Dataguiden, Vetenskapsrådet, startpage
Dataguiden, Vetenskapsrådet, startpage

More about the legal framework for research

Swedish research is governed by international conventions and laws as well as national legislation. Among other things, the regulations aim to ensure that people are not exposed to harm or unnecessary risks in research. Here is an in-depth description of the laws and regulations that apply to research.

Data protection in research

If the research involves processing of personal data, several provisions apply, which are primarily regulated in the EU General Data Protection Regulation (GDPR).

The regulation applies throughout the EU, but also to actors outside the Union who direct their services and products to EU residents. The aim is to create an uniform protection for personal data without hindering the free flow within the EU and the European Economic Area (EEA).

GDPR is supplemented by both EU rules and national legislation. In Sweden, this has been done through the Act (2018:218) containing supplementary provisions to the EU General Data Protection Regulation (the Data Protection Act) and just over 200 register legislation. There is no general register legislation regulating the processing of personal data in research.

Processing of personal data

The concepts of processing and personal data are central and determine whether data protection regulations apply.

Personal data means any information relating to an identified or identifiable natural person. This may include directly identifying details such as name or personal identification number, but also indirect information such as location data, online identifiers or attributes that describe the natural person's physical, physiological, genetic, mental, economic, cultural or social identity (Article 4.1 of the GDPR).

It is common for pseudonymised data to be used in research. Pseudonymisation means that personal data is processed in such manner that it can no longer be attributeded to a specific natural person without the use of a separate key or additional information. This information must be kept separately and subject to technical and organisational measures. Pseudonymised data is still considered personal data, but an assessment may be necessary in specific cases if the recipient of pseudonymised data processes personal data. Anonymous information is not personal data. It is information that does not relate to an identified or identifiable physical person, or personal data that has been anonymised so that the individual can no longer be identified.

In order to determine whether a person is identifiable, all reasonable means must be taken into account. The assessment of whether tools could reasonably be used to identify the individual must be made on the basis of objective factors, such as cost, time required for identification and the technology available, both at the time of processing and in light of technological developments. The requirements of the GDPR do not apply to anonymous information. Anonymous information can, for example, be statistics and results from a research study.

Certain types of personal data are considered to be particularly sensitive. Such data includes special categories of personal data and personal data related to criminal convictions and offences.

Special categories of personal data include, for example, data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership. It also includes genetic data and biometric data for the purpose of uniquely identifying a natural person, as well as data concerning health or data concerning a natural person's sex life and sexual orientation.

Personal data related to criminal convictions and offences refers to information about someone who has committed or been suspected of committing a crime, been convicted or acquitted in court, or been subject to so-called criminal procedural coercive measures.

Specific requirements apply to the processing of sensitive personal data and personal data related to criminal convictions and offences. If personal data is processed at any stage of the research, data protection rules must be followed.

Processing refers in principle to any type of handling of personal data, for example:

  • collection
  • registration
  • structuring
  • storage
  • processing or alteration
  • retrieval
  • reading
  • use
  • disclosure
  • dissemination or otherwise making available
  • alignment or combination
  • restriction
  • erasure or destruction.

Basic data protection rules

When personal data is to be processed within the framework of a research project, several data protection provisions must be taken into account before the data is collected.

If special categories of personal data or personal data related to criminal convictions and offences are to be processed, ethical review approval from the Swedish Ethical Review Authority is also required before the research may begin.

Basic principles for personal data handling

The basic principles apply to all processing of personal data (Article 5 of the GDPR). The principles mean, among other things, that:

  • the processing must have a specified, explicit and legitimate purpose (purpose limitation)
  • only adequate, relevant and limited to what is necessary data is processed (data minimisation)
  • data must not be kept for longer period of time than necessary (storage minimisation)
  • data must be processed in a manner that ensures appropriate security of the personal data using appropriate technical or organisational measures (integrity and confidentiality).
  • processing must be lawful, fair and in a transparent manner (lawfulness, fairness and transparency);
  • the controller, the personal data controller, must be able to demonstrate compliance with the basic principles (accountability).

Support in a legal basis

When personal data is processed, there must be support in one or more legal bases (Article 6 of GDPR). The legal bases relevant to the processing of personal data in research are ‘task carried out in the public interest’ or ‘the legitimate interests’ (Article 6.1 e and 6.1.f of the General Data Protection Regulation, respectively). Informed consent may also be a legal basis.

Consent means any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her (Article 4.11 of the General Data Protection Regulation).

The processing of personal data that includes special categories of personal data is, as a starting point, prohibited under the GDPR. However, there are several exceptions to the prohibition, one of which is the research exception. The processing of personal data related to criminal convictions and offences is also particularly restrictive under the GDPR.

Provisions concerning research are set out in the Ethical Review Act. This states that research involving special categories of personal data and personal data related to criminal convictions and offences requires ethical review. The preparatory work for the Ethical Review Act states that all research requiring ethical approval is a ‘task of general interest’ (Government Bill 2017/18:298, p. 54). It is the Swedish Ethical Review Authority's decision on ethical approval that authorises the processing of special categories of personal data and personal data related to criminal convictions and offences for research purposes.

Rights of data subjects

In research projects where personal data is processed, the rights of individuals must also be taken into account (Articles 12–22 of the GDPR). These include the right to:

  • information
  • access
  • rectification
  • erasure
  • restriction of processing
  • data portability
  • objection.

These rights are not absolute and usually apply in certain situations. There are also directly applicable exceptions to several of these rights that could be relevant to research, for example:

  • personal data does not need to be erased if this would make the purpose of the research impossible or difficult to achieve (Article 17.3 d of the General Data Protection Regulation)
  • information does not need to be provided to research subjects if it would involve a disproportionate effort or make it difficult for the research project in question to achieve its objectives (Article 14.5 b of the Data Protection Regulation).

Regulations concerning research

The Act (2024:1146) on certain research databases

The Act (2024:1146) on certain research databases applies to the processing of personal data in activities involving such research databases whose main purpose is to create a basis for several future projects that are of particular scientific value for research in a long-term perspective and which are carried out with the voluntary participation of the data subjects. A condition for the processing of personal data in such research databases is that the data subject has given their consent.

The Act also allows for the supplementary collection of data from sources other than those specified in connection with the consent to processing in the research database to take place without consent, but only if the data subject has been informed of the collection and does not expressly object to it. Currently, the LifeGene register and the Swedish Twin Register are covered by the Act.

Biobank Act

The Biobank Act (2023:38) regulates how human biological material may be collected, preserved in a biobank and used. The Act thus regulates, among other things, the processing of personal data in biobanks. The Act states that data in biobanks may be used for research. The use of biobank samples for research requires ethical review approval.

The Act contains provisions on informed consent and the right to object (Chapter 4, Sections 1 and 7 of the Biobank Act). Example:

  • Main rule: the sample donor must have given their consent for a sample to be collected and stored in a biobank, unless otherwise provided by the Biobank Act or other legislation.
  • As a general rule, consent to storage shall be deemed to include consent to use.
  • Consent is not required to collect, preserve and use a sample for the healthcare or treatment of the sample donor if the sample donor has been informed and has consented to healthcare or treatment in accordance with the Patient Act (2014:821) or the Dental Care Act (1985:125). The sample donor must also have been informed, among other things, of the purpose of collecting and storing the sample, the purpose of the sample collection and the permitted uses of the sample, the purposes allowed under the Biobank Act, and the right to withdraw or limit consent. Such a sample may also be stored for research, provided that the sample donor has not objected to such collection, storage or use.

If the new purpose relates to research, the Swedish Ethical Review Authority or the Ethics Review Appeals Board shall, in connection with the agency or board approving the new purpose, also decide on the requirements that shall apply in terms of information and consent for the samples in the biobank to be used for the new purpose (Chapter 4, Section 11 of the Biobank Act).

The Patient Data Act

The Patient Data Act (2008:355) regulates the processing of personal data by healthcare providers. The Act does not contain any specific provisions on the processing of personal data for research purposes or on the processing of personal data by healthcare providers for research purposes.

However, the preparatory work for the Patient Data Act states that processing of special personal data for research purposes falls outside the scope of the Act. It emphasises that patient-centred or clinical research conducted by healthcare providers is often integrated with patient care. However, research and patient care can constitute independent branches of activity in relation to each other. The preparatory work establishes that the processing of specific personal data resulting from patient-centred research should not be regulated by the Patient Data Act, which refers to documentation that is carried out solely for research purposes and has no significance for healthcare. However, the part of information management in patient-centred research that involves patient record-keeping or other documentation related to healthcare shall be regulated by the Patient Data Act. In cases where research is conducted in an integrated manner with patient care, the Patient Data Act will apply to the processing of personal data relating to care, for example in the case of documentation in the patient record (Government Bill 2007/08:126, pp. 48 and 203).

Feasibility counts

A new purpose has been added to the Patient Data Act, clarifying that healthcare providers may process personal data in order to perform feasibility counts for potential study participants (Chapter 2, Section 4, point 7 of the Patient Data Act and Government Bill 2022/23:31, p. 27).

National and regional quality registers

The Patient Data Act also regulates national and regional quality registers (Chapter 7 of the Patient Data Act). It states that data in such registers may be used for research, among other things. However, personal data may not be processed in a national or regional quality register if the natural person objects to this. If the natural person objects to the personal data handling after it has begun, the data must be deleted from the register as soon as possible.

Supervision

The Swedish Authority for Privacy Protection is responsible for supervision under the data protection regulations in Sweden. Anyone who acts in contravention of the data protection rules may be subject to penalties, including administrative fines.

Ethics in research

The ethical principles governing research have been established in international conventions and form the basis for current legislation. A key document is the Declaration of Helsinki, which was adopted by the World Medical Association (WMA) in 1964. The regulations aim to protect people from harm and unnecessary risks in research involving individuals or their data.

The Ethical Review Act

The Act (2003:460) on Ethical Review of Research Involving Humans regulates ethical review in Sweden (The Ethical Review Act).

The regulation primarily concerns balancing the societal benefit of research against the individual's right to personal integrity. The Ethical Review Act covers research defined in section 2:

scientific experimental or theoretical work or observational research studies, if the work or studies are carried out to acquire new knowledge, and/or development work on a scientific basis, but not such work or studies that are performed solely within the framework of higher education at basic or advanced level.

Research requires ethical review approval if it:

  1. involves physical intervention, on living and deceased persons alike
  2. is carried out with a method that aims to affect the research participant physically or mentally, or involves an obvious risk of harm to them in body or mind
  3. are performed on biological material from a living or deceased human being and can be traced back to that person
  4. involves processing of specific categories of personal data or of personal data relating to criminal offences.

The Swedish Ethical Review Authority decides on ethical review permits. Decisions by the Swedish Ethical Review Authority may be appealed to the Ethics Review Appeals Board (ÖNEP).

The Ethical Review Act contains provisions on informed consent for research that falls within the scope of points 1-3 above (sections 4 and 16-22 of the Ethical Review Act). The provisions on informed consent are mandatory for such research.

For studies on biological material that has previously been taken from a living human being, for example for healthcare purposes, there are special provisions on informed consent.

In the case of ethical review approval, the Swedish Ethical Review Authority shall determine the requirements that apply in terms of information and consent for the use of the material.

There are also special provisions on informed consent relating to the influence of children when guardians have given their consent to the research. Among other things, it states that despite the consent of the guardians, research may not be conducted if a research subject under the age of 15 understands what it means for him or her and objects to it being conducted. Young people between the ages of 15 and 18 give their own consent if they understand what the research means for them.

There are also special provisions on exemptions from informed consent for research involving research subjects who lack decision-making capacity.

The Ethical Review Act does not contain any direct provisions on informed consent for research that only involves the processing of sensitive personal data and personal data related to criminal convictions and offences.

In these cases, the Swedish Ethical Review Authority and the Ethics Review Appeals Board have the discretion to assess whether information and consent are required and, if so, to stipulate this as a condition in the ethical review permit.

The Ethical Review Act only applies to research conducted in Sweden (section 5). In the case of international research collaborations, ethical review is required for those parts of the research that are conducted in Sweden.

Is it research according to the Ethical Review Act?

It can sometimes be unclear whether a study is covered by the concept of research under the Ethical Review Act. For example:

Distinction from quality assurance

For the Ethical Review Act to be applicable, the work must be covered by the concept of research as defined in the Act. In most cases this is clear, but not always. For instance the distinction between what is research and what is quality assurance. It requires an overall assessment based on the nature of the project. One factor of importance for the assessment is whether there is an intention to disseminate the results externally or whether the purpose is internal. Another difference between research projects and quality assurance lies in the theoretical basis. Research analyses collected data based on a theory or hypothesis, something that does not occur in quality assurance. Quality assurance involves investigating whether an activity or product meets a predetermined (better) quality standard. Another difference between quality assurance and quantitative research is that quality assurance only uses simple descriptive statistics, while research projects almost always include an in-depth analysis of the results. The in-depth analysis part is typical of a research project and is strongly rooted in scientific theories about how the results are best analysed.

Student work

Student work at higher education at basic or advanced level is not covered by the concept of research in section 2 of the Ethical Review Act. This is because it is not reasonable to expect students to have acquired the knowledge and insights in the scope required to handle confidentiality and personal data in research (Government Bill 2007/08:44, p. 20).

This means that students should not be given responsibility for work that involves the processing of special categories of personal data or data on crimes and where there is a risk of harming individuals' privacy. The responsible institution shall ensure that student work is conducted in an ethically acceptable manner.

Penalties for inadequate compliance

Anyone who intentionally or through gross negligence conducts research without approval or violates the terms of an approval may be fined or given a custodial sentence.

The EU Regulation on Clinical Trials and the Regulation on Performance studies of Medical Devices

For clinical trials on medicinal products or clinical trials and performance studies of medical devices, there is an EU regulation together with supplementary national legislation. The legislation states that an ethical review must be carried out by an ethics committee in accordance with national law in the Member State concerned. In Sweden, the ethical review is conducted by the Swedish Ethical Review Authority and is regulated by law (2018:1091) with supplementary provisions on ethical review to the EU Regulation on clinical trials on medicinal products for human use. Among other things, the regulations require informed consent, which means that a trial subject must freely and voluntarily express their willingness to participate in a specific clinical trial after having been informed of all aspects of the clinical trial that are relevant to the trial subject's decision to participate or, if the trial subject is a minor or lacks decision-making capacity, permission or consent from the subject's legally appointed representative for the person to be included in the clinical trial.

Public access to information and secrecy in research

Researchers at public and private research principals may request information and documents for specific research projects from public data holders.

The principle of public access to official documents means that public documents, including personal data, may be requested by the general public for any purpose. In practice, however, there are restrictions.

Although public access is the main rule for public documents held by public agencies and other public actors equivalent to public agencies, such as municipal companies, data is usually covered by secrecy provisions under the Public Access to Information and Secrecy Act (OSL). A secrecy provision may be linked to a particular authority or a specific activity, and its stringency may vary, with some information being subject to absolute confidentiality, while other information is subject to reverse or direct damage requirements. In practice, this may mean that the same type of information has different secrecy provisions at different public agencies.

The possibility for private research principals to access documents

A precondition for a private research principal, such as a pharmaceutical company, to obtain information from, for example, an agency or a healthcare principal (region or municipality) is that the information requested is official documents under the Freedom of the Press Act. Sometimes, data needs to be processed in order to comply with a request for data for research purposes. If the agency's processing becomes too extensive, it is no longer considered an official document and is therefore not covered by the principle of public access to official documents.

Public agencies may access documents held by other public agencies

Public agencies cannot invoke the principle of public access to official documents to obtain documents from another public agency. Instead, a public agency must invoke the duty to provide information in Chapter 6, Section 5 of the Public Access to Information and Secrecy Act. This states that a public agency, at the request of another public agency, must provide information at its disposal, unless it is classified as secret or the disclosure would hinder the proper conduct of its work.

The obligation to provide information covers all information held by an agency, including information from documents that are not official (Government Bill 1979/80:2 Part A, pp. 89 and 361). This means that research public agencies are not subject to the restrictions in the Freedom of the Press Act when they request information for research purposes from another agency.

Secrecy of information in documents

Before a public agency discloses documents, it must assess whether the information is subject to a secrecy provision under the Public Access to Information and Secrecy Act (OSL). The strength of secrecy provision – direct harm requirement, reverse harm requirement and absolute secrecy – determines whether the information requested for research purposes may be disclosed. Direct harm requirement means that the starting point is public access, i.e. that the document can be disclosed. Reverse harm requirement means that the starting point is secrecy, and absolute secrecy means that the information may not be disclosed.

Commonly occurring secrecy provisions for data held by public data holders

Statistical secrecy

Statistical secrecy is a special form of secrecy regulated in Chapter 24, Section 8 of the OSL.

It applies to specific activities of a public agency relating to the production of statistics, as well as to comparable surveys by certain public agencies, and means that secrecy applies to information relating to an individual's personal or financial circumstances that can be attributed to that individual.

Information in several government registers, such as the National Board of Health and Welfare's health data register, the social services register, the cause of death register and information in registers held by Statistics Sweden (SCB) is covered by statistical secrecyy.

Despite statistical secrecy, information may be disclosed. This applies to information needed for research purposes. However, disclosure may only take place if it is clear that no person or related party is at risk of harm or damage (reverse damage requirement).

This exception allows researchers to access information covered by statistical secrecy for their research.

Secrecy for data in health care

Information in patient records and in Regional and National Quality Registers is covered by health care secrecy. This is a strong form of secrecy, with a so-called reverse harm requirement. Individual data may only be disclosed if it is clear that the data can be disclosed without causing harm to the individual or anyone close to them (Chapter 25, Section 1 of the Public Access to Information and Secrecy Act).

Secrecy under data protection regulations

Secrecymay also apply to a research principal under Chapter 21, Section 7 of the Public Access to Information and Secrecy Act. This provision means that personal data is classified as secrecy if it can be assumed that, after disclosure, it will be processed in contravention of the General Data Protection Regulation, the Data Protection Act (2018:218) or the Ethical Review Act.

Transfer of secrecy and secrecy exemptions in connection with research

Transfer of secrecy

The legislator has facilitated access to research data through a provision on the transfer of secrecy.

According to Chapter 11, Section 3 of the OSL, if a public agency, such as a public university, receives information covered by a secrecy provision from another public agency for its research project, the same secrecy provision applies at the receiving public agency as at the public agency that disclosed the information.

The fact that same secrecy provision accompanies the information is something that the disclosing authority takes into account in its assessment.

Secrecy relief

Secrecy relief means that secrecy provisions may be made less strict in certain situations, for example to facilitate research. Such relief is provided for in Chapter 25, Section 11, point 5 of the OSL.

Established practice regarding the disclosure of data for research

Court practice regarding the disclosure of data for research purposes is generous. This generous approach is based on a number of judgments from the Supreme Administrative Court of Sweden, RÅ 1988 ref. 103, RÅ 1994 not. 732 and RÅ 1996 not. 124. In these rulings, the court refers to preparatory work in which it is emphasised that information covered by secrecy provisions with a damage requirement – i.e. where a harm assessment is required – may often be disclosed for research purposes without any significant risk of harm.

Data held by research principals

When a research principal is subject to the Public Access to Information and Secrecy Act, the documents created, received or submitted by the organisation become official documents. This also applies to research data, such as digital texts, images, audio and video material, 3D scans, observations and experimental results. The Freedom of the Press Act contains provisions on the public's right to access official documents, known as the principle of public access to official documents. As a general rule, official documents must be disclosed upon request, provided that the document or the information in the document is not covered by a secrecy provision.

Other regulations governing research

In addition to data protection, ethical principles and secrecy rules, there are also other laws and regulations that apply to research. Some of these are mentioned below.

The Archives Act

The Archives Act (1990:782) contains provisions on the archives of public agencies and certain other bodies. According to Section 3, first paragraph, a public agency archive is formed from the official documents that arise in the agency's activities, as well as from the documents referred to in Chapter 2, Section 12 of the Freedom of the Press Act and which the agency decides should be taken care of for archiving.

The Act on Responsibility for Good Research Practice and Investigation of Misconduct in Research

The Act (2019:504) on Responsibility for Good Research Practice and Investigation of Misconduct in Research regulates both the researcher's and the research principal's responsibility for ensuring that research is conducted in accordance with good research practice. It also specifies how the investigation of suspected research misconduct should be conducted.

Open Data Act

The Act (2022:818) on the public sector's availability of data (the Open Data Act) contains rules on how public data can be shared and reused.

Publicerat den

Uppdaterat den