Notice: This document is an unofficial translation of the Swedish Authority
for Privacy Protection’s decision. Only the Swedish version is authentic. 1(9)
COMPLAINANT
See Annex
CONTROLLER
Klarna Bank AB
Act number:
IMY-2025-9240 Final decision under the General Data
Case number DE-HH SA: Protection Regulation – Klarna Bank
521.14662 / 631.407
Case register in IMI:
AB
134712
Date:
2025-11-26
Decision of the Swedish Authority for Privacy
Protection
The Swedish Authority for Privacy Protection (IMY) finds that Klarna Bank AB
(556737-0431), in its handling of the complainant’s request for access made on 15
June 2021 has processed personal data in violation of:
• Article 12(6) of the General Data Protection Regulation1 by requesting more
information than is necessary to identify the complainant
• Article 12(2) of the General Data Protection Regulation by failing to facilitate
the exercise of the applicant’s right
• Article 12(3) of the General Data Protection Regulation by failing to process
the applicant’s request for access without undue delay.
IMY issues Klarna Bank AB a reprimand under Article 58(2)(b) of the General Data
Protection Regulation (GDPR) for the infringements of Articles 12(6), 12(2) and 12(3)
of the GDPR.
Presentation of the supervisory case
Background to the case
IMY has initiated supervision in case IMY-2022-7128 to investigate 28 complaints2
against Klarna Bank AB (Klarna). IMY has subsequently decided that further
investigation of each complaint will take place in separate cases.
Postal address:
Box 8114
IMY’s investigation of the complaint in the case at hand has been limited to the
104 20 Stockholm questions whether Klarna has acted in accordance with Article 12(6) of the GDPR
Website:
when Klarna requested information to identify the complainant, facilitated the exercise
www.imy.se
1 Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of
E-mail:
[email protected] natural persons with regard to the processing of personal data and on the free movement of such data, and repealing
Directive 95/46/EC (General Data Protection Regulation).
Telephone: 2 IMY initiated oversight following 29 complaints, but on 23 September 2023, the complainant withdrew complaint 14
08-657 61 00 (DI-2021-5908).
Swedish Authority for Privacy Act number: IMY-2025-9240 2(9)
Protection
Date: 2025-11-26
of the complainant’s right of access in accordance with Article 12(2) of the GDPR and
complied with the complainant’s request for access without undue delay in accordance
with Article 12(3) of the GDPR. The examination of the case concerns Klarna’s
handling of the complainant’s request for access made on 15 June 2021. IMY will
therefore not take a position on whether Klarna's current, general procedures for
handling requests comply with the General Data Protection Regulation.
The complaint in the case has been submitted to IMY, as the lead supervisory
authority under Article 56 of the GDPR. The transfer has taken place from the
supervisory authority of the country where the complainant has lodged his complaint
(Germany) in accordance with the provisions of the Regulation on cooperation in
cross-border processing.
The proceedings at IMY were conducted by exchange of letters. IMY has made use of
the cooperation and consistency mechanisms provided for in Chapter VII of the GDPR.
The supervisory authorities concerned have been the data protection authorities of
Austria, Hungary, Denmark, Germany, Norway, Finland, Italy, the Netherlands,
Poland, Ireland, France, Estonia and Spain.
Submission by the complainant
The complainant states, in essence, the following. On 15 June 2021, the complainant
requested access to his personal data pursuant to Article 15 of the GDPR. Klarna has
requested too much information to verify his identity. Klarna knows which delivery and
e-mail addresses are used for purchases made through the company. The
complainant asked Klarna to send the register extract to the address to which his
mailings and invoices are sent, which, combined with his e-mail address, has been
sufficient evidence of his identity.
The documents submitted by the applicant show the following. In its request, the
complainant provided the following information:
• Surname(s) and first name(s)
• E-mail address
On 16 June 2021, Klarna requested the complainant to provide the following
information in order to comply with the request:
• Date of birth
• E-mail address
• Invoice number
• Name of a shop purchased by the complainant
• Phone number
• Transaction ID and IBAN number in the event that the applicant has used
Klarna Open Banking via a third-party provider and wishes to have access to
the personal data stored with it.
On 18 June 2021, the applicant sent Klarna all the additional information requested.
Swedish Authority for Privacy Act number: IMY-2025-9240 3(9)
Protection
Date: 2025-11-26
Statement by Klarna
In summary, Klarna has stated the following about the issues covered by the
supervision.
Klarna received the complainant’s request for access by email on 15 June 2021 and
started the identification process on 16 June 2021. On 18 June 2021, the applicant
submitted identification points, after which Klarna provided an extract from the register
by e-mail on 22 July 2021. Klarna has therefore exceeded the deadline, but only by
four days since the identification process was completed on 18 June 2021.
In the context of meetings between Klarna and the supervisory authority in Berlin in
June to August 2021, a further copy of the complainant’s personal data was sent to the
complainant by post on 13 August 2021.
Has Klarna had reason to doubt the identity of the complainant?
Klarna has stated that the company was granted a banking licence by
Finansinspektionen in June 2017. This means, among other things, that the company
is obliged to maintain banking secrecy in accordance with Chapter 1, Section 10 of the
Banking and Financing Business Act (2004:297) and that Klarna may thus not
unlawfully disclose individuals’ relationship with Klarna as a credit institution. In
addition, Klarna processes information that many customers perceive as sensitive,
such as credit decisions, payment history and information according to the money
laundering regulations. Klarna thus needs to ensure that information is not disclosed to
unauthorised persons and that the identity of customers is not disclosed. Therefore, in
addition to the provisions of data protection law, the requirement of banking secrecy
must also be taken into account when identifying data subjects in the context of
requests for access or deletion. Furthermore, attention should be drawn to the fact that
financial institutions, such as, inter alia, banks, are particularly vulnerable to fraud
attempts of various kinds. One example is attempts to obtain personal data from third
parties that enable identity theft. Providing personal data to an unauthorized third party
would not only enable fraud at the expense of the data subject and Klarna, but
potentially also on data subjects of online merchants who have used one of Klarna's
payment methods. Consequently, Klarna must ensure that no personal data is
exposed to unauthorised persons and, if in doubt, ask for additional data points for
identification.
Klarna continuously develops its identity verification processes to ensure that
unauthorized persons cannot access customers' personal data.
At the time of the enquiry, Klarna had reason to doubt the applicant’s identity, since the
applicant had only provided his e-mail address, i.e. one of the data points necessary to
be regarded as identified in accordance with the procedure in force at the time. For this
reason, Klarna has not been able to comply with the request.
What information has Klarna required to handle the request?
Klarna states that the complainant was asked to provide the following information:
• Name
• Date of birth
• E-mail address
• Invoice number
• Name of a shop purchased by the complainant
Swedish Authority for Privacy Act number: IMY-2025-9240 4(9)
Protection
Date: 2025-11-26
• Invoice amount
• Invoicing address
• Phone number.
Why was the information necessary to confirm the identity of the complainant?
Klarna's identification routine has always been based on the assumption that a
customer's identity can be verified by the customer entering a number of different data
points that only the customer should be aware of, and to prevent unauthorized persons
from guessing the data required for identification. In order to simplify for customers,
Klarna states in the identification process the points that in different combinations can
be used to verify a customer's identity. Since customers can remember different
information and have used payment methods that require different information, Klarna
has provided the complete list of data points. However, not all information from the list
is required in each case. Instead, different combinations of these points have been
sufficient to identify the customer, depending on when in time and in which country the
request was made. In cases where a customer service employee requested additional
data points even though a customer had already provided enough information to be
identified, the cases have been incorrectly handled. An important exception is cases
where Klarna has not been able to find the customer because the information provided
by a customer has not been consistent with the information in Klarna's system. In such
cases, for example, it has been considered necessary to request an alternative e-mail
address.
In the present complaint, according to the then applicable identification procedure for
Germany, Austria, Belgium and the Netherlands, Klarna has not been able to carry out
a secure identification of the complainant and has therefore requested additional
information to ensure that the personal data of the complainant do not fall into the
wrong hands. In doing so, Klarna has indicated all the additional data points that count
as possible data points, but different combinations of those data points have been
possible for the purposes of the secure identification of the applicant.
What data was collected when the customer relationship was established and
which are new?
For identification purposes, Klarna only collects data corresponding to the data already
collected.
Justification of the decision
Article 12(2) of the of GDPR requires the controller to facilitate the exercise of the data
subject’s rights in accordance with Articles 15 to 22.
Article 12(6) of the GDPR provides that, without prejudice to Article 11 of the GDPR,
where the controller has reasonable doubts as to the identity of the natural person
making a request pursuant to Articles 15 to 21, it may request the provision of
additional information necessary to confirm the identity of the data subject.
The European Data Protection Board (EDPB) Guidelines 01/2022 on the right of
access3 state the following.
3 European Data Protection Board (EDPB) Guidelines on the right of access – Guidelines 01/2022 on data subject
rights – Right of access, version 2.0 (finally adopted on 28 March 2023) (EDPB Guidelines 01/2022).
Swedish Authority for Privacy Act number: IMY-2025-9240 5(9)
Protection
Date: 2025-11-26
Where the controller requests or receives from the data subject the additional
information necessary to confirm the identity of the data subject, the controller
shall, on a case-by-case basis, assess what information makes it possible to
confirm the identity of the data subject and, where appropriate, ask the
requesting person additional questions or request the data subject to provide
additional identification data, where this is proportionate.4
Where the controller has reasonable grounds to doubt the identity of the
requesting person, it may, as indicated above, request additional information
to confirm the identity of the data subject. Nevertheless, the controller must at
the same time ensure that it does not collect more personal data than is
necessary to enable the authentication of the requesting person. To that end,
the controller shall carry out a proportionality assessment that takes into
account the type of personal data processed (e.g. special categories of data
or not), the type of request, the context in which the request is made, and any
harm that could result from undue disclosure. When assessing proportionality,
it should be remembered to avoid unreasonable data collection while ensuring
an adequate level of security of processing.5
The controller should put in place an authentication procedure to be sure of
the identity of the persons requesting access to their data and to ensure the
security of processing throughout the processing of an access request in
accordance with Article 32 of the general data protection regulation, such as a
secure channel where data subjects can provide additional information. The
method used for authentication should be relevant, appropriate, proportionate
and consistent with the principle of data minimisation. If the controller imposes
burdensome measures aimed at authenticating the data subject, it must
provide appropriate justification and ensure compliance with all fundamental
principles, including data minimisation and the obligation to facilitate the
exercise of data subjects’ rights (Article 12(2) of the general data protection
regulation).6
Pursuant to Article 12(3) of the GDPR, the controller, inter alia, shall provide the data
subject, without undue delay and in any event no later than one month after receiving
the request, with information on the measures taken pursuant to Article 15. That period
may be extended, if necessary, by a further two months, taking into account the
complexity of the request and the number of requests received. Where the controller
needs to communicate with the data subject due to uncertainty about the identity of the
data subject, it may be suspended until the controller has received the necessary
information from the data subject, provided that the controller has requested additional
information without undue delay.7
4 EDPB Guidelines 01/2022, paragraph 67.
5 EDPB Guidelines 01/2022, paragraph 70.
6 EDPB Guidelines 01/2022, paragraph 71.
7 EDPB Guidelines 01/2022, paragraph 159.
Swedish Authority for Privacy Act number: IMY-2025-9240 6(9)
Protection
Date: 2025-11-26
Swedish Authority for Privacy Protection’s assessment
Has Klarna acted in accordance with Article 12(6) of the GDPR when Klarna
requested up-to-date information from the complainant?
Has Klarna had reasonable grounds to doubt the identity of the complainant?
It is only where the controller has reasonable doubts about the identity of the person
making the request that further information to confirm the identity may be requested.
What constitutes ‘reasonable grounds’ in Article 12(6) of the GDPR should be
assessed in the light of the circumstances of the individual case. The assessment of
whether there are reasonable grounds in an individual case to doubt the identity of the
person making the request is normally made in the light of the information provided in
connection with the request. This is particularly true in situations where the controller
has no detailed knowledge of that person. However, the fact that an individual
assessment is required does not preclude the establishment of procedures for how the
controller normally verifies the identity of the data subject.
The requirements that can be placed on the information should typically be higher the
more sensitive the personal data processing is. In other words, a certain type of
identification information may be sufficient for identification in one processing operation
but may give rise to doubts in another.
According to the complainant, Klarna had sufficient information to confirm his identity,
since the request for access was made from an email address known to Klarna and
since he asked for the register extract to be sent to the address used for sending
shipments and invoices relating to his purchase from Klarna. Klarna stated that it had
reasonable grounds to doubt the applicant’s identity, since the applicant had provided
only two of several data points necessary to be regarded as identified in accordance
with the procedure in force at the time. In addition, Klarna states that the requirement
of banking secrecy, which it is required to maintain, must be taken into account when
identifying data subjects in connection with requests for access or deletion. In addition,
Klarna processes information that many customers perceive as sensitive and the
company thus needs to ensure that information is not disclosed to unauthorized
persons and that the identity of customers is not disclosed. Financial institutions are
particularly vulnerable to fraud attempts of various kinds and Klarna must ensure that
no personal data is exposed to unauthorised persons and, if in doubt, ask for
additional data points for identification.
IMY notes that the obligation to ensure the identity of the person making a request is
aimed, inter alia, at protecting data subjects against the wrongful making of requests in
their name by another person, which may lead to negative consequences for data
subjects. In the light of Klarna’s submissions, in particular as regards the nature of the
personal data that Klarna processes, and having regard to the information provided by
the complainant in its request for access, IMY considers that there is no reason to
question that Klarna had reasonable grounds to doubt the complainant’s identity.
Has the information requested by Klarna been necessary to confirm the identity of the
complainant?
The regulation does not explicitly regulate which data may be requested or how the
additional information is to be collected. However, the principle of data minimisation
laid down in Article 5(1)(c) of the GDPR regulation is central in that regard. Although
the controller has reasonable grounds to doubt the identity of the data subject, the
controller shall not collect more personal data than is necessary to enable the
Swedish Authority for Privacy Act number: IMY-2025-9240 7(9)
Protection
Date: 2025-11-26
identification of the data subject. Requiring data for identification purposes on a routine
basis without regard to the necessity of the data as described in Article 12(6) of the
GDPR is contrary to that provision. The controller must carry out a proportionality
assessment and be able to justify the verification method used. The proportionality
assessment must be carried out in order to determine what is appropriate in the light of
the Regulation’s requirements relating, inter alia, to security, but also in the light of the
requirement laid down in Article 12(2) of the GDPR, according to which the controller
must facilitate the exercise of the data subject’s rights. In order to avoid excessive data
collection, a request for additional information must be proportionate to the type of data
processed and the harm that may occur when disclosing data to the wrong person.
In summary, Klarna has stated that data subjects can identify themselves through
various combinations of a number of data points established in Klarna's routine. In the
identification process, all these possible data points are requested but not all are
necessary for the identification of the data subject. Klarna states that, in the complaint
at issue, it asked the applicant, in addition to her email address, to provide five
additional data points in order to identify her.
It follows, inter alia, from the EDPB Guidelines on the right of access that, in the
proportionality assessment, the controller must take into account the type of personal
data processed (e.g. special categories of data or not), the nature of the request, the
context in which the request is made and any harm that may result from undue
disclosure.8
As regards the information requested by Klarna from the complainant, IMY observes
the following. Given that Klarna carries out banking activities, the disclosure of
personal data to an unauthorised person could have serious consequences for the
applicant. The requirements for identification must therefore be set relatively high. In
addition, Klarna only requests information that corresponds to information that it
already processes about the complainant.
However, according to Klarna itself, not all of the additional information requested was
necessary to identify the complainant. As mentioned above, the controller shall make
an assessment on a case-by-case basis and shall not request more personal data
than is necessary to identify the requesting data subject. It does not appear that Klarna
made such an assessment in the complainant’s case. Requiring, as a matter of
routine, a large number of data for identification purposes in the manner that has taken
place without regard to the necessity of the data as described in Article 12(6) of the
GDPR is contrary to the provision in question.
In view of the fact that more information than was necessary to identify the
complainant has been requested, IMY considers that Klarna has processed the
complainant’s personal data in breach of Article 12(6) of the GDPR.
Has Klarna facilitated the exercise of the applicant’s right of access under
Article 12(2) of the GDPR?
Article 12(2) of the GDPR requires the controller to facilitate the exercise of the data
subject’s rights in accordance with Articles 15 to 22.
Klarna has requested the complainant to provide certain information by e-mail in order
to be able to confirm the complainant’s identity and subsequently handle the
8 EDPB Guidelines 01/2022, paragraph 70.
Swedish Authority for Privacy Act number: IMY-2025-9240 8(9)
Protection
Date: 2025-11-26
complainant’s request for access further. Furthermore, the complainant has been
asked to provide information on, among other things, the invoice number, the name of
a shop at which the complainant had previously made a purchase and the order
number. As stated above, IMY considered that not all the information requested by
Klarna was necessary to identify the complainant. This has meant that the complainant
had to carry out research in order to find several data on, inter alia, previous
purchases, even though those data were not always necessary. Against that
background, IMY considers that the verification method was too burdensome for the
complainant in such a way as to make it more difficult to exercise the right of access.
IMY thus concludes that Klarna has not facilitated the exercise of the data subject’s
right as required by Article 12(2) of the GDPR. Klarna therefore processed the
applicant’s personal data in breach of Article 12(2) of the GDPR.
Has Klarna provided the complainant with information on the measures taken
pursuant to Article 15 of the GDPR without undue delay?
The investigation in the case shows that the complainant requested access to its
personal data on 15 June 2021. Klarna requested additional information the following
day and that the complainant submitted them on 18 June 2021. Furthermore, it
appears that the extract from the register was sent to the applicant on 22 July 2021.
IMY does not dispute that Klarna initially had reason to doubt the identity of the
complainant, with the result that the time-limit was temporarily suspended. Given that
Klarna had sufficient information to verify the complainant’s identity on 18 June 2021
and the request for access was only satisfied on 22 July 2021, IMY notes that the
complainant’s request was nevertheless not met within the deadline of a maximum of
one month. IMY therefore considers that Klarna has acted in breach of Article 12(3) of
the GDPR by not providing the complainant, without undue delay, access to its
personal data and other supplementary information.
Choice of corrective measure
It follows from Article 58(2) and Article 83(2) of the GDPR that IMY has the power to
impose administrative fines in accordance with Article 83. Depending on the
circumstances of the case, administrative fines shall be imposed in addition to or
instead of the other measures referred to in Article 58(2), such as injunctions and
prohibitions. Furthermore, Article 83(2) sets out the factors to be taken into account in
deciding whether to impose an administrative fine and in determining the amount of
that fine. In the case of a minor infringement, IMY may, as indicated in recital 148,
instead of imposing a fine, issue a reprimand pursuant to Article 58(2)(b). Account
shall be taken of aggravating and mitigating circumstances of the case, such as the
nature, gravity and duration of the infringement and relevant previous infringements.
IMY notes the following relevant circumstances. IMY has found that Klarna has
requested more information than is necessary to identify the complainant. However,
the data requested by Klarna did not consist of sensitive, special categories of data or
otherwise privacy-sensitive data. Klarna only requested data that the company was
already processing in the context of its customer relationship with the complainant.
IMY has further found that Klarna did not facilitate the exercise of the complainant’s
right of access and that the request had been met out of time. However, Klarna
responded without delay to the complainant’s e-mail in order to comply with his
request for access, the request was complied with and the delay found was only a few
Swedish Authority for Privacy Act number: IMY-2025-9240 9(9)
Protection
Date: 2025-11-26
days. Against this background, the infringements found are considered to be of a less
serious nature than if the request had been left unanswered.
In the light of the foregoing, IMY considers that these are minor infringements within
the meaning of recital 148 that require Klarna to be reprimanded under Article 58(2)(b)
of the GDPR for the infringements found.
__________________________
This decision has been taken by the Department Lawyer following a
presentation by the Legal Advisor .
Appendix
Complainant’s personal data
Copy to
Data Protection Officer