Sweden Annex

ANX-SE · Draft of October 6, 2026 · revision 1 · version 1.0

Final draft for counsel's review. It is not in effect, and no clinic has accepted it. Items still to be confirmed are highlighted in the text.

This is the controlling text.

SHA-256 of this text: 4d8c9d2c872b96d7621ca2fc60dd389071114bf085c946e6eaeec7acd8d294a8

Sweden — ANX-SE: Sweden Annex

Document ID: ANX-SE · Version: 1.0 · Effective date: [[TO CONFIRM: publication date]] Language: English, with a Swedish courtesy copy [[TO CONFIRM: Swedish translation]]. English controls. Applies to: Clinics established in Sweden, together with the MDPA and the EEA Transfer Module (TM-EEA). Terms defined in the MDPA have the same meaning here. Status: PREPARED, NOT YET OFFERED to new Clinics. Sweden opens when DentalX logs every read access to patient data (clause 1.3). An existing Swedish Clinic accepts this Annex now, with the dated plan in clause 1.3.


1. Access control and log follow-up (Patient Data Act, ch. 4)

1.1 The Clinic's duties. Under chapter 4 of the Patient Data Act (2008:355), the Clinic as care provider must:

  • decide the conditions for granting access to patient data;
  • ensure that access is documented and can be checked; and
  • carry out systematic and recurring checks of whether anyone has accessed patient data without authorisation (log follow-up).

1.2 What DentalX provides. DentalX provides:

  • (a) role-based access, set by the Clinic;
  • (b) a log of every access to patient data, including every read, with the User, the patient, the time and the action (MDPA Schedule 2, C.12); and
  • (c) a log-review report the Clinic can run and export for its recurring checks.

1.3 Opening condition. Items (b) and (c) are conditions for offering DentalX to Swedish Clinics. Until they are live, DentalX's audit trail covers chart openings, exports, deletions and changes only. For a Swedish Clinic that already uses DentalX, VstreamX delivers them on this dated plan: [[TO CONFIRM: dated plan for read-access logging and the log-review report]].

2. Secrecy

2.1 Flow-down. VstreamX and its personnel are bound by an obligation of secrecy equivalent to the professional secrecy (tystnadsplikt) of the Patient Safety Act (2010:659), chapter 6 (MDPA clause 5.3). VstreamX's Sub-processors are bound by the confidentiality obligations in their data processing terms, as MDPA Schedule 3 records, and the Clinic Data is protected in their hands by the encryption in MDPA Schedule 2. VstreamX does not represent that they are bound by tystnadsplikt. [[TO CONFIRM: Swedish counsel's view that this suffices]]

2.2 Outsourcing secrecy. Where the Act (2020:914) on secrecy in the outsourcing of technical processing or storage of data applies, VstreamX's personnel are also bound by the secrecy that Act provides. [[TO CONFIRM: whether Act 2020:914 covers private dental care providers and a foreign provider]]

3. Retention

3.1 The Clinic's duty. Patient records are kept for at least 10 years after the last entry (Patient Data Act, ch. 3).

3.2 DentalX's default. DentalX applies this as the default for Swedish Clinics, and does not auto-delete clinical records.

4. Prescriptions

DentalX's prescriptions are not e-prescriptions in the national system. Prescriptions in Sweden are issued through the national e-prescription systems.

5. Security breaches

VstreamX's notice within 24 hours (MDPA clause 9) allows the Clinic to notify the Swedish Authority for Privacy Protection (IMY) within 72 hours.


Items to confirm before publication (Sweden)

  1. Publication date.
  2. The Swedish courtesy translation.
  3. The dated plan for read-access logging and the log-review report; Sweden opens to new Clinics only when they are live (§1.3).
  4. Whether Act 2020:914 covers private dental care providers and a foreign provider (§2.2).
  5. Swedish counsel's view on the Sub-processors' confidentiality (§2.1).