Home / Locations / Sweden / Stockholm
stockholm-office-420x420.jpg

Stockholm

Sweden

CMS Wistrand is a Swedish premier full-service law firm with 51 equity partners and more than 150 lawyers. Our two offices are strategically located in Stockholm and Gothenburg. CMS Wistrand has a strong presence in Sweden and a strong position within all sectors. At CMS Wistrand, we combine decades of legal expertise with a commitment to continuous learning and future-oriented practices.

In 1994, we opened our Stockholm office which rapidly expanded. Our Stockholm office is home to more than 80 lawyers. We have strong competence within practice areas such as Real Estate, Dispute Resolution and Restructuring & Insolvency.

Our experts offer clients in-depth experience in all areas of business law, with legal support and an international reach, whether you are involved in national or international activities. Our clients are active in all sectors, including leading Swedish and international companies, municipalities and public sector entities, bank and consulting companies, start-ups and listed companies.

more less

Directions

.

more less

Location

Stockholm
CMS Wistrand
Regeringsgatan 65
111 56 Stockholm
Sweden

Feed

24/04/2024
Renowned Legal Figure and Former Justice Stefan Lindskog Joins CMS Wistrand...
CMS Wistrand is thrilled to announce the appointment of Stefan Lindskog, an esteemed legal professional, to the role of Senior Counsel. His addition brings a wealth of experience and insight to our esteemed team.
24/04/2024
CMS Expert Guide to Anti-Bribery and Corruption Laws
We are delighted to present the 7th edition of the CMS Guide to Anti-Bribery and Corruption Laws. Guide is now available in both offline PDF format and online on our website. The purpose of the Guide...
23/04/2024
Cyber and Information Security - Update of the NIS Directive (NIS2)
The so-called NIS Directive[1] has been updated through the NIS2 Directive[2], which is set to be applied no later than October 18, 2024. The update aims to enhance the overall cybersecurity level of...
23/04/2024
On the Pulse webinar series 2024
Welcome to the 2024 On the Pulse webinar series.  This webinar series brings you updates on the latest legal and commercial developments in the life sciences & healthcare sector from around the world. Over the coming period, we will be hosting two webinars on:Unified Patent Court (UPC) - 23 AprilEU Pharma Package - 18 JuneEach webinar will be one hour in length with a 15-minute Q&A session.
23/04/2024
Cyber and Information Security - Update of the NIS Directive
The so-called NIS Directive[1] has been updated through the NIS2 Directive[2], which is set to be applied no later than October 18, 2024. The update aims to enhance the overall cybersecurity level of the EU and entails tightened requirements for actors in both the private and public sectors.  Further developments of the implementation of the NIS2 Directive in SwedenOn 14 December, 2022, the European Parliament and the Council adopted the NIS2 Directive, which constitutes an EU-wide legislation on cybersecurity. As a result of the adoption of the NIS2 Directive, the Swedish government appointed a special investigator with the task to suggest necessary implementation measures in Swedish law. On 5 March, 2023, the special investigator published an interim report[3] containing suggestions on implementation measures. In accordance with the interim report, such measures would mainly be incorporated through a new Swedish Cyber Security Act (the “Act”). The Act is proposed to enter into force on 1 January, 2025.[4] Which actors will be subject to the new Swedish Cyber Security Act?There are two essential differences between the current legislation in Sweden implementing the NIS1 Directive[5], and the proposed new Swedish Cyber Security Act implementing the NIS2 Directive. Firstly, the Act would apply to a larger number of operators. Operators within sectors covered by the Act would be expanded from 7 to 18 (sectors such as energy, transport, health, financial market infrastructure and digital infrastructure would be included among these new sectors). Secondly, the requirements in the Act would apply to the entire operations of such actors, not only to their essential and digital ser­vices.[6] All private operators of a certain size or specifically identified ones and public operators carrying out activities in any of the envisaged 18 sectors would be required to comply with the new provisions under the Act. With regard to private operators, the Act’s provisions would only apply to such operators which employs at least 50 people or have a minimum global annual turnover of EUR 10 million. As a result, the Act  many small businesses would be excluded. However, certain specifically identified individual operators would be subject to the provisions in the Act regardless of size (e.g. operators providing public electronic communications net­works).[7] What requirements will be stipulated in the new Swedish Cyber Security Act?The proposed Act contains several obligations which operators covered by the Act would be subject to[8]:An operator would have to register with its supervisory authority and provide information such as its identity, contact details and activities. The information would be used by the authority to classify the operators as essential or important, and register them. A separate register for cross-border operators would also be implemented. The operator would have to undertake risk management measures to protect network and information systems and its physical environments against incidents. Such measures should be based on a risk analysis, be proportional to the risk and be subject to evaluation. The operator would be required to carry out systematic, risk-based information security work, require its management to undergo training and offer training to employees. Operators would be obliged to report significant incidents to the Swedish Civil Contingencies Agency in its capacity as Computer Security Incident Response Team (CSIRT) within a specified timeframe. This means that an operator would have to report a warning to the CSIRT within 24 hours of having become aware of a significant incident. Moreover, an incident report would have to be submitted within 72 hours, and a final report within one month. What sanctions may be imposed in case of infringements of the Act?Depending on which provision has been violated, the supervisory authority’s enforcement measures consist of measures such as issuing of orders (which may be combined with a financial penalty) or administrative fines. The administrative fines may be set at no less than SEK 5 000 and no more than SEK 10 000 000.[9] Furthermore, sanctions may also be imposed on natural persons as the possibility of imposing prohibitions on persons with management responsibilities to perform management functions, is introduced in the interim report. What are the next steps?The interim report will now be circulated for formal consultation. Thereafter, the Swedish government will proceed with the preparation the new Act which is, as mentioned above, expected to enter into force on 1 January, 2025. However, until then, it will be uncertain exactly how the Act will be designed. In the meantime, organisations will benefit from reviewing the proposed scope of the Act and analyse whether their operations would be subject to its provisions and what this potentially means. In any case, the NIS2 Directive can be expected to entail major changes for both actors already covered by the NIS1 Directive and for previously unaffected actors, and not least - also for the representatives of all actors concerned. CMS Wistrand will follow the upcoming development. Please do not hesitate to contact us if you have any questions about how your business may be affected.  [1] Directive (EU) 2016/1148 of the European Parliament and of the Council of 6 July 2016 concerning measures for a high common level of security of network and information systems across the Union.[2] Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU). 2018/1972, and repealing Directive (EU) 2016/1148 (NIS2 Directive).[3] Nya regler om cybersäkerhet, SOU 2024:18.[4] Nya regler om cybersäkerhet, SOU 2024:18, p. 23 and 31.[5] Directive (EU) 2016/1148 of the European Parliament and of the Council of 6 July 2016 concerning measures for a high common level of security of network and information systems across the Union.[6] Nya regler om cybersäkerhet, SOU 2024:18, p. 24.[7] Nya regler om cybersäkerhet, SOU 2024:18, p. 25.[8] Nya regler om cybersäkerhet, SOU 2024:18, p. 26.[9] Nya regler om cybersäkerhet, SOU 2024:18, p. 28.
18/04/2024
Transforming the Legal Landscape? The Impact of LLMs
Large Language Models (LLMs) are a branch of artificial intelligence (AI) that can generate human-like text based on deep learning techniques. LLMs are trained on massive amounts of textual data, such...
18/04/2024
CMS Expert Guide to renewable energy
The Renewables Sector is now many decades old and considered a mature investment sector by many. Yet the issues it faces continue to evolve and grow at pace with the evolution and growth of the sector...
17/04/2024
CMS data protection update (04/2024)
I. The latest from the data protection authorities and current topics1. EDPB: Launch of coordinated enforcement on the right of accessThe European Data Protection Board (EDPB) selected the right of access...
11/04/2024
Navigating clinical trial disclosures: No reasonable expectation of success...
Recent EPO Board of Appeal decision T 1437/21 adds to a growing number of decisions concerning the patentability of second or further medical use inventions where the prior art relates to a clinical trial...
09/04/2024
CMS European M&A Study 2024: Optimism for M&A amid evolving market trends
The CMS Corporate/M&A Group is pleased to launch the 16th edition of the European M&A Study.It's been a wild ride for mergers and acquisitions (M&A) around the world this year. Yet, despite the turbulence...
09/04/2024
Designs practice update: EU Court of Justice upholds Advocate General’s...
BackgroundIn our previous article (here), we discussed the opinion of Advocate General Capeta in EUIPO v The KaiKai Company Jaeger Wichmann. That opinion was provided following an appeal against the General...
09/04/2024
The sum of parts: Registered design for segments of towers found valid...
BackgroundTA Towers ApS (“TA Towers”), a company based in Denmark, is the holder of the below registered Community design relating to goods for building materials, specifically, ‘building materials...