#
Comprehensive, mature GDPR-aligned omnibus framework with an active, resourced supervisory authority and clear national implementing act.
Sub-modules (5)
Regulator And AuthorityGreen
The Office of the Data Protection Ombudsman acts as Finland's sole GDPR supervisory authority, including a sanctions board that issues administrative fines and reprimands.
Claims: CLM-FI-a1b2c3d4
Act And InstrumentsGreen
The Data Protection Act (1050/2018) supplements the GDPR nationally; related sectoral amendments cover working-life privacy, the Criminal Code, and fines enforcement.
Claims: CLM-FI-b2c3d4e5, CLM-FI-c3d4e5f6
Material ScopeGreen
Material scope tracks GDPR Article 2/4 definitions of personal data and processing directly, with no identified Finnish derogation narrowing scope.
Territorial ScopeAmber
Territorial scope follows GDPR Article 3 (establishment and targeting tests) directly; no Finland-specific extension or carve-out was identified in this research pass.
Absence provenance: not recorded. Searched: Finland GDPR Article 3 territorial scope national derogation.
Regulator Registration And FilingAmber
No general controller registration/notification regime exists (abolished EU-wide by GDPR), but Section 31(3) of the Data Protection Act requires controllers processing special-category or criminal-offence data to submit a DPIA in writing to the Ombudsman at least 30 days before processing begins, unless an approved code of conduct is followed instead.
Claims: CLM-FI-d4e5f6a7
Sources and claims (4)
- ConfirmedDataGuidance — The Office of the Data Protection Ombudsman acts as the Finnish supervisory authority for GDPR and its supplementing national legislation.
- ConfirmedDataGuidance — Finland implemented the GDPR through the Data Protection Act (1050/2018), which entered into force on 1 January 2019 and repealed the Personal Data Act (523/1999).
- ConfirmedDataGuidance — GDPR implementation in Finland led to consequential amendments in sectoral legislation, including the Act on the Protection of Privacy in Working Life (759/2004, amended 2019), the Criminal Code, the Act on Enforcement of Fines, and the Act on the Grey Economy Information Unit.
- ProbableEDPB — Under Section 31(3) of the Data Protection Act, controllers processing special categories of personal data or criminal-offence data must either submit a written DPIA to the Ombudsman 30 days prior to processing, or comply with an approved code of conduct under Section 31(1) as an alternative safeguard.