← ALL REGULATIONS

Cookie consent in Sweden, under LEK and GDPR.

Sweden requires consent before a site uses cookies that are not necessary, under chapter 9, section 28 of the Electronic Communications Act (LEK). PTS supervises the cookie rule and IMY the processing that follows, and PTS expects saying no to be as easy as saying yes.

LEK at a glanceOpt-in before tracking
Applies to
Sites that set cookies on the devices of people in Sweden
Cookie rule
LEK (2022:482), chapter 9, section 28
Enforced by
PTS for the cookie rule, IMY for GDPR
Largest related fine
SEK 37 million, Apoteket, IMY 2025
WHAT LEK REQUIRES

What PTS and IMY expect from a Swedish site.

THE RULEConsent before cookies, except necessary onesPTS requires an active, informed choice before any cookie that is not necessary, given separately for each purpose.
WITH KATLAIn GDPR mode, the cookie guard refuses every cookie outside the functional category until the visitor chooses, and deletes any that were set before it ran.
THE RULEAs easy to say no as yesPTS lists pre-ticked choices and cookie walls as invalid, and expects declining to take no more effort than accepting.
WITH KATLAAccept, Reject and Customise sit together on the first layer of the banner, and nothing is pre-selected.
THE RULEA way back to the choice on every pagePTS suggests a button or icon on every page, or a link in the footer, so a visitor can change their mind without searching for it.
WITH KATLAA floating settings icon, or your own "Cookie settings" link calling katla.open(), reopens the choice on any page.
THE RULEA working banner is not the whole jobIMY fined Apoteket SEK 37 million and Apohem SEK 8 million in 2025 after a Meta pixel feature sent customers’ purchases to Meta, while their consent banners worked as intended.
WITH KATLAKatla’s scan lists every cookie and the vendor behind it, so a new tag shows up in the inventory. It does not inspect what a tag sends in its network requests.

LEK questions, answered

A summary for website owners, not legal advice. Reviewed against the sources below.

Who supervises cookies in Sweden?
PTS, the Post and Telecom Authority, supervises the cookie rule in the Electronic Communications Act. IMY supervises the processing of personal data under the GDPR, which is where the largest Swedish fines have come from.
How common are non-compliant banners in Sweden?
Common. When Katla visited 3,705 Swedish e-commerce sites as a first-time visitor in 2026, about half had set non-essential cookies before the banner asked.
Is a cookie wall allowed in Sweden?
No. PTS says a site may not stop visitors who have not accepted cookies from using it.
Can the banner be in Swedish?
Yes. Katla’s banner and generated policies are available in Swedish, and Katla is a Swedish company.
RELATED REGULATIONS

See what your site sets before anyone asks.

The free plan scans your site, classifies every cookie and generates the policy, without a card. The cookie checker needs no account at all.

Get started free