{
 "jurisdiction_id": "FI",
 "jurisdiction": "Finland",
 "url": "https://dataprotection.gi/jurisdictions/finland/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 36,
  "sub_modules": 57,
  "source_register": 12
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "green",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/finland/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Comprehensive, mature GDPR-aligned omnibus framework with an active, resourced supervisory authority and clear national implementing act.",
   "claims": [
    {
     "statement": "The Office of the Data Protection Ombudsman acts as the Finnish supervisory authority for GDPR and its supplementing national legislation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/finland",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Finland implemented the GDPR through the Data Protection Act (1050/2018), which entered into force on 1 January 2019 and repealed the Personal Data Act (523/1999).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/finland",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "GDPR implementation in Finland led to consequential amendments in sectoral legislation, including the Act on the Protection of Privacy in Working Life (759/2004, amended 2019), the Criminal Code, the Act on Enforcement of Fines, and the Act on the Grey Economy Information Unit.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/finland",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under Section 31(3) of the Data Protection Act, controllers processing special categories of personal data or criminal-offence data must either submit a written DPIA to the Ombudsman 30 days prior to processing, or comply with an approved code of conduct under Section 31(1) as an alternative safeguard.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/system/files/2022-01/legalstudy_on_the_appropriate_safeguards_89.1.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "green",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/finland/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "GDPR Art 6/9 lawful bases apply directly; national supplementary safeguards for sensitive data are documented and enforced.",
   "claims": [
    {
     "statement": "The Finnish SA fined a company for processing health information (BMI and maximal oxygen uptake data) without GDPR-compliant consent, because the consent request was not specific or sufficiently informed as to which data was being collected.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2023/finnish-sa-administrative-fine-company-processing-health-information_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Section 31(3) of the Data Protection Act requires controllers processing special-category or criminal-conviction/offence data to submit a written DPIA to the Ombudsman 30 days before processing, or alternatively to comply with a code of conduct meeting Section 31(1) derogation requirements.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/system/files/2022-01/legalstudy_on_the_appropriate_safeguards_89.1.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Ombudsman fined a company €12,500 for unnecessarily collecting sensitive data from job applicants and employees, including religious beliefs, health status, pregnancy and family status, in breach of the necessity principle under the Act on the Protection of Privacy in Working Life.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2020/finnish-dpa-imposed-three-administrative-fines-data-protection-violations_en",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "green",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/finland/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "GDPR rights framework applies directly and is actively enforced by the Ombudsman across access, objection and transparency dimensions.",
   "claims": [
    {
     "statement": "The Ombudsman fined Suomen Numerokeskus €5,000 for failing to provide data subjects access to call recordings, in violation of GDPR Articles 15(1) and 15(3).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/finland",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The EDPB's 2025 Coordinated Enforcement Framework (CEF) report, in which the Finnish Ombudsman participates as a national SA, identifies challenges and best practices in implementing the GDPR right to erasure.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/finland",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Ombudsman found that Posti Oy failed to inform data subjects of their right to object to disclosure of their personal data in connection with change-of-address notifications, resulting in a €100,000 administrative fine affecting 161,000 customers in 2019 alone.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2020/finnish-dpa-imposed-three-administrative-fines-data-protection-violations_en",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "green",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/finland/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Core GDPR accountability, DPIA, security and breach duties apply directly and are actively enforced with multiple recent fines.",
   "claims": [
    {
     "statement": "The Ombudsman fined Kymen Vesi Oy €16,000 because the company had not carried out the DPIA required by GDPR before processing employee location data via a vehicle information/tracking system.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2020/finnish-dpa-imposed-three-administrative-fines-data-protection-violations_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Taksi Helsinki Oy was fined for failing to conduct DPIAs before deploying an audio-and-video camera surveillance system and before implementing location tracking and automated decision-making/profiling in its customer loyalty scheme.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2020/finnish-dpa-imposes-administrative-fine-several-deficiencies-personal-data_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Finnish SA imposed a €865,000 fine and a reprimand on Aktia Bank for failing to comply with GDPR Article 32 (security of processing) and Article 5(1)(f) (integrity and confidentiality) following a strong electronic authentication service disruption that exposed approximately 350 customers' data, including health and financial information, across multiple connected public and private services.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2025/finnish-sa-aktia-bank-fined-data-security-shortcomings-its-strong_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Ombudsman published guidance on data breach notification obligations in November 2023, noting that approximately half of the matters brought to the Office concern notifications of personal data security breaches.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/finland-ombudsman-publishes-guidance-data-breach",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In the Taksi Helsinki case, the Deputy Data Protection Ombudsman ordered the company to immediately stop processing audio data without appropriate grounds, finding the practice inconsistent with the GDPR data-minimisation principle.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2020/finnish-dpa-imposes-administrative-fine-several-deficiencies-personal-data_en",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "amber",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/finland/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "EU-level transfer mechanisms apply directly, but active Ombudsman scrutiny of US cloud transfers signals unresolved TIA/localisation risk for government and public-sector data flows.",
   "claims": [
    {
     "statement": "The Ombudsman found insufficient protection of personal data in Finnish government cloud services, particularly regarding data transferred to the United States, raising post-Schrems II transfer-impact-assessment concerns for public-sector cloud use.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/finland",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/finland/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Multiple active sectoral overlays (financial, health, employment, credit) show real enforcement friction with the general GDPR regime, though no sector operates fully outside GDPR.",
   "claims": [
    {
     "statement": "FIN-FSA conducted a cyber resilience stress test covering 12 financial entities, finding room for improvement despite existing practices.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/finland",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Deputy Data Protection Ombudsman found deficiencies in patient-data monitoring by the Wellbeing Services County of North Ostrobothnia, resulting in unauthorized access to health records.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/finland",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Office of the Data Protection Ombudsman updated its FAQs on direct marketing, emphasizing information disclosure obligations and the need to honour opt-out requests.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/finland",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under the Act on the Protection of Privacy in Working Life, employers may only process personal data that is necessary in light of the employment relationship; Ombudsman enforcement has found violations where employers documented deficiencies or collected excessive sensitive data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2020/finnish-dpa-imposed-three-administrative-fines-data-protection-violations_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Dun & Bradstreet Finland Oy's practice of limiting free access to credit information to once per year was found non-compliant with GDPR.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/finland",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Finland's Supreme Administrative Court ruled that insurance companies can process health data to assess insurance applications before a contract is in place.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/finland",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "amber",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/finland/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Direct-marketing and consent-quality enforcement is active, but several sub-modules (dark patterns, opt-out signals, clean rooms) show no Finland-specific evidentiary record.",
   "claims": [
    {
     "statement": "LinkedIn will use user data to train AI models starting 3 November 2025, with opt-out options available, a development tracked by the Finnish Ombudsman's regulatory monitoring.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/finland",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Office of the Data Protection Ombudsman updated its FAQs on direct marketing, emphasizing disclosure of information to data subjects and the obligation to honour opt-out requests.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/finland",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/finland/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "AI Act national implementation is newly in force and institutionally still bedding in (organisational reform ongoing), while ADM/profiling enforcement is active but biometric/genetic/surveillance sub-modules lack dedicated national instruments.",
   "claims": [
    {
     "statement": "Taksi Helsinki failed to conduct the DPIA required for the automated decision-making and profiling connected to its customer loyalty scheme.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2020/finnish-dpa-imposes-administrative-fine-several-deficiencies-personal-data_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Taksi Helsinki's privacy statement did not contain information on the automated decision-making and profiling performed in its loyalty scheme, and the Deputy Data Protection Ombudsman ordered the company to change its customer-information policies accordingly.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2020/finnish-dpa-imposes-administrative-fine-several-deficiencies-personal-data_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Finland's national implementation of the EU AI Act, regulating AI systems on a risk basis, entered into force on 1 January 2026, and the Office of the Data Protection Ombudsman announced a reform of its organizational structure to address its new responsibilities under the Act.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/finland",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "High-risk AI systems in Finland will be monitored by the authorities responsible for the EU AI Act, including the Office of the Data Protection Ombudsman, the Financial Supervisory Authority, the Energy Authority, and the Finnish Medicines Agency.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/finland-cyber-resilience-act-enters-force",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/finland/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "The GDPR Art 8 framework is confirmed, but the Finland-specific age figure and children's-project substance require primary-source confirmation; education/dependent-adult sub-modules show no evidentiary record.",
   "claims": [
    {
     "statement": "Under GDPR Article 8, Member States including Finland may set the age at which a child can independently consent to information-society-service processing anywhere between 13 and 16 years old.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "Official Journal of the European Union",
     "source_url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "green",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/finland/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Active, escalating enforcement record with full GDPR corrective/fining powers and judicial appeal route in place; regulator funding/headcount data and collective-redress implementation detail remain unconfirmed.",
   "claims": [
    {
     "statement": "Under GDPR Article 58, EEA data protection authorities including Finland's Ombudsman hold investigative powers plus corrective powers such as warnings, processing bans, compliance orders, suspension of international transfers, certification withdrawal, reprimands, and administrative fines under Article 83.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/sme/find-practical-info/data-protection-authority-you_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Finnish SA imposed a €865,000 fine on Aktia Bank in 2025 for GDPR Article 32/5(1)(f) security-of-processing failures connected to its strong electronic authentication service.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2025/finnish-sa-aktia-bank-fined-data-security-shortcomings-its-strong_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In its first use of administrative fining powers, the Ombudsman's sanctions board imposed fines of €100,000 on Posti Oy, €16,000 on Kymen Vesi Oy, and €12,500 on an employer, in a single set of 2020 decisions covering transparency, DPIA, and data-minimisation violations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2020/finnish-dpa-imposed-three-administrative-fines-data-protection-violations_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Decisions of the Ombudsman's sanctions board are not final and can be appealed in the Finnish administrative court, providing a judicial-remedy pathway consistent with GDPR Articles 78-79.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2020/finnish-dpa-imposed-three-administrative-fines-data-protection-violations_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Finland's national implementation of the EU AI Act, regulating AI systems based on risk, entered into force on 1 January 2026.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/finland",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Finnish Ombudsman will participate in the 2026 EDPB Coordinated Enforcement Framework, focusing on GDPR transparency and information obligations.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/finland",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Ombudsman raised concerns about a Finnish Government draft proposal that would allow the Tax Authority to process mass data on individual account transactions.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/finland",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}