> Sweden's whistleblower act: the 50-worker rule, Sweden's sectoral external-authority model, and the official Swedish sources.

Source: https://ethicsportal.eu/whistleblower-laws/sweden/
Updated: 2026-04-24

---

# Whistleblower law in Sweden

Sweden implemented Directive (EU) 2019/1937 through **Lag (2021:890) om skydd för personer som rapporterar om missförhållanden**, in force since **17 December 2021**. Sweden combines the standard **50-worker** trigger with a **sectoral external-authority model** and supervision of internal-channel obligations by the Swedish Work Environment Authority.

## Applicable law

- [Lag (2021:890) om skydd för personer som rapporterar om missförhållanden — official Riksdag text](https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/lag-2021890-om-skydd-for-personer-som_sfs-2021-890/)
- [Government English translation of the Act](https://www.government.se/government-policy/labour-law-and-work-environment/2021890-act-on-the-protection-of-persons-reporting-irregularities-2021890/)

## Who must establish an internal channel

Public and private organisations with **at least 50 workers** must establish internal reporting channels under the Swedish act.

## External reporting authority

Sweden does not rely on one universal whistleblowing authority. The [Ordinance (2021:949)](https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/forordning-2021949-om-skydd-for-personer-som_sfs-2021-949/) designates multiple competent external authorities depending on the sector. The [Swedish Work Environment Authority](https://www.av.se/en/about-us/contact-us/) also receives reports that an employer has failed to maintain internal channels and procedures.

## Data protection authority

For GDPR complaints relating to whistleblower data handling, the relevant authority is the [Swedish Authority for Privacy Protection (IMY)](https://www.imy.se/en/individuals/forms-and-e-services/file-a-gdpr-complaint/).

## Key compliance points

- Swedish law is structurally clear but operationally decentralised, so country-specific legal content matters more than generic "EU-compliant" messaging.
- Employers should tell users which external authority is relevant for the kind of breach being reported, not just that an "external authority" exists.
- The Work Environment Authority is the clearest official supervisory body if the issue is the employer's failure to operate a compliant internal channel.

## Official sources

- [Lag (2021:890) — official Riksdag text](https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/lag-2021890-om-skydd-for-personer-som_sfs-2021-890/)
- [Government — English translation of the Act](https://www.government.se/government-policy/labour-law-and-work-environment/2021890-act-on-the-protection-of-persons-reporting-irregularities-2021890/)
- [Ordinance (2021:949) — designated competent authorities](https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/forordning-2021949-om-skydd-for-personer-som_sfs-2021-949/)
- [Swedish Work Environment Authority — contact and internal-channel supervision](https://www.av.se/en/about-us/contact-us/)
- [IMY — file a GDPR complaint](https://www.imy.se/en/individuals/forms-and-e-services/file-a-gdpr-complaint/)

---

[Deploy your reporting channel →](/pricing/)
