Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Breach notification
cite Regulation (EU) 2016/679, Arts. 33-34
stage In effect
since 2019-01-01
source Official Journal text, EUR-Lex, Regulation (EU) 2016/679
A controller must notify the Data Protection Ombudsman without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Finland, and must notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms. The Data Protection Act adds no separate national breach notification regime.
What it asks of an app →
Comprehensive regime
cite Tietosuojalaki 1050/2018 (amendments up to 29/2024 included)
stage In effect
since 2019-01-01
source Ministry of Justice, Finland, official English translation, current to amendments through Act 29/2024
The Data Protection Act specifies and supplements the General Data Protection Regulation (GDPR) within the GDPR's own scope of application. Read directly from the Ministry of Justice's official English translation: Section 5 sets the digital age of consent for information society services at 13, the lower bound GDPR Article 8 permits.
Section 24 assigns GDPR Article 83 administrative fines to a collegial Sanctions Board made up of the Data Protection Ombudsman and at least two Deputy Ombudsmen, with a three-member quorum, rather than to a single official, and bars a fine against central government and several other public bodies.
Section 27 disapplies specified GDPR articles for processing performed solely for journalistic, academic, artistic or literary purposes, including Chapter V transfer rules where applying them would infringe freedom of expression.
What it asks of an app →
Cross border transfer
cite Regulation (EU) 2016/679, Arts. 44-50; Tietosuojalaki 1050/2018 sec. 27
stage In effect
since 2019-01-01
source Official Journal text, EUR-Lex, Regulation (EU) 2016/679
Transferring personal data of a person in Finland outside the European Economic Area requires a European Commission adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5) top fine tier.
Section 27, read directly, disapplies Articles 44 to 50 for processing performed solely for journalistic, academic, artistic or literary purposes where applying them would infringe freedom of expression or information; outside that narrow exemption no Finland-specific broadening or narrowing of Chapter V was found.
What it asks of an app →
Data subject rights
cite Regulation (EU) 2016/679, Arts. 15-22; Tietosuojalaki 1050/2018 secs. 21, 33-34
stage In effect
since 2019-01-01
source Ministry of Justice, Finland, official English translation, Data Protection Act Sections 21, 33, 34
General Data Protection Regulation (GDPR) Articles 15 to 21 apply, including Article 22's qualified right against a decision based solely on automated processing with legal or similarly significant effect. Data Protection Act Section 33 restricts the Article 13/14 information duty, and Section 34 restricts the Article 15 access right, both on national security, defence, public order, offence prevention, or tax and public finance supervisory grounds, read directly from the Act.
Section 21 gives a right to refer a complaint to the Data Protection Ombudsman, with a three-month handling deadline and a right of appeal to an administrative court if that deadline is missed.
What it asks of an app →
Enforcement supervision
cite Regulation (EU) 2016/679, Arts. 82-83; Tietosuojalaki 1050/2018 sec. 24
stage In effect
since 2019-01-01
source Ministry of Justice, Finland, official English translation, Data Protection Act Section 24
The Data Protection Ombudsman is Finland's supervisory authority. Section 24, read directly, assigns a General Data Protection Regulation (GDPR) Article 83 administrative fine to a collegial Sanctions Board chaired by the Ombudsman with at least two Deputy Ombudsmen and a three-member quorum, carries a ten-year limitation period from the infringement and a five-year limitation on enforcing an already-imposed fine, and bars a fine against central government authorities, municipal authorities, and several other named public bodies.
GDPR Article 82 gives any person who suffered material or non-material damage a right to compensation from the controller or processor, enforceable in the ordinary Finnish courts.
What it asks of an app →
Sensitive categories
cite Regulation (EU) 2016/679, Art. 9; Tietosuojalaki 1050/2018 sec. 6
stage In effect
since 2019-01-01
source Ministry of Justice, Finland, official English translation, Data Protection Act Section 6
General Data Protection Regulation (GDPR) Article 9(1) classifies biometric data processed for unique identification as a special category.
Data Protection Act Section 6, read in full, lifts the Article 9(1) bar in eight named contexts (insurance claims, statutory duty, trade union membership for employment law, healthcare and social welfare delivery, anti-doping and disability sports, and research, statistics or archiving); none of the eight names biometric data, and the section carries no illustrative list or enumeration of biometric identifier types.
Biometric data processed for unique identification is therefore governed directly by GDPR Article 9 itself, with no Finland-specific narrowing or widening of the definition found.
What it asks of an app →