REGULATIONS · Knowledge hub

What the law actually requires of whoever lets staff in

Regulations and checking methods address different workplace requirements. Distinguish current rules, legislative proposals and identity checking methods.

Right to work, posted workers, personal data and access are regulated in different ways. The overview distinguishes six regulatory areas – including the Swedish CER/LOM proposal – from the method of examining identity document authenticity.

What makes it hard in practice is that the requirements have different owners. The Migration Agency, the Work Environment Authority, the Police, the Tax Agency and the data protection authority each look at their own part, while responsibility for having all the parts in place sits with whoever lets the person onto the site.

Below is what each one requires, and what Sistec Compliance Platform does about it.

OVERVIEW

Regulatory areas and checking method

Rule in force

The Aliens Act

What it requires

The employer must verify that foreign staff have the right to work in Sweden and retain the evidence. The check must happen before employment or access.

How it is supported

Work and residence permits are verified against the authorities' sources. Permits with an end date are monitored and flagged before they expire.

Rule in force

The Posting of Workers Act

What it requires

Foreign employers sending staff to Sweden must notify the Work Environment Authority no later than when the work begins.

How it is supported

Posting status is checked against the Work Environment Authority at enrolment and monitored throughout the assignment.

Rule in force

GDPR article 10

What it requires

Data on criminal convictions may only be processed under official authority or with explicit legal basis. Criminal record extracts may not be freely collected and stored.

How it is supported

The extract is ordered by the individual, presented in the original and examined in person. Only a note that it was examined is kept — never the extract itself. Sistec holds a permit from IMY to process personal data about criminal offences in background checks (reference number IMY-2026-3140).

Rule in force

The Protective Security Act (2010:305)

What it requires

Access to protected sites requires established identity. Whoever is responsible for the site must be able to show who was let in.

How it is supported

The identity document is read by machine using chip, UV and IR, and the face is matched against it. Every entry is logged.

Rule in force

The Work Environment Act

What it requires

Whoever controls a workplace is responsible for the working environment of hired staff and contractors too, and must know who is present.

How it is supported

Digital staff ledger with check-in and check-out, mandatory site induction and client-specific requirements before access.

Control method

Checking method: identity document authenticity

What it requires

Authenticity examination is a checking method, not a separate regulation. The method needs to suit the document and the purpose of the check.

How it is supported

ICAO chip reading, UV and IR examination of security features, and facial matching against the document.

Legislative proposal

The CER directive / LOM

What it requires

LOM is a legislative proposal with a proposed effective date of 1 January 2027. It includes background checking requirements for a defined group of people in critical entities.

How it is supported

Background screening designed around the LOM proposal, with a documented scoping of which roles are covered and automatic reminders before the next check.

Which of them apply to you?

Which rules reach you depends on your sector, your site and who passes through it. We will go through it with you.

Sources