must be designed so that product data and related service data, including relevant metadata, are by default easily and securely accessible, free of charge, comprehensive, structured, commonly used, and machine-readable, and – where relevant and technically feasible – directly accessible to the user.\u003c\/p\u003e\n\n\u003cp\u003eThis means that the Data Act is not just a legal contractual matter. For many businesses, it is also a matter of product architecture, API design, metadata, user portals, and internal data flows.\u003c\/p\u003e\n\n\u003ch3\u003eTrade secrets\u003c\/h3\u003e\n\u003cp\u003eThe Data Act does not mean that trade secrets must automatically be disclosed without protection, but trade secrets are not a general exception to data access either. The package therefore contains clauses for proportionate technical and organizational protective measures, documentation, and specific handling of situations where the data holder needs to withhold, suspend, or, in exceptional cases, refuse access according to the Data Act’s conditions.\u003c\/p\u003e\n\n\u003ch3\u003eUnfair data terms between businesses\u003c\/h3\u003e\n\u003cp\u003eChapter IV contains specific rules on unilaterally imposed B2B terms regarding data access, data use, liability, and remedies. Certain terms may be directly unfair or presumed to be unfair. The compliance tool therefore contains a specific agreement review tab.\u003c\/p\u003e\n\n\u003ch3\u003eThe EU Commission’s model terms\u003c\/h3\u003e\n\u003cp\u003eThe EU Commission has published non-binding model terms for data access and data use as well as standard clauses for cloud computing contracts. The templates in this package are independently designed Swedish documents that build on the Data Act’s binding requirements and use the Commission’s guidance as support. They are not a verbatim copy of the Commission’s models.\u003c\/p\u003e\n\n\u003ch3\u003eSwedish status 2026\u003c\/h3\u003e\n\u003cp\u003eThe Data Act is an EU regulation and applies directly. Sweden is simultaneously working on supplementary rules regarding, among other things, the competent authority, sanctions, and dispute resolution. SOU 2025:118 has proposed supplementary Swedish legislation and designated the Swedish Post and Telecom Authority (PTS) as the competent authority. As of the product's review date, the Swedish legislative chain is still marked as ongoing, which is taken into account in the guide.\u003c\/p\u003e\n\n\u003ch3\u003eLegal basis\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003eRegulation (EU) 2023\/2854 of the European Parliament and of the Council (Data Act)\u003c\/li\u003e\n\n\u003cli\u003eGDPR – Regulation (EU) 2016\/679, where personal data is processed\u003c\/li\u003e\n\n\u003cli\u003eapplicable Swedish contract and trade secret law\u003c\/li\u003e\n\n\u003cli\u003eEU Commission Data Act FAQ and implementation material\u003c\/li\u003e\n\n\u003cli\u003eEU Commission non-binding MCT\/SCC material\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eSuitable for, among others\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003eIoT and hardware companies\u003c\/li\u003e\n\n\u003cli\u003emachine and industrial companies\u003c\/li\u003e\n\n\u003cli\u003eautomotive and mobility services\u003c\/li\u003e\n\n\u003cli\u003eenergy and smart-grid solutions\u003c\/li\u003e\n\n\u003cli\u003eSaaS, PaaS, and IaaS providers\u003c\/li\u003e\n\n\u003cli\u003esystem integrators\u003c\/li\u003e\n\n\u003cli\u003edata and analysis services\u003c\/li\u003e\n\n\u003cli\u003ecompanies receiving product data at the customer’s request\u003c\/li\u003e\n\n\u003cli\u003elegal, compliance, and IT functions\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eImportant to know\u003c\/h3\u003e\n\u003cp\u003eThe Data Act is technically and contractually dependent on the business’s actual products, data flows, roles, and system architecture. The templates must therefore always be adapted. The package does not replace individual legal advice in complex, cross-border, or litigious situations.\u003c\/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eFormat:\u003c\/strong\u003e Word (DOCX) + PDF + Excel (XLSX)\u003cbr\u003e\n\u003cstrong\u003eLanguage:\u003c\/strong\u003e Swedish\u003cbr\u003e\n\u003cstrong\u003eJurisdiction:\u003c\/strong\u003e Sweden \/ EU\u003cbr\u003e\n\u003cstrong\u003eNumber of files:\u003c\/strong\u003e 9\u003cbr\u003e\n\u003cstrong\u003eVersion:\u003c\/strong\u003e 1.0 – 2026-10-02\u003c\/p\u003e\n","brand":"Svenska Dokumentmallar","offers":[{"title":"Default Title","offer_id":55579233321302,"sku":"DATA-ACT-2026","price":249.0,"currency_code":"SEK","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0827\/2373\/3846\/files\/data-act-mallpaket-2026.png?v=1790956180"},{"product_id":"tillganglighetslagen-ehandel-mallpaket-2026","title":"Accessibility Act E-commerce Template Package 2026 – Word\/PDF\/Excel","description":"\n\u003ch2\u003eAccessibility Act for E-commerce 2026 – complete compliance package\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003eProfessional template package for Swedish e-commerce companies that need to work in a structured manner with the Act (2023:254) on the Accessibility of Certain Products and Services (LPTT) and the European Accessibility Act (EAA).\u003c\/strong\u003e The package contains ready-to-use Word and PDF templates as well as a comprehensive Excel tool for scope assessment, auditing, defect management, suppliers, feedback, exemptions, and ongoing follow-up.\u003c\/p\u003e\n\n\u003cp\u003eThe Accessibility Act entered into force on \u003cstrong\u003eJune 28, 2025\u003c\/strong\u003e. E-commerce services covered by the act must, among other things, be accessible to persons with disabilities, provide information on the service's accessibility, and ensure that key functions such as identification, electronic signing, security, and payment can be used in an accessible manner.\u003c\/p\u003e\n\n\u003ch3\u003eIncluded – 9 files\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003eInformation on e-commerce service accessibility 2026 – Word (DOCX)\u003c\/li\u003e\n\n\u003cli\u003eInformation on e-commerce service accessibility 2026 – PDF\u003c\/li\u003e\n\n\u003cli\u003eAccessibility routine and compliance policy for e-commerce – Word (DOCX)\u003c\/li\u003e\n\n\u003cli\u003eAccessibility routine and compliance policy for e-commerce – PDF\u003c\/li\u003e\n\n\u003cli\u003eAssessment of exemptions from accessibility requirements – Word (DOCX)\u003c\/li\u003e\n\n\u003cli\u003eAssessment of exemptions from accessibility requirements – PDF\u003c\/li\u003e\n\n\u003cli\u003eAudit log for accessible e-commerce – Word (DOCX)\u003c\/li\u003e\n\n\u003cli\u003eAudit log for accessible e-commerce – PDF\u003c\/li\u003e\n\n\u003cli\u003eAccessibility Act E-commerce 2026 – Excel compliance tool (XLSX)\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003e1. Information on the service's accessibility\u003c\/h3\u003e\n\u003cp\u003eA service provider covered by the act must produce information on how the service meets accessibility requirements. The information must, among other things, describe the applicable requirements and, where necessary for the assessment, the design and function of the service.\u003c\/p\u003e\n\n\u003cp\u003eThe template contains ready-made sections for:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003eservice provider and service\u003c\/li\u003e\n\n\u003cli\u003egeneral description of the e-commerce service\u003c\/li\u003e\n\n\u003cli\u003eapplicable accessibility requirements\u003c\/li\u003e\n\n\u003cli\u003enavigation and keyboard\u003c\/li\u003e\n\n\u003cli\u003etext, contrast, and magnification\u003c\/li\u003e\n\n\u003cli\u003eimages and media\u003c\/li\u003e\n\n\u003cli\u003eforms and error messages\u003c\/li\u003e\n\n\u003cli\u003eshopping cart and checkout\u003c\/li\u003e\n\n\u003cli\u003eidentification, security, and payment\u003c\/li\u003e\n\n\u003cli\u003eaccessibility information for products sold\u003c\/li\u003e\n\n\u003cli\u003ecustomer support\u003c\/li\u003e\n\n\u003cli\u003etesting and quality assurance methods\u003c\/li\u003e\n\n\u003cli\u003eknown defects and action plan\u003c\/li\u003e\n\n\u003cli\u003eany exemptions\u003c\/li\u003e\n\n\u003cli\u003econtact path for accessibility feedback\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003eThe Swedish Post and Telecom Authority (PTS) states that this information serves a similar function to an accessibility statement under the DOS Act, even though the term \u003cem\u003eaccessibility statement\u003c\/em\u003e is not used in the LPTT. The information must be easily accessible along with the service, available to persons with disabilities, and capable of being provided in written and oral form.\u003c\/p\u003e\n\n\u003ch3\u003e2. Internal accessibility routine and compliance policy\u003c\/h3\u003e\n\u003cp\u003eThe internal policy creates an ongoing workflow for compliance. It includes, among other things:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003escope and micro-enterprise assessment\u003c\/li\u003e\n\n\u003cli\u003eresponsibility matrix for management, e-commerce, IT, content, customer service, and legal\u003c\/li\u003e\n\n\u003cli\u003eminimum checks before release\u003c\/li\u003e\n\n\u003cli\u003etest strategy\u003c\/li\u003e\n\n\u003cli\u003eprocess for public accessibility information\u003c\/li\u003e\n\n\u003cli\u003edefect and incident management\u003c\/li\u003e\n\n\u003cli\u003ereporting to authorities\u003c\/li\u003e\n\n\u003cli\u003efeedback and complaint procedure\u003c\/li\u003e\n\n\u003cli\u003erequirements for third-party components and suppliers\u003c\/li\u003e\n\n\u003cli\u003eannual and event-driven review\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003e3. Audit log for web shop and app\u003c\/h3\u003e\n\u003cp\u003eThe audit log is a practical working document for testing the parts of the website or app that belong to the e-commerce service. It is structured according to the four fundamental principles:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003e\u003cstrong\u003ePerceivable\u003c\/strong\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003cstrong\u003eOperable\u003c\/strong\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003cstrong\u003eUnderstandable\u003c\/strong\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003cstrong\u003eRobust\u003c\/strong\u003e\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003eThe log also contains specific checks for e-commerce, including accessibility product information, identification, electronic signing, CAPTCHA\/2FA, security functions, payment, order confirmation, and support.\u003c\/p\u003e\n\n\u003cp\u003eEN 301 549 and WCAG are used in the package as practical technical support where relevant. They do not replace the actual legal requirements in the LPTT, the regulation, and the PTS regulations.\u003c\/p\u003e\n\n\u003ch3\u003e4. Exemption assessment – disproportionate burden\u003c\/h3\u003e\n\u003cp\u003eThe LPTT contains the possibility, in certain situations, to make exemptions from a specific accessibility requirement if the application would result in a significant change to the fundamental nature of the service or a disproportionate burden.\u003c\/p\u003e\n\n\u003cp\u003eThe separate assessment template contains:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003eidentification of the exact accessibility requirement\u003c\/li\u003e\n\n\u003cli\u003eassessment of alternative solutions\u003c\/li\u003e\n\n\u003cli\u003enet-based cost analysis\u003c\/li\u003e\n\n\u003cli\u003ecost in relation to total costs\u003c\/li\u003e\n\n\u003cli\u003ecost in relation to net turnover\u003c\/li\u003e\n\n\u003cli\u003eassessment of user benefit\u003c\/li\u003e\n\n\u003cli\u003enumber and frequency of use for affected users\u003c\/li\u003e\n\n\u003cli\u003eassessment of external accessibility resources\u003c\/li\u003e\n\n\u003cli\u003edecision, justification, and next reassessment\u003c\/li\u003e\n\n\u003cli\u003efields for reporting to the supervisory authority\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003e5. Excel tool for practical implementation\u003c\/h3\u003e\n\u003cp\u003eThe Excel file is a complete working tool and contains separate sheets for:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eStart\u003c\/strong\u003e – dashboard with KPIs and legal reference points\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eScope\u003c\/strong\u003e – check of e-commerce service, consumer focus, and micro-enterprise exemption\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eAudit Web\/App\u003c\/strong\u003e – ongoing test register\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eCritical Functions\u003c\/strong\u003e – identification, e-signing, security, payment, and order confirmation\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eAccessibility Info\u003c\/strong\u003e – check of public information on service accessibility\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eDefects \u0026amp; Actions\u003c\/strong\u003e – prioritization, responsible party, deadline, and re-test\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eSupport \u0026amp; Feedback\u003c\/strong\u003e – user complaints and accessibility issues\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eExemptions\u003c\/strong\u003e – documentation of exemption assessments\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eSuppliers\u003c\/strong\u003e – third-party components and accessibility documentation\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eTests\u003c\/strong\u003e – test and revision log\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eSources\u003c\/strong\u003e – key legal sources and PTS guidance\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003eThe start page automatically calculates, among other things, the number of defects, critical functional defects, open actions, feedback issues, suppliers needing action, exemptions, and overdue reviews.\u003c\/p\u003e\n\n\u003ch3\u003eWhich e-retailers are covered?\u003c\/h3\u003e\n\u003cp\u003eThe Act covers e-commerce services provided at a distance via websites or services for mobile devices, electronically and at the individual request of a consumer for the purpose of concluding a consumer contract.\u003c\/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eMicro-enterprises are exempt from the accessibility requirements for services.\u003c\/strong\u003e According to the act, a micro-enterprise is a company with fewer than ten employees and an annual turnover or annual balance sheet total not exceeding 2 million euros. The package therefore contains a specific scope and micro-enterprise assessment.\u003c\/p\u003e\n\n\u003ch3\u003eWhat is required of the website and app?\u003c\/h3\u003e\n\u003cp\u003eWebsites, web applications, and mobile apps that are part of the service in question must be made accessible in a uniform and functional way by being perceivable, operable, understandable, and robust. In practice, this includes, for example, keyboard usage, focus, alternative texts, contrast, forms, error messages, semantics, support for assistive technologies, and functional user journeys.\u003c\/p\u003e\n\n\u003ch3\u003eSpecific requirements for e-commerce\u003c\/h3\u003e\n\u003cp\u003eIn addition to the general requirements, there are e-commerce-specific requirements. An e-retailer must, among other things, provide accessibility information about the products and services sold when such information is provided by the responsible economic operator.\u003c\/p\u003e\n\n\u003ch3\u003eCustomer support and assistive technologies\u003c\/h3\u003e\n\u003cp\u003eIf the company offers support services, such as a helpdesk or technical support, the support service must be able to provide information about the accessibility of the service and how the service works with assistive technologies. The information must be provided via accessible means of communication.\u003c\/p\u003e\n\n\u003ch3\u003eOngoing responsibility and PTS supervision\u003c\/h3\u003e\n\u003cp\u003eThe service provider must continuously ensure that the service meets accessibility requirements. If a service does not conform to the requirements, the provider must take the necessary measures and immediately inform the supervisory authorities in the Member States where the service is provided about the defect and the measures taken.\u003c\/p\u003e\n\n\u003cp\u003eThe Swedish Post and Telecom Authority (PTS) supervises e-commerce services. During 2025 and 2026, PTS will conduct active supervision of the accessibility of Swedish e-commerce services.\u003c\/p\u003e\n\n\u003ch3\u003eLegal basis\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003eAct (2023:254) on the Accessibility of Certain Products and Services\u003c\/li\u003e\n\n\u003cli\u003eRegulation (2023:676) on the Accessibility of Certain Products and Services\u003c\/li\u003e\n\n\u003cli\u003ePTSFS 2024:6 on the accessibility of certain services\u003c\/li\u003e\n\n\u003cli\u003ePTSFS 2024:7 on criteria for disproportionate burden\u003c\/li\u003e\n\n\u003cli\u003eDirective (EU) 2019\/882 of the European Parliament and of the Council – European Accessibility Act\u003c\/li\u003e\n\n\u003cli\u003eEN 301 549 and WCAG as technical support where relevant\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eSuitable for, among others\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003eweb shops selling to consumers\u003c\/li\u003e\n\n\u003cli\u003ecompanies with Shopify, WooCommerce, or another e-commerce platform\u003c\/li\u003e\n\n\u003cli\u003ecompanies with a mobile app for purchases\u003c\/li\u003e\n\n\u003cli\u003ee-commerce, IT, compliance, and legal departments\u003c\/li\u003e\n\n\u003cli\u003eagencies and consultants assisting e-retailers with accessibility work\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eImportant to know\u003c\/h3\u003e\n\u003cp\u003eWhich parts of a website are covered by the LPTT and what technical measures are required must be assessed based on the actual service. PTS assesses that it is the parts of the website belonging to the e-commerce service that are covered by the requirements for e-commerce. The package is a professional working document and does not replace individual legal or technical advice in complicated cases.\u003c\/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eFormat:\u003c\/strong\u003e Word (DOCX) + PDF + Excel (XLSX)\u003cbr\u003e\n\u003cstrong\u003eLanguage:\u003c\/strong\u003e Swedish\u003cbr\u003e\n\u003cstrong\u003eJurisdiction:\u003c\/strong\u003e Sweden \/ EU\u003cbr\u003e\n\u003cstrong\u003eNumber of files:\u003c\/strong\u003e 9\u003cbr\u003e\n\u003cstrong\u003eVersion:\u003c\/strong\u003e 1.0 – 2026-10-02\u003c\/p\u003e\n","brand":"Svenska Dokumentmallar","offers":[{"title":"Default Title","offer_id":55580087189846,"sku":"TILLG-EHANDEL-2026","price":149.0,"currency_code":"SEK","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0827\/2373\/3846\/files\/tillganglighetslagen-ehandel-2026.png?v=1790963710"},{"product_id":"distansarbete-hybridarbete-byod-mallpaket-2026","title":"Remote Work, Hybrid Work \u0026 BYOD Template Package 2026 – Word\/PDF","description":"\n\u003ch2\u003eRemote Work, Hybrid Work \u0026amp; BYOD Template Package 2026\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003eA complete template package for Swedish employers who want to regulate remote work, hybrid work, and the use of private equipment in a clear and professional manner.\u003c\/strong\u003e The package includes a separate remote work agreement, BYOD agreement, remote and hybrid policy, as well as a checklist\/risk assessment. All documents are provided in both Word (DOCX) and PDF format.\u003c\/p\u003e\n\n\u003cp\u003eThe template package was legally reviewed as of \u003cstrong\u003eOctober 2, 2026\u003c\/strong\u003e, and takes into account work environment liability, working hours, the Employment Protection Act's (LAS) information rules, the Co-determination Act (MBL), GDPR, information security, and the Swedish Tax Agency's rules regarding work tools and expense reimbursements.\u003c\/p\u003e\n\n\u003ch3\u003eIncluded – 8 files\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003eRemote work agreement \/ hybrid work 2026 – Word + PDF\u003c\/li\u003e\n\n\u003cli\u003eBYOD agreement 2026 – Word + PDF\u003c\/li\u003e\n\n\u003cli\u003eRemote \u0026amp; hybrid policy 2026 – Word + PDF\u003c\/li\u003e\n\n\u003cli\u003eChecklist \u0026amp; risk assessment for remote work and BYOD – Word + PDF\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eRemote work agreement 2026\u003c\/h3\u003e\n\u003cp\u003eThe separate supplementary agreement regulates, among other things:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003eremote workplace and scope\u003c\/li\u003e\n\n\u003cli\u003estandard remote days and planning\u003c\/li\u003e\n\n\u003cli\u003eworking hours, availability, breaks, and overtime\u003c\/li\u003e\n\n\u003cli\u003ework environment, ergonomics, and employee participation\u003c\/li\u003e\n\n\u003cli\u003eequipment, costs, and liability\u003c\/li\u003e\n\n\u003cli\u003einformation security and confidentiality\u003c\/li\u003e\n\n\u003cli\u003epersonal data, logging, and proportionate control\u003c\/li\u003e\n\n\u003cli\u003eillness, incidents, and work-related ill health\u003c\/li\u003e\n\n\u003cli\u003evalidity, review, and amendments\u003c\/li\u003e\n\n\u003cli\u003eappendix for work environment and equipment\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eWork environment liability also applies at home\u003c\/h3\u003e\n\u003cp\u003eThe Swedish Work Environment Authority's rules on systematic work environment management also apply when work is performed remotely, for example in the employee's home. The employer retains responsibility for the work environment and needs to manage, among other things, ergonomics, screen work, variation, recovery, workload, and organizational\/social risks.\u003c\/p\u003e\n\n\u003cp\u003eHowever, the template does not give the employer any general right to enter the employee's home. If a home visit is necessary for work environment purposes, it must be handled through a specific agreement.\u003c\/p\u003e\n\n\u003ch3\u003eBYOD agreement – private computer, phone, or tablet\u003c\/h3\u003e\n\u003cp\u003eThe BYOD section regulates the use of private equipment at work and includes, among other things:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003eapproved devices and permitted work applications\u003c\/li\u003e\n\n\u003cli\u003eminimum requirements for operating systems, updates, screen locks, and encryption\u003c\/li\u003e\n\n\u003cli\u003eMFA, antivirus\/EDR, and backup\u003c\/li\u003e\n\n\u003cli\u003eseparation between work data and private data\u003c\/li\u003e\n\n\u003cli\u003eMDM, work profile, and technical administration\u003c\/li\u003e\n\n\u003cli\u003ewhat information the employer is and is not allowed to see\u003c\/li\u003e\n\n\u003cli\u003elogging and control in accordance with GDPR\u003c\/li\u003e\n\n\u003cli\u003eloss, theft, and information security incidents\u003c\/li\u003e\n\n\u003cli\u003eselective wiping of work data\u003c\/li\u003e\n\n\u003cli\u003esupport, costs, wear and tear, and termination of BYOD\u003c\/li\u003e\n\n\u003cli\u003eappendix for approved apps, data categories, and cloud services\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eGDPR and control of employees\u003c\/h3\u003e\n\u003cp\u003eThe employer is responsible for ensuring that personal data is processed legally even when work takes place at home or on private equipment. The package therefore contains clear limitations on control and monitoring. Security logging and follow-up must be factually justified, transparent, and proportionate. The agreements do not grant the employer general access to private files, private messages, or other private communication.\u003c\/p\u003e\n\n\u003ch3\u003eRemote and hybrid policy\u003c\/h3\u003e\n\u003cp\u003eThe separate policy helps the employer create a uniform internal structure for, among other things:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003ewho is allowed to work remotely\u003c\/li\u003e\n\n\u003cli\u003estandard scope and approval\u003c\/li\u003e\n\n\u003cli\u003ework from another location or abroad\u003c\/li\u003e\n\n\u003cli\u003eplanning, meetings, and availability\u003c\/li\u003e\n\n\u003cli\u003ework environment and risk assessment\u003c\/li\u003e\n\n\u003cli\u003eIT security and personal data\u003c\/li\u003e\n\n\u003cli\u003eBYOD\u003c\/li\u003e\n\n\u003cli\u003eequipment and costs\u003c\/li\u003e\n\n\u003cli\u003efollow-up without unnecessary individual monitoring\u003c\/li\u003e\n\n\u003cli\u003eMBL, collective agreements, and division of responsibilities\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eChecklist \u0026amp; risk assessment\u003c\/h3\u003e\n\u003cp\u003eThe package also contains a practical risk assessment for employers and managers. It covers, among other things, ergonomics, display screens, lighting, noise, OSH (organizational and social health), social work environment, working hours, confidentiality, network, device security, BYOD, personal data, and incident management.\u003c\/p\u003e\n\n\u003ch3\u003eWorkplace and the Employment Protection Act (LAS)\u003c\/h3\u003e\n\u003cp\u003eLAS requires written information regarding terms that are of essential importance to the employment, including the workplace or how the workplace is determined. If such details change, the employer must normally provide written information about the change by the time it takes effect. The remote work agreement can be used as part of that documentation.\u003c\/p\u003e\n\n\u003ch3\u003eMBL and collective agreements\u003c\/h3\u003e\n\u003cp\u003eIf the employer is bound by a collective agreement, major changes to the business or work and employment conditions may entail a negotiation obligation under the Co-determination Act (MBL). The package therefore contains clear reminders to check collective agreements and MBL before a major remote work setup is introduced or changed.\u003c\/p\u003e\n\n\u003ch3\u003eEquipment and tax rules\u003c\/h3\u003e\n\u003cp\u003eThe Swedish Tax Agency distinguishes between work tools provided by the employer and cash reimbursement for items that the employee purchases themselves. The package therefore describes costs and reimbursements cautiously and leaves open fields for the company's actual model, instead of claiming that reimbursement is always tax-exempt.\u003c\/p\u003e\n\n\u003ch3\u003eWho is this package for?\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003ecompanies with recurring hybrid work\u003c\/li\u003e\n\n\u003cli\u003eemployers who allow work from home\u003c\/li\u003e\n\n\u003cli\u003ecompanies that allow private computers, phones, or tablets\u003c\/li\u003e\n\n\u003cli\u003eHR, CEOs, and managers who want to standardize remote work rules\u003c\/li\u003e\n\n\u003cli\u003ecompanies that need to combine work environment, GDPR, and information security\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eLegal basis\u003c\/h3\u003e\n\u003cp\u003eThe template package has been developed taking into account, among other things:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003eWork Environment Act (1977:1160)\u003c\/li\u003e\n\n\u003cli\u003eAFS 2023:1 on systematic work environment management\u003c\/li\u003e\n\n\u003cli\u003eEmployment Protection Act (1982:80), especially sections 6 c and 6 e\u003c\/li\u003e\n\n\u003cli\u003eWorking Hours Act (1982:673)\u003c\/li\u003e\n\n\u003cli\u003eCo-determination at Work Act (1976:580), especially section 11\u003c\/li\u003e\n\n\u003cli\u003eGeneral Data Protection Regulation (EU) 2016\/679\u003c\/li\u003e\n\n\u003cli\u003eTrade Secrets Act (2018:558)\u003c\/li\u003e\n\n\u003cli\u003ecurrent tax rules regarding work tools and expense reimbursements\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eNote\u003c\/h3\u003e\n\u003cp\u003eThe templates are general document drafts and must be adapted to the company's actual operations, collective agreements, employment contracts, IT environment, insurance, and work environment risks. Work from abroad can lead to specific questions regarding tax, social security, labor law, and information security and should not be permitted routinely without a separate assessment.\u003c\/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eFormat:\u003c\/strong\u003e Word (DOCX) + PDF\u003cbr\u003e\n\u003cstrong\u003eLanguage:\u003c\/strong\u003e Swedish\u003cbr\u003e\n\u003cstrong\u003eJurisdiction:\u003c\/strong\u003e Sweden \/ EU\u003cbr\u003e\n\u003cstrong\u003eNumber of files:\u003c\/strong\u003e 8\u003cbr\u003e\n\u003cstrong\u003eVersion:\u003c\/strong\u003e 1.0 – 2026-10-02\u003c\/p\u003e\n","brand":"Svenska Dokumentmallar","offers":[{"title":"Default Title","offer_id":55580843966806,"sku":"DISTANS-BYOD-2026","price":249.0,"currency_code":"SEK","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0827\/2373\/3846\/files\/distansarbete-hybridarbete-byod-mallpaket-2026.png?v=1790969983"},{"product_id":"dora-ikt-leverantorsavtal-compliance-mallpaket-2026","title":"DORA ICT Third-Party Provider Agreement \u0026 Compliance Template Package 2026 – Word\/PDF\/Excel","description":"\n\u003ch2\u003eDORA ICT Provider Agreement \u0026amp; Compliance Template Package 2026\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003eA complete DORA package for financial entities that need to regulate, assess, and monitor ICT third-party providers in accordance with Regulation (EU) 2022\/2554.\u003c\/strong\u003e The package combines contract templates, risk assessment, exit plans, and a practical Excel register for providers, contracts, subcontracting chains, critical\/important functions, and DORA measures.\u003c\/p\u003e\n\n\u003cp\u003eDORA began to apply on \u003cstrong\u003eJanuary 17, 2025\u003c\/strong\u003e, and includes requirements for managing ICT third-party risk, information registers, contractual provisions, concentration risk, due diligence, subcontractors, and exit strategies. The template package is legally reviewed as of \u003cstrong\u003eOctober 3, 2026\u003c\/strong\u003e, and also takes into account the supplementary technical standards from 2024–2025.\u003c\/p\u003e\n\n\u003ch3\u003eIncluded – 9 files\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003eDORA ICT Provider Agreement \/ Contract Addendum 2026 – Word + PDF\u003c\/li\u003e\n\n\u003cli\u003eAnnex for Critical\/Important Function \u0026amp; SLA – Word + PDF\u003c\/li\u003e\n\n\u003cli\u003eProvider Risk \u0026amp; Due Diligence – Word + PDF\u003c\/li\u003e\n\n\u003cli\u003eDORA Exit Plan for ICT Service – Word + PDF\u003c\/li\u003e\n\n\u003cli\u003eDORA ICT Provider Register, Risk \u0026amp; Exit Tool – Excel (XLSX)\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eDORA ICT Provider Agreement\u003c\/h3\u003e\n\u003cp\u003eThe main template is designed as an addendum to an existing ICT, SaaS, cloud, operational, or outsourcing agreement. It covers key contractual requirements under DORA Article 30, including:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003efull description of functions and ICT services\u003c\/li\u003e\n\n\u003cli\u003eclassification of critical or important function\u003c\/li\u003e\n\n\u003cli\u003eservice and data storage locations\u003c\/li\u003e\n\n\u003cli\u003eavailability, authenticity, integrity, and confidentiality\u003c\/li\u003e\n\n\u003cli\u003eaccess, recovery, and return of data\u003c\/li\u003e\n\n\u003cli\u003eservice levels and SLAs\u003c\/li\u003e\n\n\u003cli\u003eincident support and regulatory reporting\u003c\/li\u003e\n\n\u003cli\u003ecooperation with competent and resolution authorities\u003c\/li\u003e\n\n\u003cli\u003esubcontracting chains and material changes\u003c\/li\u003e\n\n\u003cli\u003eaudit, inspection, and access rights\u003c\/li\u003e\n\n\u003cli\u003econtinuity, security, and testing\u003c\/li\u003e\n\n\u003cli\u003etermination, transition services, and exit\u003c\/li\u003e\n\n\u003cli\u003edocumentation for the information register\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eFor critical and important functions\u003c\/h3\u003e\n\u003cp\u003eWhen an ICT service supports a critical or important function, enhanced DORA requirements apply. The separate SLA annex includes fields for measurable qualitative and quantitative targets, RTO\/RPO, incident levels, continuity tests, audit plans, subcontractors, and notification requirements.\u003c\/p\u003e\n\n\u003ch3\u003eSubcontractors – updated with EU 2025\/532\u003c\/h3\u003e\n\u003cp\u003eThe template package takes into account Commission Delegated Regulation (EU) 2025\/532 regarding subcontractors for ICT services that support critical or important functions. The contract section therefore includes, among other things:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003ewhich ICT services may be subcontracted\u003c\/li\u003e\n\n\u003cli\u003eprovider liability for subcontractors\u003c\/li\u003e\n\n\u003cli\u003erequirements for ongoing monitoring and reporting\u003c\/li\u003e\n\n\u003cli\u003esubcontractor service and data storage locations\u003c\/li\u003e\n\n\u003cli\u003eflow-down of security, continuity, audit, and access rights\u003c\/li\u003e\n\n\u003cli\u003eprior notification of material changes\u003c\/li\u003e\n\n\u003cli\u003eobjection process and right of termination in relevant situations\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eProvider Risk \u0026amp; Due Diligence\u003c\/h3\u003e\n\u003cp\u003eThe separate risk template supports assessment prior to contracting and during major changes. It covers aspects such as business reputation, financial stability, information security, BCP\/DR, incident management, data protection, regulatory cooperation, assurance, subcontractor management, concentration risk, substitutability, third countries, insolvency, and geopolitical risk.\u003c\/p\u003e\n\n\u003ch3\u003eConcentration risk and substitutability\u003c\/h3\u003e\n\u003cp\u003eDORA requires financial entities to assess dependencies on providers that cannot be easily replaced and situations where multiple critical or important arrangements are concentrated with the same or closely linked providers. The package therefore includes specific fields for technical lock-in, shared underlying cloud infrastructure, alternative provider, migration time, and switching costs.\u003c\/p\u003e\n\n\u003ch3\u003eDORA Exit Plan\u003c\/h3\u003e\n\u003cp\u003eFor ICT services supporting critical or important functions, exit strategies must be documented and testable. The exit plan covers:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003eexit triggers\u003c\/li\u003e\n\n\u003cli\u003emigration to a new provider or insourcing\u003c\/li\u003e\n\n\u003cli\u003edata and asset inventory\u003c\/li\u003e\n\n\u003cli\u003eexport formats and validation\u003c\/li\u003e\n\n\u003cli\u003eknowledge transfer\u003c\/li\u003e\n\n\u003cli\u003etransition period and transition services\u003c\/li\u003e\n\n\u003cli\u003eparallel operation and cut-over\u003c\/li\u003e\n\n\u003cli\u003esecure deletion and deletion certificates\u003c\/li\u003e\n\n\u003cli\u003erisks during exit\u003c\/li\u003e\n\n\u003cli\u003etabletop and technical testing\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eExcel – provider register, risk and exit\u003c\/h3\u003e\n\u003cp\u003eThe Excel tool contains separate sheets for:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003econtract register\u003c\/li\u003e\n\n\u003cli\u003eICT providers\u003c\/li\u003e\n\n\u003cli\u003esubcontracting chain\u003c\/li\u003e\n\n\u003cli\u003ecritical\/important functions\u003c\/li\u003e\n\n\u003cli\u003edue diligence and risk assessment\u003c\/li\u003e\n\n\u003cli\u003eexit plans and testing\u003c\/li\u003e\n\n\u003cli\u003eDORA measures\u003c\/li\u003e\n\n\u003cli\u003emapping to the information register\u003c\/li\u003e\n\n\u003cli\u003elegal sources\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003eThe workbook is mapped to key parts of Implementing Regulation (EU) 2024\/2956, including B_02.01\/B_02.02, B_05.01\/B_05.02, B_06.01, and B_07.01. It is an internal work and registry document and should not be described as a finished regulatory file for direct upload without verification against the Swedish Financial Supervisory Authority's (Finansinspektionen) current reporting format.\u003c\/p\u003e\n\n\u003ch3\u003eDORA Information Register\u003c\/h3\u003e\n\u003cp\u003eDORA Article 28.3 requires financial entities to maintain an up-to-date register of all contractual arrangements for the use of ICT services from third-party providers. Implementing Regulation (EU) 2024\/2956 specifies the standard templates for the register. The package helps the business gather central data in a structured way as early as the provider and contract process.\u003c\/p\u003e\n\n\u003ch3\u003eSwedish supervision\u003c\/h3\u003e\n\u003cp\u003eFor Swedish companies under the supervision of Finansinspektionen, DORA is supplemented by, among others, FFFS 2024:20 on incident reporting and information registers. Finansinspektionen has also explicitly made DORA implementation and digital operational resilience a supervisory priority.\u003c\/p\u003e\n\n\u003ch3\u003eLegal basis\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003eRegulation (EU) 2022\/2554 – DORA, particularly Articles 28–30\u003c\/li\u003e\n\n\u003cli\u003eCommission Delegated Regulation (EU) 2024\/1773\u003c\/li\u003e\n\n\u003cli\u003eCommission Implementing Regulation (EU) 2024\/2956\u003c\/li\u003e\n\n\u003cli\u003eCommission Delegated Regulation (EU) 2025\/532\u003c\/li\u003e\n\n\u003cli\u003eFFFS 2024:20, where applicable\u003c\/li\u003e\n\n\u003cli\u003eGDPR and other sector-specific regulation when relevant\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eWho is the package for?\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003ebanks and credit institutions\u003c\/li\u003e\n\n\u003cli\u003epayment institutions and electronic money institutions\u003c\/li\u003e\n\n\u003cli\u003einsurance and reinsurance undertakings\u003c\/li\u003e\n\n\u003cli\u003einvestment firms and market participants\u003c\/li\u003e\n\n\u003cli\u003efund management companies and other DORA-regulated financial entities\u003c\/li\u003e\n\n\u003cli\u003ecompliance, risk, legal, procurement, and IT security functions\u003c\/li\u003e\n\n\u003cli\u003eICT providers that need to negotiate DORA addenda with financial clients\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eNote\u003c\/h3\u003e\n\u003cp\u003eDORA's application and proportionality depend on the type of financial entity, service, function, and risk profile involved. The templates are general professional documents and must be adapted to main agreements, sector rules, regulatory status, the technical architecture of the service, and the financial entity's risk appetite. They do not replace individual legal advice.\u003c\/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eFormat:\u003c\/strong\u003e Word (DOCX) + PDF + Excel (XLSX)\u003cbr\u003e\n\u003cstrong\u003eLanguage:\u003c\/strong\u003e Swedish\u003cbr\u003e\n\u003cstrong\u003eJurisdiction:\u003c\/strong\u003e Sweden \/ EU\u003cbr\u003e\n\u003cstrong\u003eNumber of files:\u003c\/strong\u003e 9\u003cbr\u003e\n\u003cstrong\u003eVersion:\u003c\/strong\u003e 1.0 – 2026-10-03\u003c\/p\u003e\n","brand":"Svenska Dokumentmallar","offers":[{"title":"Default Title","offer_id":55582028628310,"sku":"DORA-IKT-2026","price":299.0,"currency_code":"SEK","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0827\/2373\/3846\/files\/dora-ikt-leverantorsavtal-compliance-mallpaket-2026.png?v=1790979372"},{"product_id":"dpia-konsekvensbedomning-gdpr-mallpaket-2026","title":"DPIA \/ Data Protection Impact Assessment GDPR Template Package 2026 – Word\/PDF\/Excel","description":"\n\u003ch2\u003eDPIA \/ Data Protection Impact Assessment GDPR Template Package 2026 – Word, PDF \u0026amp; Excel\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003eComplete template package for Data Protection Impact Assessment (DPIA)\u003c\/strong\u003e according to Article 35 of the GDPR. The package is designed for Swedish companies, organizations, authorities, project managers, data protection officers, information security functions, and lawyers who need to document high-risk processing of personal data in a structured, auditable, and practical manner.\u003c\/p\u003e\n\n\u003cp\u003eThe package combines \u003cstrong\u003efour professional document templates in Word\/PDF\u003c\/strong\u003e with a comprehensive \u003cstrong\u003eExcel tool for screening, risk assessment, risk-mitigating measures, consultation, Article 36 assessment, and ongoing review\u003c\/strong\u003e. A total of 9 files are included.\u003c\/p\u003e\n\n\u003ch3\u003eWhat is included – 9 files\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003eDPIA \/ Data Protection Impact Assessment GDPR 2026 – Word (DOCX)\u003c\/li\u003e\n\n\u003cli\u003eDPIA \/ Data Protection Impact Assessment GDPR 2026 – PDF\u003c\/li\u003e\n\n\u003cli\u003eDPIA Screening \/ Need Assessment – Word\u003c\/li\u003e\n\n\u003cli\u003eDPIA Screening \/ Need Assessment – PDF\u003c\/li\u003e\n\n\u003cli\u003eConsultation, DPO Opinion \u0026amp; Prior Consultation – Word\u003c\/li\u003e\n\n\u003cli\u003eConsultation, DPO Opinion \u0026amp; Prior Consultation – PDF\u003c\/li\u003e\n\n\u003cli\u003eDPIA Review, Decision \u0026amp; Change Log – Word\u003c\/li\u003e\n\n\u003cli\u003eDPIA Review, Decision \u0026amp; Change Log – PDF\u003c\/li\u003e\n\n\u003cli\u003eDPIA Risk \u0026amp; Screening Work Tool – Excel (XLSX)\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eWhen is a DPIA required?\u003c\/h3\u003e\n\u003cp\u003eAccording to Article 35 of the GDPR, the controller must carry out a data protection impact assessment \u003cstrong\u003ebefore\u003c\/strong\u003e starting a type of processing if the processing is likely to result in a high risk to the rights and freedoms of natural persons. This applies particularly to, for example, extensive profiling or automated decision-making with significant effects, large-scale processing of sensitive personal data or data relating to criminal convictions, and large-scale systematic monitoring.\u003c\/p\u003e\n\n\u003cp\u003eFurthermore, the Swedish Authority for Privacy Protection (IMY) has a specific list according to Article 35.4 and uses the nine high-risk criteria developed in European data protection guidelines. As a general rule, at least two fulfilled criteria indicate that a DPIA should be carried out, but a single criterion may suffice in an individual case. The screening template and the Excel tool are built to document exactly this assessment.\u003c\/p\u003e\n\n\u003ch3\u003eScreening \/ need assessment\u003c\/h3\u003e\n\u003cp\u003eThe screening template helps you document, before project start, why a DPIA is required – or why it is not considered mandatory. It includes checks of:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003eArticle 35.3 of the GDPR\u003c\/li\u003e\n\n\u003cli\u003eIMY's Article 35.4 list\u003c\/li\u003e\n\n\u003cli\u003eevaluation and scoring\u003c\/li\u003e\n\n\u003cli\u003eautomated decision-making with significant effects\u003c\/li\u003e\n\n\u003cli\u003esystematic monitoring\u003c\/li\u003e\n\n\u003cli\u003esensitive or highly personal data\u003c\/li\u003e\n\n\u003cli\u003elarge-scale processing\u003c\/li\u003e\n\n\u003cli\u003emerging of datasets\u003c\/li\u003e\n\n\u003cli\u003evulnerable data subjects\u003c\/li\u003e\n\n\u003cli\u003einnovative use or new technology, including AI\u003c\/li\u003e\n\n\u003cli\u003eprocessing that prevents a person from exercising a right or gaining access to a service or contract\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eComplete DPIA according to Article 35\u003c\/h3\u003e\n\u003cp\u003eThe main template is designed to document the elements required by the GDPR and highlighted by IMY in its guidance. It includes, among other things:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003esystematic description of the processing and its purposes\u003c\/li\u003e\n\n\u003cli\u003edata subjects and personal data categories\u003c\/li\u003e\n\n\u003cli\u003esensitive personal data and Article 10 data\u003c\/li\u003e\n\n\u003cli\u003esystems, technology, AI, profiling, and automated decision-making\u003c\/li\u003e\n\n\u003cli\u003edata processors and recipients\u003c\/li\u003e\n\n\u003cli\u003ethird-country transfers\u003c\/li\u003e\n\n\u003cli\u003estorage and erasure\u003c\/li\u003e\n\n\u003cli\u003edata flow and lifecycle\u003c\/li\u003e\n\n\u003cli\u003elegal basis\u003c\/li\u003e\n\n\u003cli\u003eassessment of necessity and proportionality\u003c\/li\u003e\n\n\u003cli\u003eprivacy by design and privacy by default\u003c\/li\u003e\n\n\u003cli\u003erisks to the rights and freedoms of individuals\u003c\/li\u003e\n\n\u003cli\u003erisk-mitigating technical, organizational, and legal measures\u003c\/li\u003e\n\n\u003cli\u003eresidual risk\u003c\/li\u003e\n\n\u003cli\u003edecision on whether the processing can begin\u003c\/li\u003e\n\n\u003cli\u003eneed for prior consultation with IMY\u003c\/li\u003e\n\n\u003cli\u003eplan for ongoing review\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eThe risks concern people – not the company's business risk\u003c\/h3\u003e\n\u003cp\u003eA common weakness in DPIA work is that the risk analysis drifts into business risk. The template therefore explicitly distinguishes between these areas. The DPIA risk must concern how the processing could affect \u003cstrong\u003ethe rights and freedoms of natural persons\u003c\/strong\u003e, for example through discrimination, identity theft, financial loss, reputation damage, loss of confidentiality, improper surveillance, incorrect profiling, limited self-determination, or other physical, material, or non-material damage.\u003c\/p\u003e\n\n\u003ch3\u003eExcel tool with automatic risk classification\u003c\/h3\u003e\n\u003cp\u003eThe Excel file contains separate worksheets for:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003edashboard with key performance indicators\u003c\/li\u003e\n\n\u003cli\u003eDPIA screening\u003c\/li\u003e\n\n\u003cli\u003eprocessing description\u003c\/li\u003e\n\n\u003cli\u003enecessity and proportionality\u003c\/li\u003e\n\n\u003cli\u003erisk register\u003c\/li\u003e\n\n\u003cli\u003erisk measures\u003c\/li\u003e\n\n\u003cli\u003econsultation and DPO advice\u003c\/li\u003e\n\n\u003cli\u003ereview and change log\u003c\/li\u003e\n\n\u003cli\u003eArticle 36 – documentation for prior consultation\u003c\/li\u003e\n\n\u003cli\u003elegal sources and guidance\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003eThe risk register automatically calculates a risk value based on probability and impact and shows both \u003cstrong\u003einherent risk\u003c\/strong\u003e and \u003cstrong\u003eresidual risk after planned measures\u003c\/strong\u003e. This makes it easier to track how protective measures actually change the risk landscape.\u003c\/p\u003e\n\n\u003ch3\u003eThe role of the Data Protection Officer\u003c\/h3\u003e\n\u003cp\u003eIf the organization has a data protection officer (DPO), the DPO must be consulted during the implementation of the DPIA. The DPO can, among other things, provide advice on the need for a DPIA, methodology, risks, protective measures, and whether the assessment has been carried out correctly. However, it remains the controller's responsibility to ensure that the DPIA is carried out and for the decisions made.\u003c\/p\u003e\n\n\u003cp\u003eThe package therefore contains a separate template for \u003cstrong\u003eDPO opinion and consultation\u003c\/strong\u003e where advice, deviations, and follow-up can be documented clearly.\u003c\/p\u003e\n\n\u003ch3\u003eViews of data subjects\u003c\/h3\u003e\n\u003cp\u003eThe GDPR also implies that the views of data subjects or their representatives should be sought when appropriate. The consultation template therefore contains specific fields for methodology, participants, views, how the views have been considered, and – if consultation is not carried out – why it was not appropriate or possible.\u003c\/p\u003e\n\n\u003ch3\u003eArticle 36 – prior consultation with IMY\u003c\/h3\u003e\n\u003cp\u003eIf the DPIA shows that the processing would still entail \u003cstrong\u003ea high risk despite planned risk-mitigating measures\u003c\/strong\u003e, the controller must request prior consultation with IMY before starting the processing. The package includes both document fields and a specific Excel sheet to verify that the documentation is complete before such an assessment or request is made.\u003c\/p\u003e\n\n\u003ch3\u003eDPIA is an ongoing process\u003c\/h3\u003e\n\u003cp\u003eThe impact assessment should not be archived and forgotten after the project start. IMY describes the DPIA as an ongoing process. A new or updated assessment may be needed if, for example, purposes, data categories, number of data subjects, systems, AI functionality, suppliers, recipients, third-country transfers, or security risks change.\u003c\/p\u003e\n\n\u003cp\u003eThe separate template for \u003cstrong\u003ereview, decision, and change log\u003c\/strong\u003e makes it possible to document these changes and verify that the actual processing still matches the decided DPIA.\u003c\/p\u003e\n\n\u003ch3\u003eParticularly suitable for\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003enew IT systems and SaaS services\u003c\/li\u003e\n\n\u003cli\u003eAI and automated analysis\u003c\/li\u003e\n\n\u003cli\u003eprofiling and scoring\u003c\/li\u003e\n\n\u003cli\u003eHR and personnel systems\u003c\/li\u003e\n\n\u003cli\u003ecamera and sensor solutions\u003c\/li\u003e\n\n\u003cli\u003ehealth and other sensitive personal data\u003c\/li\u003e\n\n\u003cli\u003elarge-scale customer and user databases\u003c\/li\u003e\n\n\u003cli\u003emerging of various data sources\u003c\/li\u003e\n\n\u003cli\u003enew cloud providers or third-country transfers\u003c\/li\u003e\n\n\u003cli\u003eprocessing of data of children or other vulnerable groups\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eLegal basis\u003c\/h3\u003e\n\u003cp\u003eThe package is legally reviewed as of October 3, 2026, and is based, among other things, on:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003ethe General Data Protection Regulation (EU) 2016\/679, particularly Articles 5, 6, 9, 10, 25, 32, 35, 36, and 39\u003c\/li\u003e\n\n\u003cli\u003eIMY's guidance on impact assessment and practical guide\u003c\/li\u003e\n\n\u003cli\u003eIMY's list according to Article 35.4\u003c\/li\u003e\n\n\u003cli\u003eEDPB\/WP29 Guidelines on Data Protection Impact Assessment, WP248 rev.01\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003eIn 2026, the EDPB presented a new proposal for a common European DPIA template for public consultation. However, this product is not dependent on a draft consultation not yet finalized, but is based primarily on the current GDPR and IMY's current Swedish guidance.\u003c\/p\u003e\n\n\u003ch3\u003ePlease note\u003c\/h3\u003e\n\u003cp\u003eThe templates are general compliance documentation. They do not replace an actual analysis of the planned processing or individual legal advice. A correct DPIA must be based on actual systems, data flows, purposes, suppliers, data subjects, risks, and protective measures. Special sector rules may also need to be considered.\u003c\/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eFormat:\u003c\/strong\u003e Word (DOCX) + PDF + Excel (XLSX)\u003cbr\u003e\n\u003cstrong\u003eLanguage:\u003c\/strong\u003e Swedish\u003cbr\u003e\n\u003cstrong\u003eJurisdiction:\u003c\/strong\u003e Sweden \/ EU\u003cbr\u003e\n\u003cstrong\u003eNumber of files:\u003c\/strong\u003e 9\u003cbr\u003e\n\u003cstrong\u003eVersion:\u003c\/strong\u003e 1.0 – 2026-10-03\u003c\/p\u003e\n","brand":"Svenska Dokumentmallar","offers":[{"title":"Default Title","offer_id":55582656299350,"sku":"DPIA-GDPR-2026","price":249.0,"currency_code":"SEK","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0827\/2373\/3846\/files\/dpia-konsekvensbedomning-gdpr-mallpaket-2026.png?v=1790984985"},{"product_id":"intresseavvagning-lia-gdpr-mallpaket-2026","title":"Legitimate Interest Assessment \/ LIA GDPR Template Package 2026 – Word\/PDF\/Excel","description":"\n\u003ch2\u003eLegitimate Interest Assessment (LIA) \/ GDPR 2026 – complete template package\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003eA complete documentation package for Legitimate Interest Assessment (LIA) pursuant to Article 6(1)(f) GDPR.\u003c\/strong\u003e The package helps companies and organizations document the entire three-part test: legitimate interest, necessity, and the balancing against the interests, rights, and freedoms of the data subject. It also includes a separate Article 21 assessment for objections, ongoing review, and an Excel tool for registers and control.\u003c\/p\u003e\n\n\u003cp\u003eThe template package is legally reviewed as of \u003cstrong\u003eOctober 3, 2026\u003c\/strong\u003e, against the GDPR, the Swedish Authority for Privacy Protection's (IMY) current Swedish guidance, and EDPB Guidelines 1\/2024 on Article 6(1)(f).\u003c\/p\u003e\n\n\u003ch3\u003eIncluded – 9 files\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003eLegitimate Interest Assessment \/ LIA 2026 – Word (DOCX)\u003c\/li\u003e\n\n\u003cli\u003eLegitimate Interest Assessment \/ LIA 2026 – PDF\u003c\/li\u003e\n\n\u003cli\u003eObjection assessment pursuant to Article 21 – Word\u003c\/li\u003e\n\n\u003cli\u003eObjection assessment pursuant to Article 21 – PDF\u003c\/li\u003e\n\n\u003cli\u003eLIA Review \u0026amp; change log – Word\u003c\/li\u003e\n\n\u003cli\u003eLIA Review \u0026amp; change log – PDF\u003c\/li\u003e\n\n\u003cli\u003eGuide to Legitimate Interest Assessment – Word\u003c\/li\u003e\n\n\u003cli\u003eGuide to Legitimate Interest Assessment – PDF\u003c\/li\u003e\n\n\u003cli\u003eExcel tool for LIA register, balancing matrix, objections, and review\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eThe three-part test pursuant to Article 6(1)(f)\u003c\/h3\u003e\n\u003cp\u003eFor a legitimate interest assessment to be used, three cumulative conditions must be met:\u003c\/p\u003e\n\u003col\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eLegitimate interest:\u003c\/strong\u003e the interest must be lawful, sufficiently specific, real, and current.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eNecessity:\u003c\/strong\u003e the processing of personal data must be necessary to achieve the legitimate interest. If the same goal can reasonably be reached just as effectively with less privacy intrusion, it weighs against Article 6(1)(f).\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eBalancing:\u003c\/strong\u003e the interests, fundamental rights, and freedoms of the data subject may not override the legitimate interest.\u003c\/li\u003e\n\n\n\u003c\/ol\u003e\n\n\u003ch3\u003eReasonable expectations\u003c\/h3\u003e\n\u003cp\u003eThe template contains a specific balancing matrix regarding, among other things, the relationship with the data subject, how the data was collected, what the data subject can reasonably expect, the nature of the data, the scope of processing, storage period, profiling, children and other vulnerable individuals, power imbalance, and potential negative consequences.\u003c\/p\u003e\n\n\u003cp\u003eIMY emphasizes that an overall assessment must be made in each individual case. That processing is practical or commercially desirable is not in itself sufficient.\u003c\/p\u003e\n\n\u003ch3\u003eDocumentation and accountability\u003c\/h3\u003e\n\u003cp\u003eIMY recommends that the legitimate interest assessment be documented so that the controller can demonstrate how the assessment was performed. The package therefore provides separate fields for purpose, legitimate interest, alternative solutions, data minimization, reasonable expectations, safeguards, and final conclusion.\u003c\/p\u003e\n\n\u003ch3\u003eArticle 21 – when the data subject objects\u003c\/h3\u003e\n\u003cp\u003eA separate template helps the organization assess objections to processing based on Article 6(1)(f). For processing other than direct marketing, after an objection, the controller must be able to demonstrate \u003cstrong\u003ecompelling legitimate grounds\u003c\/strong\u003e that override the interests, rights, and freedoms of the data subject, or that the processing is necessary for the establishment, exercise, or defense of legal claims.\u003c\/p\u003e\n\n\u003ch3\u003eDirect marketing\u003c\/h3\u003e\n\u003cp\u003eRecital 47 of the GDPR states that processing for direct marketing may be regarded as a legitimate interest. However, this does not mean that all direct marketing is automatically permitted. Necessity, balancing, transparency, and other applicable marketing\/ePrivacy regulations must still be assessed. If the data subject objects to direct marketing, the processing for that purpose must cease.\u003c\/p\u003e\n\n\u003ch3\u003eChildren, employees, and other vulnerable groups\u003c\/h3\u003e\n\u003cp\u003eChildren have special protection under the GDPR. The template therefore contains specific checkpoints for children and other vulnerable data subjects. In the workplace, the power imbalance between employer and employee is also considered, as well as what the employee can reasonably expect in the current work environment.\u003c\/p\u003e\n\n\u003ch3\u003eAI and new technical use cases\u003c\/h3\u003e\n\u003cp\u003eLegitimate interest assessment may also need to be evaluated when developing or using AI. The package therefore contains checkpoints for data minimization, profiling, new technology, automation, and reasonable expectations. Commercial benefit can in some cases be a legitimate interest, but it does not determine the necessity or balancing step.\u003c\/p\u003e\n\n\u003ch3\u003ePublic authorities\u003c\/h3\u003e\n\u003cp\u003eArticle 6(1)(f) may not be used by public authorities when processing personal data in the performance of their public tasks. The template therefore contains a special check for this.\u003c\/p\u003e\n\n\u003ch3\u003eTransparency pursuant to Articles 13 and 14\u003c\/h3\u003e\n\u003cp\u003eWhen Article 6(1)(f) is used, the data subject must be informed about the legitimate interest. The package contains checkpoints to ensure that the privacy notice describes the legal basis, the legitimate interest, and the right to object.\u003c\/p\u003e\n\n\u003ch3\u003eExcel tool\u003c\/h3\u003e\n\u003cp\u003eThe Excel version contains a dashboard and separate sheets for:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003eLIA register and three-part test\u003c\/li\u003e\n\n\u003cli\u003ebalancing matrix from the data subject's perspective\u003c\/li\u003e\n\n\u003cli\u003eArticle 21 objections\u003c\/li\u003e\n\n\u003cli\u003ereview and change log\u003c\/li\u003e\n\n\u003cli\u003efinal checklist\u003c\/li\u003e\n\n\u003cli\u003elegal sources\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\u003cp\u003eThe tool automatically highlights incomplete assessments, open objections, and overdue reviews.\u003c\/p\u003e\n\n\u003ch3\u003eLegal basis\u003c\/h3\u003e\n\u003cp\u003eThe template package is based on, among other things:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003eThe General Data Protection Regulation (EU) 2016\/679, particularly Articles 5, 6(1)(f), 13, 14, and 21, as well as Recital 47\u003c\/li\u003e\n\n\u003cli\u003eIMY’s guidance on legitimate interest assessment\u003c\/li\u003e\n\n\u003cli\u003eEDPB Guidelines 1\/2024 on processing of personal data based on Article 6(1)(f) GDPR\u003c\/li\u003e\n\n\u003cli\u003eEDPB’s One-Stop-Shop Case Digest: Legitimate Interest 2026\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eWho is the package for?\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003ecompanies that use legitimate interest as a legal basis\u003c\/li\u003e\n\n\u003cli\u003edata protection officers, GDPR managers, and compliance functions\u003c\/li\u003e\n\n\u003cli\u003eHR, security, IT, and marketing\u003c\/li\u003e\n\n\u003cli\u003eorganizations that need to demonstrate accountability during audits\u003c\/li\u003e\n\n\u003cli\u003ebusinesses that need to handle objections pursuant to Article 21\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eNote\u003c\/h3\u003e\n\u003cp\u003eAn LIA is not a general permission for all future processing. The assessment must be linked to a specific purpose and a concrete processing activity and should be reconsidered when purpose, technology, data categories, recipients, scope, or the data subject’s reasonable expectations change. Sensitive personal data and data on criminal convictions additionally require separate legal support pursuant to Articles 9 and 10, respectively.\u003c\/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eFormat:\u003c\/strong\u003e Word (DOCX) + PDF + Excel (XLSX)\u003cbr\u003e\n\u003cstrong\u003eLanguage:\u003c\/strong\u003e Swedish\u003cbr\u003e\n\u003cstrong\u003eJurisdiction:\u003c\/strong\u003e Sweden \/ EU\u003cbr\u003e\n\u003cstrong\u003eNumber of files:\u003c\/strong\u003e 9\u003cbr\u003e\n\u003cstrong\u003eVersion:\u003c\/strong\u003e 1.0 – 2026-10-03\u003c\/p\u003e\n","brand":"Svenska Dokumentmallar","offers":[{"title":"Default Title","offer_id":55583511740758,"sku":"LIA-GDPR-2026","price":199.0,"currency_code":"SEK","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0827\/2373\/3846\/files\/intresseavvagning-lia-gdpr-mallpaket-2026.png?v=1791009044"},{"product_id":"personuppgiftsincident-gdpr-mallpaket-2026","title":"GDPR Personal Data Breach Template Package 2026 – Word\/PDF\/Excel","description":"\n\u003ch2\u003ePersonal Data Breach GDPR Template Package 2026 – incident report, IMY notification \u0026amp; 72-hour tool\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003eA complete template package for companies and organizations that need to detect, assess, document, and manage personal data breaches according to the GDPR.\u003c\/strong\u003e The package contains professional Word\/PDF templates as well as an Excel tool for incident registers, 72-hour deadlines, risk assessments, IMY (Swedish Authority for Privacy Protection) notifications, information to data subjects, processor reporting, and post-incident analysis.\u003c\/p\u003e\n\n\u003cp\u003eThe GDPR requires that \u003cstrong\u003eall personal data breaches be documented\u003c\/strong\u003e. A breach must be reported to the supervisory authority unless it is unlikely that it will result in a risk to the rights and freedoms of natural persons. If a notification is required, it must be made without undue delay and, where feasible, within \u003cstrong\u003e72 hours\u003c\/strong\u003e of the controller becoming aware of the breach.\u003c\/p\u003e\n\n\u003ch3\u003eIncluded – 9 files\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003ePersonal Data Breach – Incident Report \u0026amp; 72-hour assessment, Word + PDF\u003c\/li\u003e\n\n\u003cli\u003eNotification to IMY – preparation documentation, Word + PDF\u003c\/li\u003e\n\n\u003cli\u003eInformation to data subjects according to Article 34 GDPR, Word + PDF\u003c\/li\u003e\n\n\u003cli\u003eProcedure for personal data breaches \/ Incident Response Playbook, Word + PDF\u003c\/li\u003e\n\n\u003cli\u003eExcel tool with incident register, 72h status, risk classification, IMY log, data subjects, processor notices, measures, and post-incident analysis\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eIncident report with complete decision-making process\u003c\/h3\u003e\n\u003cp\u003eThe main template helps the organization document the entire incident from initial detection to closure:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003etime of incident, detection, and organization awareness\u003c\/li\u003e\n\n\u003cli\u003eautomatic\/clear 72-hour deadline\u003c\/li\u003e\n\n\u003cli\u003eclassification as a confidentiality, integrity, or availability breach\u003c\/li\u003e\n\n\u003cli\u003eaffected data subjects and personal data\u003c\/li\u003e\n\n\u003cli\u003esensitive data, Article 10 data, protected personal data, and children\/vulnerable individuals\u003c\/li\u003e\n\n\u003cli\u003eimmediate containment and recovery measures\u003c\/li\u003e\n\n\u003cli\u003erisk assessment for the rights and freedoms of data subjects\u003c\/li\u003e\n\n\u003cli\u003edecision regarding IMY notification\u003c\/li\u003e\n\n\u003cli\u003edecision regarding information to data subjects\u003c\/li\u003e\n\n\u003cli\u003eroot cause, corrective measures, and lessons learned\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eWhen should the breach be reported?\u003c\/h3\u003e\n\u003cp\u003eAs a data controller, you must report the breach if it is \u003cstrong\u003enot unlikely\u003c\/strong\u003e that it will result in a risk to the rights and freedoms of natural persons. If all information is not available within 72 hours, the information may be provided in phases without undue further delay. In the event of a late notification, the reasons for the delay must be documented.\u003c\/p\u003e\n\n\u003cp\u003eThe package therefore contains a separate \u003cstrong\u003eIMY preparation template\u003c\/strong\u003e with the central information that needs to be collected before or during the reporting. The actual notification is made via IMY's current e-service or other channel designated by the authority.\u003c\/p\u003e\n\n\u003ch3\u003eHigh risk – information to data subjects\u003c\/h3\u003e\n\u003cp\u003eIf the personal data breach is likely to result in a \u003cstrong\u003ehigh risk\u003c\/strong\u003e, the data subjects must, as a general rule, be informed without undue delay. The package contains a ready-to-use and editable communication template with:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003eclear description of what has happened\u003c\/li\u003e\n\n\u003cli\u003ewhat personal data is affected\u003c\/li\u003e\n\n\u003cli\u003elikely consequences\u003c\/li\u003e\n\n\u003cli\u003eimplemented and planned measures\u003c\/li\u003e\n\n\u003cli\u003epractical advice to the data subjects\u003c\/li\u003e\n\n\u003cli\u003econtact details for the Data Protection Officer or other point of contact\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003eThe template also includes a check against Article 34 exceptions, for example, if the data was effectively encrypted, if subsequent measures eliminated the high risk, or if individual notification involves disproportionate effort.\u003c\/p\u003e\n\n\u003ch3\u003eObligations of the processor\u003c\/h3\u003e\n\u003cp\u003eA processor must report a personal data breach to the controller \u003cstrong\u003ewithout undue delay\u003c\/strong\u003e. The processor does not need to determine whether the incident entails such a risk that it must be reported to IMY – the primary responsibility for the risk and notification assessment lies with the controller.\u003c\/p\u003e\n\n\u003cp\u003eThe Excel tool therefore contains a separate register for processor notices with awareness time, initial report, time difference, missing information, and next update.\u003c\/p\u003e\n\n\u003ch3\u003eExcel – incident register with 72-hour check\u003c\/h3\u003e\n\u003cp\u003eThe Excel file serves as a practical incident management tool and contains:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003edashboard with key performance indicators\u003c\/li\u003e\n\n\u003cli\u003eincident register\u003c\/li\u003e\n\n\u003cli\u003e72-hour deadline and status \u003cem\u003eOn time \/ Urgent \/ Overdue\u003c\/em\u003e\n\n\u003c\/li\u003e\n\n\u003cli\u003erisk classification based on probability and impact\u003c\/li\u003e\n\n\u003cli\u003eIMY notification register\u003c\/li\u003e\n\n\u003cli\u003ecommunication to data subjects\u003c\/li\u003e\n\n\u003cli\u003eprocessor reporting\u003c\/li\u003e\n\n\u003cli\u003emeasures register\u003c\/li\u003e\n\n\u003cli\u003ePost-Incident Review \/ root cause analysis\u003c\/li\u003e\n\n\u003cli\u003esources and legal references\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eAll breaches must be documented\u003c\/h3\u003e\n\u003cp\u003eEven breaches that do not need to be reported to IMY must be documented. The documentation should, among other things, make it possible to verify that the organization has followed the GDPR and should also include the reasons for the decision not to notify or not to inform data subjects.\u003c\/p\u003e\n\n\u003ch3\u003eCommon incidents for which the package can be used\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003emisdirected emails or documents\u003c\/li\u003e\n\n\u003cli\u003ephishing and compromised accounts\u003c\/li\u003e\n\n\u003cli\u003eransomware and data breaches\u003c\/li\u003e\n\n\u003cli\u003eincorrect access rights\u003c\/li\u003e\n\n\u003cli\u003elost computer, phone, or storage media\u003c\/li\u003e\n\n\u003cli\u003eaccidental publication\u003c\/li\u003e\n\n\u003cli\u003eincorrect sharing via cloud service or link\u003c\/li\u003e\n\n\u003cli\u003edeletion or loss of personal data\u003c\/li\u003e\n\n\u003cli\u003eincident at a processor or subcontractor\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eLegal basis\u003c\/h3\u003e\n\u003cp\u003eThe template package has been legally reviewed as of \u003cstrong\u003eOctober 3, 2026\u003c\/strong\u003e, based on:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003eGDPR Article 4(12)\u003c\/li\u003e\n\n\u003cli\u003eGDPR Article 33 – notification to the supervisory authority and documentation\u003c\/li\u003e\n\n\u003cli\u003eGDPR Article 34 – information to data subjects\u003c\/li\u003e\n\n\u003cli\u003eIMY's current guidance on personal data breaches and e-service\u003c\/li\u003e\n\n\u003cli\u003eEDPB Guidelines 01\/2021 on Examples regarding Personal Data Breach Notification\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003eDuring 2026, the EDPB also published a proposal for a common European breach-notification-template for public consultation. The legal accuracy of this package is not based on a consultation document that has not yet been fully implemented, but on current GDPR, IMY's current guidance, and adopted EDPB guidelines.\u003c\/p\u003e\n\n\u003ch3\u003ePlease note\u003c\/h3\u003e\n\u003cp\u003eThe package is a general compliance and documentation framework. An actual incident may simultaneously be covered by other reporting regulations, such as sector-specific requirements in finance, cybersecurity, healthcare, or public operations. Therefore, always check whether additional authorities, contracting parties, insurers, or other actors need to be informed.\u003c\/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eFormat:\u003c\/strong\u003e Word (DOCX) + PDF + Excel (XLSX)\u003cbr\u003e\n\u003cstrong\u003eLanguage:\u003c\/strong\u003e Swedish\u003cbr\u003e\n\u003cstrong\u003eJurisdiction:\u003c\/strong\u003e Sweden \/ EU\u003cbr\u003e\n\u003cstrong\u003eNumber of files:\u003c\/strong\u003e 9\u003cbr\u003e\n\u003cstrong\u003eVersion:\u003c\/strong\u003e 1.0 – 2026-10-03\u003c\/p\u003e\n","brand":"Svenska Dokumentmallar","offers":[{"title":"Default Title","offer_id":55590536610134,"sku":"GDPR-INCIDENT-2026","price":249.0,"currency_code":"SEK","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0827\/2373\/3846\/files\/personuppgiftsincident-gdpr-mallpaket-2026.png?v=1791040791"},{"product_id":"gdpr-registerutdrag-registrerades-rattigheter-mallpaket-2026","title":"GDPR Subject Access Request \u0026 Data Subject Rights Template Package 2026 – Word\/PDF\/Excel","description":"\n\u003ch2\u003eGDPR Data Subject Access Request \u0026amp; Data Subject Rights Template Package 2026\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003eComplete template package for companies and organizations that need to handle requests under Articles 15–22 of the GDPR.\u003c\/strong\u003e The package includes ready-to-use response templates for data subject access requests, rectification, erasure, restriction, data portability, objection, and automated decision-making, as well as an internal processing template, deadline\/refusal template, and an Excel tool for DSAR cases.\u003c\/p\u003e\n\n\u003cp\u003eThe template package was legally reviewed as of \u003cstrong\u003eOctober 3, 2026\u003c\/strong\u003e, and is based on the GDPR, the Swedish Authority for Privacy Protection’s (IMY) current guidance, and EDPB Guidelines 01\/2022 on the right of access.\u003c\/p\u003e\n\n\u003ch3\u003eIncluded – 15 files\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003eInternal processing template for data subject rights – Word + PDF\u003c\/li\u003e\n\n\u003cli\u003eData subject access request \/ right of access under Article 15 – Word + PDF\u003c\/li\u003e\n\n\u003cli\u003eRectification \u0026amp; completion under Articles 16 and 19 – Word + PDF\u003c\/li\u003e\n\n\u003cli\u003eErasure \u0026amp; restriction under Articles 17–19 – Word + PDF\u003c\/li\u003e\n\n\u003cli\u003eData portability under Article 20 – Word + PDF\u003c\/li\u003e\n\n\u003cli\u003eObjection \u0026amp; automated decision-making under Articles 21–22 – Word + PDF\u003c\/li\u003e\n\n\u003cli\u003eExtension, refusal, fees, and identity verification under Article 12 – Word + PDF\u003c\/li\u003e\n\n\u003cli\u003eExcel tool for cases, deadlines, system searches, recipients, objections, and decision logs\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eOne month – with proper handling of extensions\u003c\/h3\u003e\n\u003cp\u003eA request under Articles 15–22 must be handled without undue delay and normally \u003cstrong\u003ewithin one month of receipt\u003c\/strong\u003e. If the request is complex or many requests are handled simultaneously, the deadline can be extended by two further months if necessary. The data subject must then be informed of the extension and the reason within the first month.\u003c\/p\u003e\n\n\u003ch3\u003eData subject access request \/ Article 15\u003c\/h3\u003e\n\u003cp\u003eThe data subject access request template helps the organization document and provide the information required by Article 15, including:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003ewhether personal data is being processed\u003c\/li\u003e\n\n\u003cli\u003epurposes and categories of personal data\u003c\/li\u003e\n\n\u003cli\u003erecipients or categories of recipients\u003c\/li\u003e\n\n\u003cli\u003estorage period or criteria\u003c\/li\u003e\n\n\u003cli\u003erights and the right to lodge a complaint with the IMY\u003c\/li\u003e\n\n\u003cli\u003esource when data has not been collected from the person\u003c\/li\u003e\n\n\u003cli\u003eautomated decision-making\/profiling where applicable\u003c\/li\u003e\n\n\u003cli\u003ethird-country transfers and safeguards\u003c\/li\u003e\n\n\u003cli\u003ecopy of personal data in an appropriate format\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eRectification, erasure, and restriction\u003c\/h3\u003e\n\u003cp\u003eThe package includes separate response templates for Articles 16–19. The templates document not only the decision itself but also the obligation to, in relevant cases, inform recipients who previously received the data.\u003c\/p\u003e\n\u003cp\u003eThe erasure template includes both grounds for erasure and exceptions, so that the organization does not incorrectly treat the right to be forgotten as absolute. The restriction section covers, among other things, contested accuracy, unlawful processing, legal claims, and ongoing objection assessment.\u003c\/p\u003e\n\n\u003ch3\u003eData portability \/ Article 20\u003c\/h3\u003e\n\u003cp\u003eThe data portability template includes eligibility checks for specific conditions: processing must, among other things, be automated and based on consent or contract. The template also distinguishes between personal data provided by the data subject and data that falls outside of Article 20.\u003c\/p\u003e\n\n\u003ch3\u003eObjection \u0026amp; direct marketing\u003c\/h3\u003e\n\u003cp\u003eThe objection template distinguishes between regular processing under Article 21.1 and direct marketing. In the case of direct marketing, processing for that purpose must cease when the data subject objects. For other processing, a documented assessment of overriding legitimate grounds or legal claims is required.\u003c\/p\u003e\n\n\u003ch3\u003eAutomated decision-making \/ Article 22\u003c\/h3\u003e\n\u003cp\u003eThe package also includes verification of whether decisions are based solely on automated processing and have legal or similarly significant effects, as well as fields for exceptions, human intervention, the opportunity to express views, contest decisions, and provide meaningful information about the logic involved.\u003c\/p\u003e\n\n\u003ch3\u003eArticle 12 – extension, refusal, and fees\u003c\/h3\u003e\n\u003cp\u003eThe separate Article 12 template helps the organization manage situations where:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003ethe deadline needs to be extended\u003c\/li\u003e\n\n\u003cli\u003ethe request is only partially granted or is refused\u003c\/li\u003e\n\n\u003cli\u003ethe request is considered manifestly unfounded or excessive\u003c\/li\u003e\n\n\u003cli\u003eadditional identity information needs to be requested due to reasonable doubts\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eIdentity verification without over-collection\u003c\/h3\u003e\n\u003cp\u003eThe templates assume that the organization should facilitate the exercise of rights. Additional identification information should only be requested when there are reasonable doubts about the identity, and the verification must be proportionate.\u003c\/p\u003e\n\n\u003ch3\u003eExcel tool with deadline monitoring\u003c\/h3\u003e\n\u003cp\u003eThe Excel tool includes a dashboard and separate worksheets for:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003eall DSAR\/GDPR rights cases\u003c\/li\u003e\n\n\u003cli\u003eautomatic standard one-month deadline\u003c\/li\u003e\n\n\u003cli\u003eextended three-month deadline when extensions are used\u003c\/li\u003e\n\n\u003cli\u003edeadline status and overdue cases\u003c\/li\u003e\n\n\u003cli\u003esystem searches and data sources\u003c\/li\u003e\n\n\u003cli\u003eArticle 19 recipients\u003c\/li\u003e\n\n\u003cli\u003eArticle 21 objections\u003c\/li\u003e\n\n\u003cli\u003edecisions, fees, refusals, and extensions\u003c\/li\u003e\n\n\u003cli\u003elegal sources\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eEDPB guidelines on the right of access\u003c\/h3\u003e\n\u003cp\u003eThe data subject access request section considers the final version of the EDPB Guidelines 01\/2022 on the right of access. The guidelines address, among other things, how the organization should understand a request, search for relevant data, handle copies, electronic formats, and the rights of other individuals.\u003c\/p\u003e\n\n\u003ch3\u003eWho is this package for?\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003ecompanies and e-retailers\u003c\/li\u003e\n\n\u003cli\u003eSaaS and IT companies\u003c\/li\u003e\n\n\u003cli\u003eHR and personnel departments\u003c\/li\u003e\n\n\u003cli\u003ecustomer service and support\u003c\/li\u003e\n\n\u003cli\u003edata protection officers\u003c\/li\u003e\n\n\u003cli\u003ecompliance and legal departments\u003c\/li\u003e\n\n\u003cli\u003eorganizations that want a traceable and consistent process for data subject rights\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eLegal basis\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003eGeneral Data Protection Regulation (EU) 2016\/679, particularly Articles 12 and 15–22, and Article 19\u003c\/li\u003e\n\n\u003cli\u003eIMY’s current guidance on data subject rights and deadlines\u003c\/li\u003e\n\n\u003cli\u003eEDPB Guidelines 01\/2022 on data subject rights – Right of access, Version 2.1\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eFormat:\u003c\/strong\u003e Word (DOCX) + PDF + Excel (XLSX)\u003cbr\u003e\n\u003cstrong\u003eLanguage:\u003c\/strong\u003e Swedish\u003cbr\u003e\n\u003cstrong\u003eJurisdiction:\u003c\/strong\u003e Sweden \/ EU\u003cbr\u003e\n\u003cstrong\u003eNumber of files:\u003c\/strong\u003e 15\u003cbr\u003e\n\u003cstrong\u003eVersion:\u003c\/strong\u003e 1.0 – 2026-10-03\u003c\/p\u003e\n\n\u003cp\u003e\u003cem\u003eThe templates are general document materials. Sector-specific regulations, confidentiality, archiving rules, accounting requirements, and other legal obligations may affect how a specific request should be handled.\u003c\/em\u003e\u003c\/p\u003e\n","brand":"Svenska Dokumentmallar","offers":[{"title":"Default Title","offer_id":55591101464918,"sku":"GDPR-RATTIGHETER-2026","price":199.0,"currency_code":"SEK","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0827\/2373\/3846\/files\/gdpr-registrerades-rattigheter-mallpaket-2026.png?v=1791043090"},{"product_id":"integritetspolicy-cookiepolicy-mallpaket-gdpr-cookies","title":"Privacy Policy \u0026 Cookie Policy Template Package – Word\/PDF\/Excel | GDPR \u0026 Cookies","description":"\n\u003ch2\u003ePrivacy Policy \u0026amp; Cookie Policy Template Package – GDPR, cookies, and web\/e-commerce\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003eA complete document package for businesses and organizations that need to publish accurate and understandable information about personal data processing and cookies on their website or e-commerce store.\u003c\/strong\u003e The package combines a full privacy policy, cookie policy, practical CMP\/cookie banner checklist, short privacy texts for web forms, a compliance checklist, and an Excel tool for inventorying processing activities, cookies, and suppliers.\u003c\/p\u003e\n\n\u003cp\u003eThe template package was legally reviewed on \u003cstrong\u003eOctober 3, 2026\u003c\/strong\u003e, against the GDPR, the Swedish Electronic Communications Act, and current guidance from the Swedish Authority for Privacy Protection (IMY) and the Swedish Post and Telecom Authority (PTS) in force at that time. The documents are intended to be relevant during \u003cstrong\u003e2026\/2027, provided that regulations remain unchanged\u003c\/strong\u003e.\u003c\/p\u003e\n\n\u003ch3\u003eIncluded – 11 files\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003ePrivacy policy for web \u0026amp; e-commerce – Word + PDF\u003c\/li\u003e\n\n\u003cli\u003eCookie policy – Word + PDF\u003c\/li\u003e\n\n\u003cli\u003eCookie banner \u0026amp; consent settings – Word + PDF\u003c\/li\u003e\n\n\u003cli\u003eShort privacy information for web forms – Word + PDF\u003c\/li\u003e\n\n\u003cli\u003eGDPR \u0026amp; Cookies – web\/e-commerce checklist – Word + PDF\u003c\/li\u003e\n\n\u003cli\u003eExcel – cookie inventory, processing activities, suppliers, consent tests, and audit control\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003ePrivacy policy according to Articles 13 and 14 of the GDPR\u003c\/h3\u003e\n\u003cp\u003eThe privacy policy is structured to help the business provide clear information about, for example:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003edata controller and contact details\u003c\/li\u003e\n\n\u003cli\u003ewhich personal data is processed\u003c\/li\u003e\n\n\u003cli\u003epurposes and legal basis\u003c\/li\u003e\n\n\u003cli\u003elegitimate interests when Article 6(1)(f) is used\u003c\/li\u003e\n\n\u003cli\u003erecipients and data processors\u003c\/li\u003e\n\n\u003cli\u003etransfers outside the EU\/EEA and safeguards\u003c\/li\u003e\n\n\u003cli\u003estorage periods and erasure criteria\u003c\/li\u003e\n\n\u003cli\u003edata subjects' rights\u003c\/li\u003e\n\n\u003cli\u003ewithdrawal of consent\u003c\/li\u003e\n\n\u003cli\u003ecomplaints to IMY\u003c\/li\u003e\n\n\u003cli\u003eautomated decision-making and profiling, where relevant\u003c\/li\u003e\n\n\u003cli\u003esources of personal data when Article 14 is applicable\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003eThe template contains specific examples for e-commerce, customer accounts, order management, payment, customer service, security work, newsletters, analytics, and marketing. The examples are intended as editable material and must be adapted to the actual processing activities taking place.\u003c\/p\u003e\n\n\u003ch3\u003eCookie policy according to Swedish cookie legislation\u003c\/h3\u003e\n\u003cp\u003eAccording to Chapter 9, Section 28 of the Electronic Communications Act (2022:482), as a general rule, information may be stored in or retrieved from a user's terminal equipment only after providing information about the purpose and obtaining consent. Exceptions apply, for instance, when the technology is necessary for a service explicitly requested by the user or for the transmission of an electronic message.\u003c\/p\u003e\n\n\u003cp\u003eThe cookie policy therefore contains structures for:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003enecessary cookies\u003c\/li\u003e\n\n\u003cli\u003epreference cookies\u003c\/li\u003e\n\n\u003cli\u003estatistics and analytics\u003c\/li\u003e\n\n\u003cli\u003epersonalization\u003c\/li\u003e\n\n\u003cli\u003emarketing\u003c\/li\u003e\n\n\u003cli\u003ecookie\/tracking names\u003c\/li\u003e\n\n\u003cli\u003eprovider and domain\u003c\/li\u003e\n\n\u003cli\u003epurpose\u003c\/li\u003e\n\n\u003cli\u003ewhat information is collected\u003c\/li\u003e\n\n\u003cli\u003estorage duration\u003c\/li\u003e\n\n\u003cli\u003ethird-party status\u003c\/li\u003e\n\n\u003cli\u003ewithdrawal and modification of consent\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eCookie banner and consent – practical implementation control\u003c\/h3\u003e\n\u003cp\u003eThe PTS states, among other things, that valid consent must be voluntary, specific, informed, and active. The user must be able to reject non-necessary cookies at the same stage and view as they can accept them, and it must be as easy to withdraw consent as it is to grant it.\u003c\/p\u003e\n\n\u003cp\u003eThe separate CMP checklist checks, among other things:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003eAccept all \/ Reject all \/ Customize choices\u003c\/li\u003e\n\n\u003cli\u003ethat non-necessary cookies are blocked before consent\u003c\/li\u003e\n\n\u003cli\u003ethat choices are not pre-selected\u003c\/li\u003e\n\n\u003cli\u003ethat design and colors do not mislead the user\u003c\/li\u003e\n\n\u003cli\u003ethat passivity is not interpreted as consent\u003c\/li\u003e\n\n\u003cli\u003ethat cookie walls are not used in an unauthorized manner\u003c\/li\u003e\n\n\u003cli\u003epurpose-specific consent\u003c\/li\u003e\n\n\u003cli\u003ewithdrawal function\u003c\/li\u003e\n\n\u003cli\u003edesktop and mobile tests\u003c\/li\u003e\n\n\u003cli\u003etechnical control of cookies, storage, tags, and third-party embeddings\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eShort privacy texts for forms\u003c\/h3\u003e\n\u003cp\u003eThe package also contains ready-to-use layer-1 texts that can be adapted and placed directly at:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003econtact forms\u003c\/li\u003e\n\n\u003cli\u003ecustomer accounts\u003c\/li\u003e\n\n\u003cli\u003echeckout and orders\u003c\/li\u003e\n\n\u003cli\u003enewsletters\u003c\/li\u003e\n\n\u003cli\u003ereviews\u003c\/li\u003e\n\n\u003cli\u003esupport and chat\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003eThe short texts are intended to link to the full privacy policy, making it easier to provide information at the time of data collection.\u003c\/p\u003e\n\n\u003ch3\u003eExcel tool for ongoing GDPR and cookie work\u003c\/h3\u003e\n\u003cp\u003eThe Excel file is more than just a simple list. It includes a dashboard and separate worksheets for:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003epersonal data processing activities\u003c\/li\u003e\n\n\u003cli\u003ecookies, local storage, pixels, SDKs, and other tracking technologies\u003c\/li\u003e\n\n\u003cli\u003esuppliers, roles, and third-country transfers\u003c\/li\u003e\n\n\u003cli\u003ecookie banner\/CMP testing\u003c\/li\u003e\n\n\u003cli\u003epublication and audit control\u003c\/li\u003e\n\n\u003cli\u003elegal sources\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003eThe tool flags, among other things, processing activities that need to be completed, non-necessary cookies, uncertain consent status, third-country transfers, and open compliance measures.\u003c\/p\u003e\n\n\u003ch3\u003eWho is this package for?\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003ee-retailers\u003c\/li\u003e\n\n\u003cli\u003eSaaS and IT companies\u003c\/li\u003e\n\n\u003cli\u003ecorporate websites\u003c\/li\u003e\n\n\u003cli\u003edigital agencies\u003c\/li\u003e\n\n\u003cli\u003econsultants and service companies\u003c\/li\u003e\n\n\u003cli\u003eassociations and organizations\u003c\/li\u003e\n\n\u003cli\u003ebusinesses using analytics, advertising, CRM, or email tools\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eLegal basis\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003eGeneral Data Protection Regulation (EU) 2016\/679, particularly Articles 5, 6, 7, 12–14, 21, 24, 28, and 32\u003c\/li\u003e\n\n\u003cli\u003eElectronic Communications Act (2022:482), particularly Chapter 9, Section 28\u003c\/li\u003e\n\n\u003cli\u003eIMY's current guidance on information to data subjects and privacy policies\u003c\/li\u003e\n\n\u003cli\u003ePTS's current guidance on cookies, consent, and withdrawal\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eFormat:\u003c\/strong\u003e Word (DOCX) + PDF + Excel (XLSX)\u003cbr\u003e\n\u003cstrong\u003eLanguage:\u003c\/strong\u003e Swedish\u003cbr\u003e\n\u003cstrong\u003eJurisdiction:\u003c\/strong\u003e Sweden \/ EU\u003cbr\u003e\n\u003cstrong\u003eNumber of files:\u003c\/strong\u003e 11\u003cbr\u003e\n\u003cstrong\u003eLegally reviewed:\u003c\/strong\u003e October 3, 2026\u003cbr\u003e\n\u003cstrong\u003eVersion:\u003c\/strong\u003e 1.0 – relevant 2026\/2027 provided regulations remain unchanged\u003c\/p\u003e\n\n\u003cp\u003e\u003cem\u003eThe documents are general templates and will not be accurate if published unchanged. They must be adapted to the business's actual personal data processing, cookies, suppliers, systems, storage periods, and legal bases.\u003c\/em\u003e\u003c\/p\u003e\n","brand":"Svenska Dokumentmallar","offers":[{"title":"Default Title","offer_id":55593095364950,"sku":"INTEGRITET-COOKIES-2026","price":249.0,"currency_code":"SEK","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0827\/2373\/3846\/files\/integritetspolicy-cookiepolicy-mallpaket-gdpr-cookies.png?v=1791061687"},{"product_id":"ramavtal-mallpaket-2026-2027-word-pdf-svensk-ratt","title":"Framework Agreement Template Package 2026\/2027 – Word\/PDF + English | Swedish Law","description":"\n\u003ch2\u003eFramework Agreement Template Package 2026\/2027 – complete B2B framework agreement in Word and PDF\u003c\/h2\u003e\n\u003cp\u003eThis is a comprehensive and professional \u003cstrong\u003eframework agreement for recurring purchases of goods and\/or services between companies\u003c\/strong\u003e. The package is designed for businesses that wish to establish common legal and commercial terms for a long-term collaboration, while each actual order is made through a separate \u003cstrong\u003ecall-off\u003c\/strong\u003e.\u003c\/p\u003e\n\u003cp\u003eThe template package is \u003cstrong\u003ereviewed against current Swedish law and official guidance as of October 4, 2026\u003c\/strong\u003e, and prepared for use during \u003cstrong\u003e2026\/2027\u003c\/strong\u003e. It contains a Swedish version, a complete English-language \u003cstrong\u003eFramework Agreement\u003c\/strong\u003e under Swedish law, and a separate detailed user guide.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eDelivery:\u003c\/strong\u003e 3 documents in both Word (DOCX) and PDF – a total of \u003cstrong\u003e6 files, 53 A4 pages, and 12 appendices\/schedules\u003c\/strong\u003e. Digital download. No physical product is sent.\u003c\/p\u003e\n\n\u003ch3\u003eThis is included\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eFramework Agreement 2026\/2027 – Swedish version\u003c\/strong\u003e, 23 pages with 28 contract sections and 12 appendices.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eFramework Agreement 2026\/2027 – English \/ Swedish law\u003c\/strong\u003e, 23 pages with a corresponding structure and 12 schedules.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eDetailed user guide\u003c\/strong\u003e, 7 pages with step-by-step instructions, legal checkpoints, and a pre-signing checklist.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eWhen is a framework agreement suitable?\u003c\/h3\u003e\n\u003cp\u003eThe template is suitable when two companies want to create a stable contractual framework for recurring orders without negotiating all basic terms for every purchase. It can be used, for example, for ongoing deliveries of components, consumables, services, support, consulting services, IT services, or combined goods and service deliveries.\u003c\/p\u003e\n\u003cp\u003eThe framework agreement regulates the basic terms. Each actual order is subsequently made through a \u003cstrong\u003eCall-off\u003c\/strong\u003e specifying, for example, scope, quantity, price, delivery date, location, and specific acceptance criteria.\u003c\/p\u003e\n\n\u003ch3\u003eImportant limitation – private B2B, not PPA\/UPA\u003c\/h3\u003e\n\u003cp\u003eThis product is a \u003cstrong\u003eprivate law B2B framework agreement\u003c\/strong\u003e. It is not designed as a framework agreement under the Swedish Public Procurement Act (LOU), the Act on Procurement in the Utilities Sectors (LUF), or other procurement legislation.\u003c\/p\u003e\n\u003cp\u003ePublic framework agreements have specific rules regarding, for example, which organizations may place call-offs, how contracts may be awarded, and the permitted duration of the framework agreement. If the agreement is to be used in public procurement, separate adjustments under procurement law are therefore required.\u003c\/p\u003e\n\n\u003ch3\u003e28 contract sections\u003c\/h3\u003e\n\u003cp\u003eThe main agreement covers, among other things:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003eparties and the purpose of the agreement,\u003c\/li\u003e\n\n\u003cli\u003econtract documents and order of priority,\u003c\/li\u003e\n\n\u003cli\u003edefinitions,\u003c\/li\u003e\n\n\u003cli\u003escope of the framework agreement,\u003c\/li\u003e\n\n\u003cli\u003ecall-offs, orders, and contract formation,\u003c\/li\u003e\n\n\u003cli\u003eforecasts, volumes, and capacity,\u003c\/li\u003e\n\n\u003cli\u003eprices, fees, and price adjustment,\u003c\/li\u003e\n\n\u003cli\u003einvoicing and payment,\u003c\/li\u003e\n\n\u003cli\u003edelivery of goods, risk, and title,\u003c\/li\u003e\n\n\u003cli\u003eservices, personnel, and subcontractors,\u003c\/li\u003e\n\n\u003cli\u003einspection, testing, and acceptance,\u003c\/li\u003e\n\n\u003cli\u003edefects, remedies, and warranties,\u003c\/li\u003e\n\n\u003cli\u003eSLA and service credits,\u003c\/li\u003e\n\n\u003cli\u003echange management,\u003c\/li\u003e\n\n\u003cli\u003eintellectual property rights,\u003c\/li\u003e\n\n\u003cli\u003epersonal data and information security,\u003c\/li\u003e\n\n\u003cli\u003econfidentiality and trade secrets,\u003c\/li\u003e\n\n\u003cli\u003ecompliance and ethical requirements,\u003c\/li\u003e\n\n\u003cli\u003edocumentation, audit, and follow-up,\u003c\/li\u003e\n\n\u003cli\u003eliability and limitation of liability,\u003c\/li\u003e\n\n\u003cli\u003einsurance,\u003c\/li\u003e\n\n\u003cli\u003eforce majeure,\u003c\/li\u003e\n\n\u003cli\u003eterm and termination,\u003c\/li\u003e\n\n\u003cli\u003econsequences of termination,\u003c\/li\u003e\n\n\u003cli\u003enotices, assignment, and amendments,\u003c\/li\u003e\n\n\u003cli\u003eSwedish law and international sales,\u003c\/li\u003e\n\n\u003cli\u003edispute resolution,\u003c\/li\u003e\n\n\u003cli\u003eother contract provisions.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003e12 professional appendices\u003c\/h3\u003e\n\u003col\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eScope of delivery\u003c\/strong\u003e – which goods and\/or services may be called off.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eVolume, forecast, and minimum commitments\u003c\/strong\u003e – including any capacity or take-or-pay solutions.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eCall-off process, authorization, and contact channels\u003c\/strong\u003e – who is authorized to order and how a Call-off becomes binding.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003ePrice list and price adjustment\u003c\/strong\u003e – currency, discount, index, freight, travel, and notice period.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eDelivery terms and product warranties\u003c\/strong\u003e – place of delivery, transport, risk, Incoterms, and warranty.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eServices, staffing, and acceptance\u003c\/strong\u003e – deliverables, milestones, key personnel, and acceptance criteria.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eSLA and support\u003c\/strong\u003e – service levels, measurement, reporting, and service credits.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eIntellectual property rights and licenses\u003c\/strong\u003e – background material, standard products, specially developed results, and third-party licenses.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eData protection and information security\u003c\/strong\u003e – GDPR, access control, incident reporting, and sub-processors.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eCompliance and sustainability requirements\u003c\/strong\u003e – e.g., anti-corruption, sanctions, export control, and product safety.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eLiability, indemnities, and insurance\u003c\/strong\u003e – liability caps, carve-outs, and insurance levels.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eTerm, termination, CISG, and dispute resolution\u003c\/strong\u003e – start date, extension, force majeure, ongoing call-offs, international sales, and forum.\u003c\/li\u003e\n\n\n\u003c\/ol\u003e\n\n\u003ch3\u003eCall-offs and contract formation\u003c\/h3\u003e\n\u003cp\u003eOne of the most common conflict points in long-term supplier relationships is ambiguity regarding when an individual order actually becomes binding and which terms apply to it. The template therefore contains an explicit \u003cstrong\u003ecall-off mechanism\u003c\/strong\u003e where authorized purchasers, ordering channels, and order confirmations can be defined.\u003c\/p\u003e\n\u003cp\u003eThere is also a clear order of priority between the main agreement, appendices, data processing agreements, call-offs, and subsequent amendment agreements so that conflicting standard terms or order texts do not inadvertently override the Framework Agreement.\u003c\/p\u003e\n\n\u003ch3\u003ePrices, indexing, and cost control\u003c\/h3\u003e\n\u003cp\u003eAppendix 4 makes it possible to document the price list, unit, currency, discounts, index or other price adjustment method, next adjustment, and special costs. The template avoids vague standard wording where the supplier can unilaterally refer to a future price list without an agreed-upon control mechanism.\u003c\/p\u003e\n\n\u003ch3\u003eGoods and the Sale of Goods Act\u003c\/h3\u003e\n\u003cp\u003eFor the purchase of personal property, the \u003cstrong\u003eSale of Goods Act (1990:931)\u003c\/strong\u003e may become applicable. The Sale of Goods Act is largely non-mandatory, meaning that the Parties can agree on other solutions. The framework agreement therefore contains its own rules regarding, for example, delivery, inspection, defects, warranty, and liability that can supplement or replace the statutory standard rules.\u003c\/p\u003e\n\u003cp\u003eHowever, the Sale of Goods Act does not apply when the service component is the predominant part of the Supplier's obligation. The template is therefore structured so that goods and service deliveries can be handled separately.\u003c\/p\u003e\n\n\u003ch3\u003eServices, acceptance, and SLA\u003c\/h3\u003e\n\u003cp\u003eFor services and project deliveries, the Parties can define clear deliverables, milestones, key personnel, and acceptance criteria in Appendix 6. Appendix 7 is used for measurable service levels and support.\u003c\/p\u003e\n\u003cp\u003eService credits or price reductions are not automatically exclusive remedies. If the Parties want a certain remedy to be exclusive, this must be stated explicitly.\u003c\/p\u003e\n\n\u003ch3\u003eChange management\u003c\/h3\u003e\n\u003cp\u003eThe template contains a formal Change Control process. No Party is required to implement a change that affects price, scope, security, schedule, or risk allocation before a Change Order has been approved by authorized representatives.\u003c\/p\u003e\n\n\u003ch3\u003eIntellectual property rights\u003c\/h3\u003e\n\u003cp\u003eAppendix 8 helps the Parties distinguish between the Supplier's background material, standard products, the Customer's material, third-party material, and results developed specifically within the collaboration. It is used to specify owners, the Customer's license or right of use, and any restrictions.\u003c\/p\u003e\n\n\u003ch3\u003eGDPR and information security\u003c\/h3\u003e\n\u003cp\u003eIf the Supplier processes personal data on the Customer's behalf, a separate data processing agreement is normally required under Article 28 of the GDPR. The framework agreement therefore does not contain a simplified clause claiming that a few sentences replace a full-scale DPA.\u003c\/p\u003e\n\u003cp\u003eAppendix 9 is used to document security requirements, incident reporting, access controls, logging, sub-processors, storage location, and deletion routines.\u003c\/p\u003e\n\n\u003ch3\u003eLiability and insurance\u003c\/h3\u003e\n\u003cp\u003eAppendix 11 makes it possible to specify liability caps, special carve-outs, any indemnities, and insurance levels. The base template distinguishes between direct and indirect loss but leaves the commercially sensitive levels open so that they can be adapted to the contract value and actual risk.\u003c\/p\u003e\n\n\u003ch3\u003eInternational sales and CISG\u003c\/h3\u003e\n\u003cp\u003eFor international sales of goods, the \u003cstrong\u003eAct (1987:822) on International Sales\u003c\/strong\u003e and the CISG may become applicable. Therefore, there is a specific selection point in Appendix 12 where the Parties can state whether the CISG is to apply or be explicitly excluded.\u003c\/p\u003e\n\u003cp\u003eFor purchases where both the seller and the buyer have their places of business in Denmark, Finland, Iceland, Norway, or Sweden, the special Nordic rule in Section 2 of the Act on International Sales applies.\u003c\/p\u003e\n\n\u003ch3\u003eEnglish Framework Agreement under Swedish law\u003c\/h3\u003e\n\u003cp\u003eThe English version contains the same structure, 28 contract sections, and 12 schedules. It is intended for situations where Swedish law is to be applied but where, for example, the supplier, customer, group, or advisors work in English.\u003c\/p\u003e\n\u003cp\u003eIt is therefore an English-language template under Swedish law – not a template under British or American law.\u003c\/p\u003e\n\n\u003ch3\u003eDetailed user guide\u003c\/h3\u003e\n\u003cp\u003eThe user guide explains when a framework agreement is the correct form of contract, the difference from public procurement, how the call-off process is built, how all 12 appendices are used, and which legal issues should be checked before signing.\u003c\/p\u003e\n\u003cp\u003eThe guide also includes a complete final checklist for parties, scope of delivery, volume, call-offs, prices, delivery, SLA, IP, GDPR, liability, term, CISG, and dispute resolution.\u003c\/p\u003e\n\n\u003ch3\u003eReviewed for 2026\/2027\u003c\/h3\u003e\n\u003cp\u003eThe legal review is dated \u003cstrong\u003eOctober 4, 2026\u003c\/strong\u003e. The package has been checked against, among other things, the \u003cstrong\u003eContracts Act (1915:218)\u003c\/strong\u003e, the \u003cstrong\u003eSale of Goods Act (1990:931)\u003c\/strong\u003e, the \u003cstrong\u003eAct (1987:822) on International Sales\u003c\/strong\u003e, the GDPR, and the \u003cstrong\u003eAct (2018:218) with supplementary provisions to the EU Data Protection Regulation\u003c\/strong\u003e, as well as the \u003cstrong\u003eTrade Secrets Act (2018:558)\u003c\/strong\u003e.\u003c\/p\u003e\n\n\u003ch3\u003eFormat and delivery\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3 documents • 6 files • 53 pages • 12 appendices\/schedules\u003c\/strong\u003e\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eWord (DOCX)\u003c\/strong\u003e – fully editable with clear fill-in fields and tables.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003ePDF\u003c\/strong\u003e – for reference, printing, and layout verification.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eDigital delivery\u003c\/strong\u003e – no physical product is sent.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eImportant\u003c\/h3\u003e\n\u003cp\u003eThis is a professional general contract template and does not replace individual legal advice. Public procurement, large international agreements, regulated business, complex IT outsourcing, extensive processing of personal data, competition law issues regarding exclusivity, or very high liability amounts should be assessed separately by a qualified advisor.\u003c\/p\u003e\n","brand":"Svenska Dokumentmallar","offers":[{"title":"Default Title","offer_id":55594221928790,"sku":"RAMAVTAL-2026-2027","price":249.0,"currency_code":"SEK","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0827\/2373\/3846\/files\/ramavtal-2026-2027-hero.png?v=1791071588"},{"product_id":"kundavtal-b2b-mallpaket-2026-2027-word-pdf-english-svensk-ratt","title":"B2B Customer Agreement Template Package 2026\/2027 – Word\/PDF + English | Swedish Law","description":"\n\u003ch2\u003eCustomer Agreement B2B Template Package 2026\/2027 – Word\/PDF in Swedish and English\u003c\/h2\u003e\n\u003cp\u003eThis is a complete and professional \u003cstrong\u003eCustomer Agreement for B2B relationships\u003c\/strong\u003e where a company sells and delivers goods and\/or services to an identified corporate client. The agreement is designed to consolidate the most important commercial and legal terms into a clear document: orders, prices, payment, deliveries, services, acceptance, warranty, SLA, intellectual property rights, GDPR, confidentiality, liability, contract term, termination, and dispute resolution.\u003c\/p\u003e\n\u003cp\u003eThe template package is \u003cstrong\u003ereviewed against current Swedish law as of October 4, 2026\u003c\/strong\u003e and developed for practical use during \u003cstrong\u003e2026\/2027\u003c\/strong\u003e. The package contains both a Swedish B2B version and a complete English-language \u003cstrong\u003eCustomer Agreement\u003c\/strong\u003e based on Swedish law, as well as a separate detailed user guide.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eDelivery:\u003c\/strong\u003e 3 documents in both Word (DOCX) and PDF – a total of \u003cstrong\u003e6 files, 43 A4 pages, and 10 appendices\/schedules\u003c\/strong\u003e. The product is delivered digitally. No physical item is sent.\u003c\/p\u003e\n\n\u003ch3\u003eIncluded\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eCustomer Agreement B2B 2026\/2027 – Swedish version\u003c\/strong\u003e, 19 pages with 22 agreement sections and 10 appendices.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eCustomer Agreement 2026\/2027 – English \/ Swedish law\u003c\/strong\u003e, 19 pages with a corresponding structure and 10 schedules.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eDetailed user guide\u003c\/strong\u003e, 5 pages with step-by-step instructions, legal checkpoints, and a pre-signature checklist.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eWhen is this Customer Agreement suitable?\u003c\/h3\u003e\n\u003cp\u003eThe template is suitable when the supplier has an identified corporate client and the parties want a cohesive agreement for the entire customer relationship. This may apply, for example, to ongoing sales of products, machinery, components, or consumables, consulting and service tasks, support, installation, digital deliveries, or combinations of goods and services.\u003c\/p\u003e\n\u003cp\u003eFor relationships with many separate call-offs, multiple delivery locations, or very extensive framework terms, a separate Framework Agreement may be more appropriate. However, the Customer Agreement is ideal when the parties want a clear master agreement for a specific customer relationship with the option to make individual Orders under the agreement.\u003c\/p\u003e\n\n\u003ch3\u003eImportant limitation – B2B, not consumer agreement\u003c\/h3\u003e\n\u003cp\u003eThis template is designed for agreements \u003cstrong\u003ebetween businesses\u003c\/strong\u003e. It should not be used unchanged in consumer relationships, where mandatory consumer protection rules may apply.\u003c\/p\u003e\n\u003cp\u003eFor the sale of goods between businesses, the Swedish Sale of Goods Act (*Köplagen*) may be applicable. The Sale of Goods Act is largely non-mandatory, meaning the parties can set other terms through the agreement. If the service component is the predominant part of the supplier’s obligation, however, the Sale of Goods Act does not normally apply to the mixed delivery. The Customer Agreement is therefore structured so that goods and services can be regulated separately.\u003c\/p\u003e\n\n\u003ch3\u003e22 agreement sections\u003c\/h3\u003e\n\u003cp\u003eThe main agreement includes, among other things:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003eparties and the purpose of the agreement,\u003c\/li\u003e\n\n\u003cli\u003eagreement documents and order of priority,\u003c\/li\u003e\n\n\u003cli\u003escope and orders,\u003c\/li\u003e\n\n\u003cli\u003eprices, taxes, and price changes,\u003c\/li\u003e\n\n\u003cli\u003einvoicing and payment,\u003c\/li\u003e\n\n\u003cli\u003edelivery of goods,\u003c\/li\u003e\n\n\u003cli\u003eservices and deliverables,\u003c\/li\u003e\n\n\u003cli\u003einspection, acceptance, and complaints,\u003c\/li\u003e\n\n\u003cli\u003edefects and remediation,\u003c\/li\u003e\n\n\u003cli\u003ewarranty and support,\u003c\/li\u003e\n\n\u003cli\u003eintellectual property rights,\u003c\/li\u003e\n\n\u003cli\u003econfidentiality and trade secrets,\u003c\/li\u003e\n\n\u003cli\u003epersonal data and information security,\u003c\/li\u003e\n\n\u003cli\u003ecompliance and marketing,\u003c\/li\u003e\n\n\u003cli\u003eliability and limitation of liability,\u003c\/li\u003e\n\n\u003cli\u003einsurance,\u003c\/li\u003e\n\n\u003cli\u003eforce majeure,\u003c\/li\u003e\n\n\u003cli\u003econtract term and termination,\u003c\/li\u003e\n\n\u003cli\u003econsequences of termination,\u003c\/li\u003e\n\n\u003cli\u003eSwedish law and international sales,\u003c\/li\u003e\n\n\u003cli\u003edispute resolution,\u003c\/li\u003e\n\n\u003cli\u003emiscellaneous provisions.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003e10 practical appendices \/ schedules\u003c\/h3\u003e\n\u003col\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eProducts and services\u003c\/strong\u003e – exactly what the agreement covers.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eOrdering process\u003c\/strong\u003e – who is authorized to order and when an order becomes binding.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003ePrice list and price adjustment\u003c\/strong\u003e – prices, currency, discounts, fees, indexes, and notice periods.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eDelivery terms for goods\u003c\/strong\u003e – place of delivery, Incoterms, transfer of risk, packaging, and warranty.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eServices and acceptance\u003c\/strong\u003e – deliverables, staffing, milestones, and acceptance criteria.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eWarranty, SLA, and support\u003c\/strong\u003e – warranty and service levels with measurable times.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eIP and licenses\u003c\/strong\u003e – background material, standard products, customer material, and specially developed results.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eGDPR and information security\u003c\/strong\u003e – roles, systems, access, incidents, and security requirements.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eCompliance requirements\u003c\/strong\u003e – e.g., regulatory requirements, security, anti-corruption, and other relevant requirements.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eLiability, contract term, termination, CISG, and disputes\u003c\/strong\u003e – liability caps, insurance, duration, termination, and venue.\u003c\/li\u003e\n\n\n\u003c\/ol\u003e\n\n\u003ch3\u003eOrders and contract conclusion\u003c\/h3\u003e\n\u003cp\u003eAppendix 2 is used to determine how Orders are to be made, which individuals are authorized to order, and when an order becomes binding. This reduces the risk that an oral order, an email, or a purchase order unintentionally creates terms other than those the parties intended.\u003c\/p\u003e\n\u003cp\u003eThe agreement also contains a clear order of priority between the main agreement, appendices, Orders, and subsequent written amendments.\u003c\/p\u003e\n\n\u003ch3\u003ePrices and price changes\u003c\/h3\u003e\n\u003cp\u003eAppendix 3 makes it possible to specify fixed prices, unit prices, currency, discounts, indexes, or other price adjustment models. The supplier cannot automatically refer to a future price list without support in the model the parties have filled in.\u003c\/p\u003e\n\u003cp\u003eIn this way, it becomes clear how price adjustments may be made, how far in advance they must be notified, and which fees may actually be charged.\u003c\/p\u003e\n\n\u003ch3\u003eInvoicing, 30 days, and penalty interest\u003c\/h3\u003e\n\u003cp\u003eThe base template uses 30-day payment terms. For B2B receivables for payment for goods or services, the Swedish Interest Act (*Räntelagen*) stipulates that a payment term longer than 30 days requires the creditor to explicitly approve the longer period.\u003c\/p\u003e\n\u003cp\u003eThe template therefore specifies that a longer payment term must be expressly agreed upon. In the event of late payment, penalty interest according to the Interest Act may apply. The Act's normal calculation is the reference rate applicable at any given time plus eight percentage points, unless otherwise validly follows from the agreement or law.\u003c\/p\u003e\n\u003cp\u003eIf the statutory conditions are met, the supplier may also be entitled to late payment compensation according to the Act on Compensation for Debt Collection Costs, etc.\u003c\/p\u003e\n\n\u003ch3\u003eDelivery of goods and the Sale of Goods Act\u003c\/h3\u003e\n\u003cp\u003eFor goods, the place of delivery, transport liability, transfer of risk, and any Incoterms are regulated in Appendix 4. The goods must correspond to the agreed specification and the warranties that the parties have filled in.\u003c\/p\u003e\n\u003cp\u003eThe Sale of Goods Act (1990:931) applies to the sale of movable property but is primarily non-mandatory. The agreement can therefore be used to create more precise rules regarding inspection, complaints, remediation, redelivery, price reduction, and rescission than would otherwise follow from the Act's standard rules.\u003c\/p\u003e\n\n\u003ch3\u003eServices and acceptance\u003c\/h3\u003e\n\u003cp\u003eFor services and digital deliveries, the parties can use Appendix 5 to define deliverables, milestones, staffing, and acceptance criteria. This is particularly useful when the agreement includes projects, installation, consulting services, support, or other performances where \"delivery\" cannot be assessed in the same way as a physical item.\u003c\/p\u003e\n\n\u003ch3\u003eWarranty, SLA, and support\u003c\/h3\u003e\n\u003cp\u003eAppendix 6 makes it possible to specify warranty periods, availability, support hours, response times, correction times, and other service levels. The formulations are intentionally measurable so that it is possible to determine if the delivery actually meets the agreed level.\u003c\/p\u003e\n\n\u003ch3\u003eIntellectual property rights\u003c\/h3\u003e\n\u003cp\u003eAppendix 7 distinguishes between the supplier's background material, standard products, customer material, and specially developed results. There, the parties can specify who owns each part and what license or right of use the customer receives.\u003c\/p\u003e\n\u003cp\u003eThis is particularly relevant in cases such as software, design, drawings, documentation, educational material, databases, technical solutions, and consulting deliveries.\u003c\/p\u003e\n\n\u003ch3\u003eGDPR and Data Processor Agreement\u003c\/h3\u003e\n\u003cp\u003eAppendix 8 helps the parties identify personal data roles, systems, access, security requirements, and incident management. If the supplier processes personal data \u003cstrong\u003eon behalf of the customer\u003c\/strong\u003e, the processing generally needs to be regulated through a separate Data Processor Agreement under Article 28 of the GDPR.\u003c\/p\u003e\n\u003cp\u003eThe Customer Agreement therefore does not claim that a short standard clause replaces a full Data Processor Agreement. Instead, it provides clear instructions on when a separate agreement needs to be established.\u003c\/p\u003e\n\n\u003ch3\u003eConfidentiality and trade secrets\u003c\/h3\u003e\n\u003cp\u003eThe agreement contains confidentiality rules and refers to the protection of trade secrets. The parties can use the agreement to protect, for example, price lists, customer data, technical information, business plans, product information, documentation, and other non-public information shared during the collaboration.\u003c\/p\u003e\n\n\u003ch3\u003eLiability and limitation of liability\u003c\/h3\u003e\n\u003cp\u003eAppendix 10 contains fill-in fields for liability caps, any exceptions to the liability cap, insurance requirements, contract term, and termination. The levels are deliberately left open because a reasonable liability cap must be assessed in relation to contract value, risk, insurance, and the type of delivery.\u003c\/p\u003e\n\n\u003ch3\u003eContract term and termination\u003c\/h3\u003e\n\u003cp\u003eThe parties can choose a fixed contract period, open-ended agreement, or another structure and specify the regular notice period. The agreement also contains provisions on material breach, cure periods, and consequences after the agreement has ended.\u003c\/p\u003e\n\n\u003ch3\u003eInternational sale of goods and CISG\u003c\/h3\u003e\n\u003cp\u003eFor international sales of goods, the Act (1987:822) on International Sales of Goods and the UN Convention on Contracts for the International Sale of Goods (CISG) may be applicable. Appendix 10 therefore contains an explicit choice where the parties can state whether the CISG is to apply or be excluded.\u003c\/p\u003e\n\n\u003ch3\u003eEnglish Customer Agreement under Swedish law\u003c\/h3\u003e\n\u003cp\u003eThe English version is a complete \u003cstrong\u003eCustomer Agreement\u003c\/strong\u003e with the same structure and 10 schedules. It is intended for corporate relationships where Swedish rules are to apply but where the customer, supplier, group functions, owners, or advisors work in English.\u003c\/p\u003e\n\u003cp\u003eThe English template is thus adapted to Swedish law and should not be confused with an agreement under British or American law.\u003c\/p\u003e\n\n\u003ch3\u003eDetailed user guide included\u003c\/h3\u003e\n\u003cp\u003eThe separate guide shows step-by-step how to use the Customer Agreement. It helps the user determine when the Customer Agreement is the right form of agreement, how to fill in the appendices, how to formulate payment terms, how to distinguish between goods and services, how to handle GDPR issues, and which checkpoints should be cleared before signing.\u003c\/p\u003e\n\n\u003ch3\u003eReviewed for 2026\/2027\u003c\/h3\u003e\n\u003cp\u003eThe legal review is dated \u003cstrong\u003eOctober 4, 2026\u003c\/strong\u003e. The template package has been checked against, among other things:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003ethe Contracts Act (1915:218),\u003c\/li\u003e\n\n\u003cli\u003ethe Sale of Goods Act (1990:931),\u003c\/li\u003e\n\n\u003cli\u003ethe Interest Act (1975:635),\u003c\/li\u003e\n\n\u003cli\u003ethe Act (1981:739) on Compensation for Debt Collection Costs, etc.,\u003c\/li\u003e\n\n\u003cli\u003ethe Act (1987:822) on International Sales of Goods,\u003c\/li\u003e\n\n\u003cli\u003ethe General Data Protection Regulation (EU) 2016\/679 (GDPR),\u003c\/li\u003e\n\n\u003cli\u003ethe Act (2018:218) supplementing the EU General Data Protection Regulation,\u003c\/li\u003e\n\n\u003cli\u003ethe Trade Secrets Act (2018:558).\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\u003cp\u003eThe designation 2026\/2027 means that the documents have been reviewed against the legal situation at the date of review and are developed for use during these years. In the event of later legislative changes, the template should always be checked against the new legal situation.\u003c\/p\u003e\n\n\u003ch3\u003eFormat and delivery\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3 documents • 6 files • 43 pages • 10 appendices\/schedules\u003c\/strong\u003e\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eWord (DOCX)\u003c\/strong\u003e – fully editable.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003ePDF\u003c\/strong\u003e – for reference, printing, and layout checking.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eDigital delivery\u003c\/strong\u003e – no physical product is sent.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eImportant\u003c\/h3\u003e\n\u003cp\u003eThe template package is professional general contractual material and does not replace individual legal advice. Large contract values, regulated activities, complicated international deliveries, IT outsourcing, extensive personal data processing, advanced intellectual property structures, or unusually high liability risks should be assessed separately by a qualified advisor.\u003c\/p\u003e\n","brand":"Svenska Dokumentmallar","offers":[{"title":"Default Title","offer_id":55594456088918,"sku":"KUNDAVTAL-B2B-2026-2027","price":99.0,"currency_code":"SEK","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0827\/2373\/3846\/files\/kundavtal-b2b-2026-2027-hero.png?v=1791074357"},{"product_id":"licensavtal-license-agreement-2026-2027-word-pdf-english-svensk-ratt","title":"License Agreement 2026\/2027 – Word\/PDF + English | Swedish Law","description":"\n\u003ch2\u003eLicense Agreement Template Package 2026\/2027 – Word\/PDF + English | Swedish Law\u003c\/h2\u003e\n\u003cp\u003eThis is a complete and professional \u003cstrong\u003eLicense Agreement for B2B Licensing of Intellectual Property\u003c\/strong\u003e. The package is designed for companies that wish to grant or acquire a clearly defined right of use for, for example, \u003cstrong\u003esoftware, copyrighted material, trademarks, patents, technical know-how, or combinations thereof\u003c\/strong\u003e.\u003c\/p\u003e\n\u003cp\u003eThe template package is \u003cstrong\u003elegally reviewed against current Swedish law and relevant EU regulations as of October 4, 2026\u003c\/strong\u003e, and prepared for practical use during \u003cstrong\u003e2026\/2027\u003c\/strong\u003e. The package includes a Swedish License Agreement, a complete English-language \u003cstrong\u003eLicense Agreement\u003c\/strong\u003e governed by Swedish law, and a separate detailed user guide.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eDelivery:\u003c\/strong\u003e 3 documents in both Word (DOCX) and PDF – a total of \u003cstrong\u003e6 files, 37 A4 pages, and 12 appendices\/schedules\u003c\/strong\u003e. Digital download. No physical product will be shipped.\u003c\/p\u003e\n\n\u003ch3\u003eIncluded in this package\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eLicense Agreement 2026\/2027 – Swedish version\u003c\/strong\u003e, 17 pages with 26 contract sections and 12 appendices.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eLicense Agreement 2026\/2027 – English \/ Swedish law\u003c\/strong\u003e, 17 pages with equivalent structure and 12 schedules.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eDetailed user guide\u003c\/strong\u003e, 3 pages with legal sources, competition law checkpoints, and a final checklist.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eWhich rights can be licensed?\u003c\/h3\u003e\n\u003cp\u003eAppendix 1 is used to precisely identify which rights are covered. The template can be adapted for, among other things:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003esoftware and computer programs,\u003c\/li\u003e\n\n\u003cli\u003ecopyrighted material, such as texts, designs, images, documentation, and educational material,\u003c\/li\u003e\n\n\u003cli\u003eregistered or unregistered trademarks,\u003c\/li\u003e\n\n\u003cli\u003epatents and patent applications,\u003c\/li\u003e\n\n\u003cli\u003eknow-how and trade secrets,\u003c\/li\u003e\n\n\u003cli\u003etechnical documentation, drawings, and design material,\u003c\/li\u003e\n\n\u003cli\u003ecombined technology and trademark licenses.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\u003cp\u003eThe agreement does not automatically transfer ownership of the IP rights. It only grants the right of use expressly specified.\u003c\/p\u003e\n\n\u003ch3\u003e26 contract sections\u003c\/h3\u003e\n\u003cp\u003eThe main agreement covers, among other things:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003ebackground and purpose,\u003c\/li\u003e\n\n\u003cli\u003edefinitions,\u003c\/li\u003e\n\n\u003cli\u003elicensed objects and chain of title,\u003c\/li\u003e\n\n\u003cli\u003escope of the license,\u003c\/li\u003e\n\n\u003cli\u003epermitted uses and restrictions,\u003c\/li\u003e\n\n\u003cli\u003esublicensing,\u003c\/li\u003e\n\n\u003cli\u003edelivery, access, and technical material,\u003c\/li\u003e\n\n\u003cli\u003elicense fees, royalties, and minimum payments,\u003c\/li\u003e\n\n\u003cli\u003ereporting, accounting, and audit,\u003c\/li\u003e\n\n\u003cli\u003etrademarks and quality control,\u003c\/li\u003e\n\n\u003cli\u003esoftware and mandatory user rights,\u003c\/li\u003e\n\n\u003cli\u003eknow-how and trade secrets,\u003c\/li\u003e\n\n\u003cli\u003eimprovements, further development, and new IP,\u003c\/li\u003e\n\n\u003cli\u003emaintenance and registration of IP,\u003c\/li\u003e\n\n\u003cli\u003einfringement and third-party claims,\u003c\/li\u003e\n\n\u003cli\u003eLicensor's warranties,\u003c\/li\u003e\n\n\u003cli\u003eLicensee's obligations,\u003c\/li\u003e\n\n\u003cli\u003eliability and indemnification,\u003c\/li\u003e\n\n\u003cli\u003ecompetition law and technology transfer,\u003c\/li\u003e\n\n\u003cli\u003eGDPR and information security,\u003c\/li\u003e\n\n\u003cli\u003econfidentiality,\u003c\/li\u003e\n\n\u003cli\u003eterm and termination,\u003c\/li\u003e\n\n\u003cli\u003eeffect of termination,\u003c\/li\u003e\n\n\u003cli\u003eassignment and change of control,\u003c\/li\u003e\n\n\u003cli\u003enotices and amendments,\u003c\/li\u003e\n\n\u003cli\u003eSwedish law and dispute resolution.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003e12 practical appendices \/ schedules\u003c\/h3\u003e\n\u003col\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eLicensed Objects and IP Register\u003c\/strong\u003e – right type, title\/version, registration number, and chain of title.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eLicense Type, Territory, and Field of Use\u003c\/strong\u003e – exclusive, sole, or non-exclusive license.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003ePermitted Uses and Restrictions\u003c\/strong\u003e – use, copying, modification, distribution, integration, and reverse engineering.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eSublicensing\u003c\/strong\u003e – if and how rights may be sublicensed.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eFees, Royalties, and Minimums\u003c\/strong\u003e – royalty base, percentage, minimum compensation, and payment frequency.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eReporting and Audit\u003c\/strong\u003e – royalty reports, archiving, and audit rights.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eTrademark, Graphic Profile, and Quality\u003c\/strong\u003e – approved marks, quality standards, and brand guidelines.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eSoftware, Technology, and Support\u003c\/strong\u003e – delivery model, version, source code, support, and security requirements.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eKnow-How, Confidentiality, and Security\u003c\/strong\u003e – protectable know-how, recipients, and deletion.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eImprovements and New IP\u003c\/strong\u003e – ownership, joint development, and grant-back.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eIP Maintenance, Infringement, and Third-Party Claims\u003c\/strong\u003e – renewals, litigation control, and costs.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eLiability, Term, Data, and Dispute\u003c\/strong\u003e – liability caps, termination, sell-off, and forum.\u003c\/li\u003e\n\n\n\u003c\/ol\u003e\n\n\u003ch3\u003eExclusive, sole, or non-exclusive license\u003c\/h3\u003e\n\u003cp\u003eAppendix 2 allows you to choose between three different license models:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eExclusive license\u003c\/strong\u003e – the exclusivity the parties expressly define within the Territory and Field of Use.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eSole license\u003c\/strong\u003e – can be used when the Licensor themselves retains certain usage rights but will not grant equivalent rights to others.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eNon-exclusive license\u003c\/strong\u003e – the Licensor can normally grant equivalent rights to multiple licensees.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\u003cp\u003eTerritory, products, services, field of use, and sales channels are documented separately so that “exclusivity” does not become an unclear umbrella term.\u003c\/p\u003e\n\n\u003ch3\u003eRoyalties – more than just a percentage\u003c\/h3\u003e\n\u003cp\u003eAppendix 5 includes support for one-time fees, ongoing royalties, fees per unit\/user, and minimum royalties. However, the most important aspect is defining the \u003cstrong\u003eroyalty base\u003c\/strong\u003e itself.\u003c\/p\u003e\n\u003cp\u003eThe parties can therefore specify how Net Sales are to be calculated and how, for example, discounts, returns, credits, taxes, freight, intra-group sales, or combination products should be treated.\u003c\/p\u003e\n\n\u003ch3\u003eAudit and royalty control\u003c\/h3\u003e\n\u003cp\u003eAppendix 6 contains a proportionate audit model where the parties can specify reporting periods, archiving time, audit notice, frequency, and cost distribution in the event of a significant identified discrepancy.\u003c\/p\u003e\n\u003cp\u003eThe audit is designed so that the Licensor can verify royalties while protecting the Licensee's own trade secrets.\u003c\/p\u003e\n\n\u003ch3\u003eSoftware license – updated according to Swedish copyright law 2026\u003c\/h3\u003e\n\u003cp\u003eThe Copyright Act expressly protects computer programs. For software, it is simultaneously important that a license agreement does not attempt to contract out of rights that are mandatory by law.\u003c\/p\u003e\n\u003cp\u003eThe template therefore pays special attention to \u003cstrong\u003eSections 26g and 26h of the Copyright Act\u003c\/strong\u003e. Any person entitled to use a computer program has, under the conditions of the law, certain rights including necessary backup copying, studying the function of the program, and decompilation when necessary for interoperability. Contractual terms restricting some of these rights are invalid.\u003c\/p\u003e\n\u003cp\u003eTherefore, the template does not use an absolute prohibition against all reverse engineering regardless of law, but ties the restriction to what is legally permitted.\u003c\/p\u003e\n\n\u003ch3\u003eSaaS and cloud services\u003c\/h3\u003e\n\u003cp\u003eAppendix 8 can be used for SaaS, APIs, and other digital technology, but a SaaS arrangement normally involves more issues than the license itself – such as operations, hosting, SLA, backup, support, data export, and information security.\u003c\/p\u003e\n\u003cp\u003eFor comprehensive SaaS services, the License Agreement should therefore be combined with or replaced by a specific SaaS\/cloud service agreement.\u003c\/p\u003e\n\n\u003ch3\u003eTrademark license under Swedish law\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003eChapter 6 of the Trademarks Act (2010:1877)\u003c\/strong\u003e contains special rules regarding licenses. A trademark license can be exclusive or non-exclusive and apply to all or parts of the registration's goods\/services and geographic area.\u003c\/p\u003e\n\u003cp\u003eFurthermore, the trademark owner can exercise their exclusive right against a licensee who violates certain key license terms, such as regarding:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003ethe validity period of the license,\u003c\/li\u003e\n\n\u003cli\u003ehow the trademark may be used,\u003c\/li\u003e\n\n\u003cli\u003ewhich goods or services the license covers,\u003c\/li\u003e\n\n\u003cli\u003egeographic area,\u003c\/li\u003e\n\n\u003cli\u003ethe quality of the licensee's goods or services.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\u003cp\u003eAppendix 7 therefore contains separate fields for trademark manuals, approval processes, and quality standards.\u003c\/p\u003e\n\n\u003ch3\u003ePatent license – new Patents Act (2024:945)\u003c\/h3\u003e\n\u003cp\u003eAs of January 1, 2025, Sweden has a new \u003cstrong\u003ePatents Act (2024:945)\u003c\/strong\u003e. Patent licenses are regulated in Chapter 13 of the Act.\u003c\/p\u003e\n\u003cp\u003eAccording to Chapter 13, Section 2, a licensee may assign or sublicense their patent license only if the patent holder has consented. Appendix 4 therefore contains an explicit choice regarding sublicensing and assignment when patents are included.\u003c\/p\u003e\n\u003cp\u003eA patent license may, upon request, be recorded in the patent register. The package also serves as a reminder regarding patent annual fees, registration maintenance, and who controls infringement proceedings.\u003c\/p\u003e\n\n\u003ch3\u003eKnow-how and trade secrets\u003c\/h3\u003e\n\u003cp\u003eKnow-how is often a central part of commercial technology licenses but is not the same as a registered exclusive right. Protection is dependent on the information actually being treated as secret and worthy of protection.\u003c\/p\u003e\n\u003cp\u003eAppendix 9 therefore contains fields for:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003edescription of know-how,\u003c\/li\u003e\n\n\u003cli\u003eauthorized recipients,\u003c\/li\u003e\n\n\u003cli\u003etechnical security measures,\u003c\/li\u003e\n\n\u003cli\u003econfidentiality after the agreement ends,\u003c\/li\u003e\n\n\u003cli\u003ereturn and deletion.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eImprovements and further development\u003c\/h3\u003e\n\u003cp\u003eAppendix 10 is used to determine who owns:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003ethe Licensor's improvements,\u003c\/li\u003e\n\n\u003cli\u003ethe Licensee's improvements,\u003c\/li\u003e\n\n\u003cli\u003ejoint development,\u003c\/li\u003e\n\n\u003cli\u003ecustomer-specific adaptations,\u003c\/li\u003e\n\n\u003cli\u003enew registerable IP rights.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\u003cp\u003eIt is also possible to document any grant-back, but this should be checked under competition law before use.\u003c\/p\u003e\n\n\u003ch3\u003eNew TTBER 2026 – important update\u003c\/h3\u003e\n\u003cp\u003eThe European Commission's new \u003cstrong\u003eRegulation (EU) 2026\/877 on technology transfer agreements\u003c\/strong\u003e entered into force on \u003cstrong\u003eMay 1, 2026\u003c\/strong\u003e, replacing the previous Regulation 316\/2014.\u003c\/p\u003e\n\u003cp\u003eThe block exemption provides a competition law safe harbor for certain technology licenses when the conditions are met. For agreements between competing companies, the market share threshold is normally \u003cstrong\u003e20% combined\u003c\/strong\u003e. For parties that are not competitors, the threshold is normally \u003cstrong\u003e30% for each party\u003c\/strong\u003e.\u003c\/p\u003e\n\u003cp\u003eThis does not mean that a license agreement above these levels is automatically prohibited, but it cannot rely on the same automatic block exemption and must then be assessed individually.\u003c\/p\u003e\n\u003cp\u003eTherefore, the template does not automatically contain far-reaching territorial restrictions, price fixing, or exclusive grant-back clauses without specific review.\u003c\/p\u003e\n\n\u003ch3\u003eTransitional rule until April 30, 2027\u003c\/h3\u003e\n\u003cp\u003eFor agreements that were already in force on April 30, 2026, and which met the conditions of the previous TTBER regulation, there is a transition period until \u003cstrong\u003eApril 30, 2027\u003c\/strong\u003e, according to the new regulation.\u003c\/p\u003e\n\u003cp\u003eThis makes the 2026\/2027 version particularly relevant for companies that are both entering into new license agreements and updating older technology licenses.\u003c\/p\u003e\n\n\u003ch3\u003eInfringement and third-party claims\u003c\/h3\u003e\n\u003cp\u003eAppendix 11 regulates who:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003epays renewal and annual fees,\u003c\/li\u003e\n\n\u003cli\u003ereceives infringement notices,\u003c\/li\u003e\n\n\u003cli\u003edecides on legal action,\u003c\/li\u003e\n\n\u003cli\u003econtrols settlements,\u003c\/li\u003e\n\n\u003cli\u003ebears the costs,\u003c\/li\u003e\n\n\u003cli\u003ehas the right to any damages or settlement compensation.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\u003cp\u003eThis is particularly important in an exclusive license where the Licensee's commercial value may depend on infringements actually being prosecuted.\u003c\/p\u003e\n\n\u003ch3\u003eLiability and IP warranties\u003c\/h3\u003e\n\u003cp\u003eThe agreement distinguishes between a warranty that the Licensor has the authority to grant the license and a much broader warranty that the IP right is completely risk-free or can never be attacked.\u003c\/p\u003e\n\u003cp\u003eThe template therefore avoids automatically providing an unlimited warranty of validity or non-infringement. Liability caps, carve-outs, and any indemnifications are filled in separately in Appendix 12.\u003c\/p\u003e\n\n\u003ch3\u003eGDPR and information security\u003c\/h3\u003e\n\u003cp\u003eIf the license involves the processing of personal data, the parties' GDPR roles must be assessed separately. If one party processes personal data on behalf of the other party, a separate data processing agreement normally needs to be entered into pursuant to Article 28 GDPR.\u003c\/p\u003e\n\n\u003ch3\u003eTermination of the agreement and sell-off\u003c\/h3\u003e\n\u003cp\u003eAppendix 12 regulates what happens when the license ends. The parties can specify:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003ewhether all use must cease immediately,\u003c\/li\u003e\n\n\u003cli\u003ewhether a limited sell-off period shall apply,\u003c\/li\u003e\n\n\u003cli\u003ewhat happens to inventory and licensed products,\u003c\/li\u003e\n\n\u003cli\u003ewhether data or documentation should be exported,\u003c\/li\u003e\n\n\u003cli\u003ewhether source code or escrow should be released,\u003c\/li\u003e\n\n\u003cli\u003ewhether support or transition assistance should continue for a period.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eEnglish License Agreement under Swedish law\u003c\/h3\u003e\n\u003cp\u003eThe English version contains the same legal structure and 12 schedules. It is intended for relationships where licensees, licensors, group functions, or advisors work in English but \u003cstrong\u003eSwedish substantive law\u003c\/strong\u003e is to apply.\u003c\/p\u003e\n\u003cp\u003eIt is therefore an English-language agreement governed by Swedish law – not a standard template according to British or US law.\u003c\/p\u003e\n\n\u003ch3\u003eDetailed user guide included\u003c\/h3\u003e\n\u003cp\u003eThe guide covers:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003ehow to identify the right type,\u003c\/li\u003e\n\n\u003cli\u003ethe difference between ownership and license,\u003c\/li\u003e\n\n\u003cli\u003eexclusive\/sole\/non-exclusive license,\u003c\/li\u003e\n\n\u003cli\u003eTTBER 2026\/877 and market share thresholds,\u003c\/li\u003e\n\n\u003cli\u003ethe software's mandatory user rights,\u003c\/li\u003e\n\n\u003cli\u003etrademark license and quality,\u003c\/li\u003e\n\n\u003cli\u003epatents and sublicensing,\u003c\/li\u003e\n\n\u003cli\u003eroyalties and audits,\u003c\/li\u003e\n\n\u003cli\u003eimprovements and new IP,\u003c\/li\u003e\n\n\u003cli\u003einfringement and rights maintenance,\u003c\/li\u003e\n\n\u003cli\u003efinal checklist before signing.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eReviewed for 2026\/2027\u003c\/h3\u003e\n\u003cp\u003eThe legal review is dated \u003cstrong\u003eOctober 4, 2026\u003c\/strong\u003e. The package has been checked against, among other things:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003eAct (1960:729) on Copyright in Literary and Artistic Works, including the rules on computer programs,\u003c\/li\u003e\n\n\u003cli\u003eTrademarks Act (2010:1877), especially Chapter 6 on licenses,\u003c\/li\u003e\n\n\u003cli\u003ePatents Act (2024:945), especially Chapter 13 on licenses,\u003c\/li\u003e\n\n\u003cli\u003eTrade Secrets Act (2018:558),\u003c\/li\u003e\n\n\u003cli\u003eCompetition Act (2008:579) and Article 101 TFEU,\u003c\/li\u003e\n\n\u003cli\u003eCommission Regulation (EU) 2026\/877 on technology transfer agreements,\u003c\/li\u003e\n\n\u003cli\u003eGeneral Data Protection Regulation (EU) 2016\/679 (GDPR),\u003c\/li\u003e\n\n\u003cli\u003eContracts Act (1915:218) regarding contracts and other legal transactions in the field of property law.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eFormat and delivery\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3 documents • 6 files • 37 pages • 12 appendices\/schedules\u003c\/strong\u003e\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eWord (DOCX)\u003c\/strong\u003e – fully editable.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003ePDF\u003c\/strong\u003e – for reference, printing, and layout control.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eSwedish + English main agreements\u003c\/strong\u003e.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eDigital delivery\u003c\/strong\u003e – no physical product is shipped.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eImportant\u003c\/h3\u003e\n\u003cp\u003eThe template package is a professional general contractual basis and does not replace individual intellectual property, competition law, tax, or data protection advice. Patent pools, FRAND\/standard-essential patents, complex open-source use, international tax\/royalty issues, large exclusive technology licenses, pharmaceuticals, life science, or very high IP values should be assessed separately.\u003c\/p\u003e\n","brand":"Svenska Dokumentmallar","offers":[{"title":"Default Title","offer_id":55594936893782,"sku":"LICENS-2026-2027","price":249.0,"currency_code":"SEK","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0827\/2373\/3846\/files\/licensavtal-2026-2027-hero.png?v=1791088375"},{"product_id":"gdpr-gallringspolicy-data-retention-2026-2027-svenska-english-retention-schedule-radering-excel","title":"GDPR Data Deletion Policy \u0026 Data Retention 2026\/2027 – Swedish + English | Retention Schedule, Erasure \u0026 Excel","description":"\n\u003cdiv id=\"om-dokumentmallen\"\u003e\n\n\u003ch2\u003eGDPR Data Deletion Policy \u0026amp; Data Retention 2026\/2027 – complete SV\/EN package with Word, PDF \u0026amp; Excel\u003c\/h2\u003e\n\n\u003cp\u003eA complete operational template package for companies and organizations that need to introduce, document, and actually comply with the \u003cstrong\u003eGDPR principle of storage limitation\u003c\/strong\u003e. The package helps the organization move from “we should delete data” to a controlled process with a retention schedule, deletion routines, legal holds, processor control, backup management, and measurable follow-up.\u003c\/p\u003e\n\n\u003cp\u003e\u003cstrong\u003e2-in-1 Swedish + English:\u003c\/strong\u003e seven templates are available in both languages and are delivered in both editable Word format and PDF. Also included is an advanced Excel register for ongoing management. In total, you get \u003cstrong\u003e14 document templates + 1 Excel register = 29 delivery files\u003c\/strong\u003e.\u003c\/p\u003e\n\n\n\u003cnav aria-label=\"About the document template\" style=\"border:1px solid #dbe4ea;padding:16px;border-radius:10px;background:#f7fafc;margin:18px 0;\"\u003e\n\u003cstrong\u003eAbout the document template\u003c\/strong\u003e\n\u003cul\u003e\n\n\u003cli\u003e\u003ca href=\"#granskad\"\u003eLegally reviewed 2026\/2027\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#detta-ingar\"\u003eWhat is included in the package\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#byggd-for\"\u003eBuilt for actual deletion – not just a policy\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#lagringsminimering\"\u003eGDPR storage limitation\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#retention\"\u003eRetention Schedule and storage period assessment\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#radering\"\u003eDeletion, anonymization, and backup\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#legal-hold\"\u003eLegal hold and legal claims\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#bitraden\"\u003eSystems and data processors\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#excel\"\u003eExcel register and Dashboard\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#faq\"\u003eFrequently asked questions\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#kallor\"\u003eLegal basis and sources\u003c\/a\u003e\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003c\/nav\u003e\n\n\u003cdiv id=\"granskad\" style=\"border:1px solid #b7dec5;background:#e9f6ee;padding:18px;border-radius:10px;margin:18px 0;\"\u003e\n\n\u003cstrong\u003eLegally reviewed: October 6, 2026\u003c\/strong\u003e\u003cbr\u003e\nThe package has been reviewed against the General Data Protection Regulation (EU) 2016\/679, the Swedish Authority for Privacy Protection (IMY) current guidance on storage limitation and deletion, as well as relevant Swedish retention rules, including the Accounting Act and the Statute of Limitations Act. The templates are designed for use during \u003cstrong\u003e2026\/2027\u003c\/strong\u003e.\n\n\u003c\/div\u003e\n\n\n\u003ch2 id=\"detta-ingar\"\u003eWhat is included in the package\u003c\/h2\u003e\n\n\u003cdiv style=\"overflow-x:auto;\"\u003e\n\n\u003ctable style=\"width:100%;border-collapse:collapse;\"\u003e\n\n\u003cthead\u003e\u003ctr\u003e\n\n\u003cth style=\"text-align:left;border:1px solid #d5dde3;padding:10px;background:#15324b;color:#fff;\"\u003eTemplate\u003c\/th\u003e\n\n\u003cth style=\"text-align:left;border:1px solid #d5dde3;padding:10px;background:#15324b;color:#fff;\"\u003eSV\u003c\/th\u003e\n\n\u003cth style=\"text-align:left;border:1px solid #d5dde3;padding:10px;background:#15324b;color:#fff;\"\u003eEN\u003c\/th\u003e\n\n\u003cth style=\"text-align:left;border:1px solid #d5dde3;padding:10px;background:#15324b;color:#fff;\"\u003eUsage\u003c\/th\u003e\n\n\n\u003c\/tr\u003e\u003c\/thead\u003e\n\n\u003ctbody\u003e\n\n\u003ctr\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eCompliance Plan\u003c\/strong\u003e\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eWord\/PDF\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eWord\/PDF\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eRoles, inventory, decision model, and implementation.\u003c\/td\u003e\n\n\n\u003c\/tr\u003e\n\n\u003ctr\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eRetention Policy\u003c\/strong\u003e\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eWord\/PDF\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eWord\/PDF\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eGoverning rules for storage, deletion, anonymization, and exemptions.\u003c\/td\u003e\n\n\n\u003c\/tr\u003e\n\n\u003ctr\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eRetention Schedule\u003c\/strong\u003e\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eWord\/PDF\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eWord\/PDF\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eJustify storage time per processing, trigger, and legal basis.\u003c\/td\u003e\n\n\n\u003c\/tr\u003e\n\n\u003ctr\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eDeletion \u0026amp; Anonymization Routine\u003c\/strong\u003e\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eWord\/PDF\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eWord\/PDF\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eOperational deletion, deletion log, verification, and backup.\u003c\/td\u003e\n\n\n\u003c\/tr\u003e\n\n\u003ctr\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eLegal Hold \u0026amp; Deletion Exemptions\u003c\/strong\u003e\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eWord\/PDF\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eWord\/PDF\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eDefined exemptions for legal claims, investigations, and audits.\u003c\/td\u003e\n\n\n\u003c\/tr\u003e\n\n\u003ctr\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eSystem, Processor \u0026amp; Backup Control\u003c\/strong\u003e\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eWord\/PDF\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eWord\/PDF\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eSaaS, subprocessors, soft delete, cache, backup, and deletion evidence.\u003c\/td\u003e\n\n\n\u003c\/tr\u003e\n\n\u003ctr\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eDetailed User Guide\u003c\/strong\u003e\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eWord\/PDF\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eWord\/PDF\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eStep-by-step from inventory to verified deletion.\u003c\/td\u003e\n\n\n\u003c\/tr\u003e\n\n\u003ctr\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eGDPR Data Retention Register\u003c\/strong\u003e\u003c\/td\u003e\n\n\u003ctd colspan=\"2\" style=\"border:1px solid #d5dde3;padding:10px;\"\u003eExcel (XLSX)\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eDashboard + operational registers with formulas and follow-up.\u003c\/td\u003e\n\n\n\u003c\/tr\u003e\n\n\n\u003c\/tbody\u003e\n\n\n\u003c\/table\u003e\n\n\n\u003c\/div\u003e\n\n\n\u003cdiv id=\"byggd-for\" style=\"background:#fff4cc;border-left:5px solid #d9a800;padding:20px;border-radius:8px;margin:22px 0;\"\u003e\n\n\u003cstrong style=\"font-size:1.1em;\"\u003eBuilt for actual deletion – not just a policy\u003c\/strong\u003e\u003cbr\u003e\nMany organizations have a statement about “personal data being stored as long as necessary” but lack the connection between purpose, storage time, system settings, and actual deletion. This package ties together the \u003cstrong\u003elaw, retention schedule, technical systems, data processors, backup, and proof of completed deletion\u003c\/strong\u003e.\n\n\u003c\/div\u003e\n\n\n\u003ch2 id=\"lagringsminimering\"\u003eGDPR principle of storage limitation\u003c\/h2\u003e\n\n\u003cp\u003eArticle 5.1(e) of the GDPR means that personal data must not be kept in a form which permits identification of data subjects for longer than is necessary for the purposes for which the personal data are processed. When the data is no longer needed, it must, as a general rule, be deleted or de-identified.\u003c\/p\u003e\n\n\u003cp\u003eThe IMY emphasizes that organizations should determine how long different personal data may be stored and have functioning routines for deletion, for example through regular checks or automated deletion.\u003c\/p\u003e\n\n\n\u003ch3\u003eThere is no general “save everything for X years” rule\u003c\/h3\u003e\n\n\u003cp\u003eA central part of the package is therefore a \u003cstrong\u003eretention assessment\u003c\/strong\u003e. Each storage period is linked to a clear purpose, legal basis, retention trigger, and a justification of why that specific time is necessary. Where there are specific legal requirements, they are documented separately.\u003c\/p\u003e\n\n\n\u003ch2 id=\"retention\"\u003eRetention Schedule – connecting law to real systems\u003c\/h2\u003e\n\n\u003cp\u003eThe Retention Schedule template helps the business to document, among other things:\u003c\/p\u003e\n\n\u003cul\u003e\n\n\u003cli\u003eprocessing and purpose,\u003c\/li\u003e\n\n\u003cli\u003elegal basis,\u003c\/li\u003e\n\n\u003cli\u003edata subjects and data categories,\u003c\/li\u003e\n\n\u003cli\u003esystems and data processors,\u003c\/li\u003e\n\n\u003cli\u003eretention trigger – e.g., end of contract, case closure, or latest activity,\u003c\/li\u003e\n\n\u003cli\u003estorage period or event-based rule,\u003c\/li\u003e\n\n\u003cli\u003enecessity assessment,\u003c\/li\u003e\n\n\u003cli\u003estatutory retention requirements,\u003c\/li\u003e\n\n\u003cli\u003elegal claims\/legal hold,\u003c\/li\u003e\n\n\u003cli\u003edeletion\/anonymization method,\u003c\/li\u003e\n\n\u003cli\u003ereview date and responsible party.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003eGDPR Article 30 also states that the record of processing activities shall, where possible, include the envisaged time limits for erasure of different categories of personal data.\u003c\/p\u003e\n\n\n\u003ch2 id=\"radering\"\u003eDeletion, anonymization, pseudonymization, and backup\u003c\/h2\u003e\n\n\u003cp\u003eThe package clearly distinguishes between several technically and legally different actions:\u003c\/p\u003e\n\n\u003cul\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eHard delete \/ purge\u003c\/strong\u003e – the data is deleted from the operational system.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eAnonymization\u003c\/strong\u003e – identification is removed in a way that makes re-identification not reasonably possible.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003ePseudonymization\u003c\/strong\u003e – reduces risk, but the data is still personal data and therefore does not count as final deletion.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eLifecycle\/TTL\u003c\/strong\u003e – automatic deletion of, for example, logs or object storage.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eBackup expiry\u003c\/strong\u003e – secure deletion through scheduled rotation instead of permanent parallel archiving.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\n\u003ch3\u003eBackup must not become a hidden permanent archive\u003c\/h3\u003e\n\n\u003cp\u003eThe system and backup control documents, among other things, the retention of the backup, whether granular deletion is possible, what happens during a restore, and how the organization ensures that previous deletion decisions are reapplied after a restore.\u003c\/p\u003e\n\n\n\u003ch2 id=\"legal-hold\"\u003eLegal hold and legal claims\u003c\/h2\u003e\n\n\u003cp\u003eIn certain situations, the organization may need to retain data longer in order to establish, exercise, or defend legal claims. The package therefore contains a separate legal hold template that requires a defined decision with affected individuals, systems, data categories, start date, and review date.\u003c\/p\u003e\n\n\u003cp\u003eThe Swedish Statute of Limitations Act generally has a ten-year limitation period for claims and normally three years for certain consumer claims. However, this does \u003cstrong\u003enot\u003c\/strong\u003e automatically mean that all personal data should be saved for ten or three years. Retention must still be necessary and proportionate for the specific claim.\u003c\/p\u003e\n\n\n\u003ch2\u003eAccounting – seven years does not mean all customer data\u003c\/h2\u003e\n\n\u003cp\u003eThe Accounting Act requires that accounting information be preserved until the end of the seventh year after the end of the calendar year in which the financial year ended. It is therefore important to distinguish between the actual accounting information and other operational customer data that is not covered by the same requirements.\u003c\/p\u003e\n\n\u003cp\u003eThe package's policy and retention schedule therefore have separate fields to document \u003cstrong\u003ewhat type of document or information is actually covered by the specific retention requirement\u003c\/strong\u003e.\u003c\/p\u003e\n\n\n\u003ch2\u003eHR and former employees\u003c\/h2\u003e\n\n\u003cp\u003eThe IMY emphasizes to employers that personal data about employees may only be stored as long as necessary for the purpose and that the employer needs to have established times and routines for deletion. When data must be retained due to, for example, legal requirements, access and authorization should be restricted.\u003c\/p\u003e\n\n\n\u003ch2 id=\"bitraden\"\u003eSystems and data processors\u003c\/h2\u003e\n\n\u003cp\u003eA well-written policy does not help if the SaaS platform cannot delete data. Therefore, the package includes a technical verification template for system owners and data processors with checks for:\u003c\/p\u003e\n\n\u003cul\u003e\n\n\u003cli\u003eindividual deletion,\u003c\/li\u003e\n\n\u003cli\u003eTTL\/lifecycle policies,\u003c\/li\u003e\n\n\u003cli\u003esoft delete,\u003c\/li\u003e\n\n\u003cli\u003esearch index and cache,\u003c\/li\u003e\n\n\u003cli\u003ebackup retention,\u003c\/li\u003e\n\n\u003cli\u003econtract termination,\u003c\/li\u003e\n\n\u003cli\u003esubprocessors,\u003c\/li\u003e\n\n\u003cli\u003edeletion certificate\/evidence,\u003c\/li\u003e\n\n\u003cli\u003erestore process and re-application of deletion.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\n\u003ch2 id=\"excel\"\u003eExcel register with Dashboard and automatic follow-up\u003c\/h2\u003e\n\n\u003cp\u003eThe included XLSX file is built for ongoing use and contains:\u003c\/p\u003e\n\n\u003cul\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eDashboard\u003c\/strong\u003e with KPIs for overdue deletion, legal holds, erasure requests, and system gaps,\u003c\/li\u003e\n\n\u003cli\u003eProcessing Register,\u003c\/li\u003e\n\n\u003cli\u003eRetention Schedule,\u003c\/li\u003e\n\n\u003cli\u003eDeletion Queue with automatic calculation of deletion dates,\u003c\/li\u003e\n\n\u003cli\u003eLegal Holds,\u003c\/li\u003e\n\n\u003cli\u003eErasure Requests with automatic response deadline,\u003c\/li\u003e\n\n\u003cli\u003eSystems \u0026amp; Processors,\u003c\/li\u003e\n\n\u003cli\u003eBackup \u0026amp; Archives,\u003c\/li\u003e\n\n\u003cli\u003eDeletion Log,\u003c\/li\u003e\n\n\u003cli\u003eEvidence Checklist and Sources.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\n\u003ch2 id=\"radering\"\u003eThe right to erasure and retention are not the same thing\u003c\/h2\u003e\n\n\u003cp\u003eArticle 17 of the GDPR provides a right to erasure in certain situations but also contains exceptions, for example when processing is necessary for compliance with a legal obligation or for the establishment, exercise, or defense of legal claims. The package's erasure request register therefore helps to distinguish between \u003cstrong\u003ethe data subject's request\u003c\/strong\u003e and the \u003cstrong\u003eorganization's regular deletion schedule\u003c\/strong\u003e.\u003c\/p\u003e\n\n\n\u003ch2 id=\"faq\"\u003eFrequently asked questions\u003c\/h2\u003e\n\n\u003ch3\u003eIs there a general GDPR rule that personal data must be saved for, for example, two or five years?\u003c\/h3\u003e\n\n\u003cp\u003eNo. As a general rule, the storage period must be derived from the purpose, necessity, and legal basis. Specific legislation may, however, require that certain information or documents be preserved for a certain time.\u003c\/p\u003e\n\n\n\u003ch3\u003eShould all customer information be saved for seven years due to the Accounting Act?\u003c\/h3\u003e\n\n\u003cp\u003eNo. The Accounting Act's retention requirements apply to accounting information. Other customer information must be assessed based on its own purpose and legal basis.\u003c\/p\u003e\n\n\n\u003ch3\u003eIs pseudonymization the same thing as deletion?\u003c\/h3\u003e\n\n\u003cp\u003eNo. Pseudonymized data is usually still personal data. Pseudonymization can reduce risk but does not replace final deletion when the retention period has expired.\u003c\/p\u003e\n\n\n\u003ch3\u003eHow should backup be handled?\u003c\/h3\u003e\n\n\u003cp\u003eBackup needs a documented retention and rotation model. It is also important to define what happens if an older backup is restored so that previously deleted personal data is not permanently reintroduced.\u003c\/p\u003e\n\n\n\u003ch3\u003eCan we stop deletion in the event of a dispute?\u003c\/h3\u003e\n\n\u003cp\u003eYes, in some cases a defined legal hold may be justified. It should be documented, proportionate, and reviewed regularly.\u003c\/p\u003e\n\n\n\u003ch3\u003eAre English documents included?\u003c\/h3\u003e\n\n\u003cp\u003eYes. All seven templates are available in a separate English version within a Swedish\/EU legal context.\u003c\/p\u003e\n\n\n\u003ch3\u003eIs Excel included?\u003c\/h3\u003e\n\n\u003cp\u003eYes. This is one of the products where Excel is central to operational management and follow-up.\u003c\/p\u003e\n\n\n\u003ch2\u003eFormat and delivery\u003c\/h2\u003e\n\n\u003cul\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003e14 document templates\u003c\/strong\u003e – 7 Swedish + 7 English.\u003c\/li\u003e\n\n\u003cli\u003e\u003cstrong\u003e14 DOCX + 14 PDF + 1 XLSX = 29 files.\u003c\/strong\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003cstrong\u003e28 A4 pages per Word\/PDF format series across SV+EN.\u003c\/strong\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003cstrong\u003eDigital product – no physical item will be sent.\u003c\/strong\u003e\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\n\u003ch2 id=\"kallor\"\u003eLegal basis and authority sources\u003c\/h2\u003e\n\n\u003cul\u003e\n\n\u003cli\u003e\u003ca href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN-SV\/TXT\/?uri=CELEX:32016R0679\"\u003eGeneral Data Protection Regulation (EU) 2016\/679 – specifically Articles 5, 13, 14, 17, and 30\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"https:\/\/www.imy.se\/vanliga-fragor-och-svar\/hur-lange-far-vi-spara-uppgifter\/\"\u003eIMY – How long may we store personal data?\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"https:\/\/www.imy.se\/verksamhet\/dataskydd\/det-har-galler-enligt-gdpr\/grundlaggande-principer\/\"\u003eIMY – Basic principles under the GDPR\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"https:\/\/www.riksdagen.se\/sv\/dokument-och-lagar\/dokument\/svensk-forfattningssamling\/bokforingslag-19991078_sfs-1999-1078\/\"\u003eAccounting Act (1999:1078)\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"https:\/\/data.riksdagen.se\/dokument\/sfs-1981-130.html\"\u003eStatute of Limitations Act (1981:130)\u003c\/a\u003e\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\n\u003cdiv style=\"background:#f3f5f7;border:1px solid #d5dde3;padding:16px;border-radius:8px;margin-top:20px;\"\u003e\n\n\u003cstrong\u003eImportant:\u003c\/strong\u003e The template package is a general compliance tool. Organizations with specific archival, medical record, supervisory, labor law, or sector-specific regulations need to supplement the retention schedule with the rules that apply to their specific operations.\n\n\u003c\/div\u003e\n\n\n\u003c\/div\u003e","brand":"Svenska Dokumentmallar","offers":[{"title":"Default Title","offer_id":55615364661590,"sku":"GDPR-RETENTION-GALLRING-2026-2027","price":149.0,"currency_code":"SEK","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0827\/2373\/3846\/files\/gdpr-gallring-data-retention-2026-2027.png?v=1791247029"},{"product_id":"dsa-marketplace-compliance-2026-2027-svenska-english-kybc-notice-action-artikel-31-32-word-pdf-excel","title":"DSA Marketplace Compliance 2026\/2027 – Swedish + English | KYBC, Notice \u0026 Action, Articles 31–32 Word\/PDF\/Excel","description":"\n\u003cdiv id=\"om-dokumentmallen\"\u003e\n\n\u003ch2\u003eDSA Marketplace Compliance 2026\/2027 – complete 2-in-1 package in Swedish + English\u003c\/h2\u003e\n\n\u003cp\u003eThis is a complete compliance package for \u003cstrong\u003eonline marketplaces and digital platforms\u003c\/strong\u003e that need to work in a structured manner with the EU's \u003cstrong\u003eDigital Services Act (DSA), Regulation (EU) 2022\/2065\u003c\/strong\u003e. The package is specifically designed for platforms that enable consumers in the EU to enter into distance contracts with traders.\u003c\/p\u003e\n\n\u003cp\u003eThe package combines legal application assessment, \u003cstrong\u003etrader traceability\/KYBC\u003c\/strong\u003e, notice-and-action, statements of reasons, internal complaint handling, compliance-by-design, listing-audit, consumer information pursuant to Article 32, and an operational Excel register.\u003c\/p\u003e\n\n\u003cp\u003e\u003cstrong\u003e2-in-1:\u003c\/strong\u003e all seven documents are available in Swedish and English. You receive \u003cstrong\u003e14 document templates, 28 Word\/PDF files + 1 Excel register = 29 delivery files in total\u003c\/strong\u003e.\u003c\/p\u003e\n\n\n\u003cnav aria-label=\"About the document template\" style=\"border:1px solid #dbe4ea;padding:16px;border-radius:10px;background:#f7fafc;margin:18px 0;\"\u003e\n\u003cstrong\u003eAbout the document template\u003c\/strong\u003e\n\u003cul\u003e\n\n\u003cli\u003e\u003ca href=\"#granskad\"\u003eLegally and operationally reviewed 2026\/2027\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#detta-ingar\"\u003eIncluded in the package\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#byggd-for\"\u003eBuilt for a complete DSA marketplace flow\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#scope\"\u003eWhich DSA rules apply to your platform?\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#artikel30\"\u003eArticle 30 – trader traceability\/KYBC\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#artikel16\"\u003eArticle 16–17 – notice \u0026amp; action and statement of reasons\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#artikel20\"\u003eArticle 20–21 – complaints and redress\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#artikel31\"\u003eArticle 31 – compliance by design\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#artikel32\"\u003eArticle 32 – illegal products\/services\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#excel\"\u003eThe Excel register\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#faq\"\u003eFrequently asked questions\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#kallor\"\u003eLegal basis and regulatory sources\u003c\/a\u003e\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003c\/nav\u003e\n\n\u003cdiv id=\"granskad\" style=\"border:1px solid #b7dec5;background:#e9f6ee;padding:18px;border-radius:10px;margin:18px 0;\"\u003e\n\n\u003cstrong\u003eLegally and operationally reviewed: October 6, 2026\u003c\/strong\u003e\u003cbr\u003e\nThe package has been reviewed against the current Digital Services Act, relevant EU guidance, and Swedish supervisory information from PTS. The DSA has been fully applied since \u003cstrong\u003eFebruary 17, 2024\u003c\/strong\u003e. The templates are designed for use during \u003cstrong\u003e2026\/2027\u003c\/strong\u003e, but actual obligations always depend on the type of service, company size, any exemptions, and whether the platform is a VLOP\/VLOSE.\n\n\u003c\/div\u003e\n\n\n\u003ch2 id=\"detta-ingar\"\u003eIncluded in the package\u003c\/h2\u003e\n\n\u003cdiv style=\"overflow-x:auto;\"\u003e\n\n\u003ctable style=\"width:100%;border-collapse:collapse;\"\u003e\n\n\u003cthead\u003e\u003ctr\u003e\n\n\u003cth style=\"text-align:left;border:1px solid #d5dde3;padding:10px;background:#15324b;color:#fff;\"\u003eDocument\u003c\/th\u003e\n\n\u003cth style=\"text-align:left;border:1px solid #d5dde3;padding:10px;background:#15324b;color:#fff;\"\u003eSwedish\u003c\/th\u003e\n\n\u003cth style=\"text-align:left;border:1px solid #d5dde3;padding:10px;background:#15324b;color:#fff;\"\u003eEnglish\u003c\/th\u003e\n\n\u003cth style=\"text-align:left;border:1px solid #d5dde3;padding:10px;background:#15324b;color:#fff;\"\u003ePurpose\u003c\/th\u003e\n\n\n\u003c\/tr\u003e\u003c\/thead\u003e\n\n\u003ctbody\u003e\n\n\u003ctr\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eCompliance Plan \u0026amp; Application Assessment\u003c\/strong\u003e\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eYes\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eYes\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eService classification, micro\/SME exemptions, VLOP status, responsibilities, and release gate.\u003c\/td\u003e\n\n\n\u003c\/tr\u003e\n\n\u003ctr\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eTrader Traceability \u0026amp; KYBC\u003c\/strong\u003e\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eYes\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eYes\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eArticle 30 onboarding, register check, ID, payment account, and self-certification.\u003c\/td\u003e\n\n\n\u003c\/tr\u003e\n\n\u003ctr\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eNotice \u0026amp; Action + Statement of Reasons\u003c\/strong\u003e\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eYes\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eYes\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eArticle 16–17: reporting illegal content, processing, moderation decisions, and justification.\u003c\/td\u003e\n\n\n\u003c\/tr\u003e\n\n\u003ctr\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eInternal Complaint Handling \u0026amp; Redress\u003c\/strong\u003e\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eYes\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eYes\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eArticle 20–21: six-month window, reconsideration, and out-of-court dispute settlement.\u003c\/td\u003e\n\n\n\u003c\/tr\u003e\n\n\u003ctr\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eCompliance by Design \u0026amp; Listing Audit\u003c\/strong\u003e\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eYes\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eYes\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eArticle 31: mandatory listing fields, pre-publish check, and random post-checks.\u003c\/td\u003e\n\n\n\u003c\/tr\u003e\n\n\u003ctr\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eIllegal Product\/Service – Consumer Information\u003c\/strong\u003e\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eYes\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eYes\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eArticle 32: six-month purchase window, direct information, public notice, and redress.\u003c\/td\u003e\n\n\n\u003c\/tr\u003e\n\n\u003ctr\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eDetailed User Guide\u003c\/strong\u003e\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eYes\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eYes\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eStep-by-step from scope assessment to operational drift and supervisory evidence.\u003c\/td\u003e\n\n\n\u003c\/tr\u003e\n\n\u003ctr\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eDSA Marketplace Compliance Register.xlsx\u003c\/strong\u003e\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\" colspan=\"2\"\u003eCommon operational register\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eDashboard, traders, notices, moderation, complaints, listing audit, article 32, and evidence.\u003c\/td\u003e\n\n\n\u003c\/tr\u003e\n\n\n\u003c\/tbody\u003e\n\n\n\u003c\/table\u003e\n\n\n\u003c\/div\u003e\n\n\n\u003cdiv id=\"byggd-for\" style=\"background:#fff4cc;border-left:5px solid #d9a800;padding:20px;border-radius:8px;margin:22px 0;\"\u003e\n\n\u003cstrong style=\"font-size:1.1em;\"\u003eBuilt for a complete DSA marketplace flow\u003c\/strong\u003e\u003cbr\u003e\nThe DSA is layered. An online marketplace can simultaneously be a \u003cstrong\u003ehosting service, online platform, and marketplace\u003c\/strong\u003e. Therefore, a single “DSA policy” is not enough. The package links together \u003cstrong\u003escope assessment, trader onboarding, illegal-content notices, moderation decisions, complaints, listing-compliance, product checks, and consumer information\u003c\/strong\u003e in the same operational model.\n\n\u003c\/div\u003e\n\n\n\u003ch2 id=\"scope\"\u003eWhich DSA rules apply to your platform?\u003c\/h2\u003e\n\n\u003cp\u003eThe DSA applies to intermediary services offered to recipients in the EU. The exact level of obligation depends on the type of service the platform provides.\u003c\/p\u003e\n\n\u003cul\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eHosting services\u003c\/strong\u003e are covered by, among other things, notice-and-action under Article 16 and statements of reasons under Article 17.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eOnline platforms\u003c\/strong\u003e are covered by additional rules, but Article 19 contains an important exemption for micro and small enterprises, except when the platform is designated as a VLOP.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eOnline marketplaces\u003c\/strong\u003e that allow consumers to enter into distance contracts with traders are covered by Articles 30–32 when these rules are applicable. Article 29 contains a separate micro\/SME exemption, also with exceptions for VLOPs.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003eThe compliance plan therefore contains a specific classification matrix so that the business does not activate the wrong requirements or miss obligations that apply despite the SME exemption.\u003c\/p\u003e\n\n\n\u003ch2 id=\"artikel30\"\u003eArticle 30 – trader traceability and KYBC\u003c\/h2\u003e\n\n\u003cp\u003eArticle 30 requires that an online marketplace, when the provision applies, collects specific information about the trader \u003cstrong\u003ebefore\u003c\/strong\u003e they are allowed to use the platform to offer products or services to consumers in the EU.\u003c\/p\u003e\n\n\u003cp\u003eThe package contains fields and control steps for, among other things:\u003c\/p\u003e\n\n\u003cul\u003e\n\n\u003cli\u003ename, address, phone number, and email,\u003c\/li\u003e\n\n\u003cli\u003eID document or relevant electronic identification,\u003c\/li\u003e\n\n\u003cli\u003epayment account details,\u003c\/li\u003e\n\n\u003cli\u003etrade register\/public register and registration number,\u003c\/li\u003e\n\n\u003cli\u003ethe trader's self-declaration to only offer products\/services that comply with applicable EU law,\u003c\/li\u003e\n\n\u003cli\u003everification against official databases and reliable documents,\u003c\/li\u003e\n\n\u003cli\u003emismatch, correction requests, restrictions, and onboarding decisions.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003eArticle 30(7) is handled separately: the information that must be displayed publicly must be made clear, easily accessible, and understandable, at least on the page where the product\/service information is displayed.\u003c\/p\u003e\n\n\n\u003ch2 id=\"artikel16\"\u003eArticle 16–17 – notice \u0026amp; action and statement of reasons\u003c\/h2\u003e\n\n\u003cp\u003eHosting services must provide an electronic and user-friendly mechanism where individuals and organizations can notify specific information they consider to be illegal. The package structures this notification so that, for example, exact URL, legal justification, the notifier's contact details, and a good-faith statement can be documented.\u003c\/p\u003e\n\n\u003cp\u003eThe workflow then continues with assessment, decision, and \u003cstrong\u003estatement of reasons\u003c\/strong\u003e. The templates capture, among other things:\u003c\/p\u003e\n\n\u003cul\u003e\n\n\u003cli\u003ethe restriction taken,\u003c\/li\u003e\n\n\u003cli\u003eterritorial scope and duration,\u003c\/li\u003e\n\n\u003cli\u003ethe facts and circumstances the decision is based on,\u003c\/li\u003e\n\n\u003cli\u003elegal or contractual basis,\u003c\/li\u003e\n\n\u003cli\u003ewhether automated means have been used,\u003c\/li\u003e\n\n\u003cli\u003eavailable opportunities for reconsideration and redress.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003eFor online platforms covered by Article 24(5), the package also includes a check of whether the statement of reasons should be submitted to the European Commission's \u003cstrong\u003eDSA Transparency Database\u003c\/strong\u003e.\u003c\/p\u003e\n\n\n\u003ch2 id=\"artikel20\"\u003eArticle 20–21 – internal complaints and redress\u003c\/h2\u003e\n\n\u003cp\u003eWhen Article 20 applies, affected users and certain reporters must have access to an effective, electronic, and cost-free internal complaint system for at least \u003cstrong\u003esix months\u003c\/strong\u003e from the relevant decision.\u003c\/p\u003e\n\n\u003cp\u003eThe template therefore automatically includes six-month windows in the Excel register and a reconsideration checklist for, among other things, new information, proportionality, risk of discrimination, automation, and decisions to uphold, modify, or overturn the previous action.\u003c\/p\u003e\n\n\u003cp\u003eThe decision must also inform about available out-of-court dispute settlement pursuant to Article 21 and other avenues for redress.\u003c\/p\u003e\n\n\n\u003ch2 id=\"artikel31\"\u003eArticle 31 – compliance by design\u003c\/h2\u003e\n\n\u003cp\u003eFor online marketplaces covered by Article 31, the interface must be designed so that traders can provide necessary information about, for example, product\/service, trader, economic operator, and relevant labeling or safety information.\u003c\/p\u003e\n\n\u003cp\u003eThe package includes a concrete listing audit for:\u003c\/p\u003e\n\n\u003cul\u003e\n\n\u003cli\u003emandatory publication fields,\u003c\/li\u003e\n\n\u003cli\u003epre-publish completeness check,\u003c\/li\u003e\n\n\u003cli\u003eproduct\/service identification and images,\u003c\/li\u003e\n\n\u003cli\u003eeconomic operator and contact details,\u003c\/li\u003e\n\n\u003cli\u003elabeling and safety information,\u003c\/li\u003e\n\n\u003cli\u003erandom post-checks against official, freely available, and machine-readable databases.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003eFor consumer products, there is also a clear link to the GPSR so that DSA Article 31 and the product safety process can share control libraries without confusing the regulations.\u003c\/p\u003e\n\n\n\u003ch2 id=\"artikel32\"\u003eArticle 32 – when an illegal product or service has already been sold\u003c\/h2\u003e\n\n\u003cp\u003eWhen the marketplace becomes aware that a trader has offered an illegal product or service, it must, to the extent contact information is available, inform consumers who purchased it via the platform during the \u003cstrong\u003esix months\u003c\/strong\u003e preceding the knowledge.\u003c\/p\u003e\n\n\u003cp\u003eThe information must include:\u003c\/p\u003e\n\n\u003cul\u003e\n\n\u003cli\u003ethat the product or service is illegal,\u003c\/li\u003e\n\n\u003cli\u003ethe trader's identity,\u003c\/li\u003e\n\n\u003cli\u003erelevant opportunities for redress.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003eIf the platform lacks contact information for all affected consumers, corresponding information must be made public and easily accessible on the platform's interface. The package therefore contains both a direct-notice and public-notice log.\u003c\/p\u003e\n\n\n\u003ch2\u003eSwedish DSA supervision\u003c\/h2\u003e\n\n\u003cp\u003eThe \u003cstrong\u003eSwedish Post and Telecom Authority (PTS)\u003c\/strong\u003e is Sweden's Digital Services Coordinator. Supervision is shared between PTS, the Swedish Consumer Agency (Konsumentverket), and the Swedish Press and Broadcasting Authority, depending on the DSA provision. According to PTS, the Swedish Consumer Agency has, among other things, supervisory responsibility for Articles 31 and 32.\u003c\/p\u003e\n\n\u003cp\u003eThe user guide therefore helps the business document which competent authority is relevant in the specific case, rather than assuming that the same authority handles all DSA matters.\u003c\/p\u003e\n\n\n\u003ch2 id=\"excel\"\u003eDSA Marketplace Compliance Register – Excel\u003c\/h2\u003e\n\n\u003cp\u003eThe Excel file is intended as an operational system-of-record and contains:\u003c\/p\u003e\n\n\u003cul\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eDashboard\u003c\/strong\u003e – open traders, notices, decisions, complaints, and Article 32 cases.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eScope \u0026amp; Exemptions\u003c\/strong\u003e – service classification and Article 19\/29 exemptions.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eTrader Register\u003c\/strong\u003e and \u003cstrong\u003eTrader Verification\u003c\/strong\u003e.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eNotice \u0026amp; Action\u003c\/strong\u003e and \u003cstrong\u003eModeration Decisions\u003c\/strong\u003e.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eComplaints \u0026amp; Redress\u003c\/strong\u003e with automatic six-month windows.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eListing Audit\u003c\/strong\u003e for Article 31.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eIllegal Product Cases\u003c\/strong\u003e with automatic purchase cut-off six months back.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eTransparency Metrics\u003c\/strong\u003e for, among other things, notices, decisions, complaints, and statements of reasons.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eEvidence Checklist\u003c\/strong\u003e and \u003cstrong\u003eSources\u003c\/strong\u003e.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\n\u003ch2 id=\"faq\"\u003eFrequently asked questions about DSA Marketplace Compliance\u003c\/h2\u003e\n\n\u003ch3\u003eDoes the DSA apply to all marketplaces?\u003c\/h3\u003e\n\n\u003cp\u003eThe DSA fundamentally covers intermediary services offered to recipients in the EU, but the concrete obligations vary significantly depending on the type of service and size. Therefore, the package always starts with an application assessment.\u003c\/p\u003e\n\n\n\u003ch3\u003eAre small marketplaces exempt from everything?\u003c\/h3\u003e\n\n\u003cp\u003eNo. Article 19 and Article 29 contain specific exemptions for certain micro and small enterprises, but these apply to different sections. Hosting obligations such as notice-and-action under Article 16 and statements of reasons under Article 17 must be assessed separately.\u003c\/p\u003e\n\n\n\u003ch3\u003eWhat is KYBC in the DSA?\u003c\/h3\u003e\n\n\u003cp\u003eIt is the practical verification of the trader information required by Article 30 before a trader is allowed to sell via the marketplace, including identity, registry data, payment account, and self-certification.\u003c\/p\u003e\n\n\n\u003ch3\u003eMust the marketplace check that every product is legal?\u003c\/h3\u003e\n\n\u003cp\u003eArticle 31 does not require general monitoring or full product certification. The platform must, among other things, build an interface that enables correct information, make best efforts to verify that the information has been provided, and make reasonable random checks against relevant official databases.\u003c\/p\u003e\n\n\n\u003ch3\u003eHow long can a DSA complaint be submitted?\u003c\/h3\u003e\n\n\u003cp\u003eWhen Article 20 applies, the internal complaint system must be available for relevant complaints for at least six months from the decision in question.\u003c\/p\u003e\n\n\n\u003ch3\u003eWhat happens if an illegal product has already been sold?\u003c\/h3\u003e\n\n\u003cp\u003eArticle 32 requires specific information to affected consumers for purchases during the six months preceding the platform's knowledge, as well as public information when direct contact is not possible.\u003c\/p\u003e\n\n\n\u003ch3\u003eAre Swedish and English documents included?\u003c\/h3\u003e\n\n\u003cp\u003eYes. All seven documents are available in both Swedish and English versions.\u003c\/p\u003e\n\n\n\u003ch3\u003eIs Excel included?\u003c\/h3\u003e\n\n\u003cp\u003eYes. The Excel register is a central part of the package and contains practical registers, status fields, data validation, and automatic six-month calculations.\u003c\/p\u003e\n\n\n\u003ch2\u003eFormat and delivery\u003c\/h2\u003e\n\n\u003cul\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003e14 document templates\u003c\/strong\u003e – 7 Swedish + 7 English.\u003c\/li\u003e\n\n\u003cli\u003e\u003cstrong\u003e28 Word\/PDF files + 1 Excel register = 29 files total.\u003c\/strong\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003cstrong\u003eWord (DOCX) + PDF + Excel (XLSX).\u003c\/strong\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003cstrong\u003e28 A4 pages per Word\/PDF format series across Swedish + English.\u003c\/strong\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003cstrong\u003eDigital product – no physical goods are sent.\u003c\/strong\u003e\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\n\u003ch2 id=\"kallor\"\u003eLegal basis and regulatory sources\u003c\/h2\u003e\n\n\u003cul\u003e\n\n\u003cli\u003e\n\n\u003ca href=\"https:\/\/eur-lex.europa.eu\/eli\/reg\/2022\/2065\"\u003eRegulation (EU) 2022\/2065 – Digital Services Act\u003c\/a\u003e, especially Articles 14, 16–17, 19–21, 24, 29–32, 33, and 93.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003ca href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/digital-services-act\"\u003eEuropean Commission – Digital Services Act\u003c\/a\u003e.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003ca href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/dsa-notice-and-action-mechanism\"\u003eEuropean Commission – Notice \u0026amp; Action\u003c\/a\u003e.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003ca href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/faqs\/dsa-transparency-database-questions-and-answers\"\u003eEuropean Commission – DSA Transparency Database\u003c\/a\u003e.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003ca href=\"https:\/\/pts.se\/internet-och-telefoni\/dsa-forordningen---regler-om-digitala-tjanster-for-en-sakrare-onlinemiljo\/\"\u003ePTS – DSA Regulation\u003c\/a\u003e.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\n\u003cdiv style=\"background:#f3f5f7;border:1px solid #d5dde3;padding:16px;border-radius:8px;margin-top:20px;\"\u003e\n\n\u003cstrong\u003eImportant:\u003c\/strong\u003e The DSA is a complex layered regulatory framework. In cases of unclear service classification, micro\/SME exemptions, VLOP\/VLOSE status, regulatory orders, suspected criminal activity, systematic trader violations, or cross-border supervision, specialized legal advice should be sought.\n\n\u003c\/div\u003e\n\n\n\u003c\/div\u003e","brand":"Svenska Dokumentmallar","offers":[{"title":"Default Title","offer_id":55615403295062,"sku":"DSA-MARKETPLACE-COMPLIANCE-2026-2027","price":149.0,"currency_code":"SEK","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0827\/2373\/3846\/files\/dsa-marketplace-compliance-2026-2027.png?v=1791248315"}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0827\/2373\/3846\/collections\/saas-avtal-svensk-ratt-2026-word-pdf.png?v=1790501655","url":"https:\/\/mallbutiken.se\/en\/collections\/it-avtal-digitala-tjanster-mallar.oembed?page=2","provider":"Mallbutiken","version":"1.0","type":"link"}