Finland Data Protection Act (Tietosuojalaki, 1050/2018)
Evidence request list. 11 controls, 11 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Finland DPA: Bilingual Transparency, Data Subject Rights Coordination with GDPR + Children
Tietosuojalaki + Language Act + Constitution coordination for transparency + data subject rights. BILINGUAL TRANSPARENCY: under the Constitution Section 17 + Language Act 423/2003, Finland is officially bilingual (Finnish + Swedish) + the SAAMI LANGUAGE ACT 1086/2003 protects Sami languages in the Sami homeland; data subject information notices + privacy notices + consent forms must be provided in BOTH FINNISH + SWEDISH where the controller serves the broader population or in BILINGUAL MUNICIPALITIES; SAMI language where relevant for Sami-administrative-region. ENGLISH + OTHER LANGUAGES: encouraged for inclusiveness but not mandatory unless the audience is specifically non-Finnish-speaking. DATA SUBJECT RIGHTS: GDPR Articles 12-22 apply directly + the Tietosuojalaki Section 34 carries derogations for archival + research + journalism. CHILDREN'S DATA: GDPR Article 8 age-of-digital-consent
- Bilingual + multilingual notice templates
- Age-of-digital-consent compliance
- Rights derogation documentation
- Notices only in English or Finnish without Swedish
- Age 16 used (GDPR default) when 13 applies in Finland
- Rights derogations unclear or undocumented
Finland DPA: Data Protection Ombudsman (Tietosuojavaltuutettu) and Supervisory Authority
Tietosuojalaki Sections 8-13 - Data Protection Ombudsman (Tietosuojavaltuutettu, official English title: Office of the Data Protection Ombudsman). The Tietosuojavaltuutettu is the Finnish GDPR supervisory authority + responsible for: (a) MONITORING + ENFORCING GDPR + the Tietosuojalaki + sectoral data-protection rules; (b) HANDLING COMPLAINTS from data subjects + investigating breaches; (c) ISSUING GUIDANCE + DECISIONS on the application of GDPR + the Act; (d) MAINTAINING the REGISTER OF DATA PROTECTION OFFICERS + processing-activities + statutory notifications; (e) COOPERATING with other Member States via the EUROPEAN DATA PROTECTION BOARD (EDPB) + the GDPR ONE-STOP-SHOP mechanism for cross-border processing; (f) IMPOSING ADMINISTRATIVE FINES via the Sanctions Collegium (see separate control); (g) CONDUCTING AUDITS + INSPECTIONS with statutory cooperation rights including entry to contr
- DPO appointment + Tietosuojavaltuutettu notification evidence
- Audit cooperation procedure
- One-Stop-Shop lead-supervisor designation if applicable
- DPO not notified to Tietosuojavaltuutettu
- Audit cooperation slow or incomplete
- One-Stop-Shop lead designation missing or stale
Finland DPA: Lawful Basis, Personal Identity Code (Henkilotunnus) and Special Categories
Tietosuojalaki Sections 4-5 (lawful basis) + Section 29 (personal identity code). SECTION 4 LAWFUL BASIS: GDPR Article 6(1)(e) public-interest task + Article 6(1)(c) legal obligation are clarified for Finnish public authorities + statutorily-tasked private entities; processing for archival + scientific research + statistical purposes in the public interest is also covered. SECTION 5 OUTPUTS: GDPR Article 6(1)(c)/(e) bases may be invoked when processing is necessary for performance of statutory tasks. SECTION 29 PERSONAL IDENTITY CODE (Henkilotunnus): the Henkilotunnus is the central Finnish national identifier (11-character: DDMMYY-NNNX). Processing requires: (a) the data subject's CONSENT; OR (b) statutorily provided; OR (c) necessary to UNIQUELY IDENTIFY the data subject for performance of a statutory task or contract + identification by other means insufficient. PURPOSE LIMITATION: th
- Lawful basis register including statutory tasks
- Henkilotunnus processing policy + necessity test
- Identifier-minimisation evidence on printed + displayed documents
- Henkilotunnus used as default identifier without necessity
- Identifier printed unnecessarily on documents
- Lawful basis ambiguous for statutorily-tasked private entities
Tietosuojalaki Sections 6-7 - GDPR Article 9-10 national-level derogations. SECTION 6 SPECIAL CATEGORIES (Erityiset henkilotietoryhmat): processing of special-category personal data (race + ethnicity + political opinions + religious beliefs + trade union + genetic + biometric + health + sex life + sexual orientation) is permitted on bases of EMPLOYMENT + SOCIAL SECURITY (Section 6(1)(1)); CONSENT (Section 6(1)(2)); PUBLIC INTEREST + VITAL INTERESTS (Section 6(1)(3)); LEGITIMATE NON-PROFIT ACTIVITIES (Section 6(1)(4)); MANIFESTLY MADE PUBLIC (Section 6(1)(5)); LEGAL CLAIMS (Section 6(1)(6)); SUBSTANTIAL PUBLIC INTEREST + JOURNALISM (Section 6(1)(7)); HEALTH + OCCUPATIONAL MEDICINE (Section 6(1)(8)); PUBLIC HEALTH (Section 6(1)(9)); ARCHIVING + RESEARCH + STATISTICS (Section 6(1)(10)). SECTION 7 CRIMINAL OFFENCES DATA (Rikostuomioita ja rikoksia koskevat henkilotiedot): processing of perso
- Special-category processing register
- Criminal-data lawful basis + supervision
- DPIA records for Section 6 + 7
- Processor agreements with special-category provisions
- Section 6(1)(1-10) basis ambiguous or undocumented
- Criminal-data processing without statutory authorisation
- DPIA skipped for high-risk processing
Finland DPA: Sanctions Collegium, Administrative Fines and Enforcement
Tietosuojalaki Section 24 - Sanctions Collegium (Seuraamuskollegio). The Seuraamuskollegio is a 3-MEMBER COLLEGIAL DECISION-MAKING BODY within the Tietosuojavaltuutettu Office, composed of the Tietosuojavaltuutettu + 2 Deputy Ombudsmen; the Collegium decides on administrative fines under GDPR Articles 83-84 + the Tietosuojalaki. ADMINISTRATIVE FINE TIERS: up to EUR 10 MILLION or 2% of global annual turnover (lower tier - GDPR Article 83(4)); up to EUR 20 MILLION or 4% of global annual turnover (higher tier - GDPR Article 83(5)+(6)); the Sanctions Collegium considers the GDPR Article 83(2) criteria + Finnish administrative-law proportionality principles. PUBLIC AUTHORITY EXEMPTION (Section 24(4)): Finland uses the GDPR Article 83(7) Member State derogation + EXEMPTS public authorities + bodies from administrative fines; public authorities are instead subject to other enforcement measures
- Sanctions Collegium engagement procedure
- Fine calculation + Article 83(2) criteria
- Administrative Court appeals procedure
- Sanctions Collegium decision not understood + responded to
- Article 83(2) criteria not addressed in defence
- Appeals window missed
Finland DPA: Scope, Application, Definitions and Sectoral Coordination
Tietosuojalaki Chapter 1 (Yleiset saannokset) Sections 1-3. SECTION 1 SCOPE (Soveltamisala): the Act supplements + specifies GDPR in Finland; applies in respect to the processing of personal data falling within the scope of GDPR + the Law Enforcement Directive (EU) 2016/680 (transposed by Tietosuojarikoslaki 1054/2018). SECTION 2 MATERIAL SCOPE (Lain soveltamisala): the Act applies to natural-person personal data + supplementary national rules on lawful basis + special categories + criminal data + identification code + research + statistics + freedom of expression. SECTION 3 DEFINITIONS (Maaritelmat): definitions cross-reference GDPR Article 4 + additional Finnish-specific terms including 'Henkilotunnus' (personal identity code) + 'Tietosuojavaltuutettu' (Data Protection Ombudsman) + 'Seuraamuskollegio' (Sanctions Collegium). The Act is a 'sui generis' national supplement to GDPR + does
- GDPR-Tietosuojalaki applicability mapping
- Henkilotunnus inventory
- Definitions glossary
- Tietosuojalaki applied as standalone (ignoring GDPR base)
- Henkilotunnus treated as ordinary personal data
- Definitions assumed identical to other Member States
Finland DPA: Sectoral Acts (Working Life 759/2004, SVTSL 917/2014, Cybersecurity Act 2024)
Finnish data-protection coordination with EU framework. GDPR (Regulation (EU) 2016/679): Tietosuojalaki supplements + does not duplicate GDPR; GDPR controls (Articles 5-7 + 12-22 + 25-32 + 33-34 + 44-49 + 83-84) apply directly + Tietosuojalaki adds Finnish derogations + specifications. EU NIS2 (Directive (EU) 2022/2555 + Finnish Cybersecurity Act 2024): essential + important entity registration + risk management + incident reporting + supervised by Traficom; coordinates with Tietosuojalaki for personal-data-related incidents. EU DSA (Digital Services Act Regulation (EU) 2022/2065): very-large-online-platform obligations + transparency reporting + risk assessment supervised by the Finnish Competition and Consumer Authority (Kilpailu- ja kuluttajavirasto, KKV) + the Tietosuojavaltuutettu for data protection aspects. EU DGA (Data Governance Act Regulation (EU) 2022/868): data-intermediation
- EU regulation tracking + transposition log
- Sectoral authority engagement (Traficom + KKV + Tietosuojavaltuutettu)
- Cross-regulation coordination policy
- EU regulations not transposed or out-of-date
- Sectoral authorities not engaged
- Cross-regulation coordination ad-hoc
Finnish sectoral acts coordinating with Tietosuojalaki + GDPR. SVTSL (Information Society Code 917/2014 / Sahkoisen viestinnan palveluista annettu laki): regulates electronic communications services + ePrivacy + cookies + electronic marketing. SVTSL Section 205 transposes ePrivacy Directive 2002/58/EC + requires PRIOR CONSENT for cookies + similar tracking technologies except for strictly-necessary cookies + first-party analytics under recital-25-style limited interpretation; consent must be freely given + specific + informed + unambiguous + GDPR Article 7 valid; the Finnish Transport and Communications Agency (Traficom) supervises ePrivacy + the Tietosuojavaltuutettu supervises GDPR overlap; DIRECT MARKETING by email or SMS requires PRIOR CONSENT except for customer-existing-relationship soft opt-in for similar products; UNSUBSCRIBE link required in every marketing message. INFORMATION
- SVTSL Section 205 cookie consent implementation
- E-marketing consent + soft opt-in evidence
- Cybersecurity Act 2024 risk management + IR plan + Traficom registration
- Cookie consent missing or implied (PROHIBITED)
- E-marketing without consent or soft opt-in basis
- Cybersecurity Act 2024 essential-entity registration overdue
Tietosuojalaki implementation status + EU coordination + 2024-2025 trends. STATUS: Tietosuojalaki 1050/2018 in force since 1 January 2019 + amended 2019 + 2021 + 2023 (Henkilotunnus reform) + 2024 (Cybersecurity Act integration). EU AI ACT INTERPLAY (Regulation (EU) 2024/1689): Finland designates Traficom + Tukes (Safety and Chemicals Agency) + Tietosuojavaltuutettu as competent authorities for the AI Act; the Tietosuojavaltuutettu covers AI systems processing personal data + biometric identification + emotion recognition + automated decision-making; the AI Act phases in 2025-2027 + coordinates with GDPR Article 22 + the Tietosuojalaki. NORDIC-BALTIC WORKING GROUP ON DATA PROTECTION: Finland + Sweden + Norway + Denmark + Iceland + Estonia + Latvia + Lithuania coordinate on common positions at EDPB + cross-border-cooperation + sectoral interpretations. EU ONE-STOP-SHOP: Finnish controller
- Tietosuojalaki version tracking
- AI Act competent-authority engagement
- Nordic-Baltic cooperation evidence
- One-Stop-Shop lead designation
- Tietosuojalaki amendments not tracked
- AI Act competent authority not identified
- One-Stop-Shop lead designation incorrect
Finland DPA: Specific Processing Situations (Journalism, Research, Working Life, Public Sector)
Tietosuojalaki Specific Processing Situations. SECTION 27 JOURNALISTIC + ACADEMIC + ARTISTIC + LITERARY EXEMPTIONS (Journalistiseen seka akateemisen, taiteellisen tai kirjallisen ilmaisun): substantial GDPR derogations for personal-data processing solely for journalistic + academic + artistic + literary purposes; aligned with Constitution Section 12 freedom of expression + the European Convention Article 10. The journalism exemption permits processing necessary for editorial purposes + applies to traditional media + bloggers + social media accounts engaged in journalistic activity (per CJEU Saturator-style precedent + Tietosuojavaltuutettu guidance). SECTION 31 SCIENTIFIC + HISTORICAL RESEARCH + STATISTICAL PURPOSES (Tieteellinen ja historiallinen tutkimus seka tilastolliset tarkoitukset): derogations from data subject rights of access + rectification + objection where rights would rende
- Journalism exemption + editorial purpose assessment
- Research safeguards + ethics committee approval
- Archiving derogation + safeguards
- Public sector transparency + access-to-info coordination
- Journalism exemption over-applied to commercial activity
- Research safeguards insufficient (no pseudonymisation + minimisation)
- Archiving without safeguards
- Public sector transparency conflicting with personal data
Act on Privacy in Working Life (Laki yksityisyyden suojasta tyoelamassa, 759/2004) - Finnish workplace privacy law operating alongside the Tietosuojalaki. SCOPE: applies to all employer-employee relationships in Finland + processing of employee personal data. KEY PROVISIONS: (a) NECESSITY PRINCIPLE - employer may process only personal data necessary for the employment relationship; (b) DIRECT-FROM-EMPLOYEE COLLECTION - employer must collect personal data from the employee in the first instance + may collect from third parties only with employee consent + statutory basis; (c) DRUG TESTING - permitted only under statutory basis + with employee notification; (d) PERSONALITY + APTITUDE TESTING - permitted with employee consent + use of validated methods; (e) HEALTH DATA - special protection + occupational health practitioner safeguards; (f) ELECTRONIC COMMUNICATIONS + EMAIL INSPECTION - empl
- Employee data necessity assessment
- Email inspection procedure + Section 18-22 compliance
- Co-operation Act consultation records
- Workplace monitoring transparency
- Employee data collected from third parties without basis
- Email inspection without statutory conditions
- Co-operation Act consultation skipped
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.