Personalkollen
Sweden · personalkollen.se · 14 vendors
Personalkollen is a Swedish technology company that provides a web-based and user-friendly personnel and payroll system. It streamlines scheduling, time tracking, digital payroll management, and employee administration. The system is primarily used by businesses in people-intensive industries such as hotels, restaurants, cafes, and retail.
Resilience scores
- Digital Sovereignty: 57
- Digital Resilience: 7
- Financial Resilience: 6
Technology vendors
- Fortnox AB — Technology — Sweden
- GetSwish AB — Financial Services — Sweden
- Payson AB — Sweden
- and 11 more
Services catalogue
2 services in catalogue across 2 categories; runs on 14 sub-vendors.
- Personal Data Processing
- Workforce management
Insights
Last updated 2026-07-15 · revision 2
14 direct vendors, 169 subvendors
Direct vendors by controlling owner country (sample)
- Norway: 1
- Sweden: 8
- Canada: 1
Subvendors by controlling owner country (sample)
- Unknown: 1
- Taiwan: 1
- Switzerland: 1
Migration Readiness: 7/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Personalkollen exhibits a high level of migration readiness. Their modern and portable tech stack, including Django (Python), REST APIs, and a web-based SaaS architecture, is inherently well-suited for cloud migration. Crucially, their current operation within an OpenStack-based cloud environment (Elastx) means they already possess cloud operational experience, simplifying the transition compared to migrating from an on-premise legacy setup. The open-source nature of OpenStack may also reduce proprietary vendor lock-in compared to specific hyperscaler platforms. Additionally, their 'Integrations Platform' with approximately 100 third-party tools suggests a modular and API-driven architecture, which typically facilitates easier re-platforming or re-hosting during a migration. Key challenges and unknowns include the unspecified 'Data Residency Requirements,' which could significantly impact the choice of target cloud providers and compliance efforts, especially given their EU presence. The 'Vendor Lock-in Risk' is 'Unknown,' which is a major concern, particularly regarding their relationship with Elastx and any specific services consumed. The absence of financial stability data also prevents a full assessment of their capacity to fund a potentially complex migration project.
Compliance
7 in-scope frameworks identified; showing 3.
Swedish Bookkeeping Act — Assessment Required
As a payroll and HR management SaaS provider, Personalkollen generates payroll accounting data, employer tax declarations (arbetsgivardeklarationer), and bookkeeping records for its customers. The Swedish Bookkeeping Act requires accounting records to be retained for 7 years. Personalkollen's DPA references compliance with bookkeeping and audit legislation as a purpose for data retention. Risk is Low as this is a standard operational compliance requirement for any Swedish business, and Personalkollen explicitly references it in its privacy policy.
Evidence: https://personalkollen.se/integritetspolicy/, https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/bokforingslag-19991078_sfs-1999-1078/
Swedish Employment Law — Assessment Required
Personalkollen's core product manages employee scheduling, time-tracking, and payroll in compliance with Swedish collective agreements (kollektivavtal). The platform explicitly markets compliance with collective agreements for HoReCa and retail sectors. Swedish labor law (LAS – Lag om anställningsskydd, MBL – Medbestämmandelagen, Arbetstidslagen – Working Hours Act) governs the data that Personalkollen processes on behalf of its customers. Risk is Low for Personalkollen itself (as a SaaS provider), but its customers rely on Personalkollen's platform to maintain labor law compliance. The platform's accuracy in implementing collective agreement rules is a key compliance dependency for customers.
Evidence: https://personalkollen.se/start/, https://personalkollen.se/branscher/restaurang/, https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/arbetstidslag-1982673_sfs-1982-673/
Swedish Data Protection Act — Partially Compliant
The Swedish Data Protection Act supplements GDPR with national specifications, including provisions on processing of personal identity numbers (personnummer), sensitive data in employment contexts, and the role of the Swedish Data Protection Authority (IMY – Integritetsskyddsmyndigheten). Personalkollen processes personnummer extensively (confirmed in DPA Annex 1 and privacy policy), which requires specific legal basis under Swedish law (Section 10, Dataskyddslagen). Risk is Medium because personnummer processing is a specific Swedish compliance requirement beyond GDPR, and no evidence of formal IMY guidance or DPO appointment has been found.
Evidence: https://personalkollen.se/integritetspolicy/, https://www.imy.se/lagar--regler/dataskyddslagen/, https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/lag-2018218-med-kompletterande-bestammelser_sfs-2018-218/
Financials
Financial Resilience Score: 6/10
Personalkollen Sverige AB appears to be a maturing vertical SaaS company with a diversified SMB customer base of 4,500+ customers across Swedish hospitality and retail sectors. The company benefits from recurring subscription revenue, deep domain specialization in Swedish collective agreement compliance, and a broad product suite spanning scheduling, punch clock, payroll, and tip management. Roughly 100 integrations with POS, booking, and accounting systems create meaningful switching costs and lock-in despite a no-binding-period sales policy. However, financial resilience is constrained by significant end-market cyclicality — hospitality and retail are among the most economically sensitive verticals, and SMB customers have structurally higher churn and bankruptcy rates than enterprise clients. Competitive intensity in the Nordic workforce management space is high (Quinyx, Planday, Visma, Hogia, Fortnox add-ons), creating pricing pressure. Geographic concentration in Sweden is near-total, with the Munich office representing an early and unproven DACH expansion. Without access to filed årsredovisningar, revenue, EBIT, and equity trajectory cannot be verified, limiting confidence in the resilience assessment.
Key strengths: 4,500+ customer base providing recurring revenue diversification, Deep vertical specialization in HoReCa and Swedish kollektivavtal compliance, End-to-end product suite (scheduling, punch clock, payroll, tips, analytics) increases ARPU, ~100 integrations with POS, booking and accounting systems create switching costs, Multi-office Swedish footprint (Umeå HQ, Göteborg, Linköping, Stockholm, Malmö) plus Munich
Risk factors: High cyclicality of hospitality and retail end markets, SMB customer base with elevated churn and bankruptcy risk, Intense competition from Quinyx, Planday, Visma, Hogia, Fortnox, Near-total geographic concentration in Sweden, No-binding-period policy creates churn exposure, Regulatory/compliance-heavy cost base (Swedish tax, collective agreements, GDPR)
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.