evidoria

← Back to browse

Good practice Imported

IMY's Regulatory Sandbox — Testing Crowd-Safety LiDAR Sensors Against Sweden's Privacy Law

Sweden · Stockholm · See the Sweden profile · See the Stockholm profile

Evidence: Descriptive / self-reported Top 50% 60/100 · Ask Evidence Copilot about this practice

Sweden's data-protection authority ran a 2023 sandbox pilot with Stockholm's Traffic Office, testing whether LiDAR sensors counting women, men and children in public squares are lawful under the GDPR and Camera Surveillance Act, publishing its legal findings in February 2024.

IMY's Regulatory Sandbox — Testing Crowd-Safety LiDAR Sensors Against Sweden's Privacy Law

Details

Maturity
Established
Promoter
Integritetsskyddsmyndigheten (IMY) with City of Stockholm Traffic Office, IoT Sverige and Kista Science City AB
Period
2023-2024
Region (NUTS)
SE11
Keywords
data protection, IoT, urban safety, regulatory guidance

Context

Sweden's data-protection authority IMY established a regulatory sandbox in 2022 to give organisations dialogue-based guidance on applying data-protection law to specific innovation projects.

Objectives

The second sandbox pilot, run in summer and autumn 2023, aimed to clarify whether LiDAR sensors and an AI classifier that estimate the gender and age of people crossing public squares are lawful under Sweden's GDPR and Camera Surveillance Act.

Activities

IMY worked with the City of Stockholm's Traffic Office, IoT Sverige and Kista Science City AB on a project using LiDAR sensors to build 3D point-clouds and classify people as women, men or children, testing the hypothesis that squares visited by more women and children are perceived as safer.

Results

IMY found it highly probable that the LiDAR/AI output constitutes personal-data processing under GDPR, and that the sensors are typically covered by the Camera Surveillance Act when a public authority operates them in a public place, even though no identifiable images are stored. It published its full reasoning in a report and webinar on 9 February 2024.

Conclusions

The sandbox delivered legal clarity, not a deployment authorisation -- IMY did not exempt the Traffic Office from GDPR or camera-surveillance rules, and after two completed pilots IMY made the sandbox a permanent institution later in 2023 with a widened mandate and recurring project rounds.

Implementation

Indicative cost
Low (< €50k)
Time to results
Short (< 1 year)
Staffing & skills
Integritetsskyddsmyndigheten (IMY), City of Stockholm Traffic Office, IoT Sverige, Kista Science City AB

Conditions for success

  • Dialogue-based regulatory sandbox structure enabling in-depth guidance rather than a simple yes/no approval
  • Multi-partner project design combining a public agency, an innovation cluster and a science-park operator
  • Public reporting of legal reasoning building institutional trust and transferability

Common failure modes

  • Sandbox produced legal clarity but not a deployment green light, leaving the Traffic Office's own compliance decision unresolved

Commonly funded by

National / regional programmes Digital Europe Programme

Indicative funding routes for practices of this type — always check each programme's current calls and eligibility rules.

Do you run this practice? Claim it — verified implementers get a public contact pathway and can propose corrections.

Data sources

Where this practice's information was retrieved from, and when.

Attachments

Similar practices you may find useful