IMY Sweden: Personnummer and Luhn Checks
Updated for 2026
Sweden's data authority is IMY — Integritetsskyddsmyndigheten. It tested PII tools in active use. The result: 45% failed to detect the personnummer. That is Sweden's main national ID. And 79% of Swedish adults use their GDPR rights every year. That is the highest rate in the EU. Weak detection creates a direct compliance gap.
Personnummer Format and the Luhn Check
The personnummer has two forms. Short form: YYMMDD-XXXX (10 digits). Long form: YYYYMMDD-XXXX (12 digits). The last digit is a Luhn check digit.
The Luhn check: Take the digits from right to left. Double every second one. If doubling gives two digits, add them. Sum all values. The result must divide evenly by 10.
The Luhn check also appears in credit cards and the Canadian SIN. But the personnummer holds a date in the first six digits. That creates constraints that differ from financial Luhn checks. Tools that skip the date logic get false positives.
The Samordningsnummer Gap
Sweden gives foreign residents a coordination number called a samordningsnummer. It is needed before a full personnummer is issued. The format is the same. The difference: 60 is added to the birth-day digits.
- Personnummer, born January 15: day digits = 15.
- Samordningsnummer, same date: day digits = 75 (15 + 60).
Valid day values for a samordningsnummer run from 61 to 91. Tools that only accept 01 to 31 will miss every one of them.
Foreign-born residents are about 20% of Sweden's population. For firms with non-Swedish staff or clients, this gap means a large share of records go undetected.
IMY's Anonymization Rules
IMY's 2023 anonymization guide is the most detailed of any EU data authority. Twelve other DPAs cite it.
Three rules apply to Swedish datasets:
- k-anonymity ≥ 5. Each record must be indistinguishable from at least four others on all key fields. Age, gender, municipality, and job are typical quasi-identifiers. Sweden's small population makes small groups easy to isolate.
- l-diversity for health and finance data. k-anonymity alone does not stop inference attacks. l-diversity requires each group to hold at least l distinct sensitive values.
- Formal proof required. IMY does not accept claimed compliance. Technical documentation must show the thresholds are met.
The 79% Rate: What It Means in Practice
For a firm with 50,000 Swedish users, 79% means about 39,500 rights requests per year. Each one must be answered within 30 days.
Manual handling cannot scale to that volume. Firms need automated PII search across all storage: main databases, backups, analytics, and AI training sets. Systems must find personnummer and samordningsnummer. Both need Luhn checks and the 60-day offset rule.
That technical accuracy is the base requirement for responding to Swedish rights requests at scale. Without it, automated inventory systems will miss a significant share of the records they are required to find and return.
See our IMY GDPR anonymization and Nordic guide for the full anonymization framework and IMY's 2024 enforcement record.
For comparison across EU states, see our BFDI Germany GDPR technical guide.