Cookie Banners in Sweden: What the Law Requires
By CodexierPublished 6 min read
Most Swedish company websites have a cookie banner, and most of those banners are not compliant: they load analytics before anyone clicks, hide the reject option, or treat scrolling as consent. The rules come from two laws, the Electronic Communications Act (LEK) enforced by PTS and GDPR enforced by IMY. This guide shows what they actually require and how to build a banner, or avoid needing one.
The short answer
We build every company website so that the banner is either compliant or unnecessary, and the second option is more often available than people think.
What a valid consent looks like
GDPR defines consent as freely given, specific, informed and unambiguous, expressed by a clear affirmative action. Applied to a banner, that means four things must be true. Nothing non-essential loads until the visitor clicks accept. The banner says in plain language what the cookies are for and who receives the data. The visitor can choose per purpose, not only all or nothing. And the visitor can withdraw consent as easily as giving it, typically through a link in the footer that reopens the settings.
- Load the consent tool first and gate every tag behind it. Google Tag Manager with Consent Mode does this if configured correctly; a banner pasted on top of already-loaded scripts does not.
- Name the purposes: necessary, statistics, marketing. Do not bury forty vendors in an expandable list and call it informed.
- Write the button labels as choices, not as instructions. Accept all and Reject all, not OK and Settings.
- Store the consent record with a timestamp and the version of your policy the visitor saw.
Reject as easy as accept
This is the point where most banners fail, and the one IMY and other EU regulators have written decisions about. If accepting is one green button and rejecting is a grey link that opens a second screen with toggles, the consent is not freely given, because the design pushes the visitor towards one answer. The same applies to a close cross that silently means accept, to a banner that blocks the page until you accept, and to reappearing banners that ask again on every visit until you give in.
The safe pattern is boring: two buttons of equal size and colour, Accept all and Reject all, plus a third link for settings. A visitor who rejects gets the same website, only without the tracking. If your business model depends on nudging people into accepting, the model, not the banner, is the problem.
Documenting consent
Under GDPR you must be able to demonstrate that consent was given. In practice that means your consent tool logs each choice with a pseudonymous identifier, a timestamp, the purposes accepted and the policy version, and keeps the log for as long as you rely on the consent. Most consent management platforms do this for you; a home-made banner with a single cookie rarely does. Pair the log with a cookie policy page that lists every cookie, its purpose, its lifetime and the party that sets it, and update that list every time a developer adds a script. A launch is the natural moment to audit it, which is why it sits in our website launch checklist.
Frequently asked questions
Is a cookie banner mandatory in Sweden?
No. What is mandatory is consent before any non-essential cookie is set. If your site only uses strictly necessary cookies, or cookie-free analytics, you need a cookie policy page but no banner. The banner is the mechanism for consent, not a legal requirement in itself.
Can I treat continued browsing or scrolling as consent?
No. Both PTS guidance and the European Data Protection Board are clear that consent requires an active choice. Scrolling, closing the banner or continuing to browse do not count, and scripts loaded on that basis are loaded without a legal ground.
Who enforces the rules, and what happens if we get it wrong?
PTS supervises the cookie rules in the Electronic Communications Act and IMY supervises the GDPR side, including the tracking that follows once a cookie is set. Both can order changes and IMY can issue administrative fines. For a small company the more common consequence is a complaint from a visitor or a competitor that forces a rushed fix.
Does Google Consent Mode make Google Analytics compliant?
Consent Mode makes Google's tags respect the visitor's choice, which is necessary but not sufficient. You still need a banner that meets the rules above, and you should read our separate guide on whether Google Analytics is acceptable in Sweden at all after IMY's decisions.
Not sure your banner would pass?
Send us your site address. On a fifteen-minute call we check which scripts load before consent, whether reject is as easy as accept, and whether you could drop the banner entirely.
Book a free 15-minute call