The Swedish constitutional shield is narrower than advertised
On 9 July 2026 the Court of Justice of the European Union delivered its judgment in Case C-199/24, ND v Legal Newsdesk Sweden AB, formerly Garrapatica AB (ECLI:EU:C:2026:564), on a reference from Attunda tingsrätt. The Fifth Chamber held that a Member State cannot use Article 85(1) of Regulation (EU) 2016/679 to create derogations wider than Article 85(2) allows, and that a person whose criminal convictions are published online for payment cannot be left with defamation law as their only remedy.
The assumption among Swedish data services has been that a voluntary utgivningsbevis, the publication certificate issued by Myndigheten för press, radio och tv, takes the GDPR off the table. That rested on Chapter 1, Section 7 of lagen (2018:218), whose first subparagraph disapplies the GDPR where applying it would contravene the Freedom of the Press Act or the Fundamental Law on Freedom of Expression.
What was before the Court?
Legal Newsdesk Sweden operates the Lexbase database, which lets users search people and companies involved in criminal proceedings before a Swedish court. ND had been convicted by a judgment of 17 January 2011, which stayed accessible until February 2024. ND asked for erasure, but the data were not erased immediately and came down later under the company’s own retention policy. ND then sued for SEK 300,000 plus interest, and the company answered that its certificate, with the database rule in Chapter 1, Section 4 of the Fundamental Law on Freedom of Expression, disapplied the GDPR.
What the Court decided
The judgment answers three questions, and each answer matters independently.
The derogation list is exhaustive
Article 85(2) lets Member States derogate from specified chapters for processing carried out for journalistic purposes or for academic, artistic or literary expression. The Court held that Article 85(1) precludes Member States going beyond that for processing pursued for other purposes, even where the national legislature considers the wider derogation necessary to reconcile data protection with freedom of expression.
Defamation is not a substitute for GDPR remedies
A national measure cannot provide that the only remedies for a convicted person whose conviction data are published online for payment are criminal defamation proceedings or an action for damages for defamation. The remedies the Court protected sit in Chapter VIII: complaint to a supervisory authority under Article 77(1), judicial remedy against a supervisory authority under Article 78(1) and (2), judicial remedy against a controller or processor under Article 79(1), and compensation under Article 82(1).
Paid access to judgments is not automatically journalism
Making public documents consisting of criminal convictions available online for payment cannot be regarded as processing for journalistic purposes under Article 85(2) unless its purpose is the disclosure to the public of information, opinions or ideas, in compliance with the ethical rules and codes of conduct of the journalistic profession, after editing or adaptation or at least in accordance with an editorial policy, and after verification of the factual allegations. Whether Lexbase meets that description is for Attunda tingsrätt to decide.
Our reading of the judgment
Some commentary has treated this as a Lexbase problem. That understates it. The Court did not rule on one company’s editorial practices; it removed the assumption that a formal publication status can displace a directly applicable EU regulation for processing that is not journalistic in substance.
The second holding is the one businesses should worry about, because it restores a damages route Swedish operators assumed was closed. Integritetsskyddsmyndigheten said the same day that it would analyse what the judgment means for its four ongoing supervisory cases against search services holding certificates. The inquiry SOU 2024:75 of 20 November 2024 had already proposed tightening the carve-out, but it predates the judgment. The exposure exists now.
A worked example
A Swedish company sells a subscription that aggregates court decisions, company filings and adverse media into risk profiles on named individuals. It obtained a certificate on advice that this placed the service outside the GDPR, and has no lawful basis analysis and no erasure process. After C-199/24 that is untenable unless the service meets the journalistic purposes test, which an automated product with no editorial policy cannot easily do.
Common mistakes
The first is treating the certificate as a status attaching to the company rather than to the processing. The Court’s test looks at what the activity does, and one organisation can hold a certificate while carrying out processing that falls outside Article 85(2) entirely.
The second is assuming that because data are public, republishing them is unregulated. The Court noted that the sensitivity of criminal conviction data under Article 10 bears on whether a derogation is justified, though not on whether processing counts as journalism at all. The third is buying a Swedish data product for screening or AI training on the seller’s assurance of constitutional protection.
Recommended actions
If your organisation relies on a certificate for any part of its processing, separate that processing into what is genuinely journalistic and what is not, and document the distinction against the Court’s criteria of editorial policy, professional ethical rules and verification. Anything on the wrong side needs a lawful basis under Article 6.
Put a working erasure process in place before the first request arrives, and record when each request is received and actioned, because the gap between the two is where damages claims are made. If you buy data about identified individuals from a Swedish supplier, ask in writing what its lawful basis is.
Frequently asked questions
Is an utgivningsbevis now worthless?
No. It still confers constitutional protection under the Fundamental Law on Freedom of Expression, and the Article 85(2) derogation remains available for genuinely journalistic processing. What it no longer does is disapply the GDPR for commercial processing that does not meet the Court’s description of journalism.
Does the judgment apply outside Sweden?
The interpretation of Article 85(1) and Article 85(2) binds every Member State. Any national derogation reaching beyond processing for journalistic, academic, artistic or literary purposes is affected, so the reasoning travels well beyond the Swedish certificate system.
Can affected individuals now claim damages?
The Court held that national law cannot confine them to defamation remedies, so the GDPR routes remain open, including compensation under Article 82(1). Whether a claim succeeds still depends on proving an infringement and actual damage before the national court.
Conclusion
C-199/24 is a short judgment with a long reach. It tells Swedish businesses that a formal publication status cannot buy an exemption from a regulation written to apply directly, and it tells the individuals in those databases that they have the ordinary GDPR toolkit after all. The companies that respond well will stop asking whether they hold a certificate and start asking whether their processing survives Article 6.
At Lawgent, we help companies assess whether their data services fall inside or outside the journalistic purposes derogation, rebuild the GDPR documentation for the parts that fall outside, and respond to supervisory proceedings and compensation claims. Get in touch if you would like us to review how C-199/24 affects your data products.