{
  "meta": {
    "site": "https://registry.uhoh.app",
    "title": "Uh Oh statute registry",
    "publishedAt": "2026-09-22",
    "registryVersion": "2026-09-22.1",
    "registrySource": "src/lib/compliance/statutes.ts",
    "whatThisIs": "The published Uh Oh screening catalog, with a dated source review for each entry. Text signals identify potentially relevant frameworks; they do not establish legal applicability or a duty to report. Future duties and unresolved scope questions are identified in the entries.",
    "catalogDraftedBy": {
      "name": "Gemini",
      "tool": "Antigravity CLI (agy)",
      "session": "437f50c1-263e-4e54-8063-cffc96147f93",
      "role": "Wrote the catalog prose: titles, summaries, playbooks, clocks, and most citations. This was not a parser reading the official text into fields."
    },
    "laterEditsBy": {
      "name": "Grok 4.7",
      "vendor": "xAI",
      "commit": "3ebb3ae",
      "date": "2026-09-21",
      "role": "Changed two citations after reading official pages: AFS 2015:4 and AFS 2001:1 now name AFS 2023:2 and AFS 2023:1, and Lex Sarah now cites Socialtjänstlag (2025:400) 27 kap. 2–6 §§. Also pointed the AI prompt at those instruments."
    },
    "factCheckBy": {
      "name": "GPT-6 Astra",
      "vendor": "OpenAI",
      "date": "2026-09-22",
      "role": "Reviewed and corrected all 32 entries using official legal texts and regulator guidance, with three parallel source-review agents and an integrating review. Added per-entry sources and limits, corrected runtime screening and synchronization, and implemented immutable public version history. No human legal sign-off is claimed."
    },
    "method": "GPT-6 Astra read official EU and Swedish legal texts and regulator guidance on 22 September 2026, checking cited provisions, current amendments where identified, duty holders, recipients, triggers, exceptions and operational suggestions. Three parallel reviews covered all entries; a second selective cross-review checked material corrections. Each row records the actual sources and remaining limits. Automated tests check software behavior and catalog consistency, not legal truth.",
    "previousFactCheckBy": {
      "name": "Grok 4.7",
      "vendor": "xAI",
      "date": "2026-09-22",
      "role": "Read the cited provision in the official text and wrote the finding on this page. No model was asked whether a row was correct. Playbook steps were not compared sentence by sentence to the statute."
    },
    "limitations": "This is a bounded source review, not a guarantee of 100% accuracy or an exhaustive legal opinion. No human lawyer has signed off this release. Incident facts, organisational scope, collective agreements, permits, substance/product classifications, case law and some implementation/transition questions require separate assessment. The REACH/CLP overview is not an audit of every article or annex. See each entry’s specific limitations.",
    "runtimePolicy": "All automatic deadlineHours values are null. The legal periods remain in the timing text; report creation is not a confirmed awareness, receipt or classification trigger. Matches and severity are screening indicators. Current API reads re-screen assessments from older registry versions while preserving stored records; older checklist completions do not certify changed playbook steps. Installed apps can retain older bundled or cached content until they synchronize or receive an app update.",
    "release": {
      "id": "2026-09-22.1",
      "kind": "catalog-release",
      "recordedAt": "2026-09-22T05:44:19.512Z",
      "summary": "Source-reviewed corrections to all 32 screening entries; current legal scope and timing qualifications; removal of unsupported automatic clocks; GPT-6 Astra attribution; strict versioned synchronization; public immutable history.",
      "attribution": "GPT-6 Astra (OpenAI), assisted by three parallel GPT-6 Astra review agents. Prior model contributions are preserved in provenance and historical snapshots."
    },
    "registryUpdatedAt": "2026-09-22T05:44:19.512Z",
    "entryCount": 32,
    "verdicts": [
      {
        "id": "holds",
        "label": "Holds",
        "tone": "ok"
      },
      {
        "id": "holds-with-limit",
        "label": "Holds, with a limit",
        "tone": "limit"
      },
      {
        "id": "clock-not-in-text",
        "label": "Clock is not in the text",
        "tone": "warn"
      },
      {
        "id": "does-not-match",
        "label": "Does not match the text",
        "tone": "danger"
      },
      {
        "id": "not-checked",
        "label": "Not checked line by line",
        "tone": "unknown"
      }
    ]
  },
  "entries": [
    {
      "key": "GDPR_ART_33",
      "code": "GDPR-ART-33",
      "shortLabel": "GDPR Art. 33",
      "title": "Personal Data Breach Notification to Authority",
      "statute": "Regulation (EU) 2016/679, Article 33",
      "eurLexUrl": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng",
      "deadlineHours": null,
      "deadlineLabel": "Controller: without undue delay; where feasible within 72 hours of awareness, unless risk is unlikely. Processor: notify controller without undue delay.",
      "authority": {
        "name": "Competent data protection supervisory authority; IMY where Sweden is competent",
        "acronym": "IMY / competent DPA",
        "country": "SE",
        "portalUrl": "https://www.imy.se/verksamhet/utfora-arenden/anmala-personuppgiftsincident/"
      },
      "summary": "A controller must notify the competent supervisory authority of a personal data breach unless it is unlikely to risk individuals’ rights and freedoms. The clock starts at controller awareness, not the app report date. Breaches include loss of availability or integrity as well as disclosure. A processor instead informs its controller without undue delay.",
      "requiredFacts": [
        "personal_data_compromise"
      ],
      "remedialPlaybook": [
        "Suggested operational action: contain the incident and establish the controller, processors, affected data and actual awareness timeline.",
        "Assess and document risk to individuals. Encryption or containment alone does not automatically remove the reporting duty.",
        "If notification is required, notify the competent authority without undue delay and, where feasible, within 72 hours of awareness; explain a later notification.",
        "Include available breach categories and scale, a contact point, likely consequences and measures; provide missing information in phases without undue further delay.",
        "Document every personal data breach, its effects and remedial action under Article 33(5)."
      ],
      "severity": "critical",
      "factCheck": {
        "verdict": "holds-with-limit",
        "finding": "Read Article 33(1)–(5) in the official EUR-Lex text and IMY incident guidance on 2026-09-22. Corrected the risk exception, controller/processor distinction and awareness trigger. Removed the unencrypted-or-uncontained match requirement: it is not a legal prerequisite. The 72-hour figure remains conditional, and delay requires reasons. Cross-border competence can mean an authority other than IMY. Automatic deadline arithmetic is disabled because this registry has no confirmed legal awareness timestamp.",
        "sources": [
          {
            "label": "GDPR Article 33; Articles 55–56 on competence",
            "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng"
          },
          {
            "label": "IMY: handling personal data breaches",
            "url": "https://www.imy.se/verksamhet/dataskydd/det-har-galler-enligt-gdpr/personuppgiftsincidenter/hantering-av-personuppgiftsincidenter/"
          },
          {
            "label": "IMY: current notification service",
            "url": "https://www.imy.se/verksamhet/utfora-arenden/anmala-personuppgiftsincident/"
          }
        ],
        "checkedBy": "GPT-6 Astra",
        "checkedAt": "2026-09-22",
        "limitations": [
          "A detected fact is a screening signal, not proof that GDPR applies or that the notification threshold is met.",
          "This review does not determine controller awareness, competent lead authority or incident-specific risk."
        ],
        "label": "Holds, with a limit",
        "tone": "limit"
      }
    },
    {
      "key": "GDPR_ART_34",
      "code": "GDPR-ART-34",
      "shortLabel": "GDPR Art. 34",
      "title": "Personal Data Breach Communication to Data Subjects",
      "statute": "Regulation (EU) 2016/679, Article 34",
      "eurLexUrl": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng",
      "deadlineHours": null,
      "deadlineLabel": "Without undue delay if high risk is likely; Article 34(3) exceptions apply.",
      "authority": {
        "name": "Affected data subjects; IMY or another competent DPA supervises",
        "acronym": "Data subjects / DPA",
        "country": "SE"
      },
      "summary": "The controller communicates a personal data breach to affected individuals without undue delay when high risk to their rights and freedoms is likely. This does not require special-category data. Article 34(3) contains exceptions for effective protection and subsequent risk removal; disproportionate effort requires an equally effective public communication or similar measure.",
      "requiredFacts": [
        "personal_data_compromise"
      ],
      "remedialPlaybook": [
        "Assess likely high risk to individuals separately from the Article 33 authority-notification threshold.",
        "Check Article 34(3): effective protection that makes affected data unintelligible, subsequent measures removing the likely high risk, or disproportionate effort requiring equally effective public communication.",
        "Where required, communicate promptly in clear language: describe the breach, contact point, likely consequences and measures taken or proposed.",
        "Suggested operational action: record the assessment and tailor practical protective advice to the affected individuals."
      ],
      "severity": "critical",
      "factCheck": {
        "verdict": "holds-with-limit",
        "finding": "Read Article 34(1)–(4), its cross-reference to Article 33(3)(b)–(d), and IMY guidance on 2026-09-22. Corrected the special-category-only match and added all three statutory exceptions. The recipient of this communication is the data subject, not IMY. The provision sets no numerical incident clock; the authority may require communication or conclude an exception applies.",
        "sources": [
          {
            "label": "GDPR Article 34",
            "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng"
          },
          {
            "label": "IMY: information for affected individuals",
            "url": "https://www.imy.se/verksamhet/dataskydd/det-har-galler-enligt-gdpr/personuppgiftsincidenter/hantering-av-personuppgiftsincidenter/"
          }
        ],
        "checkedBy": "GPT-6 Astra",
        "checkedAt": "2026-09-22",
        "limitations": [
          "Neither sensitive-data keywords nor a model score establishes likely high risk.",
          "Effective encryption must be assessed for the affected data and incident; its presence is not a universal exemption."
        ],
        "label": "Holds, with a limit",
        "tone": "limit"
      }
    },
    {
      "key": "EU_AI_ACT_ART_5",
      "code": "AI-ACT-ART-5",
      "shortLabel": "AI Act Prohibited",
      "title": "Prohibited Artificial Intelligence Practices",
      "statute": "Regulation (EU) 2024/1689, Articles 5, 75 and 113, as amended by Regulation (EU) 2026/1744",
      "eurLexUrl": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng",
      "deadlineHours": null,
      "deadlineLabel": "Original Article 5 prohibitions apply since 2 February 2025; new points (ba)/(bb) apply from 2 December 2026. No general reporting clock.",
      "authority": {
        "name": "Relevant AI supervisor: Swedish PTS, IMY or Finansinspektionen by use; AI Office where Article 75 applies",
        "acronym": "PTS / IMY / FI / AI Office",
        "country": "EU",
        "portalUrl": "https://pts.se/ai/"
      },
      "summary": "Article 5 prohibits defined harmful manipulation and vulnerability exploitation, certain social scoring and individual crime-risk profiling, untargeted facial-image scraping, workplace/education emotion inference, sensitive biometric categorisation and certain real-time police biometric identification. Each category has its own conditions and exceptions; workplace emotion inference includes a medical/safety exception. New sexual-content prohibitions apply from 2 December 2026.",
      "requiredFacts": [
        "ai_system_involved",
        "ai_prohibited_practice"
      ],
      "remedialPlaybook": [
        "Suggested assessment: identify the exact Article 5 category, operator role, territorial scope and applicable date before concluding a practice is prohibited.",
        "For workplace or education emotion inference, assess the biometric definition and medical/safety exception; other biometric and law-enforcement provisions have separate limits.",
        "If a practice falls within an applicable prohibition, stop the prohibited conduct. Suggested operational action: preserve necessary evidence lawfully and assess safe remediation.",
        "Suggested operational action: confirm the competent supervisor and any separate reporting duty; Article 5 itself does not set a general incident-notification period."
      ],
      "severity": "critical",
      "factCheck": {
        "verdict": "holds-with-limit",
        "finding": "Read consolidated Articles 3, 5, 75 and 113 at EUR-Lex (version 2026-07-27), the 2026/1744 amending act, and Swedish decision Fi2026/01365 on 2026-09-22. Added the omitted conditions and exceptions and distinguished the new Article 5(1)(ba)/(bb), (1a)/(1b) provisions, applicable 2026-12-02, from existing prohibitions. Corrected the generic AI Office routing: national responsibilities depend on use, with Article 75 exceptions. Preservation and legal consultation are suggested responses, not standalone Article 5 duties.",
        "sources": [
          {
            "label": "AI Act consolidated on 27 July 2026, Articles 3, 5, 75, 113",
            "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng"
          },
          {
            "label": "Digital Omnibus on AI: Regulation (EU) 2026/1744",
            "url": "https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng"
          },
          {
            "label": "Swedish competent-authority decision Fi2026/01365, pages 1–3",
            "url": "https://www.regeringen.se/contentassets/0377f932c1b74404895c0bbdaa5abb08/uppdrag-att-vara-nationella-behoriga-myndigheter-enligt-ai-forordningen.pdf"
          }
        ],
        "checkedBy": "GPT-6 Astra",
        "checkedAt": "2026-09-22",
        "limitations": [
          "This concise row is a screening summary, not the full prohibition tests or all law-enforcement exceptions.",
          "The new sexual-content provisions are not yet applicable on the review date; other applicable law may already prohibit the conduct.",
          "The cited Swedish interim authority assignment lasts through 2026-12-31 and must be rechecked thereafter."
        ],
        "label": "Holds, with a limit",
        "tone": "limit"
      }
    },
    {
      "key": "EU_AI_ACT_HIGH_RISK_WORKPLACE",
      "code": "AI-ACT-ANNEX-III-4",
      "shortLabel": "AI Act workplace — future duties",
      "title": "High-Risk Workplace AI: Article 26 Duties from 2 December 2027",
      "statute": "Regulation (EU) 2024/1689, Articles 6(2)–(4), 26, 27, 111 and 113(c); Annex III(4), as amended by Regulation (EU) 2026/1744",
      "eurLexUrl": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng",
      "deadlineHours": null,
      "deadlineLabel": "Annex III Article 26 duties apply from 2 December 2027, subject to Article 111 transition; relevant information is due before workplace use.",
      "authority": {
        "name": "Post- och telestyrelsen for Annex III(4) under the interim Swedish assignment; AI Office where Article 75 applies",
        "acronym": "PTS / relevant AI supervisor",
        "country": "SE",
        "portalUrl": "https://pts.se/ai/"
      },
      "summary": "Specified recruitment and worker-management uses fall in Annex III(4), subject to Article 6(3) exclusions; Annex III systems profiling people remain high risk. Article 26 duties for this category start on 2 December 2027 under amended Article 113, with legacy-system transition rules. They are not current universal employer duties as of 22 September 2026.",
      "requiredFacts": [
        "ai_system_involved",
        "ai_workplace_or_recruitment_risk"
      ],
      "remedialPlaybook": [
        "Suggested preparation: assess the intended use against Annex III(4), Article 6 exceptions and Article 111 transition. Separately comply with already applicable data-protection, employment and prohibited-practice rules.",
        "For when Article 26 applies, plan competent human oversight, use according to instructions, monitoring and appropriate input data.",
        "Article 26(7) requires employer deployers to inform worker representatives and affected workers before workplace use; paragraph (11) concerns information to people subject to qualifying AI-assisted decisions.",
        "Article 26(6) requires logs under the deployer’s control to be retained for an appropriate period of at least six months unless applicable law provides otherwise; financial-sector provisions also apply.",
        "Assess Article 27 FRIA scope separately: it covers specified public bodies, private providers of public services and listed credit/life-or-health-insurance uses, not every private employer."
      ],
      "severity": "high",
      "factCheck": {
        "verdict": "holds-with-limit",
        "finding": "Read consolidated Articles 6, 26, 27, 111 and 113 and Annex III(4), plus the 2026/1744 amendment and Swedish authority decision on 2026-09-22. Corrected the obsolete applicability date, the worker-notice reference from 26(11) to 26(7), the blanket FRIA instruction and authority. Confirmed that deployers do have a six-month log provision in Article 26(6), subject to control and applicable-law qualifications; the earlier fact-check had not established that. This is a future-duty preparation row on the review date.",
        "sources": [
          {
            "label": "AI Act consolidated on 27 July 2026, Articles 6, 26–27, 111, 113 and Annex III(4)",
            "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng"
          },
          {
            "label": "Regulation (EU) 2026/1744",
            "url": "https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng"
          },
          {
            "label": "Commission: AI Omnibus entry into force and revised timetable",
            "url": "https://digital-strategy.ec.europa.eu/en/news/ai-omnibus-enters-force"
          },
          {
            "label": "Swedish authority decision Fi2026/01365",
            "url": "https://www.regeringen.se/contentassets/0377f932c1b74404895c0bbdaa5abb08/uppdrag-att-vara-nationella-behoriga-myndigheter-enligt-ai-forordningen.pdf"
          }
        ],
        "checkedBy": "GPT-6 Astra",
        "checkedAt": "2026-09-22",
        "limitations": [
          "The intended purpose, material influence on decisions, profiling and legacy-system status require evidence; keyword matching cannot establish them.",
          "The interim Swedish authority assignment expires before these duties generally apply and must be rechecked.",
          "This row does not enumerate every Article 26 obligation."
        ],
        "label": "Holds, with a limit",
        "tone": "limit"
      }
    },
    {
      "key": "GDPR_ART_22",
      "code": "GDPR-ART-22",
      "shortLabel": "GDPR Profiling",
      "title": "Solely Automated Decisions with Legal or Similarly Significant Effects",
      "statute": "Regulation (EU) 2016/679, Article 22",
      "eurLexUrl": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng",
      "deadlineHours": null,
      "deadlineLabel": "No incident-notification deadline in Article 22; safeguards apply to qualifying decisions.",
      "authority": {
        "name": "Integritetsskyddsmyndigheten or other competent data protection authority",
        "acronym": "IMY / DPA",
        "country": "SE",
        "portalUrl": "https://www.imy.se/"
      },
      "summary": "Article 22 concerns decisions based solely on automated processing that have legal or similarly significant effects. Profiling alone is insufficient. Exceptions are contract necessity, authorisation by applicable law with safeguards, or explicit consent. Additional safeguards and restrictions apply, especially to special-category data.",
      "requiredFacts": [
        "automated_profiling"
      ],
      "remedialPlaybook": [
        "Suggested assessment: identify the decision, meaningful human involvement and its legal or similarly significant effect on the person.",
        "If Article 22 applies, establish an Article 22(2) exception as well as the other GDPR requirements; ordinary contract wording or nominal consent does not by itself establish the exception.",
        "For contract-necessity or explicit-consent exceptions, provide suitable safeguards including human intervention, the person’s views and a way to challenge the decision; a law-based exception must supply suitable safeguards.",
        "Check Article 22(4) restrictions on special-category data and separately assess whether a DPIA is required under Article 35."
      ],
      "severity": "high",
      "factCheck": {
        "verdict": "holds-with-limit",
        "finding": "Read Article 22(1)–(4) in EUR-Lex and IMY automated-decision guidance, last updated 2026-05-27, on 2026-09-22. Removed the invented incident deadline and blanket DPIA claim for all profiling. Article 22 is narrower than the existing automated_profiling screening flag. Article 35 has its own risk and processing criteria. The safeguards differ between contract/consent and law-based exceptions.",
        "sources": [
          {
            "label": "GDPR Articles 22 and 35",
            "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng"
          },
          {
            "label": "IMY: automated decision-making",
            "url": "https://www.imy.se/verksamhet/dataskydd/innovationsportalen/vagledning-om-gdpr-och-ai/gdpr-och-ai/automatiserat-beslutsfattande/"
          },
          {
            "label": "IMY: when a DPIA is required",
            "url": "https://www.imy.se/verksamhet/dataskydd/det-har-galler-enligt-gdpr/konsekvensbedomning/nar-ska-en-konsekvensbedomning-genomforas/"
          }
        ],
        "checkedBy": "GPT-6 Astra",
        "checkedAt": "2026-09-22",
        "limitations": [
          "A profiling keyword does not establish solely automated decision-making or significant effect.",
          "Consent validity, meaningful human involvement, lawful restrictions and relevant case law need case-specific analysis."
        ],
        "label": "Holds, with a limit",
        "tone": "limit"
      }
    },
    {
      "key": "EU_AI_ACT_ART_73",
      "code": "AI-ACT-ART-73",
      "shortLabel": "AI Act",
      "title": "Serious Incidents: High-Risk AI Provider Reporting",
      "statute": "Regulation (EU) 2024/1689, Articles 3(49), 73, 75(1a), 111 and 113; deployer duties separately in Article 26(5)",
      "eurLexUrl": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng",
      "deadlineHours": null,
      "deadlineLabel": "If applicable: immediate reporting under Article 73; maxima 2, 10 or 15 days from awareness depending on the statutory case. No 72-hour baseline.",
      "authority": {
        "name": "Market surveillance authority in the incident Member State; AI Office for providers covered by Article 75(1a)",
        "acronym": "Competent AI supervisor",
        "country": "EU",
        "portalUrl": "https://pts.se/ai/"
      },
      "summary": "Article 73 addresses providers of high-risk AI systems placed on the EU market and defined serious incidents, including serious health harm, specified critical-infrastructure disruption, infringed EU fundamental-rights obligations or serious property/environmental harm. Reporting depends on classification, applicability and transition rules; suspected bias alone does not establish the duty. Article 75(1a) changes the recipient for certain AI Office-supervised providers.",
      "requiredFacts": [
        "ai_system_involved",
        "ai_severe_harm_or_bias"
      ],
      "remedialPlaybook": [
        "Suggested urgent assessment: confirm the legal role, high-risk classification, applicability and Article 111 legacy-system position; do not assume all AI incidents fall within Article 73.",
        "When Article 73 applies, report immediately on establishing a causal link or reasonable likelihood, with a general maximum of 15 days from provider or, where applicable, deployer awareness.",
        "For widespread infringement or Article 3(49)(b) critical-infrastructure disruption, report immediately and within two days; for death, report on establishing or suspecting causality and within ten days. Apply any shorter relevant category.",
        "An incomplete initial report may be followed by a complete report when necessary for timeliness. Check Article 73(9)–(10) sector limits and the Article 75(1a) AI Office reporting route.",
        "After a required report, investigate without delay, assess risk and take corrective action; inform competent authorities before alterations that could affect cause evaluation. Suggested operational action: preserve necessary evidence and limit harm.",
        "Separately assess deployer escalation under Article 26(5) when that provision applies, including its future application dates; it is not the same as the provider duty."
      ],
      "severity": "high",
      "factCheck": {
        "verdict": "holds-with-limit",
        "finding": "Read consolidated Articles 3(49), 26(5), 73, 75(1a), 111 and 113 on 2026-09-22. Removed the invented 72-hour baseline and broad provider/deployer claim. Confirmed 2/10/15-day maxima and causality/awareness triggers, sector exceptions and the new AI Office recipient exception. Article 113 delays Chapter III sections 1–3, but does not expressly delay Article 73 in Chapter IX. This review therefore does not assert that every provider is already subject to this duty or that Article 73 is universally postponed: classification and Article 111 transition must be resolved for the actual system.",
        "sources": [
          {
            "label": "AI Act consolidated on 27 July 2026, Articles 3, 26, 73, 75, 111, 113",
            "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng"
          },
          {
            "label": "Regulation (EU) 2026/1744, including new Article 75(1a)",
            "url": "https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng"
          },
          {
            "label": "Swedish authority decision Fi2026/01365",
            "url": "https://www.regeringen.se/contentassets/0377f932c1b74404895c0bbdaa5abb08/uppdrag-att-vara-nationella-behoriga-myndigheter-enligt-ai-forordningen.pdf"
          }
        ],
        "checkedBy": "GPT-6 Astra",
        "checkedAt": "2026-09-22",
        "limitations": [
          "Application of Article 73 to a particular system during the amended transition remains a case-specific legal question; this row is not an applicability determination.",
          "This review does not establish awareness, causality, qualifying harm or equivalent sectoral reporting."
        ],
        "label": "Holds, with a limit",
        "tone": "limit"
      }
    },
    {
      "key": "EU_WB_DIR_2019_1937",
      "code": "EU-WB-2019-1937",
      "shortLabel": "Whistleblower",
      "title": "Swedish Whistleblower Protection and Internal Channel Follow-up",
      "statute": "Lag (2021:890), 1, 3–5 and 9 kap.; Directive (EU) 2019/1937",
      "eurLexUrl": "https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/lag-2021890-om-skydd-for-personer-som_sfs-2021-890/",
      "deadlineHours": null,
      "deadlineLabel": "Internal channel: acknowledge within 7 days of receipt, subject to exceptions; feedback within 3 months of acknowledgment or the statutory fallback date.",
      "authority": {
        "name": "Internal independent reporting function; Arbetsmiljöverket supervises internal-channel requirements",
        "acronym": "Internal channel / AV",
        "country": "SE",
        "portalUrl": "https://www.av.se/arbetsmiljoarbete-och-inspektioner/lagar-och-regler-om-arbetsmiljo/visselblasarlagen/"
      },
      "summary": "Swedish whistleblower protection covers qualifying work-related reports of public-interest misconduct or specified EU-law breaches, subject to statutory conditions. Internal channels are generally required for operators with at least 50 workers at the year’s start. The 7-day acknowledgment and 3-month feedback periods concern the internal reporting process, not an authority filing.",
      "requiredFacts": [
        "whistleblower_misconduct"
      ],
      "remedialPlaybook": [
        "Suggested assessment: determine protected-report scope, channel duties and any special sector or permissible collective-agreement rules; route the matter to independent authorised handlers.",
        "For the statutory internal channel, acknowledge within seven days of receipt unless the reporter declines or acknowledgment is expected to reveal the person’s identity.",
        "Provide feedback to a reasonable extent within three months of acknowledgment; if no acknowledgment was given and this was not due to the reporter, calculate from seven days after receipt.",
        "Prevent retaliation and unauthorised identity disclosure. Apply statutory disclosure rules and public-sector secrecy law rather than promising absolute secrecy.",
        "Suggested operational action: document follow-up and access decisions with appropriate data minimisation and safeguards."
      ],
      "severity": "high",
      "factCheck": {
        "verdict": "holds-with-limit",
        "finding": "Read Lag (2021:890), especially 1 kap. 2 §, 4 kap., 5 kap. 2, 5 and 8 §§ and 9 kap. 1–2 §§, and Arbetsmiljöverket guidance on 2026-09-22. Corrected scope, acknowledgment exceptions and feedback anchor. Removed absolute confidentiality, which conflicts with lawful disclosures and public-sector secrecy rules. The 7-day clock is not a deadline to notify AV. External channels have separate rules and are not represented by this internal-channel row.",
        "sources": [
          {
            "label": "Lag (2021:890), consolidated Swedish text",
            "url": "https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/lag-2021890-om-skydd-for-personer-som_sfs-2021-890/"
          },
          {
            "label": "Arbetsmiljöverket: scope and independent handlers",
            "url": "https://www.av.se/arbetsmiljoarbete-och-inspektioner/lagar-och-regler-om-arbetsmiljo/visselblasarlagen/fordjupning-om-visselblasarlagen/"
          },
          {
            "label": "Arbetsmiljöverket: internal channel requirements",
            "url": "https://www.av.se/arbetsmiljoarbete-och-inspektioner/lagar-och-regler-om-arbetsmiljo/visselblasarlagen/"
          }
        ],
        "checkedBy": "GPT-6 Astra",
        "checkedAt": "2026-09-22",
        "limitations": [
          "Protection depends on statutory reporting conditions, including reasonable grounds to believe the information was true.",
          "Sector rules and permissible collective-agreement deviations may affect internal-channel procedures; external reporting needs a separate assessment."
        ],
        "label": "Holds, with a limit",
        "tone": "limit"
      }
    },
    {
      "key": "NIS2_ART_23",
      "code": "NIS2-ART-23",
      "shortLabel": "NIS2 / Cybersäkerhetslagen",
      "title": "Swedish Significant Cyber Incident Reporting",
      "statute": "Cybersäkerhetslag (2025:1506), 1 kap. and 2 kap. 5–10 §§; Cybersäkerhetsförordning (2025:1507); Directive (EU) 2022/2555 Article 23",
      "eurLexUrl": "https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/cybersakerhetslag-20251506_sfs-2025-1506/",
      "deadlineHours": null,
      "deadlineLabel": "As soon as possible: early warning ≤24h; notification ≤72h (trust services ≤24h) after awareness. Final report normally within 1 month after notification.",
      "authority": {
        "name": "Nationellt cybersäkerhetscenter at Försvarets radioanstalt, through CERT-SE; relevant sector supervisor receives forwarded reports",
        "acronym": "FRA / NCSC / CERT-SE",
        "country": "SE",
        "portalUrl": "https://cyberportal.mcf.se/"
      },
      "summary": "Covered Swedish entities report significant incidents under the Cybersäkerhetslag, in force since 15 January 2026. Scope, exemptions and sector-specific significance criteria must be checked. Reporting is to NCSC/CERT-SE at FRA, which took over the cyber functions on 1 July 2026. A generic cyber event or financial loss alone does not establish all legal conditions.",
      "requiredFacts": [
        "cyber_infrastructure_incident"
      ],
      "remedialPlaybook": [
        "Suggested assessment: confirm coverage under 1 kap., applicable exemptions including DORA, sector-specific incident thresholds and the actual awareness time.",
        "For a reportable significant incident, send the early warning as soon as possible and at most 24 hours after awareness.",
        "Submit the incident notification as soon as possible and at most 72 hours after awareness; trust-service providers have a 24-hour notification maximum. Supply requested progress updates.",
        "Submit the final report within one month after the incident notification; if the incident is ongoing, submit a progress report then and the final report within one month after handling the incident.",
        "Use the current NCSC reporting instructions and assess service-recipient information duties under 2 kap. 9–10 §§ separately."
      ],
      "severity": "critical",
      "factCheck": {
        "verdict": "holds-with-limit",
        "finding": "Read Cybersäkerhetslag (2025:1506), notably 1 kap. scope/exemptions and 2 kap. 5–10 §§, consolidated Cybersäkerhetsförordning (2025:1507) through amendment 2026:623, MCFFS 2026:8 and current NCSC/FRA guidance on 2026-09-22. Added the Swedish implementing law, corrected the final-report anchor, included the trust-service exception and replaced obsolete MSB routing. FRA confirms the transfer on 2026-07-01; NCSC still links the reporting service hosted at cyberportal.mcf.se. Threshold and reporting-content rules vary by covered sector.",
        "sources": [
          {
            "label": "Cybersäkerhetslag (2025:1506)",
            "url": "https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/cybersakerhetslag-20251506_sfs-2025-1506/"
          },
          {
            "label": "Cybersäkerhetsförordning (2025:1507), amended through 2026:623",
            "url": "https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/cybersakerhetsforordning-20251507_sfs-2025-1507/"
          },
          {
            "label": "MCFFS 2026:8, in force 1 July 2026",
            "url": "https://www.mcf.se/contentassets/bf5f875837754fecaf5627012e1762ce/mcffs-2026-8.pdf"
          },
          {
            "label": "NCSC: current incident reporting process",
            "url": "https://www.ncsc.se/sv/radgivning-och-stod/cybersakerhetslagen-nis2/incidentrapportering-enligt-cybersakerhetslagen/"
          },
          {
            "label": "FRA: transfer of cyber functions on 1 July 2026",
            "url": "https://www.fra.se/nyheter/nyheter/nyhetsarkiv/news/cyberverksamhetensamlashosfra.5.1c31366219e925a6069d1.html"
          }
        ],
        "checkedBy": "GPT-6 Astra",
        "checkedAt": "2026-09-22",
        "limitations": [
          "The review does not classify an organisation or apply all MCFFS, PTS and EU implementing thresholds to an actual incident.",
          "The portal hostname retains mcf.se; the cited current NCSC page identifies NCSC/CERT-SE as recipient.",
          "The app report date is not a verified legal awareness date."
        ],
        "label": "Holds, with a limit",
        "tone": "limit"
      }
    },
    {
      "key": "SWE_AML_3_3A",
      "code": "AML-3-3A",
      "shortLabel": "Arbetsmiljöolycka",
      "title": "Allvarligt tillbud eller personskada (Arbetsmiljölagen)",
      "statute": "Arbetsmiljölagen (1977:1160) 3 kap. 3 a §; arbetsmiljöförordningen (1977:1166) 2 §",
      "eurLexUrl": "https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/arbetsmiljolag-19771160_sfs-1977-1160/",
      "deadlineHours": null,
      "deadlineLabel": "Utan dröjsmål; ingen generell 24-timmarsfrist.",
      "authority": {
        "name": "Arbetsmiljöverket",
        "acronym": "AV",
        "country": "SE",
        "portalUrl": "https://www.anmalarbetsskada.se/"
      },
      "summary": "Arbetsgivaren ska utan dröjsmål underrätta Arbetsmiljöverket om arbetsrelaterat dödsfall eller svårare personskada, skador som samtidigt drabbat flera arbetstagare samt tillbud som inneburit allvarlig fara för liv och hälsa. En allmän riskindikator räcker inte för att fastställa att dessa kriterier är uppfyllda.",
      "requiredFacts": [
        "workplace_accident_or_hazard"
      ],
      "remedialPlaybook": [
        "Föreslagen praktisk åtgärd: ordna första hjälpen och akut vård vid behov samt förebygg fortsatt skada.",
        "Bedöm om händelsen omfattas av 3 kap. 3 a §; underrätta då Arbetsmiljöverket utan dröjsmål, exempelvis via den gemensamma anmälningstjänsten.",
        "Föreslagen praktisk åtgärd: dokumentera händelsen och säkra relevanta uppgifter utan att hindra räddningsinsatser.",
        "Bedöm separat skyldigheter om skyddsombud, utredning och arbetsskadeanmälan; de följer inte alla av just denna bestämmelse."
      ],
      "severity": "critical",
      "factCheck": {
        "verdict": "holds-with-limit",
        "finding": "Read 3 kap. 3 a § AML and 2 § AMF in Riksdagen’s consolidated texts on 2026-09-22. Corrected the nonexistent AMF 3 a § citation and removed the invented 24-hour deadline. AMF 2 § expressly identifies Arbetsmiljöverket. The statutory categories concern severe work-related harm, simultaneous injuries or serious near misses; the heuristic also catches lesser hazards. First aid and preservation are framed as operational suggestions, with other duties assessed separately.",
        "sources": [
          {
            "label": "Arbetsmiljölagen 3 kap. 3 a §",
            "url": "https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/arbetsmiljolag-19771160_sfs-1977-1160/"
          },
          {
            "label": "Arbetsmiljöförordningen 2 §",
            "url": "https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/arbetsmiljoforordning-19771166_sfs-1977-1166/"
          }
        ],
        "checkedBy": "GPT-6 Astra",
        "checkedAt": "2026-09-22",
        "limitations": [
          "This row does not decide severity or whether an event occurred in connection with work.",
          "Shipboard work has separate reporting provisions identified in AML 3 kap. 3 a §; those are not audited here."
        ],
        "label": "Holds, with a limit",
        "tone": "limit"
      }
    },
    {
      "key": "SWE_DISCRIMINATION_ACT",
      "code": "DISKRIM-2008-567",
      "shortLabel": "Diskrimineringslagen",
      "title": "Arbetsgivarens utredning och åtgärder vid trakasserier",
      "statute": "Diskrimineringslagen (2008:567) 1 kap. 4 § och 2 kap. 3 §; DO:s vägledning",
      "eurLexUrl": "https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/diskrimineringslag-2008567_sfs-2008-567/",
      "deadlineHours": null,
      "deadlineLabel": "Agera skyndsamt vid kännedom enligt DO:s vägledning; 2 kap. 3 § anger ingen timfrist.",
      "authority": {
        "name": "Diskrimineringsombudsmannen",
        "acronym": "DO",
        "country": "SE",
        "portalUrl": "https://www.do.se/"
      },
      "summary": "När arbetsgivaren får kännedom om att en arbetstagare anser sig arbetsrelaterat trakasserad eller sexuellt trakasserad av någon som arbetar eller praktiserar hos arbetsgivaren ska omständigheterna utredas. I förekommande fall krävs skäliga åtgärder mot framtida trakasserier. Skyddet omfattar även praktikanter och inhyrd eller inlånad personal. Bestämmelsen avser inte alla former av diskriminering.",
      "requiredFacts": [
        "discrimination_or_sexual_harassment"
      ],
      "remedialPlaybook": [
        "Bedöm om uppgifterna omfattas av 2 kap. 3 §. Trakasserier enligt lagen har samband med en diskrimineringsgrund; sexuella trakasserier är en egen form.",
        "Utred vid kännedom; DO:s vägledning säger utan dröjsmål. Någon formell anmälan från den berörda krävs inte.",
        "Föreslagen praktisk åtgärd enligt DO:s vägledning: tala diskret med berörda och vid behov vittnen, bedöm stödbehov och dokumentera arbetet.",
        "Om utredningen visar trakasserier, vidta de åtgärder som skäligen kan krävas för att förhindra fortsättning och följ upp resultatet. Bedöm även repressalieförbudet separat."
      ],
      "severity": "high",
      "factCheck": {
        "verdict": "holds-with-limit",
        "finding": "Read 1 kap. 4 § and 2 kap. 3 § in Riksdagen’s consolidated act and DO guidance updated 2026-08-19, retrieved 2026-09-22. Added the perpetrator/work connection and extended worker categories. The statute does not literally prescribe an hourly clock or the phrase utan dröjsmål, but DO’s current application guidance expressly requires prompt investigation. The revised label distinguishes that guidance from statutory wording. Customer or supplier harassment is outside this particular investigation provision, though work-environment duties can apply.",
        "sources": [
          {
            "label": "Diskrimineringslagen 1 kap. 4 § and 2 kap. 3 §",
            "url": "https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/diskrimineringslag-2008567_sfs-2008-567/"
          },
          {
            "label": "DO: investigation, action and scope",
            "url": "https://www.do.se/jobbet-skolan-samhallet/diskriminering-pa-jobbet/sexuella-trakasserier-och-trakasserier-jobbet"
          }
        ],
        "checkedBy": "GPT-6 Astra",
        "checkedAt": "2026-09-22",
        "limitations": [
          "The broad discrimination_or_sexual_harassment flag includes situations outside this provision.",
          "Case-specific evidence, proportionality, other discrimination provisions and limitation periods are not determined here."
        ],
        "label": "Holds, with a limit",
        "tone": "limit"
      }
    },
    {
      "key": "SWE_AFS_2015_4",
      "code": "AFS-2015-4",
      "shortLabel": "AFS 2023:2 — OSA",
      "title": "Kränkande särbehandling: förebyggande arbete och rutiner",
      "statute": "AFS 2023:2, 2 kap. 10–11 §§ (ersätter AFS 2015:4 från 1 januari 2025)",
      "eurLexUrl": "https://www.av.se/arbetsmiljoarbete-och-inspektioner/publikationer/foreskrifter/afs-20232/",
      "deadlineHours": null,
      "deadlineLabel": "Löpande förebyggande skyldigheter och rutiner för snabb hjälp; ingen generell timfrist.",
      "authority": {
        "name": "Arbetsmiljöverket",
        "acronym": "AV",
        "country": "SE",
        "portalUrl": "https://www.av.se/"
      },
      "summary": "Arbetsgivaren ska klargöra att kränkande särbehandling inte accepteras och motverka förhållanden som kan ge upphov till den. Rutiner ska ange vem som tar emot uppgifter, hur de hanteras och hur och var utsatta snabbt får hjälp. Rutinerna ska vara kända för alla arbetstagare.",
      "requiredFacts": [
        "victimization_or_bullying"
      ],
      "remedialPlaybook": [
        "Tillämpa och gör rutinerna enligt 2 kap. 11 § kända: mottagare, hantering av uppgifter och vägar till snabb hjälp.",
        "Föreslagen praktisk åtgärd: bedöm stödbehov och anlita företagshälsovård eller annan sakkunnig när det behövs; bestämmelsen kräver inte samma stödform i varje fall.",
        "Motverka organisatoriska förhållanden som kan orsaka kränkande särbehandling.",
        "Föreslagen praktisk åtgärd: följ upp arbetsmiljöriskerna sakligt. Bedöm separat när utredningsskyldighet följer av SAM-reglerna; AFS 2023:2 kräver inte en skuldprövning av varje anklagelse."
      ],
      "severity": "medium",
      "factCheck": {
        "verdict": "holds-with-limit",
        "finding": "Read AFS 2023:2, 2 kap. 10–11 §§ and accompanying general advice on Arbetsmiljöverket’s official page on 2026-09-22. The current citation is correct. Narrowed the playbook to distinguish binding prevention/routine duties from suggested support and investigation methods. The rules specify routes to quick help, not an automatic deadline or mandatory professional treatment in every case. The legacy internal key/code is retained for data compatibility and does not mean AFS 2015:4 remains in force.",
        "sources": [
          {
            "label": "Arbetsmiljöverket: AFS 2023:2, 2 kap. 10–11 §§ and general advice",
            "url": "https://www.av.se/arbetsmiljoarbete-och-inspektioner/publikationer/foreskrifter/afs-20232/"
          }
        ],
        "checkedBy": "GPT-6 Astra",
        "checkedAt": "2026-09-22",
        "limitations": [
          "General advice is distinct from binding provisions.",
          "This row does not determine whether particular conduct is kränkande särbehandling or replace other SAM/harassment duties."
        ],
        "label": "Holds, with a limit",
        "tone": "limit"
      }
    },
    {
      "key": "EU_OSH_DIR_89_391",
      "code": "EU-OSH-89-391",
      "shortLabel": "EU OSH Framework",
      "title": "Occupational safety framework and Swedish implementation",
      "statute": "Directive 89/391/EEC, Articles 6 and 9; Swedish implementation: Arbetsmiljölagen (1977:1160) and AFS 2023:1",
      "eurLexUrl": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:31989L0391",
      "deadlineHours": null,
      "deadlineLabel": "Ongoing prevention; accident reporting follows applicable national law",
      "authority": {
        "name": "Arbetsmiljöverket (Swedish work environment supervision)",
        "acronym": "AV",
        "country": "SE",
        "portalUrl": "https://www.av.se/"
      },
      "summary": "The directive requires employer risk assessment, prevention, information and training. Article 9 requires records of accidents causing more than three working days of incapacity and accident reports under national rules. In Sweden, assess the duties under Arbetsmiljölagen and AFS 2023:1; the directive creates no uniform EU accident-reporting clock.",
      "requiredFacts": [
        "workplace_accident_or_hazard"
      ],
      "remedialPlaybook": [
        "Assess occupational risks and identify the responsible employer and applicable Swedish requirements.",
        "Apply preventive measures, prioritising elimination of risks and collective protection.",
        "Provide suitable information and training, and document the risk assessment.",
        "Separately assess Swedish accident and serious near-miss reporting duties; use the SWE_AML_3_3A entry for that screening."
      ],
      "severity": "medium",
      "factCheck": {
        "verdict": "holds-with-limit",
        "finding": "Corrected the authority from EU-OSHA to Sweden's work environment supervisor. Articles 6 and 9 support the revised framework summary; reporting details depend on national law and the accident-list threshold is more than three working days of incapacity.",
        "sources": [
          {
            "label": "Directive 89/391/EEC, Articles 6 and 9",
            "url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:31989L0391"
          },
          {
            "label": "Arbetsmiljöverket: AFS 2023:1",
            "url": "https://www.av.se/arbetsmiljoarbete-och-inspektioner/publikationer/foreskrifter/afs-20231/"
          },
          {
            "label": "Arbetsmiljöverket: reporting serious accidents and near misses",
            "url": "https://www.av.se/arbetsmiljoarbete-och-inspektioner/arbetsgivarens-ansvar-for-arbetsmiljon/anmal-arbetsskada-dodsfall-och-allvarliga-tillbud-till-arbetsmiljoverket/"
          }
        ],
        "checkedBy": "GPT-6 Astra",
        "checkedAt": "2026-09-22",
        "limitations": [
          "Directive-level summary; Swedish duties must be assessed under domestic implementation. A heuristic match does not establish a reportable accident."
        ],
        "label": "Holds, with a limit",
        "tone": "limit"
      }
    },
    {
      "key": "SWE_AFS_2001_1",
      "code": "AFS-2001-1",
      "shortLabel": "SAM (AFS 2023:1)",
      "title": "Systematiskt arbetsmiljöarbete: undersökning, utredning och åtgärder",
      "statute": "AFS 2023:1, 11–14 §§ (ersatte AFS 2001:1 den 1 januari 2025)",
      "eurLexUrl": "https://www.av.se/arbetsmiljoarbete-och-inspektioner/publikationer/foreskrifter/afs-20231/",
      "deadlineHours": null,
      "deadlineLabel": "Åtgärder omedelbart eller så snart det är praktiskt möjligt; ingen generell timfrist",
      "authority": {
        "name": "Arbetsmiljöverket",
        "acronym": "AV",
        "country": "SE",
        "portalUrl": "https://www.av.se/"
      },
      "summary": "Arbetsgivaren ska regelbundet undersöka arbetsmiljön och bedöma risker, även inför ändringar. Riskbedömningar ska vara skriftliga. Arbetsrelaterad ohälsa, olycksfall och allvarliga tillbud ska utredas. Nödvändiga åtgärder genomförs omedelbart eller så snart det är praktiskt möjligt; senare åtgärder dokumenteras i handlingsplan och genomförda åtgärder kontrolleras.",
      "requiredFacts": [
        "systematic_workplace_hazard"
      ],
      "remedialPlaybook": [
        "Undersök riskerna och dokumentera vilka risker som finns och om de är allvarliga.",
        "Utred orsaker till arbetsrelaterad ohälsa, olycksfall och allvarliga tillbud.",
        "Genomför nödvändiga åtgärder; ange ansvarig och genomförandetid i en skriftlig plan för sådant som inte genomförs omedelbart.",
        "Kontrollera genomförda åtgärder och följ upp arbetsmiljöarbetet årligen."
      ],
      "severity": "medium",
      "factCheck": {
        "verdict": "holds-with-limit",
        "finding": "Checked sections 11–14 of AFS 2023:1. Corrected the incident investigation scope and distinguished immediate measures from measures taken as soon as practically possible. The old registry key/code is retained for compatibility; AFS 2001:1 is no longer the applicable instrument.",
        "sources": [
          {
            "label": "AFS 2023:1, sections 11–14 and commencement provisions",
            "url": "https://www.av.se/arbetsmiljoarbete-och-inspektioner/publikationer/foreskrifter/afs-20231/"
          }
        ],
        "checkedBy": "GPT-6 Astra",
        "checkedAt": "2026-09-22",
        "limitations": [
          "A candidate match does not establish the employer's actual risk assessment or compliance. Sector-specific work environment rules may add duties."
        ],
        "label": "Holds, with a limit",
        "tone": "limit"
      }
    },
    {
      "key": "SWE_MBL_11",
      "code": "MBL-11",
      "shortLabel": "MBL Förhandling",
      "title": "Förhandling inför viktigare förändringar",
      "statute": "Lag (1976:580) om medbestämmande i arbetslivet, 4 och 11–16 §§",
      "eurLexUrl": "https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/lag-1976580-om-medbestammande-i-arbetslivet_sfs-1976-580/",
      "deadlineHours": null,
      "deadlineLabel": "Normalt före beslut om viktigare förändring; undantag och kollektivavtal måste bedömas",
      "authority": {
        "name": "Berörd arbetstagarorganisation (förhandlingspart; ingen myndighetsanmälan enligt 11 §)",
        "acronym": "Facklig organisation",
        "country": "SE"
      },
      "summary": "En arbetsgivare ska enligt 11 § på eget initiativ förhandla med kollektivavtalsbunden arbetstagarorganisation före viktigare verksamhetsförändring eller viktigare ändring av medlemmars arbets- eller anställningsförhållanden. Synnerliga skäl kan medge beslut och verkställighet före fullgjord förhandling. Även 13 § och kollektivavtal kan påverka skyldigheten.",
      "requiredFacts": [
        "worker_surveillance_or_major_change"
      ],
      "remedialPlaybook": [
        "Bedöm om förändringen är viktigare och vilka organisationer som berörs enligt 11–14 §§ och tillämpligt kollektivavtal.",
        "Initiera förhandling före beslut när skyldigheten gäller och lägg fram det underlag förhandlingen kräver.",
        "Kontrollera lokal och eventuell central förhandlingsordning; bedöm synnerliga skäl innan beslut fattas i förtid.",
        "Dokumentera förhandlingen; protokoll ska föras och justeras om part begär det."
      ],
      "severity": "high",
      "factCheck": {
        "verdict": "holds-with-limit",
        "finding": "Added the collective-agreement relationship, section 13 extensions, section 4 contractual departures and the exceptional-reasons rule. Monitoring technology is not named in section 11 and does not automatically trigger negotiation. The union is a negotiating party, not a reporting authority.",
        "sources": [
          {
            "label": "MBL, sections 4 and 11–16",
            "url": "https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/lag-1976580-om-medbestammande-i-arbetslivet_sfs-1976-580/"
          }
        ],
        "checkedBy": "GPT-6 Astra",
        "checkedAt": "2026-09-22",
        "limitations": [
          "No particular collective agreement, workplace facts or relevant labour-court judgments were assessed."
        ],
        "label": "Holds, with a limit",
        "tone": "limit"
      }
    },
    {
      "key": "SWE_LEX_MARIA",
      "code": "LEX-MARIA",
      "shortLabel": "Lex Maria",
      "title": "Vårdgivarens anmälan av allvarlig vårdskada",
      "statute": "Patientsäkerhetslagen (2010:659), 1 kap. 5 § och 3 kap. 3, 5 och 8 §§; HSLF-FS 2017:41",
      "eurLexUrl": "https://www.ivo.se/vard-omsorgsgivare/anmal-lex-maria-lex-sarah/lex-maria/",
      "deadlineHours": null,
      "deadlineLabel": "Snarast efter händelsen; ingen generell 48-timmarsfrist",
      "authority": {
        "name": "Inspektionen för vård och omsorg",
        "acronym": "IVO",
        "country": "SE",
        "portalUrl": "https://www.ivo.se/vard-omsorgsgivare/anmal-lex-maria-lex-sarah/lex-maria/"
      },
      "summary": "Vårdgivaren ska snarast anmäla händelser i den egna verksamheten som medfört eller kunnat medföra allvarlig vårdskada. Vårdskada avser undvikbar skada; allvarlig vårdskada är bestående och inte ringa, eller medför väsentligt ökat vårdbehov eller dödsfall. Utredningen lämnas med anmälan eller snarast därefter. Särregler kan gälla försvarsverksamhet.",
      "requiredFacts": [
        "patient_harm_or_medical_error"
      ],
      "remedialPlaybook": [
        "Rekommenderat första steg: ordna behövlig vård och skydda patienten från ytterligare skada.",
        "Låt ansvarig vårdgivare bedöma vårdskada, allvarlighet och anmälningsskyldighet samt utreda händelsen.",
        "Anmäl snarast till IVO när förutsättningarna är uppfyllda; lämna utredningen samtidigt eller snarast därefter via godkänd säker kanal.",
        "Informera en patient som drabbats av vårdskada enligt 3 kap. 8 §, inklusive förebyggande åtgärder och möjligheten till patientskadeersättning."
      ],
      "severity": "critical",
      "factCheck": {
        "verdict": "holds-with-limit",
        "finding": "Removed the unsupported 48-hour clock and corrected the definition of serious care injury. HSLF-FS 2017:41 governs Lex Maria notifications; the previous citation to 2017:40 alone did not identify that notification regulation. IVO confirms that patients and individual complainants do not submit the provider's Lex Maria notification.",
        "sources": [
          {
            "label": "Patientsäkerhetslagen, 1:5 and 3:3, 3:5, 3:8",
            "url": "https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/patientsakerhetslag-2010659_sfs-2010-659/"
          },
          {
            "label": "IVO: Lex Maria, including correction of medical-device cross-reference",
            "url": "https://www.ivo.se/vard-omsorgsgivare/anmal-lex-maria-lex-sarah/lex-maria/"
          },
          {
            "label": "IVO HSLF-FS 2017:41",
            "url": "https://www.ivo.se/globalassets/dokument/publikationer/foreskrifter/hslf-fs-2017-41.pdf"
          }
        ],
        "checkedBy": "GPT-6 Astra",
        "checkedAt": "2026-09-22",
        "limitations": [
          "Avoidability and seriousness require clinical and legal assessment. Separate medical-device and defence-sector reporting duties are not exhaustively covered."
        ],
        "label": "Holds, with a limit",
        "tone": "limit"
      }
    },
    {
      "key": "SWE_LEX_SARAH",
      "code": "LEX-SARAH",
      "shortLabel": "Lex Sarah",
      "title": "Intern rapport och verksamhetens IVO-anmälan av missförhållanden",
      "statute": "Socialtjänstlag (2025:400), 27 kap. 2–6 §§; lag (1993:387) om stöd och service till vissa funktionshindrade, 24 b–f §§",
      "eurLexUrl": "https://www.ivo.se/vard-omsorgsgivare/anmal-lex-maria-lex-sarah/lex-sarah/",
      "deadlineHours": null,
      "deadlineLabel": "Intern rapport genast; allvarligt missförhållande eller påtaglig risk för sådant anmäls snarast till IVO",
      "authority": {
        "name": "Inspektionen för vård och omsorg (extern anmälan); lagens interna mottagare för rapporten",
        "acronym": "IVO / intern mottagare",
        "country": "SE",
        "portalUrl": "https://www.ivo.se/vard-omsorgsgivare/anmal-lex-maria-lex-sarah/lex-sarah/"
      },
      "summary": "Den som fullgör uppgifter inom berörd SoL- eller LSS-verksamhet ska genast rapportera missförhållanden eller påtagliga risker internt till lagens mottagare. Missförhållanden ska dokumenteras, utredas och avhjälpas. Ansvarig nämnd, enskild verksamhetsutövare eller myndighetschefen vid Statens institutionsstyrelse anmäler allvarliga missförhållanden eller påtaglig risk för sådana snarast till IVO.",
      "requiredFacts": [
        "social_care_abuse_or_neglect"
      ],
      "remedialPlaybook": [
        "Rapportera genast enligt verksamhetens rutiner till ansvarig mottagare; lagens mottagare beror på driftsform.",
        "Dokumentera, utred och avhjälp eller undanröj missförhållandet eller risken genast enligt SoL respektive utan dröjsmål enligt LSS.",
        "Låt ansvarig anmälare bedöma allvarligheten och snarast anmäla till IVO när tröskeln är uppfylld.",
        "Bifoga utredningen och hantera eventuella kompletteringar enligt IVO:s anvisningar; enskild verksamhet ska även informera berörd nämnd enligt lagen."
      ],
      "severity": "critical",
      "factCheck": {
        "verdict": "holds-with-limit",
        "finding": "Removed the invented 24-hour deadline. Corrected the distinction between the individual's immediate internal report and the responsible organisation's IVO notification. The trigger includes a palpable risk of serious misconduct, not only actual serious misconduct. SoL 27:5 says genast; LSS 24 e says utan dröjsmål.",
        "sources": [
          {
            "label": "Socialtjänstlag (2025:400), chapter 27",
            "url": "https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/socialtjanstlag-2025400_sfs-2025-400/"
          },
          {
            "label": "LSS, sections 24 b–f",
            "url": "https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/lag-1993387-om-stod-och-service-till-vissa_sfs-1993-387/"
          },
          {
            "label": "IVO: Lex Sarah",
            "url": "https://www.ivo.se/vard-omsorgsgivare/anmal-lex-maria-lex-sarah/lex-sarah/"
          }
        ],
        "checkedBy": "GPT-6 Astra",
        "checkedAt": "2026-09-22",
        "limitations": [
          "The incident description alone does not establish covered activity, a palpable risk or seriousness. Detailed investigation and supplementary-filing rules are not reproduced."
        ],
        "label": "Holds, with a limit",
        "tone": "limit"
      }
    },
    {
      "key": "EU_DORA_ART_19",
      "code": "DORA-ART-19",
      "shortLabel": "DORA ICT",
      "title": "Major ICT incident reporting by covered financial entities",
      "statute": "Regulation (EU) 2022/2554, Articles 18–20; Delegated Regulation (EU) 2024/1772 (classification); Delegated Regulation (EU) 2025/301, Article 5 (time limits); Implementing Regulation (EU) 2025/302",
      "eurLexUrl": "https://eur-lex.europa.eu/eli/reg_del/2025/301/oj",
      "deadlineHours": null,
      "deadlineLabel": "Generally initial: 4h after major classification and within 24h of awareness; intermediate: 72h after initial; final: one month after latest intermediate; exceptions apply",
      "authority": {
        "name": "Finansinspektionen for covered financial entities under its supervision; otherwise the relevant DORA competent authority",
        "acronym": "FI / competent authority",
        "country": "SE",
        "portalUrl": "https://www.fi.se/sv/marknad/rapportering2/ikt-risker-dora/"
      },
      "summary": "Covered financial entities report major ICT incidents under Article 19 and the delegated classification criteria. Delegated Regulation 2025/301 sets reporting stages and clocks. If major classification occurs more than 24 hours after awareness, the initial notice is due within four hours of classification. Significant cyber-threat reporting is voluntary. Sweden's FI receives reports from entities under its supervision.",
      "requiredFacts": [
        "financial_ict_disruption"
      ],
      "remedialPlaybook": [
        "Confirm DORA scope and major-incident classification; record awareness, classification and submission times separately.",
        "Submit the initial notification as early as possible within the applicable Article 5 time limit, using the authority's reporting system and prescribed template.",
        "Submit the intermediate report within 72 hours of initial notification and update without undue delay, in any case when regular activities recover. Submit the final report within one month of the intermediate report or its latest update.",
        "Check Article 5(4)–(5) before applying weekend or bank-holiday relief. If unable to report on time, inform the authority without undue delay and by the applicable deadline, explaining why."
      ],
      "severity": "critical",
      "factCheck": {
        "verdict": "holds-with-limit",
        "finding": "The clocks are supported by the binding delegated regulation, which the previous review had not read. Removed the misleading single 24-hour value, corrected intermediate/final start events, and added late classification and delay notice. Article 5 permits noon-next-working-day relief for weekends/bank holidays, but excludes initial/intermediate reports by credit institutions, central counterparties, trading-venue operators and NIS2 essential/important financial entities.",
        "sources": [
          {
            "label": "DORA Article 19",
            "url": "https://eur-lex.europa.eu/legal-content/ENG/ALL/?uri=CELEX:32022R2554"
          },
          {
            "label": "Delegated Regulation (EU) 2025/301, Article 5",
            "url": "https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=OJ:L_202500301"
          },
          {
            "label": "Finansinspektionen: reporting, classification standards and Fidac",
            "url": "https://www.fi.se/sv/marknad/rapportering2/ikt-risker-dora/"
          }
        ],
        "checkedBy": "GPT-6 Astra",
        "checkedAt": "2026-09-22",
        "limitations": [
          "Entity scope, major-incident classification thresholds and calendar exceptions require assessment; no clock can be calculated from app report creation. Classification thresholds and templates are referenced, not exhaustively reproduced."
        ],
        "label": "Holds, with a limit",
        "tone": "limit"
      }
    },
    {
      "key": "SWE_AML_CFT_ACT",
      "code": "AML-CFT-2017-630",
      "shortLabel": "Penningtvättslagen",
      "title": "Rapportering av skälig misstanke till Finanspolisen",
      "statute": "Lag (2017:630), 1 kap., 3 kap. 3 §, 4 kap. 1–3 och 8–9 §§ samt 5 kap. 3–4 §§",
      "eurLexUrl": "https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/lag-2017630-om-atgarder-mot-penningtvatt-och_sfs-2017-630/",
      "deadlineHours": null,
      "deadlineLabel": "Utan dröjsmål när rapporteringsskyldighetens misstanketröskel är uppfylld; ingen 24-timmarsfrist",
      "authority": {
        "name": "Polismyndigheten (Finanspolisen)",
        "acronym": "Finanspolisen",
        "country": "SE",
        "portalUrl": "https://fipogoaml.polisen.se/Home"
      },
      "summary": "Verksamhetsutövare som omfattas av lagen ska efter bedömning rapportera utan dröjsmål när det finns skälig grund att misstänka penningtvätt, terrorfinansiering eller att egendom annars härrör från brott. Rapport krävs även för vissa avbrutna eller planerade transaktioner. Undantag finns för viss rättslig rådgivning. Obehörigt röjande av granskning eller rapport är förbjudet.",
      "requiredFacts": [
        "money_laundering_or_terrorist_financing"
      ],
      "remedialPlaybook": [
        "Bedöm lagens tillämplighet, misstanke och eventuellt undantag enligt 4 kap. 8 §.",
        "Rapportera rapporteringspliktiga omständigheter utan dröjsmål till Finanspolisen genom goAML; rapporten är inte samma sak som en polisanmälan.",
        "Bedöm transaktionsförbudet och undantagen i 3 kap. 3 §; inför inte en generell frysning av kundens medel enbart utifrån denna screening.",
        "Följ röjandeförbudet med dess lagliga undantag och bevarandereglernas perioder, startpunkter och gallringskrav."
      ],
      "severity": "critical",
      "factCheck": {
        "verdict": "holds-with-limit",
        "finding": "Removed the unsupported 24-hour clock, blanket transaction freeze, absolute tipping-off wording and open-ended minimum retention advice. The law contains transaction and disclosure exceptions; five-year retention has defined starting points and conditional extension up to ten years.",
        "sources": [
          {
            "label": "Lag (2017:630), chapters 1, 3–5",
            "url": "https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/lag-2017630-om-atgarder-mot-penningtvatt-och_sfs-2017-630/"
          },
          {
            "label": "Polismyndigheten: Finanspolisen and goAML reporting",
            "url": "https://polisen.se/om-polisen/polisens-arbete/finanspolisen/"
          }
        ],
        "checkedBy": "GPT-6 Astra",
        "checkedAt": "2026-09-22",
        "limitations": [
          "The registry does not determine regulated-entity status, suspicion, legal professional exceptions or whether disclosure is authorised. Other freezing or sanctions powers require a separate legal basis."
        ],
        "label": "Holds, with a limit",
        "tone": "limit"
      }
    },
    {
      "key": "SWE_MILJO_BALKEN",
      "code": "MILJO-1998-808",
      "shortLabel": "Miljöbalken Förorening",
      "title": "Underrättelse vid upptäckt förorening eller driftstörning",
      "statute": "Miljöbalken (1998:808), 10 kap. 11 §; förordning (1998:901) om verksamhetsutövares egenkontroll, 1 och 6 §§",
      "eurLexUrl": "https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/miljobalk-1998808_sfs-1998-808/",
      "deadlineHours": null,
      "deadlineLabel": "Genast enligt 10 kap. 11 §; omgående enligt egenkontrollförordningen 6 §; ingen generell 24-timmarsfrist",
      "authority": {
        "name": "Behörig miljötillsynsmyndighet för fastigheten eller verksamheten, ofta kommunen eller länsstyrelsen",
        "acronym": "Miljötillsynsmyndighet",
        "country": "SE"
      },
      "summary": "Fastighetsägare eller brukare ska genast underrätta tillsynsmyndigheten om en upptäckt förorening kan medföra skada eller olägenhet för hälsa eller miljö. Separat ska verksamhetsutövare som omfattas av egenkontrollförordningen omgående underrätta myndigheten om driftstörning eller liknande händelse som kan medföra sådana olägenheter. Förordningens tillämpningsområde måste kontrolleras.",
      "requiredFacts": [
        "environmental_spill_or_pollution"
      ],
      "remedialPlaybook": [
        "Rekommenderat första steg: begränsa exponering och spridning på ett säkert sätt; kontakta räddningstjänst vid akut fara.",
        "Fastställ ägar-/brukarroll, verksamhetens tillstånds- eller anmälningsplikt och behörig tillsynsmyndighet.",
        "Underrätta genast eller omgående när den aktuella bestämmelsens förutsättningar är uppfyllda.",
        "Rekommenderad uppföljning: dokumentera plats, ämnen, mängder och åtgärder och samordna undersökning med tillsynsmyndigheten; bedöm separat reglerna om allvarlig miljöskada."
      ],
      "severity": "critical",
      "factCheck": {
        "verdict": "holds-with-limit",
        "finding": "Corrected the duty holder in chapter 10 section 11 and replaced the irrelevant broad reference to 1998:899 with the applicable incident duty in 1998:901 section 6. The latter is scope-limited by section 1. Removed the invented 24-hour allowance and mandatory generic investigation/report instructions.",
        "sources": [
          {
            "label": "Miljöbalken, chapter 10 sections 11–13",
            "url": "https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/miljobalk-1998808_sfs-1998-808/"
          },
          {
            "label": "Förordning (1998:901), sections 1 and 6",
            "url": "https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/forordning-1998901-om-verksamhetsutovares_sfs-1998-901/"
          },
          {
            "label": "Naturvårdsverket: oversight of contaminated areas",
            "url": "https://www.naturvardsverket.se/49dcf7/globalassets/vagledning/miljobalken/tillsyn---nat-strategi/fokusomraden-fororenade-omraden/lagesbild-fororenade-omraden.pdf"
          }
        ],
        "checkedBy": "GPT-6 Astra",
        "checkedAt": "2026-09-22",
        "limitations": [
          "Authority allocation, permit conditions, contamination risk and serious environmental damage need case-specific assessment. The entry is not an exhaustive environmental-emergency procedure."
        ],
        "label": "Holds, with a limit",
        "tone": "limit"
      }
    },
    {
      "key": "EU_GPSR_ART_20",
      "code": "GPSR-ART-20",
      "shortLabel": "GPSR Produktolycka",
      "title": "Notification of serious accidents caused by consumer products",
      "statute": "Regulation (EU) 2023/988, Articles 2 and 20; dangerous-product duties separately in Articles 9, 11 and 12",
      "eurLexUrl": "https://eur-lex.europa.eu/eli/reg/2023/988/oj/eng",
      "deadlineHours": null,
      "deadlineLabel": "Without undue delay after knowledge of a qualifying accident; no 72-hour allowance",
      "authority": {
        "name": "Competent product-safety authority in the Member State of the accident, through Safety Business Gateway; Swedish authority depends on product category",
        "acronym": "Market surveillance authority",
        "country": "EU",
        "portalUrl": "https://www.konsumentverket.se/produktsakerhet-foretag/om-du-salt-en-farlig-vara-eller-tjanst/"
      },
      "summary": "For covered products, manufacturers must ensure notification through Safety Business Gateway of accidents causing death or serious permanent or temporary adverse health/safety effects. Importers and distributors inform the manufacturer without undue delay; the EU responsible person ensures notification where the manufacturer is outside the EU. A product defect alone does not establish the Article 20 accident trigger.",
      "requiredFacts": [
        "product_safety_defect"
      ],
      "remedialPlaybook": [
        "Confirm product scope, the accident's effects, the responsible economic operator and the affected Member State.",
        "The manufacturer must ensure notification through Safety Business Gateway without undue delay after knowledge; importers/distributors inform it, with Article 20(3)–(4) arrangements where applicable.",
        "Include the product type, identifier and known accident circumstances; provide further relevant information when requested.",
        "Separately assess dangerous-product corrective action and notification duties; recalls and warnings depend on the applicable safety rules and risk assessment."
      ],
      "severity": "high",
      "factCheck": {
        "verdict": "holds-with-limit",
        "finding": "Replaced the general dangerous-product description with Article 20's serious-accident duty and operator-specific responsibilities. Removed 72 hours. The Safety Business Gateway is a reporting channel, not an authority; Konsumentverket is not competent for every product category.",
        "sources": [
          {
            "label": "GPSR, Articles 2 and 20",
            "url": "https://eur-lex.europa.eu/eli/reg/2023/988/oj/eng"
          },
          {
            "label": "Konsumentverket: accident reporting and dangerous products",
            "url": "https://www.konsumentverket.se/produktsakerhet-foretag/om-du-salt-en-farlig-vara-eller-tjanst/"
          },
          {
            "label": "Konsumentverket: GPSR scope and sector-specific legislation",
            "url": "https://www.konsumentverket.se/produktsakerhet-foretag/lagar-och-regler-inom-produktsakerhet/"
          }
        ],
        "checkedBy": "GPT-6 Astra",
        "checkedAt": "2026-09-22",
        "limitations": [
          "The product_safety_defect fact is only a screening signal. Product exclusions, interaction with harmonised product legislation and actual accident severity require confirmation."
        ],
        "label": "Holds, with a limit",
        "tone": "limit"
      }
    },
    {
      "key": "EU_DSA_ART_18",
      "code": "DSA-ART-18",
      "shortLabel": "DSA Säkerhetshot",
      "title": "Hosting providers' notification of suspected offences threatening life or safety",
      "statute": "Regulation (EU) 2022/2065, Article 18",
      "eurLexUrl": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022R2065",
      "deadlineHours": null,
      "deadlineLabel": "Promptly after awareness of information giving rise to the specified suspicion; no 24-hour period",
      "authority": {
        "name": "Law enforcement or judicial authorities of the Member State(s) concerned; in Sweden, relevant police or judicial authority",
        "acronym": "Police / judicial authority",
        "country": "EU",
        "portalUrl": "https://polisen.se/"
      },
      "summary": "A hosting provider aware of information suggesting an offence threatening someone's life or safety has occurred, is occurring or is likely must promptly notify the relevant Member State's law enforcement or judicial authorities and provide available relevant information. If the state cannot reasonably be identified, Article 18(2) provides establishment/legal-representative-state police or Europol routes.",
      "requiredFacts": [
        "digital_services_safety_threat"
      ],
      "remedialPlaybook": [
        "Confirm hosting-provider scope and whether the information gives rise to the suspicion specified in Article 18.",
        "Promptly inform law enforcement or judicial authorities in the Member State(s) concerned and provide relevant available information.",
        "If the Member State cannot reasonably be identified, use the Article 18(2) national-police or Europol route, or both.",
        "Recommended operational step: document the assessment and protect relevant evidence lawfully. Assess Article 16 notice handling separately where applicable."
      ],
      "severity": "critical",
      "factCheck": {
        "verdict": "holds-with-limit",
        "finding": "Removed 24 hours and separated Article 18 from the Article 16 notice-and-action process. Added the Member State routing rule and clarified that the duty covers hosting providers; PTS is not the police/judicial recipient of an Article 18 crime report.",
        "sources": [
          {
            "label": "Digital Services Act, Article 18",
            "url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022R2065"
          }
        ],
        "checkedBy": "GPT-6 Astra",
        "checkedAt": "2026-09-22",
        "limitations": [
          "A safety-related content flag does not establish provider status or the statutory suspicion. Article 18 itself imposes no general retention period or monitoring duty."
        ],
        "label": "Holds, with a limit",
        "tone": "limit"
      }
    },
    {
      "key": "EU_DATA_ACT_ART_32",
      "code": "DATA-ACT-2023-2854",
      "shortLabel": "Data Act Art. 32",
      "title": "Safeguards against conflicting third-country governmental access to non-personal data",
      "statute": "Regulation (EU) 2023/2854, Article 32",
      "eurLexUrl": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32023R2854",
      "deadlineHours": null,
      "deadlineLabel": "Ongoing safeguards; customer notice before complying with a governmental request, subject to Article 32(5)'s exception",
      "authority": {
        "name": "Post- och telestyrelsen (Data Act competent authority); Article 32(3) opinions involve the relevant authority for international legal cooperation",
        "acronym": "PTS / relevant authority",
        "country": "SE",
        "portalUrl": "https://pts.se/internet-och-telefoni/dataforordningen/"
      },
      "summary": "Providers of data processing services must safeguard non-personal data held in the EU against third-country governmental access or transfer that conflicts with EU or national law, subject to Article 32(2)–(3). Permitted disclosures are limited to the minimum data. The customer is informed before compliance unless the law-enforcement exception applies. This is not a general connected-device breach notification rule.",
      "requiredFacts": [
        "connected_device_data_breach"
      ],
      "remedialPlaybook": [
        "Check whether this involves a data processing service, non-personal data held in the EU, and third-country governmental access. A connected-device breach by itself is insufficient.",
        "Assess the request against Article 32(2)–(3) and the applicable international agreement or safeguards before disclosing data.",
        "Obtain an opinion from the relevant national body when required by Article 32(3), including the national-security or defence condition.",
        "Where compliance is lawful, limit disclosure and notify the customer in accordance with Article 32(4)–(5). Assess any personal-data breach separately under GDPR."
      ],
      "severity": "high",
      "factCheck": {
        "verdict": "holds-with-limit",
        "finding": "Replaced the mismatched IoT-breach summary and unsupported PTS breach-notification instruction with Article 32's actual scope. Article 11 permits technical protection measures; it is not the claimed reporting duty. PTS confirms its designation but states that enforcement possibilities remain limited pending complementary legislation.",
        "sources": [
          {
            "label": "Data Act, Articles 11, 32 and 50",
            "url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32023R2854"
          },
          {
            "label": "PTS: Data Act designation and current limits on enforcement",
            "url": "https://pts.se/internet-och-telefoni/dataforordningen/"
          }
        ],
        "checkedBy": "GPT-6 Astra",
        "checkedAt": "2026-09-22",
        "limitations": [
          "The legacy connected_device_data_breach key is retained solely as a broad screening signal and cannot establish Article 32 applicability. The relevant Article 32(3) international-cooperation authority depends on the request; PTS must not automatically be treated as that authority."
        ],
        "label": "Holds, with a limit",
        "tone": "limit"
      }
    },
    {
      "key": "EU_CRA_ART_11",
      "code": "CRA-ART-14",
      "shortLabel": "CRA Sårbarhet",
      "title": "Manufacturer reporting of exploited product vulnerabilities and severe security incidents",
      "statute": "Regulation (EU) 2024/2847, Articles 2, 14, 16, 69(3) and 71",
      "eurLexUrl": "https://eur-lex.europa.eu/eli/reg/2024/2847/oj",
      "deadlineHours": null,
      "deadlineLabel": "From manufacturer awareness: without undue delay, early warning within 24 hours and notification within 72 hours; different final-report triggers apply",
      "authority": {
        "name": "Designated coordinating CSIRT and ENISA; CERT-SE at NCSC for Sweden",
        "acronym": "CERT-SE / ENISA",
        "country": "EU",
        "portalUrl": "https://portal.cra-srp.enisa.europa.eu/"
      },
      "summary": "Since 11 September 2026, manufacturers of products within CRA scope must report actively exploited vulnerabilities and severe product-security incidents through the single reporting platform. Article 14, rather than Article 11, establishes this duty. The deadline starts when the manufacturer becomes aware, not when an app report is created.",
      "requiredFacts": [
        "product_cyber_vulnerability"
      ],
      "remedialPlaybook": [
        "Suggested workflow: confirm CRA product scope, the responsible manufacturer, exploitation or incident severity, and the time of awareness.",
        "Where the duty applies, submit the early warning and subsequent notification through ENISA's platform to the appropriate coordinating CSIRT.",
        "Track the final report separately: vulnerabilities, within 14 days after a corrective or mitigating measure becomes available; severe incidents, within one month after the incident notification.",
        "Suggested workflow: coordinate mitigation and user communications with the security team and retain the reporting evidence."
      ],
      "severity": "critical",
      "factCheck": {
        "verdict": "holds-with-limit",
        "finding": "Corrected the article, reporting recipient and legal trigger. Article 14 applies from 11 September 2026, including its transitional application to products already on the market. Most other CRA obligations apply from 11 December 2027. The national CSIRT is CERT-SE at NCSC; the former MSB attribution is obsolete.",
        "sources": [
          {
            "label": "CRA, Articles 2, 14, 16, 69 and 71",
            "url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R2847"
          },
          {
            "label": "European Commission: CRA reporting obligations and platform",
            "url": "https://digital-strategy.ec.europa.eu/en/policies/cra-reporting"
          },
          {
            "label": "NCSC: Swedish CRA reporting and CERT-SE",
            "url": "https://www.ncsc.se/sv/radgivning-och-stod/krav-och-regler-inom-informationssakerhet-och-cybersakerhet/cyberresiliensforordningen/"
          }
        ],
        "checkedBy": "GPT-6 Astra",
        "checkedAt": "2026-09-22",
        "limitations": [
          "A vulnerability keyword does not establish active exploitation, manufacturer status, product scope or awareness time. Article 2 exclusions require individual assessment.",
          "No automatic deadline is calculated from the incident record's timestamp.",
          "The legacy registry key EU_CRA_ART_11 is retained for compatibility; its corrected citation and display code identify Article 14."
        ],
        "label": "Holds, with a limit",
        "tone": "limit"
      }
    },
    {
      "key": "EU_PAY_TRANSPARENCY_DIR",
      "code": "EU-PAY-2023-970",
      "shortLabel": "Lönetransparens",
      "title": "EU pay-transparency framework; Swedish implementation must be checked",
      "statute": "Directive (EU) 2023/970, Articles 7, 9, 10 and 34",
      "eurLexUrl": "https://eur-lex.europa.eu/eli/dir/2023/970/oj",
      "deadlineHours": null,
      "deadlineLabel": "Directive: requested pay information within two months; this is not a verified general Swedish employer deadline",
      "authority": {
        "name": "Diskrimineringsombudsmannen (Swedish equal-pay supervision and implementation information)",
        "acronym": "DO",
        "country": "SE",
        "portalUrl": "https://www.do.se/for-arbetsgivare-och-utbildningsanordnare/lonetransparens-och-jamstallda-loner"
      },
      "summary": "The directive provides rights to individual pay information and sex-disaggregated averages for equal work or work of equal value. Its transposition deadline was 7 June 2026. DO reports that Sweden has not presented an implementing bill; do not present all directive provisions as enacted Swedish employer duties.",
      "requiredFacts": [
        "pay_secrecy_or_gender_gap"
      ],
      "remedialPlaybook": [
        "Suggested workflow: check the applicable Swedish law, employer category and any relevant collective agreement before determining an enforceable duty.",
        "Suggested workflow: document the request, pay categories and objective gender-neutral criteria while protecting personal data.",
        "Where Article 7 is applicable, provide the required written information within a reasonable period, at most two months after the request.",
        "For employers subject to Article 9 reporting, Article 10's joint assessment requires all three conditions: a category gap of at least 5%, no objective gender-neutral justification, and no remedy within six months after the pay report."
      ],
      "severity": "medium",
      "factCheck": {
        "verdict": "holds-with-limit",
        "finding": "Corrected the 5% threshold and the cumulative joint-assessment conditions. Salary disclosure protection under Article 7(5) concerns enforcing equal pay; it is not an unrestricted right to disclose colleagues' data. Swedish implementation remains unresolved in the official DO information reviewed.",
        "sources": [
          {
            "label": "Directive 2023/970, Articles 7, 9, 10 and 34",
            "url": "https://eur-lex.europa.eu/eli/dir/2023/970/oj"
          },
          {
            "label": "DO: implementation status and existing equal-pay work",
            "url": "https://www.do.se/for-arbetsgivare-och-utbildningsanordnare/lonetransparens-och-jamstallda-loner"
          },
          {
            "label": "Government, June 2026: continued implementation preparations",
            "url": "https://www.regeringen.se/contentassets/e15d015960a3483fb3ed90cc8fbb89a4/uppdrag-att-fortsatta-forberedelserna-av-genomforande-av-lonetransparensdirektivet-genom-framjandeinsatser.pdf"
          }
        ],
        "checkedBy": "GPT-6 Astra",
        "checkedAt": "2026-09-22",
        "limitations": [
          "This entry does not resolve whether a particular provision has direct effect against a particular public-sector employer.",
          "Existing Swedish anti-discrimination and pay-survey duties remain separate from the unimplemented directive provisions.",
          "The screening fact does not establish reporting headcount thresholds or all joint-assessment conditions."
        ],
        "label": "Holds, with a limit",
        "tone": "limit"
      }
    },
    {
      "key": "EU_CSDDD_DIR_2024",
      "code": "EU-CSDDD-2024-1760",
      "shortLabel": "CSDDD Due Diligence",
      "title": "Future corporate sustainability due-diligence framework",
      "statute": "Directive (EU) 2024/1760, Articles 2, 7–12 and 37, as amended by Directives (EU) 2025/794 and 2026/470",
      "eurLexUrl": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:02024L1760-20260318",
      "deadlineHours": null,
      "deadlineLabel": "Company application from 26 July 2029; no CSDDD incident-report countdown as of this review",
      "authority": {
        "name": "National supervisory authority designated under the applicable implementing law",
        "acronym": "National authority",
        "country": "EU"
      },
      "summary": "The amended directive establishes future due-diligence duties concerning adverse human-rights and environmental impacts. Main EU-company thresholds are more than 5,000 employees and worldwide turnover above EUR 1.5 billion; alternative parent-company, non-EU and franchise/licensing rules also apply. It is not a current general reporting duty for every supply-chain incident.",
      "requiredFacts": [
        "supply_chain_human_rights_abuse"
      ],
      "remedialPlaybook": [
        "Suggested preparation: assess company and group scope under the amended Article 2 and the national implementation timetable.",
        "Suggested preparation: document reported impacts and assess duties already applicable under employment, environmental and other law.",
        "Suggested preparation: develop proportionate due-diligence, prevention, mitigation and remediation procedures with responsible specialists.",
        "Suggested preparation: assess supplier engagement and any suspension individually; this entry does not prescribe automatic contract termination or compensation."
      ],
      "severity": "high",
      "factCheck": {
        "verdict": "holds-with-limit",
        "finding": "The March 2026 consolidated text includes Directive 2026/470. It changes scope and postpones company application to 26 July 2029, with national transposition due by 26 July 2028. Prevention and cessation/minimisation are addressed by Articles 10 and 11; the previous present-tense description and automatic termination/compensation playbook overstated the law.",
        "sources": [
          {
            "label": "CSDDD consolidated 18 March 2026",
            "url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:02024L1760-20260318"
          },
          {
            "label": "Amending Directive 2026/470",
            "url": "https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32026L0470"
          },
          {
            "label": "European Commission: current CSDDD scope and application",
            "url": "https://international-partnerships.ec.europa.eu/eu-due-diligence-navigator-partner-countries/corporate-sustainability-due-diligence-directive-csddd_en"
          }
        ],
        "checkedBy": "GPT-6 Astra",
        "checkedAt": "2026-09-22",
        "limitations": [
          "No Swedish implementing act or final Swedish supervisory designation was verified; no specific Swedish recipient is asserted.",
          "The scope summary is not an exhaustive Article 2 eligibility test; financial-year, parent, franchise and exemption conditions require separate assessment.",
          "This entry cannot establish whether another current law already requires action for the reported harm."
        ],
        "label": "Holds, with a limit",
        "tone": "limit"
      }
    },
    {
      "key": "EU_MDR_ART_87",
      "code": "MDR-ART-87",
      "shortLabel": "MDR Medicinteknik",
      "title": "Manufacturer reporting of serious incidents under the Medical Devices Regulation",
      "statute": "Regulation (EU) 2017/745, Articles 87 and 89",
      "eurLexUrl": "https://eur-lex.europa.eu/eli/reg/2017/745/oj",
      "deadlineHours": null,
      "deadlineLabel": "Manufacturer awareness: at most 2 days for a serious public-health threat; 10 days for death or unanticipated serious deterioration; 15 days otherwise; earlier reporting duties apply",
      "authority": {
        "name": "Läkemedelsverket for relevant incidents in Sweden",
        "acronym": "Läkemedelsverket",
        "country": "SE",
        "portalUrl": "https://www.lakemedelsverket.se/sv/rapportera-biverkningar/medicinteknik"
      },
      "summary": "Article 87 concerns manufacturers of devices made available on the EU market, excluding investigational devices. Reportable serious incidents and field safety corrective actions have distinct rules. In-vitro diagnostics are governed separately by Regulation (EU) 2017/746; a malfunction or software involvement alone does not establish MDR reportability.",
      "requiredFacts": [
        "medical_device_malfunction"
      ],
      "remedialPlaybook": [
        "Suggested workflow: identify the responsible manufacturer, device regime, incident severity, awareness time and causal relationship.",
        "When reportable, follow Läkemedelsverket's current reporting instructions. Article 87 requires reporting before the outer deadline once the relevant causal threshold is met; serious public-health threats require immediate reporting.",
        "Where reportability is uncertain, Article 87(7) still requires reporting within the applicable period. An incomplete initial report can be followed by a complete report.",
        "Suggested workflow: preserve evidence and coordinate investigation, risk controls, corrective actions and safety communications with the manufacturer and authority."
      ],
      "severity": "critical",
      "factCheck": {
        "verdict": "holds-with-limit",
        "finding": "Removed the misleading universal 48-hour clock, IVD scope and Commission-as-recipient wording. Article 87 has 2/10/15-day outer limits, causal-trigger rules, an expected-side-effect exception, and authority-agreed periodic reporting. FSCA normally must be reported in advance without undue delay, except urgent action. Current Commission material describes the December 2025 simplification as a proposal, not an enacted replacement clock.",
        "sources": [
          {
            "label": "MDR Article 87, consolidated 10 January 2025",
            "url": "https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:02017R0745-20250110"
          },
          {
            "label": "Läkemedelsverket: medical-device reporting",
            "url": "https://www.lakemedelsverket.se/sv/rapportera-biverkningar/medicinteknik"
          },
          {
            "label": "European Commission: current medical-device legislation and proposals",
            "url": "https://health.ec.europa.eu/medical-devices-new-regulations/overview_en"
          }
        ],
        "checkedBy": "GPT-6 Astra",
        "checkedAt": "2026-09-22",
        "limitations": [
          "The screening fact does not establish medical-device classification, seriousness, causality, responsible actor or applicable transition rules.",
          "EUDAMED module availability and the appropriate submission route must be checked against the authority's current instructions; no universally available EUDAMED route is asserted.",
          "Healthcare-provider reporting and IVDR Article 82 require separate assessment."
        ],
        "label": "Holds, with a limit",
        "tone": "limit"
      }
    },
    {
      "key": "EU_ELD_2004_35",
      "code": "ELD-2004-35",
      "shortLabel": "Miljöansvarsdirektivet",
      "title": "Serious environmental damage and imminent threats: Swedish notification duties",
      "statute": "Directive 2004/35/EC; Miljöbalken (1998:808), 10 kap. 1 and 12–14 §§; Förordning (2007:667) om allvarliga miljöskador",
      "eurLexUrl": "https://data.riksdagen.se/dokument/sfs-1998-808",
      "deadlineHours": null,
      "deadlineLabel": "Genast on discovering an imminent threat of, or actual, serious environmental damage under Miljöbalken 10 kap. 12–13 §§; no fixed 24-hour period",
      "authority": {
        "name": "The competent environmental supervisory authority, determined for the activity and location",
        "acronym": "Tillsynsmyndigheten",
        "country": "SE",
        "portalUrl": "https://www.naturvardsverket.se/vagledning-och-stod/fororenade-omraden/ansvar-for-avhjalpande-av-fororeningsskada/"
      },
      "summary": "Swedish operators must immediately notify the competent supervisory authority when they discover an imminent threat of serious environmental damage or actual serious environmental damage. The statutory severity definition must be met. The EU framework's strict liability covers Annex III activities; liability for other activities is narrower and fault-dependent.",
      "requiredFacts": [
        "environmental_spill_or_pollution"
      ],
      "remedialPlaybook": [
        "Suggested workflow: obtain competent environmental assessment, identify the operator and supervisory authority, and document the threat or damage.",
        "Where Miljöbalken 10 kap. 12–13 §§ applies, notify immediately and provide the required information about measures taken, planned and needed.",
        "If preventive measures do not avert the threat, provide the further notification required by 12 § as soon as possible.",
        "Suggested workflow: coordinate safe containment, assessment and remediation with the authority; check approvals needed before remediation work."
      ],
      "severity": "critical",
      "factCheck": {
        "verdict": "holds-with-limit",
        "finding": "Verified the Swedish operator notifications in 10 kap. 12–13 §§ and removed the invented 24-hour limit. Naturvårdsverket is not a universal incident recipient. The EU scope is supported by the Commission's environmental-liability explanation; the former blanket assertion of strict liability was too broad.",
        "sources": [
          {
            "label": "Miljöbalken, especially 10 kap. 1 and 12–14 §§",
            "url": "https://data.riksdagen.se/dokument/sfs-1998-808"
          },
          {
            "label": "Förordning (2007:667) om allvarliga miljöskador",
            "url": "https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/forordning-2007667-om-allvarliga-miljoskador_sfs-2007-667/"
          },
          {
            "label": "European Commission: environmental-liability scope",
            "url": "https://environment.ec.europa.eu/law-and-governance/environmental-compliance-assurance/environmental-liability_en"
          },
          {
            "label": "Naturvårdsverket: Swedish remediation liability and notification",
            "url": "https://www.naturvardsverket.se/vagledning-och-stod/fororenade-omraden/ansvar-for-avhjalpande-av-fororeningsskada/"
          }
        ],
        "checkedBy": "GPT-6 Astra",
        "checkedAt": "2026-09-22",
        "limitations": [
          "A pollution keyword does not establish serious environmental damage, causation or operator liability.",
          "All ELD exclusions, limitation periods and liability defences were not individually audited; the operative Swedish notification provisions were read directly.",
          "Identify the competent authority for the particular site; commonly this is a municipality or county administrative board, but the allocation is not universal."
        ],
        "label": "Holds, with a limit",
        "tone": "limit"
      }
    },
    {
      "key": "EU_IED_2024_1785",
      "code": "IED-2024-1785",
      "shortLabel": "IED Industriutsläpp",
      "title": "Industrial incidents, permit breaches and Swedish operational-disturbance notification",
      "statute": "Directive 2010/75/EU, Articles 7–8, as amended by Directive (EU) 2024/1785; Förordning (1998:901) om verksamhetsutövares egenkontroll, 1 and 6 §§",
      "eurLexUrl": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:02010L0075-20240804",
      "deadlineHours": null,
      "deadlineLabel": "Immediately under IED Articles 7–8; omgående under Swedish egenkontroll 6 § when its disturbance and scope conditions are met; no 24-hour allowance",
      "authority": {
        "name": "Competent environmental supervisory authority for the installation",
        "acronym": "Tillsynsmyndigheten",
        "country": "SE"
      },
      "summary": "IED addresses significant incidents and permit breaches at installations within its scope. Separately, Sweden's egenkontroll ordinance requires covered operators to notify promptly of an operational disturbance or similar event that can cause harm or nuisance to health or the environment. An emissions keyword does not determine installation scope or the applicable permit.",
      "requiredFacts": [
        "industrial_emission_exceedance"
      ],
      "remedialPlaybook": [
        "Suggested workflow: confirm the installation's legal scope, permit conditions, actual exceedance or disturbance and competent supervisory authority.",
        "Where the Swedish notification conditions are met, notify the supervisory authority promptly under egenkontroll 6 §.",
        "Suggested workflow: use the site's approved emergency procedures and competent personnel to limit harm and restore compliance.",
        "Assess suspension under the applicable law and permit: IED Article 8(3) addresses breaches posing immediate danger to health or an immediate significant environmental threat."
      ],
      "severity": "high",
      "factCheck": {
        "verdict": "holds-with-limit",
        "finding": "Corrected the operative articles, Swedish notification source and authority role. A permitting delegation is not automatically the supervisory recipient. Removed the invented 24-hour period and the generic instruction to bypass production controls. The EU amendment's national transposition deadline was 1 July 2026.",
        "sources": [
          {
            "label": "IED consolidated 4 August 2024, Articles 7–8",
            "url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:02010L0075-20240804"
          },
          {
            "label": "Förordning (1998:901), scope and operational-disturbance duty",
            "url": "https://data.riksdagen.se/dokument/sfs-1998-901"
          },
          {
            "label": "Naturvårdsverket: amendments to IED and transposition timetable",
            "url": "https://www.naturvardsverket.se/vagledning-och-stod/industriutslapp-ied/industriutslappsdirektivet-ied/andringar-i-ied/"
          }
        ],
        "checkedBy": "GPT-6 Astra",
        "checkedAt": "2026-09-22",
        "limitations": [
          "Full Swedish implementation of every 2024/1785 amendment was not verified; the Swedish notification statement is grounded in the separately verified egenkontroll provision.",
          "The registry does not encode installation categories, permit conditions or transitional application dates.",
          "Technical shutdown, containment and monitoring measures must be selected for the actual installation."
        ],
        "label": "Holds, with a limit",
        "tone": "limit"
      }
    },
    {
      "key": "EU_SEVESO_III",
      "code": "SEVESO-III-2012-18",
      "shortLabel": "Seveso Kemikalieolycka",
      "title": "Accident reporting at dangerous installations and Seveso supervision",
      "statute": "Directive 2012/18/EU; Lag (1999:381); Förordning (2003:789) om skydd mot olyckor, 2 kap. 4 §",
      "eurLexUrl": "https://data.riksdagen.se/dokument/sfs-2003-789",
      "deadlineHours": null,
      "deadlineLabel": "Omgående to the municipality and Myndigheten för civilt försvar under FSO 2 kap. 4 §; call 112 for an emergency; no fixed 24-hour period",
      "authority": {
        "name": "Municipality and Myndigheten för civilt försvar; Länsstyrelsen for Seveso supervision",
        "acronym": "Kommun / MCF / Länsstyrelsen",
        "country": "SE",
        "portalUrl": "https://www.mcf.se/"
      },
      "summary": "At installations covered by LSO 2 kap. 4 §, the owner or operator must promptly inform the municipality and Myndigheten för civilt försvar of an accident capable of causing serious human or environmental damage, or an imminent danger of such an accident. Seveso coverage depends on specified dangerous substances and thresholds.",
      "requiredFacts": [
        "major_chemical_accident_or_seveso"
      ],
      "remedialPlaybook": [
        "Suggested emergency response: call 112 when emergency assistance is needed and follow the site's emergency procedures and rescue-service directions.",
        "Where FSO 2 kap. 4 § applies, promptly inform the municipality and MCF about the circumstances, dangerous substances, available impact information and rescue measures.",
        "Provide planned restoration and recurrence-prevention information as soon as possible under the same provision.",
        "Suggested workflow: preserve incident evidence and coordinate follow-up with the relevant supervisory authority."
      ],
      "severity": "critical",
      "factCheck": {
        "verdict": "holds-with-limit",
        "finding": "Replaced the unsubstantiated 24-hour clock with the Swedish operative duty and its actual recipients. FSO 2 kap. 4 § includes imminent danger as well as accidents. The consolidated law reflects the agency's change from MSB to Myndigheten för civilt försvar. Länsstyrelsen remains a Seveso supervisory authority, distinct from the FSO reporting recipients.",
        "sources": [
          {
            "label": "FSO (2003:789), 2 kap. 4 §, amended by 2025:1114",
            "url": "https://data.riksdagen.se/dokument/sfs-2003-789"
          },
          {
            "label": "Seveso law (1999:381), including 15 §",
            "url": "https://data.riksdagen.se/dokument/sfs-1999-381"
          },
          {
            "label": "Seveso ordinance (2015:236), scope, thresholds and supervision",
            "url": "https://data.riksdagen.se/dokument/sfs-2015-236"
          },
          {
            "label": "MCF: Seveso public information",
            "url": "https://www.mcf.se/sv/amnesomraden/skydd-mot-olyckor-och-farliga-amnen/farlig-verksamhet/seveso/information-till-allmanheten-i-narheten-av-en-sevesoverksamhet/"
          }
        ],
        "checkedBy": "GPT-6 Astra",
        "checkedAt": "2026-09-22",
        "limitations": [
          "The screening fact does not establish dangerous-installation designation, Seveso quantities or the installation's lower/higher tier.",
          "An emergency call does not replace the separate statutory information requirements.",
          "Site-specific permit and emergency-plan requirements are outside this summary."
        ],
        "label": "Holds, with a limit",
        "tone": "limit"
      }
    },
    {
      "key": "EU_WASTE_REG_2024",
      "code": "WASTE-2020-614",
      "shortLabel": "Farligt avfall & Avfallsförordningen",
      "title": "Swedish hazardous-waste records and electronic reporting",
      "statute": "Avfallsförordningen (2020:614), 6 kap. 1–5 and 11–14 §§; transport documents under 6 kap. 19 §",
      "eurLexUrl": "https://data.riksdagen.se/dokument/sfs-2020-614",
      "deadlineHours": null,
      "deadlineLabel": "Electronic reporting no later than two working days after the applicable record-making or compilation deadline; corrections as soon as possible",
      "authority": {
        "name": "Naturvårdsverket (waste register); relevant environmental supervisory authority",
        "acronym": "Naturvårdsverket",
        "country": "SE",
        "portalUrl": "https://www.naturvardsverket.se/verktyg-och-tjanster/e-tjanster/avfallsregistret/"
      },
      "summary": "Actors required to record hazardous-waste information under 6 kap. 1–5 §§ must generally submit it electronically to the waste register within the separate 11 § reporting period. Record deadlines vary by activity. Two working days is not 48 hours, and the period does not begin when a suspected violation is reported in this app.",
      "requiredFacts": [
        "hazardous_waste_violation"
      ],
      "remedialPlaybook": [
        "Suggested workflow: identify the waste classification, actor role, handling event and applicable recording deadline.",
        "Where required, submit the recorded information to Naturvårdsverket's waste register within the statutory working-day period.",
        "If submitted information is incorrect, provide corrected information electronically as soon as possible under 6 kap. 12 §.",
        "Suggested workflow: verify transport documentation and authorisations; assess any spill, suspected crime or cross-border shipment separately."
      ],
      "severity": "high",
      "factCheck": {
        "verdict": "holds-with-limit",
        "finding": "Corrected the source, deadline unit and trigger. The two-working-day register rule comes from Swedish 6 kap. 11 §, not Regulation 2024/1157. Removed an unsupported blanket immediate duty to report every suspected illegal dumping event and the claim that carriers must be 'certified'.",
        "sources": [
          {
            "label": "Avfallsförordningen, 6 kap. 1–5 and 11–14 §§",
            "url": "https://data.riksdagen.se/dokument/sfs-2020-614"
          },
          {
            "label": "Naturvårdsverket: recording and reporting requirements",
            "url": "https://www.naturvardsverket.se/avfallsregister"
          },
          {
            "label": "Naturvårdsverket: register service",
            "url": "https://www.naturvardsverket.se/verktyg-och-tjanster/e-tjanster/avfallsregistret/"
          },
          {
            "label": "Naturvårdsverket: domestic waste transport",
            "url": "https://www.naturvardsverket.se/vagledning-och-stod/avfall/avfallstransporter-inom-sverige/"
          }
        ],
        "checkedBy": "GPT-6 Astra",
        "checkedAt": "2026-09-22",
        "limitations": [
          "Reporting exemptions and special routes, including security-classified information and defence authorities, need individual assessment.",
          "Cross-border shipment obligations under Regulation 2024/1157 are not audited or represented by this domestic-register entry.",
          "The legacy key is retained; its title and citation now accurately identify the rule reviewed."
        ],
        "label": "Holds, with a limit",
        "tone": "limit"
      }
    },
    {
      "key": "EU_EUDR_2023_1115",
      "code": "EUDR-2023-1115",
      "shortLabel": "EUDR Avskogningsförordningen",
      "title": "Deforestation-free products: upcoming duties and commodity-specific scope",
      "statute": "Regulation (EU) 2023/1115, Articles 3–5 and 38 and Annex I, as amended by Regulations (EU) 2024/3234, 2025/2650 and Delegated Regulation (EU) 2026/2102",
      "eurLexUrl": "https://eur-lex.europa.eu/eli/reg/2023/1115/oj",
      "deadlineHours": null,
      "deadlineLabel": "Main application 30 December 2026; qualifying micro/small operators 30 June 2027; newly added Annex I products 30 December 2027; role-specific pre-market/export requirements",
      "authority": {
        "name": "Skogsstyrelsen",
        "acronym": "Skogsstyrelsen",
        "country": "SE",
        "portalUrl": "https://www.skogsstyrelsen.se/lag-och-tillsyn/avskogningsforordningen/"
      },
      "summary": "As of this review, the main EUDR operator/trader requirements have not started applying. Once applicable, listed products associated with cattle, cocoa, coffee, oil palm, rubber, soya and wood must meet deforestation-free, legality and documentation conditions. Product codes, role, size and transitional rules determine the actual duties; certification alone is insufficient.",
      "requiredFacts": [
        "deforestation_or_illegal_timber"
      ],
      "remedialPlaybook": [
        "Suggested preparation: determine the product's current Annex I code, actor role, size and applicable start date, including the September 2026 Annex amendment.",
        "Suggested preparation: collect origin and legality evidence and determine the applicable traceability and due-diligence requirements.",
        "Where required after application begins, complete due diligence and the appropriate EU information-system submission before placing on the market or exporting; simplified and downstream rules differ.",
        "Suggested workflow: assess current EU Timber Regulation and Swedish-law duties separately and consult Skogsstyrelsen about suspected illegal timber."
      ],
      "severity": "medium",
      "factCheck": {
        "verdict": "holds-with-limit",
        "finding": "Added the 2025 postponement and simplification and the Annex I amendment that entered into force on 18 September 2026. Newly added products apply from 30 December 2027. A universal immediate DDS duty and mandatory certification claim were incorrect. Micro/small operators already covered by the EU Timber Regulation do not receive the general June 2027 deferral.",
        "sources": [
          {
            "label": "EUDR consolidated 26 December 2025",
            "url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:02023R1115-20251226"
          },
          {
            "label": "Regulation 2025/2650: postponed application and actor simplification",
            "url": "https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=CELEX:32025R2650"
          },
          {
            "label": "Delegated Regulation 2026/2102: updated Annex I",
            "url": "https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32026R2102"
          },
          {
            "label": "Skogsstyrelsen: current dates, scope and Swedish authority",
            "url": "https://www.skogsstyrelsen.se/lag-och-tillsyn/avskogningsforordningen/"
          },
          {
            "label": "European Commission: current EUDR application and new product dates",
            "url": "https://environment.ec.europa.eu/topics/forests/deforestation/regulation-deforestation-free-products_en"
          }
        ],
        "checkedBy": "GPT-6 Astra",
        "checkedAt": "2026-09-22",
        "limitations": [
          "The registry does not encode all customs codes, exceptions, transitional timber rules or the simplified micro/small primary-operator regime.",
          "Annex I was checked for the amendment and its application dates, not as a complete product-by-product classification audit.",
          "A deforestation keyword cannot establish EUDR scope or a present breach."
        ],
        "label": "Holds, with a limit",
        "tone": "limit"
      }
    },
    {
      "key": "EU_REACH_CLP",
      "code": "REACH-CLP-1907-2006",
      "shortLabel": "REACH & CLP Kemikaliesäkerhet",
      "title": "Substance-specific chemical restrictions, authorisation and hazard communication",
      "statute": "Regulation (EC) 1907/2006 (REACH), including Articles 31, 33, 56 and 67 and Annexes XIV/XVII; Regulation (EC) 1272/2008 (CLP)",
      "eurLexUrl": "https://eur-lex.europa.eu/eli/reg/2006/1907/oj",
      "deadlineHours": null,
      "deadlineLabel": "No single incident-notification clock; duties and dates depend on the substance, use, actor and applicable provision",
      "authority": {
        "name": "Kemikalieinspektionen and other competent authorities according to product, activity and supervision allocation",
        "acronym": "KemI / relevant authority",
        "country": "SE",
        "portalUrl": "https://www.kemi.se/"
      },
      "summary": "REACH restrictions and authorisation requirements depend on listed substances, uses, thresholds and exemptions. SVHC Candidate List status is not itself a general ban, and PFAS are not universally prohibited. Applicable chemical products require CLP classification, labelling and packaging and REACH safety information. This entry does not establish a general incident-report duty to KemI.",
      "requiredFacts": [
        "toxic_chemical_or_pfas_hazard"
      ],
      "remedialPlaybook": [
        "Suggested workflow: identify the substance, concentration, product type, use and supply-chain role before determining any restriction or authorisation requirement.",
        "Suggested workflow: check the current binding REACH annex entry and other applicable regimes, including POPs and product-specific PFAS rules where relevant.",
        "Review classification, labels and safety data sheets; REACH Article 31(9) requires SDS updates without delay on its specified new-information, authorisation or restriction triggers.",
        "Suggested workflow: assess exposure and environmental risks with competent personnel and determine the particular corrective and reporting duties; do not assume an automatic KemI report."
      ],
      "severity": "high",
      "factCheck": {
        "verdict": "holds-with-limit",
        "finding": "Replaced the blanket SVHC/PFAS prohibition and unsupported general notification claim with substance-specific scope. KemI's current information distinguishes Candidate List status, authorisation, restrictions and the proposed broad PFAS restriction. The SDS update trigger is real but is not a universal incident deadline. CLP has continuing amendments and transitional rules.",
        "sources": [
          {
            "label": "KemI: Candidate List and resulting duties",
            "url": "https://www.kemi.se/lagar-och-regler/lagstiftningar-inom-kemikalieomradet/eu-gemensam-lagstiftning/reach-forordningen/kandidatforteckningen"
          },
          {
            "label": "KemI: current PFAS rules and proposed broad restriction",
            "url": "https://www.kemi.se/hallbarhet/amnen-och-material/pfas"
          },
          {
            "label": "KemI: safety data sheets and Article 31 update triggers",
            "url": "https://www.kemi.se/lagar-och-regler/lagstiftningar-inom-kemikalieomradet/eu-gemensam-lagstiftning/reach-forordningen/sakerhetsdatablad"
          },
          {
            "label": "KemI: CLP scope and requirements",
            "url": "https://www.kemi.se/lagar-och-regler/lagstiftningar-inom-kemikalieomradet/eu-gemensam-lagstiftning/clp-forordningen/kort-om-clp-forordningen"
          },
          {
            "label": "EUR-Lex: CLP and current consolidation link",
            "url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32008R1272"
          }
        ],
        "checkedBy": "GPT-6 Astra",
        "checkedAt": "2026-09-22",
        "limitations": [
          "This is an agency-guidance-supported overview, not a complete audit of every amended REACH/CLP article or chemical annex entry.",
          "No particular PFAS product or concentration has been legally classified by this review; additional POPs, packaging or national rules may apply.",
          "The screening fact cannot determine authorisation, restrictions, SDS applicability or the competent enforcement authority."
        ],
        "label": "Holds, with a limit",
        "tone": "limit"
      }
    }
  ]
}
