Requesting records of a data breach
If an organisation has had a personal data breach that affects you, you can request the notification it sent to the Swedish Authority for Privacy Protection (IMY) and the decisions in the case. Insyna helps you write the request to the right authority.
- Legal basis
- Freedom of the Press Act, Chapter 2 (Tryckfrihetsförordningen 1949:105) · GDPR Articles 33–34 (personal data breaches)
- Response time
- Promptly
- Contact
- Registrar of the Swedish Authority for Privacy Protection (IMY)
When must a breach be reported?
Under the GDPR (Articles 33–34), an organisation must report serious personal data breaches to IMY, usually within 72 hours, and in some cases also inform the individuals affected. The notification and IMY’s subsequent decisions are generally official documents.
Some information may, however, be confidential — for example technical details that could reveal security weaknesses and lead to further breaches, or sensitive data about other people.
How Insyna helps you
Chydenius helps you write a request to IMY’s registrar for the notification, decisions and relevant correspondence in the supervisory case. You do not need to know the case reference number — it is enough to describe the organisation and incident you mean.
How to do it, step by step
Describe the incident
Tell Chydenius which authority or organisation you suspect leaked or mishandled your personal data.
We request the records
Chydenius drafts a request for the incident report and the notification to IMY, citing the correct legal basis.
Send and await a reply
The request is sent anonymously; public records must be released promptly.
Take it further
If you want to report the incident or demand rectification, Chydenius helps you with the next step towards IMY.
What you can request
- A data breach notification an organisation sent to IMY
- IMY decisions and opinions in a supervisory case about an incident
- Correspondence between IMY and the reporting organisation (subject to confidentiality)
What you cannot request
- Information that could reveal security weaknesses and risk new incidents
- Sensitive personal data about other individuals named in the notification
- Trade secrets or other information that could harm the company if disclosed
- Information that is part of an ongoing criminal investigation
Frequently asked questions
Can I get a company’s data breach notification?
Usually, yes. A notification to IMY is generally an official document. Parts that reveal security arrangements or sensitive data about others may be confidential.
Which authority do I turn to?
The Swedish Authority for Privacy Protection (IMY), which receives data breach notifications and carries out supervision. Insyna directs your request to IMY’s registrar.
Do I need to know the exact case number at IMY?
No. It is enough to describe the organisation and roughly when the incident occurred. IMY’s registrar can usually locate the notification and case from that description.
Will I be told if my own data was part of a breach?
The organisation that suffered the breach must notify affected individuals directly if the breach is likely to result in a high risk to their rights and freedoms — separately from any request you make for the documents themselves.
The email we send
This is the actual email Chydenius writes and sends to the authority for you — in correct Swedish, anonymously (never in your name), always asking for a reply by email. You don’t need to write Swedish yourself.
Bästa Handläggare, Jag önskar ta del av den anmälan om personuppgiftsincident som en av mina tidigare tjänsteleverantörer har lämnat till Integritetsskyddsmyndigheten, samt myndighetens beslut och yttranden i tillsynsärendet. Denna begäran grundar sig på offentlighetsprincipen enligt tryckfrihetsförordningen (1949:105) 2 kap. Jag önskar ta del av handlingarna digitalt (via e-post) i första hand. Vid helt eller delvis avslag begär jag ett skriftligt, överklagbart beslut med besvärshänvisning. I avvaktan på Ert svar, En Medborgare