Finland flag

Finland

Finland Data Privacy Laws: GDPR, Finnish Data Protection Act & Enforcement (2026)

By Recording Law Editorial TeamReviewed September 11, 202621 min read
Finland Data Privacy Laws: GDPR, Finnish Data Protection Act & Enforcement (2026)

Frequently Asked Questions

What is Finland's primary data protection law beyond the GDPR?

Finland's primary national data protection legislation is the Data Protection Act (Tietosuojalaki 1050/2018), which entered into force on 1 January 2019. It supplements the GDPR with provisions on personal identity codes (Section 29), a digital consent age of 13 (Section 5), scientific research and archiving derogations (Sections 31 and 32), and a penal provision (Section 26) routing the data protection offense to Chapter 38, Section 9 of the Criminal Code. The Act on the Protection of Privacy in Working Life (759/2004) adds a separate layer for the employment context.

Who imposes GDPR fines in Finland?

GDPR administrative fines in Finland are imposed by the Sanctions Board (seuraamuskollegio), a collegial body consisting of the Data Protection Ombudsman and two Deputy Data Protection Ombudsmen. This three-official structure provides additional deliberation before significant penalties attach. Fines can reach EUR 10 million or 2 % of worldwide turnover for lower-tier violations and EUR 20 million or 4 % for upper-tier violations under Articles 83(4) and 83(5) of the GDPR respectively. Section 24(4) of the Data Protection Act exempts state and municipal authorities, independent public-law institutions, the offices of Parliament, the Office of the President and the Lutheran and Orthodox Churches from administrative fines entirely, leaving orders, reprimands and conditional fines as the tools against them. A pending bill, HE 46/2026 vp, would change that.

Can Finnish employers monitor employee emails?

Generally no. Work email communications are constitutionally protected as confidential under Section 10 of the Finnish Constitution. Retrieving or opening an employee's messages outside the statutory conditions is punishable by a fine under Section 24 of Act 759/2004, and reading another person's messages can amount to viestintäsalaisuuden loukkaus under Criminal Code 38:3, punishable by a fine or up to two years' imprisonment, with up to three years for the aggravated form in 38:4. Limited access is permitted only under the conditions in Sections 18 to 20 of Act 759/2004, which require unexpected employee absence, a reasonable belief that business-critical messages exist, exclusive work use of the address, and strict procedural safeguards.

Can employees consent to employer data processing that is not necessary for the employment relationship?

No. Section 3 of the Act on the Protection of Privacy in Working Life contains an absolute necessity requirement that cannot be overridden by employee consent. The law reflects the view that the inherent power imbalance in employment prevents genuinely voluntary consent. If the data is not directly necessary for the employment relationship, no legal basis for employer processing exists regardless of what the employee has signed.

What is Finland's digital consent age?

Finland set the digital consent age at 13 years under Section 5 of the Data Protection Act 1050/2018. Children aged 13 and older may independently consent to information society services. For children under 13, consent must be given or authorized by a parent or legal guardian. Finland chose the GDPR's minimum permissible threshold, the same as Denmark and Portugal.

Are there criminal penalties for data protection violations in Finland?

Yes. Section 26 of the Data Protection Act 1050/2018 cross-refers to the Criminal Code, where Chapter 38, Section 9 sets out the data protection offense (tietosuojarikos): a fine or imprisonment of up to one year for a person acting intentionally or with gross negligence otherwise than as the GDPR controller or processor. On 18 December 2025 the Helsinki Court of Appeal (R 23/1330) dismissed that charge against Vastaamo's former CEO, holding that a failure to notify under GDPR Article 33 does not satisfy the statutory elements of the offense and that no unambiguous statutory duty had been shown from which chief-executive criminal liability could be derived. Criminal liability may attach to individuals, in addition to administrative fines imposed on the organization.

How does Finland supervise AI systems under the EU AI Act?

Act 1377/2025, in force from 1 January 2026, establishes Finland's decentralized AI Act supervision framework. The Finnish Transport and Communications Agency (Traficom) supervises the Article 50 transparency obligations and is Finland's single point of contact under Article 70(2). General-purpose AI models are enforced by the European Commission through the AI Office under Article 88(1), not by any national authority. Sectoral authorities supervise AI within their own domains, with the Data Protection Ombudsman covering Annex III high-risk systems in biometrics, education, employment, law enforcement, migration and the administration of justice. A penalty-payment board (seuraamusmaksulautakunta) attached to Traficom imposes every fine under the Act on a proposal from the competent authority, with no monetary threshold.

What transfer mechanisms may Finnish organizations use to send personal data outside the EEA?

Finnish organizations may transfer personal data outside the EEA using European Commission adequacy decisions, the EU-US Data Privacy Framework for certified US organizations (since July 2023), Standard Contractual Clauses (2021 version) accompanied by a transfer impact assessment, Binding Corporate Rules approved by the relevant supervisory authority, or the Article 49 derogations where the specific conditions are met. The Data Protection Ombudsman treats Article 49 derogations as exceptional rather than routine.

What did the Helsinki Administrative Court decide in the Posti GDPR case?

In November 2025, the Helsinki Administrative Court reversed the EUR 2.4 million fine the Sanctions Board had imposed on Posti Jakelu Oy in November 2024. The court found that Posti was entitled under freedom of enterprise and freedom of contract to bundle its digital services into a single package and had a lawful basis under Article 6(1)(b) of the GDPR to process personal data connected to the automatically created OmaPosti mailbox. The court upheld a reprimand for insufficient transparency in informing customers.

Does the EU Data Act create new obligations for Finnish organizations?

Yes. The EU Data Act (Regulation 2023/2854) became applicable from 12 September 2025. It creates data-sharing obligations for manufacturers and providers of connected products and related services, and rights for users to access and share the data generated by those products. The Data Protection Ombudsman supervises Data Act provisions that intersect with personal data protection. Finland's implementing law, the Act on the Supervision of Data Management and Sharing (1148/2025), entered into force on 1 January 2026 and makes Traficom the main supervisory authority and national data coordinator.

Updates

Corrected the Finnish statute references throughout (the digital consent age is Section 5 of the Data Protection Act, the criminal offence is Section 26 pointing to Criminal Code Chapter 38 Section 9, and the employer email rules are Sections 18 to 20 of Act 759/2004), added the Section 24(4) rule that administrative fines cannot be imposed on Finnish public-sector bodies, corrected the employer email penalties (a fine under Act 759/2004, up to two years under Criminal Code 38:3), updated the Verkkokauppa.com fine to the final EUR 792,639 confirmed by the Supreme Administrative Court on 12 June 2026, restated what the Helsinki Court of Appeal actually held in the Vastaamo CEO case, removed two unsupported EU AI Act claims about Traficom and a EUR 300,000 fine threshold, and brought the enforcement, Data Act and AI Act sections up to September 2026.

Expanded from ~2,400 to ~6,200 words. Added: constitutional basis (s. 10), legal bases / consent, data subject rights, EU AI Act national implementation (Act 1377/2025, Traficom), DPO requirements, and expanded recent developments with 2024-2025 enforcement actions (Verkkokauppa.com, Posti, Vastaamo, and the Helsinki Court of Appeal ruling in the Vastaamo CEO case). Updated penalties section, cross-border transfers section, and compliance section. Set is_published = true. Several statements in that revision were found to be inaccurate and were corrected on 10 September 2026; see the entry of that date in this log.

Sources and References

  1. Office of the Data Protection Ombudsman – Legislation(tietosuoja.fi).gov
  2. Data Protection Act 1050/2018 – Finlex(finlex.fi).gov
  3. Ministry of Economic Affairs – Protection of Privacy at Work(tem.fi).gov
  4. Data Protection Ombudsman – Working Life FAQ(tietosuoja.fi).gov
  5. Finnish Government – National Supervision of EU AI Act(valtioneuvosto.fi).gov
  6. Ministry of Economic Affairs – National Supervision of EU AI Act(tem.fi).gov
  7. EDPB – Finnish SA Fine EUR 856,000 Verkkokauppa.com (2024)(edpb.europa.eu).gov
  8. EDPB – Finnish SA Fine EUR 2.4m Posti (2024)(edpb.europa.eu).gov
  9. Data Protection Ombudsman – Vastaamo Fine Decision(tietosuoja.fi).gov
  10. Data Protection Ombudsman – EU Data Act(tietosuoja.fi).gov
  11. GDPRhub – Finnish DPA Enforcement Tracker(gdprhub.eu)
  12. Tietosuojalaki 1050/2018, consolidated text (Finlex) – Sections 5, 24(4) and (5), 26, 27, 31 and 32, Chapter 3(finlex.fi).gov
  13. Laki yksityisyyden suojasta työelämässä 759/2004, consolidated text (Finlex) – Sections 5a, 16, 18 to 20 and 24(finlex.fi).gov
  14. Rikoslaki 39/1889, Chapter 38 (Finlex) – Section 3 viestintäsalaisuuden loukkaus, Section 4 aggravated form, Section 9 tietosuojarikos(finlex.fi).gov
  15. Laki eräiden tekoälyjärjestelmien valvonnasta 1377/2025 (Finlex) – Traficom as Article 50 market surveillance authority and Article 70(2) contact point, penalty-payment board(finlex.fi).gov
  16. HE 46/2026 vp – Government proposal to extend administrative fines to authorities and public administration bodies (Finlex)(finlex.fi).gov
  17. Laki yksityisyyden suojasta työelämässä annetun lain 4 ja 21 §:n muuttamisesta 945/2025 (Finlex)(finlex.fi).gov
  18. Data Protection Ombudsman – Supreme Administrative Court upheld the fine imposed on Verkkokauppa.com, reduced to EUR 792,639 (12 June 2026, KHO 12.6.2026/1604)(tietosuoja.fi).gov
  19. Data Protection Ombudsman – Administrative Court ruling on the Yliopiston Apteekki fine and the public-sector sanctions reform (2 June 2026)(tietosuoja.fi).gov
  20. Data Protection Ombudsman – EUR 100 million fine on Yango operator MLU B.V. for personal data transfers to Russia (8 May 2026)(tietosuoja.fi).gov
  21. Data Protection Ombudsman – Supreme Administrative Court rulings on Finland’s early GDPR fines, KHO:2023:81 and KHO:2023:82 (13 September 2023)(tietosuoja.fi).gov
  22. Helsinki Court of Appeal – charge of data protection offence against Vastaamo Oy’s former CEO dismissed, R 23/1330 (18 December 2025)(tuomioistuimet.fi).gov
  23. Helsinki Administrative Court – EUR 2.4 million fine on Posti Jakelu Oy over the OmaPosti service quashed, decision 6850/2025 (3 November 2025)(tuomioistuimet.fi).gov
  24. Finnish Government – Data Act implementing legislation confirmed 5 December 2025, in force 1 January 2026(valtioneuvosto.fi).gov
  25. Regulation (EU) 2024/1689 (AI Act), consolidated text as at 27 July 2026 – Article 70(2) and Article 88(1)(eur-lex.europa.eu).gov
Share: