Law / Finland

Finland

privacy

Finland's private-sector regime is the General Data Protection Regulation (GDPR) plus the Data Protection Act (Tietosuojalaki 1050/2018), which specifies and supplements the GDPR within its own scope rather than creating a separate substantive regime.

Distinctive national features, read directly from the Act's own English translation, include a digital age of consent set at 13 (Section 5), a collegial Sanctions Board of the Data Protection Ombudsman and Deputy Ombudsmen that decides administrative fines (Section 24) rather than a single official, and a journalistic and academic expression exemption (Section 27) that disapplies a named list of GDPR articles, including the cross-border transfer chapter, in that narrow context. As at 2026-08-24; later amendment to the Tietosuojalaki is not independently confirmed this pass.

18 instruments named 6 researched in detail As of 2026-08-24

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Breach notification

GDPR Articles 33-34, Breach Notification in Finland

cite Regulation (EU) 2016/679, Arts. 33-34 stage In effect since 2019-01-01 source Official Journal text, EUR-Lex, Regulation (EU) 2016/679

A controller must notify the Data Protection Ombudsman without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Finland, and must notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms. The Data Protection Act adds no separate national breach notification regime.

What it asks of an app

Comprehensive regime

Data Protection Act (Tietosuojalaki)

cite Tietosuojalaki 1050/2018 (amendments up to 29/2024 included) stage In effect since 2019-01-01 source Ministry of Justice, Finland, official English translation, current to amendments through Act 29/2024

The Data Protection Act specifies and supplements the General Data Protection Regulation (GDPR) within the GDPR's own scope of application. Read directly from the Ministry of Justice's official English translation: Section 5 sets the digital age of consent for information society services at 13, the lower bound GDPR Article 8 permits.

Section 24 assigns GDPR Article 83 administrative fines to a collegial Sanctions Board made up of the Data Protection Ombudsman and at least two Deputy Ombudsmen, with a three-member quorum, rather than to a single official, and bars a fine against central government and several other public bodies.

Section 27 disapplies specified GDPR articles for processing performed solely for journalistic, academic, artistic or literary purposes, including Chapter V transfer rules where applying them would infringe freedom of expression.

What it asks of an app

Cross border transfer

GDPR Chapter V, Cross-Border Transfer of Personal Data from Finland

cite Regulation (EU) 2016/679, Arts. 44-50; Tietosuojalaki 1050/2018 sec. 27 stage In effect since 2019-01-01 source Official Journal text, EUR-Lex, Regulation (EU) 2016/679

Transferring personal data of a person in Finland outside the European Economic Area requires a European Commission adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5) top fine tier.

Section 27, read directly, disapplies Articles 44 to 50 for processing performed solely for journalistic, academic, artistic or literary purposes where applying them would infringe freedom of expression or information; outside that narrow exemption no Finland-specific broadening or narrowing of Chapter V was found.

What it asks of an app

Data subject rights

GDPR Article 22 and Data Protection Act Sections 33-34, Data Subject Rights in Finland

cite Regulation (EU) 2016/679, Arts. 15-22; Tietosuojalaki 1050/2018 secs. 21, 33-34 stage In effect since 2019-01-01 source Ministry of Justice, Finland, official English translation, Data Protection Act Sections 21, 33, 34

General Data Protection Regulation (GDPR) Articles 15 to 21 apply, including Article 22's qualified right against a decision based solely on automated processing with legal or similarly significant effect. Data Protection Act Section 33 restricts the Article 13/14 information duty, and Section 34 restricts the Article 15 access right, both on national security, defence, public order, offence prevention, or tax and public finance supervisory grounds, read directly from the Act.

Section 21 gives a right to refer a complaint to the Data Protection Ombudsman, with a three-month handling deadline and a right of appeal to an administrative court if that deadline is missed.

What it asks of an app

Enforcement supervision

GDPR Articles 82-83 and Data Protection Act Section 24, Enforcement in Finland

cite Regulation (EU) 2016/679, Arts. 82-83; Tietosuojalaki 1050/2018 sec. 24 stage In effect since 2019-01-01 source Ministry of Justice, Finland, official English translation, Data Protection Act Section 24

The Data Protection Ombudsman is Finland's supervisory authority. Section 24, read directly, assigns a General Data Protection Regulation (GDPR) Article 83 administrative fine to a collegial Sanctions Board chaired by the Ombudsman with at least two Deputy Ombudsmen and a three-member quorum, carries a ten-year limitation period from the infringement and a five-year limitation on enforcing an already-imposed fine, and bars a fine against central government authorities, municipal authorities, and several other named public bodies.

GDPR Article 82 gives any person who suffered material or non-material damage a right to compensation from the controller or processor, enforceable in the ordinary Finnish courts.

What it asks of an app

Sensitive categories

GDPR Article 9 and Data Protection Act Section 6, Special Categories in Finland

cite Regulation (EU) 2016/679, Art. 9; Tietosuojalaki 1050/2018 sec. 6 stage In effect since 2019-01-01 source Ministry of Justice, Finland, official English translation, Data Protection Act Section 6

General Data Protection Regulation (GDPR) Article 9(1) classifies biometric data processed for unique identification as a special category.

Data Protection Act Section 6, read in full, lifts the Article 9(1) bar in eight named contexts (insurance claims, statutory duty, trade union membership for employment law, healthcare and social welfare delivery, anti-doping and disability sports, and research, statistics or archiving); none of the eight names biometric data, and the section carries no illustrative list or enumeration of biometric identifier types.

Biometric data processed for unique identification is therefore governed directly by GDPR Article 9 itself, with no Finland-specific narrowing or widening of the definition found.

What it asks of an app

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.