Briqpay

More insights

Knowledge Hub

CCD2 Update: Sweden's New Consumer Credit Act Is Now Law, Here's What Merchants Need to Know Before November 2026

Logo

Björn Widerström

Co-founder Briqpay

August 7, 2026 at 12:00 PM

The proposal is now law

When we first covered CCD2 and Sweden's incoming consumer credit rules, the new konsumentkreditlagen was still a proposal working its way through the legislative process. That has now changed. On May 27, 2026, the Riksdag voted to approve the Civil Committee's recommendation on Proposition 2025/26:223, and the finished law was issued on June 4, 2026 as Konsumentkreditlag (2026:1011). It replaces the old consumer credit act from 2010 and enters into force on November 20, 2026, the same date the EU's underlying directive becomes fully applicable across every member state.

If you read our first guide, most of the structural points we flagged back then (the disappearance of the old exemption thresholds, licensing for BNPL and invoice providers, the SEKKI disclosure requirement) have held up exactly as described. What's new is that we now have a finished statute to point to instead of a draft, a confirmed supervisory model from Finansinspektionen, fresh guidance from Svensk Handel, a public position from Klarna, and just over three months left on the clock before enforcement begins. This post is meant to sit alongside our original guide and update it with everything that has happened since.

What the EU directive actually says, in its own words

It's worth going back to the source instead of relying only on second-hand summaries, because a few details get simplified or lost in translation as they move from Brussels to Stockholm.

Directive (EU) 2023/2225, commonly called CCD2, was published in the Official Journal in October 2023. According to the European Commission's own legislative summary, member states were required to transpose it into national law by November 20, 2025, but the substantive rules "should apply from 20 November 2026." Sweden's law arrived several months after that transposition deadline, but it lands squarely on the application date that matters for merchants, so the compliance clock is the same one every other EU market is working against.

On scope, the directive is explicit that short-term, interest-free "buy now, pay later" products are meant to be caught by the new rules, not left sitting outside them. Recital 16 of the directive states that BNPL-style schemes "should be included in the scope of this Directive," closing the gap that let many installment and invoice products avoid consumer credit regulation entirely under the old 2008 directive. The directive does preserve a narrow carve-out (in Article 2) for interest-free, fee-free deferred payment given directly by a supplier, but only if it is repaid within 50 days, which is the same 50-day and 14-day structure Svensk Handel and our original guide both describe.

On creditworthiness, the directive requires that a consumer's "ability and propensity to repay the credit is assessed and verified before a credit agreement is concluded," based on accurate information about income, expenses and existing financial commitments, while explicitly barring the use of special categories of data such as health information or data drawn from social networks. On disclosure, pre-contractual information has to be delivered through the Standard European Consumer Credit Information form, with the key details visible on the first page instead of buried in later sections. And on dark patterns, the directive is direct: "silence, inactivity or default option such as pre-ticked boxes should not be considered to constitute agreement by the consumer," which is the legal basis for banning pre-selected credit options at checkout. CCD2 EU

What Sweden's finished law adds on top

The Swedish implementation follows the EU text closely but fills in some national detail that merchants should know about.

The 50-day interest-free invoice exemption survives in the new law, but Sweden narrows it further for larger online sellers: outside the small and medium enterprise category, the repayment window for exempt "special invoice credits" drops to 14 days, and the underlying debt can't be sold or assigned to a third party during that period. That is a stricter national reading than the EU floor requires, and it specifically targets the largest e-commerce operators, not smaller merchants using simple invoicing.

Supervision is split by size. Finansinspektionen has confirmed that it will directly supervise larger subsidiary credit providers and intermediaries (broadly, those with more than 250 employees and either turnover above EUR 50 million or a balance sheet above EUR 43 million), while Konsumentverket takes on smaller providers. Companies that are already active have until November 20, 2027 to submit their license application, but any new entrant launching after November 20, 2026 has to be authorized before it can offer credit at all. FI has also been reaching out directly to existing consumer credit institutions this year: in a February 2026 notice, Anders Dölling, who heads FI's consumer credit unit, confirmed the authority was contacting all roughly 50 remaining institutions about the higher bar for lending, a number that was closer to 60 or 65 before an earlier, related tightening of the rules in 2025 already pushed several firms out of the market or into applying for a full credit market company license.

Penalties are meaningful too. Violations of the new law can trigger sanctions of up to 10 million SEK or 10% of annual turnover, alongside outright lending bans for repeat or serious breaches. Sweden SEKKI

Why the government is pushing this now

None of this is happening in a vacuum. Sweden's household debt figures give some sense of why lawmakers were motivated to move. Kronofogden, the Swedish Enforcement Authority, reported in January 2026 that total enforced debt reached 154 billion SEK, up 12% year on year and 76% higher than five years earlier, spread across nearly 450,000 people and growing by roughly 44 million SEK every single day. Private claims, including consumer loans, credits and subscriptions, made up about two-thirds of that figure.

Layered on top of that is Sweden's position as, by some measures, the country with the highest share of BNPL payments in e-commerce anywhere in the world, a point reported via Riksbanken data and one that's been particularly pronounced among younger shoppers. When Financial Markets Minister Niklas Wykman announced the finished proposal in March 2026, he framed it as a continuation of earlier steps: "Regeringen har i flera steg gjort förändringar för att komma åt problemen med överskuldsättning" (the government has taken successive steps to address the problem of over-indebtedness). The January 2026 government release that preceded it was even more direct about who the law targets by name, listing interest-free retail credit from providers including Klarna, Qliro and Riverty as squarely within scope.

How the industry is reacting

The reaction has been mixed, which is roughly what you'd expect from a rule that reorganizes an entire product category.

Klarna, as one of the providers named directly in government communications, has taken a public and fairly consistent position. In a 2023 statement responding to the directive itself, the company said it supports the new rules "as they raise standards and enhance consumer protections," while arguing that the real risk is inconsistent implementation between member states creating a fragmented market. In a more recent statement specific to the Swedish debate, Klarna leaned on its own performance data to argue for treating all credit providers under one consistent standard instead of carving out exemptions for retailer-issued credit: the company cites a default rate to the Enforcement Authority of just 0.0267%, an on-time payment rate of 98%, and credit losses below 0.4%, alongside a claim that 90% of its users agree all credit providers should follow the same rules. Whether or not you find that framing persuasive, it's a useful reminder that the industry itself is not uniformly opposed to CCD2. Much of the pushback has been about consistency of application, not the underlying principle of stricter oversight.

On the merchant side, Svensk Handel, Sweden's largest retail trade body, has published its own guidance summarizing the changes for its members: tighter marketing rules for credit products, stricter credit assessment obligations, expanded SECCI/SEKKI information requirements, and a licensing regime split by company size. Their framing to members is practical, not alarmist, essentially "here is what changed and here is what you now need to check," which tracks with how most of the legal commentary we found (from firms like Mannheimer Swartling and PwC Sweden) is treating this: as a significant but manageable compliance project, not an existential threat to online credit as a payment option.

What this means for your checkout, concretely

Pulling the EU text, the Swedish statute and the regulator guidance together, four things change at the checkout level that merchants should be actively preparing for right now.

Credit can no longer be visually or structurally favored over other payment methods. Pre-ticked boxes, default-selected installment plans, and unequal visual weight between a credit option and a non-credit option are all things the directive explicitly rules out as valid consent. If your checkout currently nudges shoppers toward a "buy now, pay later" tile by making it larger, pre-selected, or more prominent than a card or bank transfer option, that needs to change before November.

The SEKKI form has to appear, and it has to be legible on the device shoppers actually use. Since the majority of e-commerce traffic for most Swedish merchants is mobile, a standardized disclosure form that was designed with desktop banking portals in mind needs real UX work to be genuinely readable, not just technically present.

Creditworthiness checks are getting real teeth, and that means more declines, not fewer. A rule that requires actual verification of income and expenses instead of a lightweight proprietary score will, almost by definition, decline shoppers who would previously have been approved. That's the entire point of the law from a consumer protection standpoint, but from a commercial standpoint it means checkout abandonment risk goes up unless merchants have planned for what happens next.

And licensing status now has commercial consequences beyond compliance risk. A BNPL or invoice provider that hasn't secured its license, or is mid-application past the November 2027 deadline for existing providers, is a business continuity risk for any merchant relying on them as a primary payment method. checkout shift mandates

Where a payment optimization platform actually earns its keep here

This is the part that's easy to miss if you're reading CCD2 purely as a legal compliance exercise instead of a checkout design problem, and it's the part we think about most, since it's exactly the layer Briqpay sits in.

Fallback matters more, not less, once credit checks tighten. If stricter, verified creditworthiness assessments mean more shoppers get declined at the point of BNPL or invoice checkout, the question that actually determines whether you keep the sale is what happens in the next few seconds. In our own analysis of more than 31,500 checkout retries across our merchant network, we found that when a BNPL attempt failed, 41% of shoppers completed with a mobile payment method instead, and the median time between a failed attempt and a successful one was under two minutes. CCD2 is going to generate more of these decline events by design. A checkout that can surface a genuinely different, low-friction payment option the instant a credit check fails will recover meaningfully more of that traffic than one that simply shows an error and hopes the shopper tries again with the same provider.

Compliance shouldn't mean picking one credit provider and living with it. Because licensing, national exemption thresholds, and even the exact wording of SEKKI disclosures differ slightly by market, a merchant operating across the Nordics and wider Europe faces a genuinely different compliance surface in each country. A payment orchestration layer that already integrates multiple BNPL, invoice and card providers means a merchant isn't structurally dependent on any single credit provider clearing its FI licensing hurdle on time. If one provider's authorization is delayed, checkout logic can route around it instead of the merchant losing access to installment payments in that market entirely.

Equal-prominence and no-dark-pattern rules are easier to enforce centrally than per-integration. When every payment method is plugged in separately by different teams at different times, it's very easy to end up with exactly the kind of inconsistent visual hierarchy the directive now prohibits. Managing checkout method presentation, ordering and disclosure logic through a single platform makes it far more straightforward to guarantee, and demonstrate to a regulator if asked, that credit options are never structurally favored over non-credit options.

Creditworthiness data needs a better pipeline than manual uploads. Article-level obligations to verify actual income and expenses push providers toward open banking instead of self-reported forms, both because it's faster for the shopper and because it produces an auditable data trail. A platform that already handles open banking connections as part of checkout orchestration turns a compliance requirement into a conversion opportunity instead of a new source of drop-off, which is the same dynamic we flagged in our original CCD2 guide when we noted that automated verification tends to lift conversion versus manual document review.

Audit trails become a genuine deliverable, not an afterthought. With penalties of up to 10% of turnover on the table and a supervisory body that has already shown it will proactively contact firms about compliance, having a single, centralized record of what was disclosed, when, to which shopper, and through which provider is the difference between a straightforward regulatory conversation and a painful one.

None of this replaces the legal work of actually getting licensed or rewriting your terms and disclosures, that part is unavoidable and worth doing with proper legal counsel, not a blog post. But the checkout experience layer, how credit options are surfaced, how declines are handled, and how disclosures are delivered, is very much a product and payments infrastructure problem, and it's one that gets meaningfully harder to solve well if it's spread across a dozen separate point-to-point integrations instead of one orchestration layer built for exactly this kind of regulatory shift.

What to do between now and November 20

If you haven't already, audit every credit and installment method live in your checkout today and confirm its provider's licensing status and timeline. Check your checkout UI specifically for pre-selected credit options, unequal method sizing, or any flow where a non-credit method requires more clicks than a credit one. Review whether your current SEKKI or SECCI implementation is genuinely mobile-legible, not just technically compliant. And plan explicitly for the decline case: what a shopper sees and is offered in the moment a credit check fails is going to matter more after November 20, 2026 than it does today, simply because there will be more of those moments.

Sweden went from proposal to finished law faster than some expected, and the November deadline is now fixed, not provisional. The merchants who treat the next few months as a checkout design project, not just a legal filing exercise, are the ones who will come out the other side with both a compliant checkout and a converting one. CCD2 Checklist

REQUEST A DEMO

Ready to simplify your payment setup?

Connect any payment provider. Optimize your payment flow. Scale without limitations - with Briqpay’s Payment Integration Platform.

STAY CONNECTED

Subscribe now for exclusive insights and updates.

Briqpay logo
Contact
Slöjdgatan 9, 111 57 Stockholm Sweden
hello@briqpay.com
Copyright © 2026 Briqpay AB All rights reserved
Terms & Privacy