Data protection · Knowledge hub

Sistec holds a permit from IMY to process data about criminal offences

The Swedish Authority for Privacy Protection (IMY) has granted Sistec AB a permit to process personal data about criminal offences in background checks. Here is what the permit covers and the conditions we work under.

Personal data about criminal offences, such as information about crimes and criminal convictions, has particularly strong protection under Article 10 of the General Data Protection Regulation (GDPR). Where no law or other statute provides for the processing, a private organisation may only process such data with a permit from IMY.

Sistec AB holds such a permit, reference number IMY-2026-3140. It covers the processing of personal data about criminal offences within the background check service Sistec provides to clients, and comes with conditions on who may be checked and which data may be recorded.

The decision is published in IMY’s list of companies permitted to process personal data about criminal offences to carry out background checks. The link is under Sources at the bottom of this page.

SCOPE

What the permit covers

  • Before an agreement. Checks on people before employment or an assignment, before agreements with customers or suppliers, and on representatives of legal entities before a company acquisition or an agreement.
  • When crime is suspected. Checks on existing employees, contracted consultants and representatives of legal entities the client already has a business relationship with, where there is suspicion of crime or other serious misconduct.
  • When duties change. Checks on existing employees or contracted consultants when they are given new duties or powers.
CONDITIONS

The conditions we work under

  • Only roles where it matters. We only check people in a position, assignment or equivalent where data about criminal offences could significantly affect the client’s reputation, security or finances – and candidates for such a position or assignment.
  • Verified and decisive. We only record data that has been verified and is decisive for the person’s suitability for the position or assignment, or for assessing suitability when entering into an agreement.
  • No outdated data. Data that is no longer relevant because of the time that has passed since the offence is not recorded – and never data that would have been removed from the Swedish criminal records register under sections 16–18 of the Criminal Records Act (1998:620).
  • A balancing of interests in every case. Data is only recorded after a balancing of interests in the individual case has shown that the interests, rights and freedoms of the person checked do not outweigh the client’s legitimate interest in the processing.
  • Surplus data is deleted. Data about criminal offences that may not be recorded under the conditions is deleted immediately.
FAQ

Common questions about the IMY permit

Yes, if the company processes personal data about criminal offences and no law or other statute provides for the processing. IMY examines the application and normally attaches conditions to the permit.

Background checks with Sistec

We go through what your positions require and which checks are justified before anything is ordered.

Sources