See the Aaron Schwartz trial which was about essentially the same thing.
No, you may not in this case :) That is why people keep emphasising the way in which the data was published. This is Sweden, not the US.
> the city didn't publish their information through an API
Yes, they did.
> and also explicitly stated that they did not want Christian's app to access their information
If you cannot reasonably be said to have circumvented any technical measures to secure the data (cryptographic keys, some sort of login, IP range blocks, etc) it is not a breach. In that case, it is just you consuming what is there for everyone (like unencrypted wifi - harvesting those signals using SDRs is not an issue because you are not bypassing any security), which is okay.
Edit: Legally okay, that is. How you feel about it ethically is up to you, I'm not talking about that.
Here is the relevant paragraph:
"För dataintrång döms den som olovligen bereder sig tillgång till en uppgift som är avsedd för automatisk behandling eller olovligen ändrar, utplånar, blockerar eller i register för in sådan uppgift"
The requisites are: "olovligen", "bereder sig tillgång till", and "uppgift som är avsedd för automatisk behandling". Christian's app full fills the requisites.
API means "Application Programming Interface" and if you think the city created or intended to create such a thing you don't know what an API is.
> If you cannot reasonably be said to have circumvented any technical measures to secure the data (cryptographic keys, some sort of login, IP range blocks, etc) it is not a breach.
You have no idea what you are talking about. There are several precedents that show that circumventing technical measures is not required for data breach to have occurred.
>For data intrusion, a person who illegally prepares access to information that is intended for automatic processing or illegally changes, deletes, blocks or registers such information is sentenced
This app does not appear to meet this definition as the data they are exposing is not intended for automatic processing, but it is exposing manually consumed data (i.e. the parents were already consuming this data manually) in a different, more accessible way.
I agree the city obviously wasn't intending to expose an API.
Which precedents are you talking about. I don't know much of anything about Swedish law so any precedent you can show would be educational for me.
Given that you know significantly more than me perhaps you could give me some examples. I'm always interested to see countries in which such jurisprudence is different from the norm, especially in Europe. Thanks :)