🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
FI · run data-protection-2026-08-03 v13-gdpri-1.0.0
content: ai_generated 12 sources retrieved model claude-sonnet-5 ·

Finland

FI schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 36 claims · 12 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
36Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No categories are currently flagged red.

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive, mature GDPR-aligned omnibus framework with an active, resourced supervisory authority and clear national implementing act.

Primary frameworkGDPR (Regulation (EU) 2016/679) as supplemented by the Data Protection Act (1050/2018)
Traffic-light rationale — GreenComprehensive, mature GDPR-aligned omnibus framework with an active, resourced supervisory authority and clear national implementing act.

Sub-modules (5)

Regulator And AuthorityGreen

The Office of the Data Protection Ombudsman acts as Finland's sole GDPR supervisory authority, including a sanctions board that issues administrative fines and reprimands.

Claims: CLM-FI-a1b2c3d4

Act And InstrumentsGreen

The Data Protection Act (1050/2018) supplements the GDPR nationally; related sectoral amendments cover working-life privacy, the Criminal Code, and fines enforcement.

Claims: CLM-FI-b2c3d4e5, CLM-FI-c3d4e5f6

Material ScopeGreen

Material scope tracks GDPR Article 2/4 definitions of personal data and processing directly, with no identified Finnish derogation narrowing scope.

Territorial ScopeAmber

Territorial scope follows GDPR Article 3 (establishment and targeting tests) directly; no Finland-specific extension or carve-out was identified in this research pass.

Absence provenance: not recorded. Searched: Finland GDPR Article 3 territorial scope national derogation.

Regulator Registration And FilingAmber

No general controller registration/notification regime exists (abolished EU-wide by GDPR), but Section 31(3) of the Data Protection Act requires controllers processing special-category or criminal-offence data to submit a DPIA in writing to the Ombudsman at least 30 days before processing begins, unless an approved code of conduct is followed instead.

Claims: CLM-FI-d4e5f6a7

Category narrative65 words

Finland is an EU Member State operating under the directly-applicable GDPR, nationally supplemented by the Data Protection Act (1050/2018), which entered into force 1 January 2019 and repealed the earlier Personal Data Act (523/1999). The Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto) is the sole national supervisory authority for GDPR and its supplementing legislation, including a dedicated sanctions board empowered to impose administrative fines.

Sources and claims (4)
  1. ConfirmedDataGuidanceThe Office of the Data Protection Ombudsman acts as the Finnish supervisory authority for GDPR and its supplementing national legislation.
  2. ConfirmedDataGuidanceFinland implemented the GDPR through the Data Protection Act (1050/2018), which entered into force on 1 January 2019 and repealed the Personal Data Act (523/1999).
  3. ConfirmedDataGuidanceGDPR implementation in Finland led to consequential amendments in sectoral legislation, including the Act on the Protection of Privacy in Working Life (759/2004, amended 2019), the Criminal Code, the Act on Enforcement of Fines, and the Act on the Grey Economy Information Unit.
  4. ProbableEDPBUnder Section 31(3) of the Data Protection Act, controllers processing special categories of personal data or criminal-offence data must either submit a written DPIA to the Ombudsman 30 days prior to processing, or comply with an approved code of conduct under Section 31(1) as an alternative safeguard.

#

GDPR Art 6/9 lawful bases apply directly; national supplementary safeguards for sensitive data are documented and enforced.

Primary frameworkGDPR Articles 6, 7, 9 as supplemented by Data Protection Act (1050/2018) Section 31
Traffic-light rationale — GreenGDPR Art 6/9 lawful bases apply directly; national supplementary safeguards for sensitive data are documented and enforced.

Sub-modules (4)

Lawful BasesGreen

Finland applies GDPR Article 6 lawful bases directly with no identified national restriction of the enumerated bases.

Special CategoriesAmber

Special-category processing (Art 9) is subject to Section 31 Data Protection Act safeguards requiring DPIA submission or code-of-conduct adherence; enforcement has targeted deficient consent for health data and unnecessary collection of sensitive employee data (religion, health, pregnancy, family status).

Claims: CLM-FI-f6a7b8c9, CLM-FI-a7b8c9d0

Pseudonymisation And AnonymisationRed

No Finland-specific pseudonymisation/anonymisation safe-harbour distinct from GDPR Art 4(5)/Recital 26 was identified in this research pass.

Absence provenance: not recorded. Searched: Finland Data Protection Act pseudonymisation anonymisation safe harbour.

Category narrative51 words

Finland relies directly on the GDPR Article 6 lawful bases and Article 9 special-category regime, with the Data Protection Act adding national safeguards (Section 31) for special categories and criminal-offence data, generally requiring a DPIA or code-of-conduct compliance. Enforcement activity shows the Ombudsman actively policing consent quality for special-category (health) data.

Sources and claims (3)
  1. ConfirmedEDPBThe Finnish SA fined a company for processing health information (BMI and maximal oxygen uptake data) without GDPR-compliant consent, because the consent request was not specific or sufficiently informed as to which data was being collected.
  2. ProbableEDPBSection 31(3) of the Data Protection Act requires controllers processing special-category or criminal-conviction/offence data to submit a written DPIA to the Ombudsman 30 days before processing, or alternatively to comply with a code of conduct meeting Section 31(1) derogation requirements.
  3. ConfirmedEDPBThe Ombudsman fined a company €12,500 for unnecessarily collecting sensitive data from job applicants and employees, including religious beliefs, health status, pregnancy and family status, in breach of the necessity principle under the Act on the Protection of Privacy in Working Life.

#

GDPR rights framework applies directly and is actively enforced by the Ombudsman across access, objection and transparency dimensions.

Primary frameworkGDPR Articles 12-22
Traffic-light rationale — GreenGDPR rights framework applies directly and is actively enforced by the Ombudsman across access, objection and transparency dimensions.

Sub-modules (5)

Access RightAmber

The Ombudsman actively enforces Article 15 access rights; a company was fined for failing to provide access to call recordings.

Claims: CLM-FI-b8c9d0e1

Rectification And ErasureGreen

Rectification/erasure follow GDPR Art 16/17 directly; Finland's Ombudsman participates in EDPB coordinated work on erasure implementation challenges.

Claims: CLM-FI-c9d0e1f2

Restriction And ObjectionAmber

Enforcement action against Posti Oy found the company failed to properly inform customers of their right to object to disclosure of personal data collected via change-of-address notifications.

Claims: CLM-FI-d0e1f2a3

Data PortabilityAmber

Portability rights follow GDPR Art 20 directly; no Finland-specific enforcement or derogation was identified in this pass.

Absence provenance: not recorded. Searched: Finland Data Protection Ombudsman data portability enforcement decision.

Deadlines And Response WindowsGreen

Statutory response deadlines follow GDPR Art 12(3) (one month, extendable by two further months for complex requests) directly, with no Finnish national variation identified.

Category narrative37 words

Finland applies the GDPR Chapter III data subject rights (Articles 12-22) directly, with no material national derogation identified. Enforcement activity demonstrates active policing of the access right, the right to object, and transparency obligations connected to profiling.

Sources and claims (3)
  1. ConfirmedDataGuidanceThe Ombudsman fined Suomen Numerokeskus €5,000 for failing to provide data subjects access to call recordings, in violation of GDPR Articles 15(1) and 15(3).
  2. ProbableDataGuidanceThe EDPB's 2025 Coordinated Enforcement Framework (CEF) report, in which the Finnish Ombudsman participates as a national SA, identifies challenges and best practices in implementing the GDPR right to erasure.
  3. ConfirmedEDPBThe Ombudsman found that Posti Oy failed to inform data subjects of their right to object to disclosure of their personal data in connection with change-of-address notifications, resulting in a €100,000 administrative fine affecting 161,000 customers in 2019 alone.

#

Core GDPR accountability, DPIA, security and breach duties apply directly and are actively enforced with multiple recent fines.

Primary frameworkGDPR Articles 24-39 as supplemented by Data Protection Act (1050/2018)
Traffic-light rationale — GreenCore GDPR accountability, DPIA, security and breach duties apply directly and are actively enforced with multiple recent fines.

Sub-modules (7)

Accountability And DpiaAmber

DPIA obligations under GDPR Art 35 are actively enforced; Kymen Vesi Oy and Taksi Helsinki Oy were both sanctioned for failing to conduct required DPIAs before high-risk processing (location tracking, camera/audio surveillance, ADM-driven loyalty schemes).

Claims: CLM-FI-e1f2a3b4, CLM-FI-f2a3b4c5

Dpo RequirementsAmber

GDPR Art 37-39 DPO appointment thresholds apply directly; the Ombudsman has requested organisations update their registered DPO contact details, but the substantive detail of the current DPO notification mechanism could not be fully confirmed via open-access sources in this pass.

Absence provenance: not recorded. Searched: Finland Ombudsman DPO notification update requirement 2025.

Ropa RequirementsGreen

Records of Processing Activities obligations follow GDPR Art 30 directly; no Finland-specific ROPA derogation or template mandate was identified.

Joint Controller ArrangementsAmber

Joint-controller arrangements follow GDPR Art 26/28 directly; no Finland-specific joint-controller enforcement or guidance was identified in this pass.

Absence provenance: not recorded. Searched: Finland Ombudsman joint controller Article 26 guidance.

Security MeasuresAmber

Article 32 security-of-processing and Article 25 data-protection-by-design obligations are actively enforced, most notably in the 2025 Aktia Bank case concerning a strong electronic authentication service defect.

Claims: CLM-FI-a3b4c5d6

Breach NotificationGreen

Breach notification follows GDPR Art 33/34 directly; the Ombudsman published dedicated guidance on breach notification obligations in November 2023, noting that roughly half of the matters it receives are data-breach notifications.

Claims: CLM-FI-b4c5d6e7

Retention And DisposalAmber

Retention/disposal duties flow from the GDPR data-minimisation and storage-limitation principles; enforcement has ordered deletion of unnecessarily collected data and cessation of excessive audio-data processing.

Claims: CLM-FI-c5d6e7f8

Category narrative53 words

GDPR Articles 24-39 apply directly with the Data Protection Act layering national procedural detail for special-category DPIAs. Finnish enforcement demonstrates consistent action on missing DPIAs, security-of-processing failures (Article 32), and data minimisation lapses, and the Ombudsman has published dedicated guidance on breach notification given that roughly half of matters received concern breach notifications.

Sources and claims (5)
  1. ConfirmedEDPBThe Ombudsman fined Kymen Vesi Oy €16,000 because the company had not carried out the DPIA required by GDPR before processing employee location data via a vehicle information/tracking system.
  2. ConfirmedEDPBTaksi Helsinki Oy was fined for failing to conduct DPIAs before deploying an audio-and-video camera surveillance system and before implementing location tracking and automated decision-making/profiling in its customer loyalty scheme.
  3. ConfirmedEDPBThe Finnish SA imposed a €865,000 fine and a reprimand on Aktia Bank for failing to comply with GDPR Article 32 (security of processing) and Article 5(1)(f) (integrity and confidentiality) following a strong electronic authentication service disruption that exposed approximately 350 customers' data, including health and financial information, across multiple connected public and private services.
  4. ConfirmedDataGuidanceThe Ombudsman published guidance on data breach notification obligations in November 2023, noting that approximately half of the matters brought to the Office concern notifications of personal data security breaches.
  5. ConfirmedEDPBIn the Taksi Helsinki case, the Deputy Data Protection Ombudsman ordered the company to immediately stop processing audio data without appropriate grounds, finding the practice inconsistent with the GDPR data-minimisation principle.

#

EU-level transfer mechanisms apply directly, but active Ombudsman scrutiny of US cloud transfers signals unresolved TIA/localisation risk for government and public-sector data flows.

Primary frameworkGDPR Articles 44-49 (Chapter V)
Traffic-light rationale — AmberEU-level transfer mechanisms apply directly, but active Ombudsman scrutiny of US cloud transfers signals unresolved TIA/localisation risk for government and public-sector data flows.

Sub-modules (6)

Transfer MechanismsGreen

Transfer mechanisms (adequacy, SCCs, BCRs, Art 49 derogations) apply directly under GDPR Chapter V; Finland has no additional national transfer gateway.

Adequacy ReceivedAmber

Adequacy decisions are adopted by the European Commission on behalf of all EU Member States including Finland; there is no separate Finland-specific adequacy determination.

Absence provenance: not recorded. Searched: Finland national adequacy decision GDPR.

Adequacy GrantedAmber

Adequacy is granted by the European Commission for the EU as a bloc; Finland does not issue independent adequacy findings toward third countries.

Absence provenance: not recorded. Searched: Finland grants adequacy third country.

Sccs And BcrsGreen

EU Standard Contractual Clauses and BCRs are available and used by Finnish controllers/processors per the EU-wide GDPR framework; no Finland-specific SCC/BCR variant was identified.

Transfer Impact AssessmentAmber

Following Schrems II, the Ombudsman has actively scrutinised US-bound transfers, finding insufficient protection of personal data in Finnish government cloud services where data was transferred to the United States.

Claims: CLM-FI-d6e7f8a9

Data LocalisationAmber

No comprehensive data-localisation mandate was identified for Finland beyond sector-specific public-sector cloud-transfer concerns.

Absence provenance: not recorded. Searched: Finland data localisation mandate personal data.

Category narrative69 words

As an EU Member State, Finland relies on the GDPR Chapter V mechanisms (adequacy decisions, SCCs, BCRs, derogations) which are adopted at EU level rather than negotiated bilaterally by Finland; 'adequacy received/granted' therefore operates through the European Commission rather than a distinct Finnish determination. Post-Schrems II transfer-impact-assessment scrutiny is active: the Ombudsman has flagged insufficient protection for personal data transferred to the United States via Finnish government cloud services.

Sources and claims (1)
  1. ProbableDataGuidanceThe Ombudsman found insufficient protection of personal data in Finnish government cloud services, particularly regarding data transferred to the United States, raising post-Schrems II transfer-impact-assessment concerns for public-sector cloud use.

#

Multiple active sectoral overlays (financial, health, employment, credit) show real enforcement friction with the general GDPR regime, though no sector operates fully outside GDPR.

Primary frameworkGDPR supplemented by sector laws: Act on the Protection of Privacy in Working Life (759/2004); Credit Information Act; FIN-FSA supervisory framework
Traffic-light rationale — AmberMultiple active sectoral overlays (financial, health, employment, credit) show real enforcement friction with the general GDPR regime, though no sector operates fully outside GDPR.

Sub-modules (7)

Financial Sector OverlayAmber

FIN-FSA (Finanssivalvonta) conducts cyber-resilience stress testing of financial entities, while the Ombudsman separately enforces GDPR security duties against banks, as shown by the Aktia Bank fine.

Claims: CLM-FI-e7f8a9b0

Health Sector OverlayAmber

The Deputy Data Protection Ombudsman found deficiencies in patient-data access monitoring by a Wellbeing Services County, leading to unauthorized access to health records.

Claims: CLM-FI-f8a9b0c1

Telecoms And EprivacyAmber

ePrivacy rules apply to Finnish electronic communications; the Ombudsman has updated FAQ guidance on direct-marketing communications, but the specific Finnish implementing instrument for the ePrivacy Directive was not independently re-confirmed in this pass.

Absence provenance: not recorded. Searched: Finland Act on Electronic Communications Services ePrivacy Directive implementation.

Claims: CLM-FI-a9b0c1d2

Employment DataAmber

The Act on the Protection of Privacy in Working Life (759/2004, as amended 2019) restricts employers to processing only data necessary for the employment relationship; enforcement actions have penalised excess collection and undocumented processing.

Claims: CLM-FI-b0c1d2e3

Credit And ScoringAmber

Credit-reporting practices have drawn GDPR enforcement scrutiny in Finland, including a finding that Dun & Bradstreet Finland Oy's practice of limiting free access to credit information to once per year was non-compliant with GDPR.

Claims: CLM-FI-c1d2e3f4

EducationRed

No education-sector-specific data protection overlay or enforcement action was identified for Finland in this research pass.

Absence provenance: not recorded. Searched: Finland education sector data protection overlay student data.

InsuranceGreen

Finland's Supreme Administrative Court ruled that insurance companies may process health data to assess insurance applications before a contract is in place.

Claims: CLM-FI-d2e3f4a5

Category narrative74 words

Finland layers sector-specific overlays atop the GDPR baseline: FIN-FSA (Finanssivalvonta) oversight of financial-sector cyber resilience intersects with DP security duties (as in the Aktia Bank case); health-sector patient-data governance has drawn Ombudsman scrutiny; the Act on the Protection of Privacy in Working Life constrains employment-data processing; and credit-reporting practices (Suomen Asiakastieto, Dun & Bradstreet Finland) have been found non-compliant with GDPR access/transparency norms. The Supreme Administrative Court has also clarified insurance-sector health-data processing rules.

Sources and claims (6)
  1. ProbableDataGuidanceFIN-FSA conducted a cyber resilience stress test covering 12 financial entities, finding room for improvement despite existing practices.
  2. ProbableDataGuidanceThe Deputy Data Protection Ombudsman found deficiencies in patient-data monitoring by the Wellbeing Services County of North Ostrobothnia, resulting in unauthorized access to health records.
  3. ProbableDataGuidanceThe Office of the Data Protection Ombudsman updated its FAQs on direct marketing, emphasizing information disclosure obligations and the need to honour opt-out requests.
  4. ConfirmedEDPBUnder the Act on the Protection of Privacy in Working Life, employers may only process personal data that is necessary in light of the employment relationship; Ombudsman enforcement has found violations where employers documented deficiencies or collected excessive sensitive data.
  5. ProbableDataGuidanceDun & Bradstreet Finland Oy's practice of limiting free access to credit information to once per year was found non-compliant with GDPR.
  6. ProbableDataGuidanceFinland's Supreme Administrative Court ruled that insurance companies can process health data to assess insurance applications before a contract is in place.

#

Direct-marketing and consent-quality enforcement is active, but several sub-modules (dark patterns, opt-out signals, clean rooms) show no Finland-specific evidentiary record.

Primary frameworkePrivacy Directive (2002/58/EC) and GDPR consent framework
Traffic-light rationale — AmberDirect-marketing and consent-quality enforcement is active, but several sub-modules (dark patterns, opt-out signals, clean rooms) show no Finland-specific evidentiary record.

Sub-modules (6)

Cookies And TrackersAmber

Cookie/tracker consent follows the EU ePrivacy Directive as nationally transposed, operating alongside GDPR; the specific Finnish transposing instrument was not independently re-confirmed in this research pass.

Absence provenance: not recorded. Searched: Finland cookie consent law ePrivacy transposition.

Dark PatternsRed

No Finland-specific dark-pattern prohibition or enforcement action distinct from general GDPR transparency/consent requirements was identified.

Absence provenance: not recorded. Searched: Finland dark patterns enforcement Ombudsman.

Opt Out SignalsRed

No Finland-specific recognition of technical opt-out signals (e.g., Global Privacy Control) was identified.

Absence provenance: not recorded. Searched: Finland Global Privacy Control opt-out signal recognition.

Clean Rooms And DcrRed

No Finland-specific clean-room/data-collaboration-room guidance was identified.

Absence provenance: not recorded. Searched: Finland data clean room guidance Ombudsman.

Cross Context AdvertisingAmber

The Finnish Ombudsman's monitoring feed tracks pan-EU commercial developments such as LinkedIn's planned use of user data to train AI models from November 2025 with opt-out options, relevant to Finnish data subjects though not a Finland-specific rule.

Claims: CLM-FI-e3f4a5b6

Direct MarketingAmber

Direct marketing is subject to GDPR consent/objection rules; the Ombudsman updated FAQs emphasising disclosure obligations and honouring opt-out requests, and the Posti case established enforcement precedent on informing customers of objection rights connected to direct marketing.

Claims: CLM-FI-f4a5b6c7

Category narrative67 words

Finland's cookie/tracker regime derives from the EU ePrivacy Directive as transposed nationally, operating alongside GDPR consent standards; the Ombudsman has refreshed direct-marketing FAQ guidance emphasising disclosure and opt-out honouring. Broader commercial-privacy questions (dark patterns, opt-out signals, clean rooms) show no dedicated Finnish enforcement record in this pass, and pan-EU developments such as LinkedIn's AI-training data use are monitored by the Ombudsman's feed but are not Finland-specific rules.

Sources and claims (2)
  1. UncertainDataGuidanceLinkedIn will use user data to train AI models starting 3 November 2025, with opt-out options available, a development tracked by the Finnish Ombudsman's regulatory monitoring.
  2. ProbableDataGuidanceThe Office of the Data Protection Ombudsman updated its FAQs on direct marketing, emphasizing disclosure of information to data subjects and the obligation to honour opt-out requests.

#

AI Act national implementation is newly in force and institutionally still bedding in (organisational reform ongoing), while ADM/profiling enforcement is active but biometric/genetic/surveillance sub-modules lack dedicated national instruments.

Primary frameworkGDPR Article 22; EU AI Act as nationally implemented in Finland (effective 1 January 2026)
Traffic-light rationale — AmberAI Act national implementation is newly in force and institutionally still bedding in (organisational reform ongoing), while ADM/profiling enforcement is active but biometric/genetic/surveillance sub-modules lack dedicated national instruments.

Sub-modules (6)

Profiling RestrictionsAmber

Profiling restrictions under GDPR Art 22 are actively enforced; Taksi Helsinki's loyalty-scheme profiling lacked a required DPIA.

Claims: CLM-FI-a5b6c7d8

Automated Decision Making TransparencyAmber

ADM transparency failures were found where Taksi Helsinki's privacy statement did not disclose the automated decision-making and profiling performed within its loyalty scheme.

Claims: CLM-FI-b6c7d8e9

Ai Risk AssessmentsAmber

Finland's national AI Act implementation entered into force on 1 January 2026; the Ombudsman announced an organisational restructuring to take on new AI Act supervisory responsibilities, and high-risk AI systems will be monitored jointly by the Ombudsman, FIN-FSA, the Energy Authority, and the Finnish Medicines Agency.

Claims: CLM-FI-c7d8e9f0, CLM-FI-d8e9f0a1

Biometric RegimeAmber

Biometric data is treated as a GDPR Article 9 special category; no distinct Finnish biometric-specific statute (e.g., dedicated facial-recognition law) was identified in this pass.

Absence provenance: not recorded. Searched: Finland biometric data facial recognition law.

Genetic DataAmber

Genetic data is treated as a GDPR Article 9 special category; no distinct Finnish genetic-data statute was identified in this pass.

Absence provenance: not recorded. Searched: Finland genetic data protection law biobank.

State Surveillance CarveoutsRed

No Finland-specific state-surveillance carve-out or national-security exemption beyond general GDPR Article 23 restriction provisions was identified in this pass.

Absence provenance: not recorded. Searched: Finland national security surveillance data protection exemption.

Category narrative101 words

Profiling/ADM transparency obligations under GDPR Article 22 are actively enforced (Taksi Helsinki loyalty-scheme case). Finland's national implementation of the EU AI Act entered into force on 1 January 2026, and the Office of the Data Protection Ombudsman has reformed its organisational structure to take on new AI Act responsibilities; high-risk AI systems will be monitored jointly by the Ombudsman, the Financial Supervisory Authority, the Energy Authority and the Finnish Medicines Agency. Biometric and genetic data are covered as GDPR Article 9 special categories with no distinct national biometric statute identified, and no specific state-surveillance carve-out beyond general GDPR/national-security exemptions was located.

Sources and claims (4)
  1. ConfirmedEDPBTaksi Helsinki failed to conduct the DPIA required for the automated decision-making and profiling connected to its customer loyalty scheme.
  2. ConfirmedEDPBTaksi Helsinki's privacy statement did not contain information on the automated decision-making and profiling performed in its loyalty scheme, and the Deputy Data Protection Ombudsman ordered the company to change its customer-information policies accordingly.
  3. ConfirmedDataGuidanceFinland's national implementation of the EU AI Act, regulating AI systems on a risk basis, entered into force on 1 January 2026, and the Office of the Data Protection Ombudsman announced a reform of its organizational structure to address its new responsibilities under the Act.
  4. ConfirmedDataGuidanceHigh-risk AI systems in Finland will be monitored by the authorities responsible for the EU AI Act, including the Office of the Data Protection Ombudsman, the Financial Supervisory Authority, the Energy Authority, and the Finnish Medicines Agency.

#

The GDPR Art 8 framework is confirmed, but the Finland-specific age figure and children's-project substance require primary-source confirmation; education/dependent-adult sub-modules show no evidentiary record.

Primary frameworkGDPR Article 8, as fixed nationally by the Data Protection Act (1050/2018)
Traffic-light rationale — AmberThe GDPR Art 8 framework is confirmed, but the Finland-specific age figure and children's-project substance require primary-source confirmation; education/dependent-adult sub-modules show no evidentiary record.

Sub-modules (5)

Age VerificationAmber

No dedicated Finnish age-verification mandate distinct from the GDPR Article 8 consent-age framework was identified.

Absence provenance: not recorded. Searched: Finland age verification law information society services.

Minor Profiling BansRed

The Ombudsman launched a project (GDPR4chldrn) focused on children's data protection, but the substantive content and any profiling-ban specifics were behind a paywall and could not be verified in this pass.

Absence provenance: not recorded. Searched: Finland Ombudsman GDPR4chldrn project children profiling.

Education SettingsRed

No education-sector-specific children's-data rule was identified for Finland in this pass.

Absence provenance: not recorded. Searched: Finland education settings student data protection rules.

Dependent AdultsRed

No dependent-adult/vulnerable-adult-specific DP overlay was identified for Finland in this pass.

Absence provenance: not recorded. Searched: Finland dependent adults vulnerable adults data protection.

Category narrative87 words

GDPR Article 8 sets an EU-wide range (13-16) within which each Member State fixes the age at which a child may independently consent to information-society-service processing. Finland's specific statutory figure under the Data Protection Act (commonly understood to be 13) could not be independently re-confirmed against a primary Finlex source within this research pass, so it is carried at reduced confidence. The Ombudsman has run a dedicated children's-data project (GDPR4chldrn), though substantive detail was not accessible this run. No dedicated education-sector or dependent-adult DP overlay was identified.

Sources and claims (1)
  1. ProbableOfficial Journal of the European UnionUnder GDPR Article 8, Member States including Finland may set the age at which a child can independently consent to information-society-service processing anywhere between 13 and 16 years old.

#

Active, escalating enforcement record with full GDPR corrective/fining powers and judicial appeal route in place; regulator funding/headcount data and collective-redress implementation detail remain unconfirmed.

Primary frameworkGDPR Articles 58, 77-84, as supplemented by the Data Protection Act (1050/2018)
Traffic-light rationale — GreenActive, escalating enforcement record with full GDPR corrective/fining powers and judicial appeal route in place; regulator funding/headcount data and collective-redress implementation detail remain unconfirmed.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

The Ombudsman's sanctions board exercises GDPR Art 58 investigative, corrective and authorisation powers, including warnings, compliance orders, processing bans, certification withdrawal, and Art 83 administrative fines.

Claims: CLM-FI-f0a1b2c3

Enforcement Activity IndexAmber

Finland shows sustained enforcement activity across 2020-2025, spanning security failures (Aktia Bank, €865,000), transparency/objection failures (Posti, €100,000 and a later €2.4 million fine, Verkkokauppa.com €856,000), DPIA failures (Kymen Vesi €16,000), and access-right failures (Suomen Numerokeskus €5,000).

Claims: CLM-FI-a1b2c3d5, CLM-FI-b2c3d5e6

Regulator Funding And CapacityRed

No specific data on the Ombudsman's budget or headcount was identified in this research pass.

Absence provenance: not recorded. Searched: Office of the Data Protection Ombudsman Finland budget headcount staffing.

Collective Redress And Class ActionsRed

GDPR Article 80 representative-action mechanisms apply at EU level; Finland's specific transposition of the EU Representative Actions Directive for data protection collective redress was not independently confirmed in this pass.

Absence provenance: not recorded. Searched: Finland Representative Actions Directive GDPR Article 80 collective redress transposition.

Private Right Of ActionGreen

Data subjects and the Ombudsman's decisions are both subject to judicial oversight: Ombudsman sanctions-board decisions are not final and can be appealed to the Finnish administrative court, consistent with GDPR Article 78/79 judicial remedy rights.

Claims: CLM-FI-c3d5e6f7

Recent Developments 180DAmber

Within the last 180 days, Finland's national AI Act implementation entered into force (1 January 2026); the Ombudsman confirmed participation in the 2026 EDPB Coordinated Enforcement Framework focused on transparency and information obligations; NCSC-FI published quantum-secure encryption transition guidance; and the Ombudsman raised concerns about a government proposal to let the Tax Authority process mass account-transaction data.

Claims: CLM-FI-d5e6f7a8, CLM-FI-e6f7a8b9, CLM-FI-f7a8b9c0

Category narrative82 words

The Ombudsman's sanctions board exercises the full GDPR Article 58 investigative/corrective toolkit and Article 83 fining powers, with a sustained and growing enforcement record (Aktia Bank €865,000; Posti €100,000 then a later €2.4 million fine; Verkkokauppa.com €856,000; Kymen Vesi €16,000; Suomen Numerokeskus €5,000; various smaller fines). Decisions are appealable to the Finnish administrative courts before becoming final. Recent 180-day developments include Finland's AI Act national implementation entering into force, continued CEF participation, and public scrutiny of a government Tax Authority mass-data-processing proposal.

Sources and claims (7)
  1. ConfirmedEDPBUnder GDPR Article 58, EEA data protection authorities including Finland's Ombudsman hold investigative powers plus corrective powers such as warnings, processing bans, compliance orders, suspension of international transfers, certification withdrawal, reprimands, and administrative fines under Article 83.
  2. ConfirmedEDPBThe Finnish SA imposed a €865,000 fine on Aktia Bank in 2025 for GDPR Article 32/5(1)(f) security-of-processing failures connected to its strong electronic authentication service.
  3. ConfirmedEDPBIn its first use of administrative fining powers, the Ombudsman's sanctions board imposed fines of €100,000 on Posti Oy, €16,000 on Kymen Vesi Oy, and €12,500 on an employer, in a single set of 2020 decisions covering transparency, DPIA, and data-minimisation violations.
  4. ConfirmedEDPBDecisions of the Ombudsman's sanctions board are not final and can be appealed in the Finnish administrative court, providing a judicial-remedy pathway consistent with GDPR Articles 78-79.
  5. ConfirmedDataGuidanceFinland's national implementation of the EU AI Act, regulating AI systems based on risk, entered into force on 1 January 2026.
  6. ConfirmedDataGuidanceThe Finnish Ombudsman will participate in the 2026 EDPB Coordinated Enforcement Framework, focusing on GDPR transparency and information obligations.
  7. ProbableDataGuidanceThe Ombudsman raised concerns about a Finnish Government draft proposal that would allow the Tax Authority to process mass data on individual account transactions.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Finland
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 36 claim(s), 12 source(s) in the cumulative register.