No, you may not in this case :) That is why people keep emphasising the way in which the data was published. This is Sweden, not the US.
> the city didn't publish their information through an API
Yes, they did.
> and also explicitly stated that they did not want Christian's app to access their information
If you cannot reasonably be said to have circumvented any technical measures to secure the data (cryptographic keys, some sort of login, IP range blocks, etc) it is not a breach. In that case, it is just you consuming what is there for everyone (like unencrypted wifi - harvesting those signals using SDRs is not an issue because you are not bypassing any security), which is okay.
Edit: Legally okay, that is. How you feel about it ethically is up to you, I'm not talking about that.