This guide is informational. Always verify how the rules apply to your specific case.
In May 2026, Dagens Nyheter reported that a police officer in Skaraborg had for several years handed information from police records to a business owner. According to DN, the entrepreneur is working on the recovery of stolen cars taken abroad and since 2021 is supposed to have contacted the police privately with questions about vehicles and people. The questions are often sent to the police officer's private email, forwarded to the work email and subsequently led to searches in the police system
.It's important to start where the legal process is: the man is charged, not convicted in the current case. But the indictment, and the prosecution's description of how data should have been ordered, puts its finger on a larger issue. What happens when a public authority slips from government duty to private service?
What the indictment relates to
TV4 summarizes the indictment as 21 counts of aggravated data breach, 16 counts of data breach of normal degree and one case of gross breach of confidentiality. The 21 more serious cases, according to Chief Prosecutor Per Nichols, relate to beatings allegedly carried out at the behest of a car business owner, via phone calls, text messages or emails, in several sensitive police systems. The other 16 cases, according to the report, relate to private beatings around relatives.
DN reiterates that the indictment deals with classified information that must have been disclosed on 21 occasions, and that the police intelligence unit must have responded to anomalous patterns of beatings. According to the prosecutor, the breadth of the schemes and scope are central reasons why the acts are judged as aggravated. TV4 quotes Nichols as saying that information about whether a person could come to Sweden or was wanted is, according to him, sensitive data from the police record system and could constitute a gross breach of the
duty of confidentiality.The police officer has, according to DN, admitted to some searches but described them as a duty or service action. That very explanation is at the heart of the problem. Government records become dangerous when the person with authority begins to see the access as something that can be given to the caller with the right person, has the right relationship, or appears practically useful.
The legal floor: permission is not free access
The Supreme Court has already struck down the principle in NJA 2014 p. 221. A police superintendent made searches about himself in the police IT system. He had technical clearance, but the searches were not necessary for a job assignment. HD ruled that he should be convicted of computer hacking. The Court stressed that the punishable offence is the unlawful access itself: there is no need for any particular harm to occur or for the data to be
disseminated further.What matters is not whether the employee can log in. What matters is whether the beating is needed for an actual work task. Therefore, expressions such as “I only helped” or “it was a service action” become legally and democratically risky. They shift the line from law-guided exercise of authority to personal judgment.
Why the Entrepreneur Case Is More Than a Personnel Case
When a private actor gains access to government records through a personal relationship, multiple damages occur simultaneously. The first is the damage to the privacy of the person being sought on. The person often does not know that the search is taking place, cannot respond to it, and does not know how the task is used. The second is the harm of competition and power: a company can gain information advantages that other companies lack. The third is the damage to trust in the police, as any legitimate record-breaking becomes harder to defend when the system can
be suspected of leaking through informal channels.This is also why logs are more than internal IT administration. In the Skaraborg case, according to DN, it was the police intelligence unit that reacted to anomalous patterns. Without a functioning log check, the same behavior can continue until an affected person accidentally discovers something, or until the data has already had consequences outside
the authority.The same pattern is seen in social services
The problem is not limited to the police. The social services system contains data on children, sheltered accommodation, intimate partner violence, finances, substance abuse, health and family conflicts. There, too, broad authority, weak log tracking and curiosity can become a government intrusion
.Blendow Lexnova has reported on a social services employee who was convicted of 20 counts of computer hacking after unlawful beatings in the medical records of a woman and her children. The family had been up to date with social services, the woman had been staying in sheltered accommodation and logs showed that the employee had read the records even though she was not a competent caseworker. The Court of Appeal held that it must have been clear that she was not allowed to read in cases without reason
.In Österåker, the local newspaper Kanal described how a social secretary was dismissed and reported to the police after reading more than 6,000 pages from the files of more than 200 people. According to the municipality's investigation, the material included medical records, medical certificates and protective assessments from areas such as intimate partner violence and children and young people. Social Services made the IVO notification, started the Lex Sarah investigation and suspended the social worker during the investigation.
There is a clear legal parallel. Section 10 of the Act (2001:454) on the processing of personal data in social services requires that access is limited to what each person needs for their duties, that access is documented and can be controlled, and that systematic and periodic checks are made on unauthorized access. The rule is not cosmetic. It is the answer to the very kind of snooping that is otherwise difficult for the individual to detect
.The Difficult Situation of the Individual
For anyone who suspects that a police officer, social worker or other government employee has hit private schemes, the problem is practically difficult. You often don't know what system was used. You don't know if the logs are kept, how long they are kept, or which manager is reviewing them. In addition, you may encounter privacy arguments when you want to know what
has happened.But it is possible to work methodically. Request written notification of which logs exist, request records where the rules give the right to it, ask the authority to confirm whether unauthorized access has been investigated and ask for a record number for any incident report, Lex Sarah, IVO, IMY or police report. Our guides on requesting government documents, privacy against authorities and JO notification show you how you can keep track
.The real question: who controls the controller?
The Skaraborg case shows not only that an individual police officer can be suspected of crossing the border. It shows that authorities must be able to detect when authorization is used incorrectly, even when the user of the system is experienced, trusted and able to articulate their actions as helpful. The same goes for social services. When systems lack barriers or when sampling stops, public protection becomes dependent on the self-discipline of
the individual officer.Therefore, it is not enough for the authority to say that rules exist. The question is whether permissions are actually restricted, whether logs are actually audited, whether anomalous patterns actually lead to action, and whether the affected person is being told enough to be able to guard their entitlement. Otherwise, the registry power becomes asymmetric: the state sees the citizen, but the citizen cannot see when the state
looks back without reason.Sources
- Dagens Nyheter: Police shared secret data with business owners
- TV4: Police charged - sensitive data shared from police register
- Lidköpingsnytt: Police charged with 38 offences
- NJA 2014 p. 221
- Blendow Lexnova: Social Services Employee Sentenced for 20 Data Breaches
- Local newspaper Kanalen: Social secretary sacked — snooped on hundreds of cases
- Act (2001:454) on the Processing of Personal Data in Social Services




