Skip to content

Evidence request lists

Finland Data Protection Act (Tietosuojalaki, 1050/2018)

Evidence request list. 11 controls, 11 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Finland DPA: Bilingual Transparency, Data Subject Rights Coordination with GDPR + Children

FiDPA-Bilingual-Rights-Children
Bilingual Transparency, Data Subject Rights Coordination with GDPR + Children

Tietosuojalaki + Language Act + Constitution coordination for transparency + data subject rights. BILINGUAL TRANSPARENCY: under the Constitution Section 17 + Language Act 423/2003, Finland is officially bilingual (Finnish + Swedish) + the SAAMI LANGUAGE ACT 1086/2003 protects Sami languages in the Sami homeland; data subject information notices + privacy notices + consent forms must be provided in BOTH FINNISH + SWEDISH where the controller serves the broader population or in BILINGUAL MUNICIPALITIES; SAMI language where relevant for Sami-administrative-region. ENGLISH + OTHER LANGUAGES: encouraged for inclusiveness but not mandatory unless the audience is specifically non-Finnish-speaking. DATA SUBJECT RIGHTS: GDPR Articles 12-22 apply directly + the Tietosuojalaki Section 34 carries derogations for archival + research + journalism. CHILDREN'S DATA: GDPR Article 8 age-of-digital-consent

Artefacts an auditor will ask for
  • Bilingual + multilingual notice templates
  • Age-of-digital-consent compliance
  • Rights derogation documentation
Where this commonly fails
  • Notices only in English or Finnish without Swedish
  • Age 16 used (GDPR default) when 13 applies in Finland
  • Rights derogations unclear or undocumented

Finland DPA: Data Protection Ombudsman (Tietosuojavaltuutettu) and Supervisory Authority

FiDPA-Tietosuojavaltuutettu
Data Protection Ombudsman (Tietosuojavaltuutettu) - Supervisory Authority

Tietosuojalaki Sections 8-13 - Data Protection Ombudsman (Tietosuojavaltuutettu, official English title: Office of the Data Protection Ombudsman). The Tietosuojavaltuutettu is the Finnish GDPR supervisory authority + responsible for: (a) MONITORING + ENFORCING GDPR + the Tietosuojalaki + sectoral data-protection rules; (b) HANDLING COMPLAINTS from data subjects + investigating breaches; (c) ISSUING GUIDANCE + DECISIONS on the application of GDPR + the Act; (d) MAINTAINING the REGISTER OF DATA PROTECTION OFFICERS + processing-activities + statutory notifications; (e) COOPERATING with other Member States via the EUROPEAN DATA PROTECTION BOARD (EDPB) + the GDPR ONE-STOP-SHOP mechanism for cross-border processing; (f) IMPOSING ADMINISTRATIVE FINES via the Sanctions Collegium (see separate control); (g) CONDUCTING AUDITS + INSPECTIONS with statutory cooperation rights including entry to contr

Artefacts an auditor will ask for
  • DPO appointment + Tietosuojavaltuutettu notification evidence
  • Audit cooperation procedure
  • One-Stop-Shop lead-supervisor designation if applicable
Where this commonly fails
  • DPO not notified to Tietosuojavaltuutettu
  • Audit cooperation slow or incomplete
  • One-Stop-Shop lead designation missing or stale

Finland DPA: Lawful Basis, Personal Identity Code (Henkilotunnus) and Special Categories

FiDPA-LawfulBasis-IdCode
Lawful Basis Under Public Interest + Personal Identity Code (Henkilotunnus) (Section 4-5, 29)

Tietosuojalaki Sections 4-5 (lawful basis) + Section 29 (personal identity code). SECTION 4 LAWFUL BASIS: GDPR Article 6(1)(e) public-interest task + Article 6(1)(c) legal obligation are clarified for Finnish public authorities + statutorily-tasked private entities; processing for archival + scientific research + statistical purposes in the public interest is also covered. SECTION 5 OUTPUTS: GDPR Article 6(1)(c)/(e) bases may be invoked when processing is necessary for performance of statutory tasks. SECTION 29 PERSONAL IDENTITY CODE (Henkilotunnus): the Henkilotunnus is the central Finnish national identifier (11-character: DDMMYY-NNNX). Processing requires: (a) the data subject's CONSENT; OR (b) statutorily provided; OR (c) necessary to UNIQUELY IDENTIFY the data subject for performance of a statutory task or contract + identification by other means insufficient. PURPOSE LIMITATION: th

Artefacts an auditor will ask for
  • Lawful basis register including statutory tasks
  • Henkilotunnus processing policy + necessity test
  • Identifier-minimisation evidence on printed + displayed documents
Where this commonly fails
  • Henkilotunnus used as default identifier without necessity
  • Identifier printed unnecessarily on documents
  • Lawful basis ambiguous for statutorily-tasked private entities
FiDPA-SpecialCategories-CriminalData
Special Categories of Personal Data + Criminal Offences Data (Sections 6-7)

Tietosuojalaki Sections 6-7 - GDPR Article 9-10 national-level derogations. SECTION 6 SPECIAL CATEGORIES (Erityiset henkilotietoryhmat): processing of special-category personal data (race + ethnicity + political opinions + religious beliefs + trade union + genetic + biometric + health + sex life + sexual orientation) is permitted on bases of EMPLOYMENT + SOCIAL SECURITY (Section 6(1)(1)); CONSENT (Section 6(1)(2)); PUBLIC INTEREST + VITAL INTERESTS (Section 6(1)(3)); LEGITIMATE NON-PROFIT ACTIVITIES (Section 6(1)(4)); MANIFESTLY MADE PUBLIC (Section 6(1)(5)); LEGAL CLAIMS (Section 6(1)(6)); SUBSTANTIAL PUBLIC INTEREST + JOURNALISM (Section 6(1)(7)); HEALTH + OCCUPATIONAL MEDICINE (Section 6(1)(8)); PUBLIC HEALTH (Section 6(1)(9)); ARCHIVING + RESEARCH + STATISTICS (Section 6(1)(10)). SECTION 7 CRIMINAL OFFENCES DATA (Rikostuomioita ja rikoksia koskevat henkilotiedot): processing of perso

Artefacts an auditor will ask for
  • Special-category processing register
  • Criminal-data lawful basis + supervision
  • DPIA records for Section 6 + 7
  • Processor agreements with special-category provisions
Where this commonly fails
  • Section 6(1)(1-10) basis ambiguous or undocumented
  • Criminal-data processing without statutory authorisation
  • DPIA skipped for high-risk processing

Finland DPA: Sanctions Collegium, Administrative Fines and Enforcement

FiDPA-SanctionsCollegium
Sanctions Collegium (Seuraamuskollegio) and Administrative Fines

Tietosuojalaki Section 24 - Sanctions Collegium (Seuraamuskollegio). The Seuraamuskollegio is a 3-MEMBER COLLEGIAL DECISION-MAKING BODY within the Tietosuojavaltuutettu Office, composed of the Tietosuojavaltuutettu + 2 Deputy Ombudsmen; the Collegium decides on administrative fines under GDPR Articles 83-84 + the Tietosuojalaki. ADMINISTRATIVE FINE TIERS: up to EUR 10 MILLION or 2% of global annual turnover (lower tier - GDPR Article 83(4)); up to EUR 20 MILLION or 4% of global annual turnover (higher tier - GDPR Article 83(5)+(6)); the Sanctions Collegium considers the GDPR Article 83(2) criteria + Finnish administrative-law proportionality principles. PUBLIC AUTHORITY EXEMPTION (Section 24(4)): Finland uses the GDPR Article 83(7) Member State derogation + EXEMPTS public authorities + bodies from administrative fines; public authorities are instead subject to other enforcement measures

Artefacts an auditor will ask for
  • Sanctions Collegium engagement procedure
  • Fine calculation + Article 83(2) criteria
  • Administrative Court appeals procedure
Where this commonly fails
  • Sanctions Collegium decision not understood + responded to
  • Article 83(2) criteria not addressed in defence
  • Appeals window missed

Finland DPA: Scope, Application, Definitions and Sectoral Coordination

FiDPA-Ch1-Scope-Defs
Chapter 1 - Scope, Application and Definitions (Tietosuojalaki Sections 1-3)

Tietosuojalaki Chapter 1 (Yleiset saannokset) Sections 1-3. SECTION 1 SCOPE (Soveltamisala): the Act supplements + specifies GDPR in Finland; applies in respect to the processing of personal data falling within the scope of GDPR + the Law Enforcement Directive (EU) 2016/680 (transposed by Tietosuojarikoslaki 1054/2018). SECTION 2 MATERIAL SCOPE (Lain soveltamisala): the Act applies to natural-person personal data + supplementary national rules on lawful basis + special categories + criminal data + identification code + research + statistics + freedom of expression. SECTION 3 DEFINITIONS (Maaritelmat): definitions cross-reference GDPR Article 4 + additional Finnish-specific terms including 'Henkilotunnus' (personal identity code) + 'Tietosuojavaltuutettu' (Data Protection Ombudsman) + 'Seuraamuskollegio' (Sanctions Collegium). The Act is a 'sui generis' national supplement to GDPR + does

Artefacts an auditor will ask for
  • GDPR-Tietosuojalaki applicability mapping
  • Henkilotunnus inventory
  • Definitions glossary
Where this commonly fails
  • Tietosuojalaki applied as standalone (ignoring GDPR base)
  • Henkilotunnus treated as ordinary personal data
  • Definitions assumed identical to other Member States

Finland DPA: Sectoral Acts (Working Life 759/2004, SVTSL 917/2014, Cybersecurity Act 2024)

FiDPA-Coord-GDPR-NIS2-DSA
Coordination with GDPR, NIS2, DSA, DGA, eIDAS and EU Framework

Finnish data-protection coordination with EU framework. GDPR (Regulation (EU) 2016/679): Tietosuojalaki supplements + does not duplicate GDPR; GDPR controls (Articles 5-7 + 12-22 + 25-32 + 33-34 + 44-49 + 83-84) apply directly + Tietosuojalaki adds Finnish derogations + specifications. EU NIS2 (Directive (EU) 2022/2555 + Finnish Cybersecurity Act 2024): essential + important entity registration + risk management + incident reporting + supervised by Traficom; coordinates with Tietosuojalaki for personal-data-related incidents. EU DSA (Digital Services Act Regulation (EU) 2022/2065): very-large-online-platform obligations + transparency reporting + risk assessment supervised by the Finnish Competition and Consumer Authority (Kilpailu- ja kuluttajavirasto, KKV) + the Tietosuojavaltuutettu for data protection aspects. EU DGA (Data Governance Act Regulation (EU) 2022/868): data-intermediation

Artefacts an auditor will ask for
  • EU regulation tracking + transposition log
  • Sectoral authority engagement (Traficom + KKV + Tietosuojavaltuutettu)
  • Cross-regulation coordination policy
Where this commonly fails
  • EU regulations not transposed or out-of-date
  • Sectoral authorities not engaged
  • Cross-regulation coordination ad-hoc
FiDPA-Sectoral-SVTSL-Cyber2024
Sectoral Acts - SVTSL (917/2014), Cybersecurity Act 2024, Information Society Code

Finnish sectoral acts coordinating with Tietosuojalaki + GDPR. SVTSL (Information Society Code 917/2014 / Sahkoisen viestinnan palveluista annettu laki): regulates electronic communications services + ePrivacy + cookies + electronic marketing. SVTSL Section 205 transposes ePrivacy Directive 2002/58/EC + requires PRIOR CONSENT for cookies + similar tracking technologies except for strictly-necessary cookies + first-party analytics under recital-25-style limited interpretation; consent must be freely given + specific + informed + unambiguous + GDPR Article 7 valid; the Finnish Transport and Communications Agency (Traficom) supervises ePrivacy + the Tietosuojavaltuutettu supervises GDPR overlap; DIRECT MARKETING by email or SMS requires PRIOR CONSENT except for customer-existing-relationship soft opt-in for similar products; UNSUBSCRIBE link required in every marketing message. INFORMATION

Artefacts an auditor will ask for
  • SVTSL Section 205 cookie consent implementation
  • E-marketing consent + soft opt-in evidence
  • Cybersecurity Act 2024 risk management + IR plan + Traficom registration
Where this commonly fails
  • Cookie consent missing or implied (PROHIBITED)
  • E-marketing without consent or soft opt-in basis
  • Cybersecurity Act 2024 essential-entity registration overdue
FiDPA-Status-AIAct-Nordic
Implementation Status, EU AI Act Interplay, Nordic-Baltic Coordination

Tietosuojalaki implementation status + EU coordination + 2024-2025 trends. STATUS: Tietosuojalaki 1050/2018 in force since 1 January 2019 + amended 2019 + 2021 + 2023 (Henkilotunnus reform) + 2024 (Cybersecurity Act integration). EU AI ACT INTERPLAY (Regulation (EU) 2024/1689): Finland designates Traficom + Tukes (Safety and Chemicals Agency) + Tietosuojavaltuutettu as competent authorities for the AI Act; the Tietosuojavaltuutettu covers AI systems processing personal data + biometric identification + emotion recognition + automated decision-making; the AI Act phases in 2025-2027 + coordinates with GDPR Article 22 + the Tietosuojalaki. NORDIC-BALTIC WORKING GROUP ON DATA PROTECTION: Finland + Sweden + Norway + Denmark + Iceland + Estonia + Latvia + Lithuania coordinate on common positions at EDPB + cross-border-cooperation + sectoral interpretations. EU ONE-STOP-SHOP: Finnish controller

Artefacts an auditor will ask for
  • Tietosuojalaki version tracking
  • AI Act competent-authority engagement
  • Nordic-Baltic cooperation evidence
  • One-Stop-Shop lead designation
Where this commonly fails
  • Tietosuojalaki amendments not tracked
  • AI Act competent authority not identified
  • One-Stop-Shop lead designation incorrect

Finland DPA: Specific Processing Situations (Journalism, Research, Working Life, Public Sector)

FiDPA-SpecificProcessing
Specific Processing Situations - Journalism, Research, Statistics, Public Sector (Sections 27, 31, 32, 33)

Tietosuojalaki Specific Processing Situations. SECTION 27 JOURNALISTIC + ACADEMIC + ARTISTIC + LITERARY EXEMPTIONS (Journalistiseen seka akateemisen, taiteellisen tai kirjallisen ilmaisun): substantial GDPR derogations for personal-data processing solely for journalistic + academic + artistic + literary purposes; aligned with Constitution Section 12 freedom of expression + the European Convention Article 10. The journalism exemption permits processing necessary for editorial purposes + applies to traditional media + bloggers + social media accounts engaged in journalistic activity (per CJEU Saturator-style precedent + Tietosuojavaltuutettu guidance). SECTION 31 SCIENTIFIC + HISTORICAL RESEARCH + STATISTICAL PURPOSES (Tieteellinen ja historiallinen tutkimus seka tilastolliset tarkoitukset): derogations from data subject rights of access + rectification + objection where rights would rende

Artefacts an auditor will ask for
  • Journalism exemption + editorial purpose assessment
  • Research safeguards + ethics committee approval
  • Archiving derogation + safeguards
  • Public sector transparency + access-to-info coordination
Where this commonly fails
  • Journalism exemption over-applied to commercial activity
  • Research safeguards insufficient (no pseudonymisation + minimisation)
  • Archiving without safeguards
  • Public sector transparency conflicting with personal data
FiDPA-WorkingLifeAct
Act on Privacy in Working Life (759/2004) - Workplace Monitoring + Email Inspection

Act on Privacy in Working Life (Laki yksityisyyden suojasta tyoelamassa, 759/2004) - Finnish workplace privacy law operating alongside the Tietosuojalaki. SCOPE: applies to all employer-employee relationships in Finland + processing of employee personal data. KEY PROVISIONS: (a) NECESSITY PRINCIPLE - employer may process only personal data necessary for the employment relationship; (b) DIRECT-FROM-EMPLOYEE COLLECTION - employer must collect personal data from the employee in the first instance + may collect from third parties only with employee consent + statutory basis; (c) DRUG TESTING - permitted only under statutory basis + with employee notification; (d) PERSONALITY + APTITUDE TESTING - permitted with employee consent + use of validated methods; (e) HEALTH DATA - special protection + occupational health practitioner safeguards; (f) ELECTRONIC COMMUNICATIONS + EMAIL INSPECTION - empl

Artefacts an auditor will ask for
  • Employee data necessity assessment
  • Email inspection procedure + Section 18-22 compliance
  • Co-operation Act consultation records
  • Workplace monitoring transparency
Where this commonly fails
  • Employee data collected from third parties without basis
  • Email inspection without statutory conditions
  • Co-operation Act consultation skipped
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.