Finland
Finland Data Privacy Laws: GDPR, Finnish Data Protection Act & Enforcement (2026)

Finland enforces data privacy through the EU GDPR, the Data Protection Act (Tietosuojalaki 1050/2018), and the Act on the Protection of Privacy in Working Life (759/2004). The Office of the Data Protection Ombudsman supervises compliance and its Sanctions Board may impose fines up to EUR 20 million or 4% of worldwide annual turnover on private-sector controllers. Section 24(4) of the Data Protection Act bars administrative fines against Finnish public-sector bodies, a carve-out Parliament is now being asked to remove.
Finland implements the EU General Data Protection Regulation (GDPR) through a layered national framework anchored in the Data Protection Act (Tietosuojalaki 1050/2018) and supplemented by the Act on the Protection of Privacy in Working Life (759/2004). The Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto) supervises compliance, and a collegial Sanctions Board composed of the Ombudsman and two deputies imposes administrative fines. This guide covers every layer of Finland's data protection regime, including the enforcement actions of 2024 to 2026, the appeals that have reshaped several of them, and the EU AI Act supervision framework that entered into force on 1 January 2026.
Information last verified on 10 September 2026. This article has not been reviewed by a licensed lawyer. Consult a qualified attorney licensed in Finland for advice on your specific situation.
Jurisdiction scope: This article covers data protection law in Finland, including the EU GDPR as directly applicable EU law, the Finnish Data Protection Act 1050/2018, the Act on the Protection of Privacy in Working Life 759/2004, and Act 1377/2025 on the supervision of certain AI systems. It does not address data protection law in other EU member states. For the broader EU framework, see our EU data privacy laws guide.
Quick Answer: Finland's Data Protection Framework at a Glance
Finland's data protection law operates on three levels. First, the GDPR applies directly as binding EU law. Second, the Data Protection Act 1050/2018 fills the gaps the GDPR leaves to member state discretion, addressing personal identity codes, the supervisory authority's structure, criminal penalties, and a digital consent age of 13. Third, the Act on the Protection of Privacy in Working Life 759/2004 governs the employment relationship exclusively, applying a necessity standard stricter than the GDPR's general rules. The Office of the Data Protection Ombudsman enforces all three layers. Fines for serious violations can reach EUR 20 million or 4 % of worldwide annual turnover, but Section 24(4) of the Data Protection Act bars administrative fines against state and municipal authorities and other Finnish public-sector bodies. Since 2019, Finnish supervisory authorities have issued fines against organizations including the national postal service, a major e-commerce retailer, a pharmacy chain, and a psychotherapy centre, with Finnish courts actively reviewing and in several cases reducing or overturning those decisions on appeal.
Constitutional Basis for Data Protection
Finland gives data protection constitutional weight. Section 10 of the Finnish Constitution (Suomen perustuslaki 731/1999) protects everyone's private life, honour, and the sanctity of the home. Section 10 also expressly states that the protection of personal data is regulated by an Act of Parliament, a constitutional delegation that grounds the Data Protection Act 1050/2018 and the workplace privacy law.
Section 12 of the Constitution guarantees freedom of expression and access to information, and Finnish courts balance these rights against data protection in cases involving journalism, research, and public-interest processing. The constitutional status of both rights means that neither automatically overrides the other; proportionality analysis is required.
Importantly, the Finnish Constitution treats communications transmitted over electronic networks as having the same confidential status as sealed correspondence. This constitutional protection forms the foundation for Finland's strict rules on employer access to employee email, discussed in detail below.
GDPR and the Finnish Data Protection Act 1050/2018
The GDPR entered into force across all EU member states on 25 May 2018 and applies directly in Finland without requiring domestic transposition. The Data Protection Act 1050/2018 entered into force on 1 January 2019, replacing the earlier Personal Data Act (523/1999).
The Data Protection Act supplements the GDPR in areas where the regulation expressly permits member-state specification. The Act's key national provisions cover:
- Personal identity codes (henkilötunnus). Section 29 of the Data Protection Act restricts the use of Finland's personal identity codes, which function as universal identifiers across public and private sector systems. Controllers may process a personal identity code only when the data subject has given consent, when processing is provided for by law, or when unambiguous identification of the data subject is important for a purpose connected to the employment relationship, healthcare, social welfare, credit operations, or insurance. The controller must ensure that a personal identity code is not unnecessarily included in printed documents or data-file outputs.
- Digital consent age. Section 5 of the Data Protection Act sets 13 years as the minimum age at which a child may independently consent to information society services. For children under 13, parental or guardian consent is required.
- Scientific research, statistics, and archiving. Section 31 allows derogations for scientific or historical research and statistical purposes, and Section 32 for archiving in the public interest, both subject to appropriate safeguards. Section 33 is a separate provision restricting the controller's duty to supply information to the data subject.
- Journalistic and expressive purposes. Section 27 disapplies a long list of GDPR provisions where personal data are processed solely for journalistic purposes or for academic, artistic or literary expression, in order to safeguard freedom of expression and freedom of information. Sections 28 to 30 cover separate subjects: the publicity principle, personal identity codes, and processing in the employment relationship.
- Criminal penalties. Section 26 is the Act's penal provision, and it does not itself create an offense: it cross-refers to the Criminal Code. The data protection offense (tietosuojarikos) sits in Chapter 38, Section 9 of the Criminal Code (39/1889), inserted by Act 1051/2018, and carries a fine or imprisonment of up to one year. It reaches a person who acts intentionally or with gross negligence otherwise than as the controller or processor under the GDPR. Section 24 of the Data Protection Act, by contrast, is the administrative-fine and Sanctions Board provision.
Supplementary Sector Legislation
Finland also maintains sector-specific data protection provisions. The Act on Electronic Communications Services (917/2014) implements the ePrivacy framework, including rules on cookies, direct marketing, and the confidentiality of electronic communications. The Act on the Protection of Privacy in Working Life (759/2004) governs employment data. Healthcare and social welfare legislation contains additional rules on sensitive health data.
The Office of the Data Protection Ombudsman

The Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto) is Finland's independent GDPR supervisory authority, established under Article 51 of the GDPR and structured in detail by Chapter 3 of the Data Protection Act 1050/2018, which covers the supervisory authority in Sections 8 to 20. The office is headed by the Data Protection Ombudsman and two Deputy Data Protection Ombudsmen, all appointed by the Finnish government for five-year terms. Each of the three officials holds independent decision-making authority, meaning any one of them may issue binding orders on data protection matters without requiring the agreement of the others.
The Sanctions Board
The three officials collectively form the Sanctions Board (seuraamuskollegio), which is the body responsible for imposing administrative fines under Article 83 of the GDPR. Under Section 24 of the Data Protection Act, the Sanctions Board decides fine cases collegially, providing an additional deliberation layer before significant penalties attach. This structure distinguishes Finland from most EU member states, where fine authority rests with a single official.
Powers
The Office holds the full range of GDPR supervisory powers under Article 58. These include: conducting investigations and on-site inspections; issuing warnings, reprimands, and binding orders requiring controllers or processors to bring processing into compliance; imposing temporary or permanent prohibitions on processing; ordering rectification, erasure, or restriction of personal data; and referring fine cases to the Sanctions Board.
Legal Bases for Processing Personal Data
Finnish controllers must ground every processing activity in one of the six legal bases listed in Article 6(1) of the GDPR. The bases available in practice for Finnish organizations are:
| Legal Basis | Article 6(1) | Typical Finnish Application |
|---|---|---|
| Consent | (a) | Marketing, cookies, non-essential analytics |
| Contract performance | (b) | Customer account management, employment contract administration |
| Legal obligation | (c) | Tax records, anti-money-laundering, occupational safety reporting |
| Vital interests | (d) | Emergency medical situations |
| Public task | (e) | Public authorities and entities exercising official authority |
| Legitimate interests | (f) | Fraud prevention, network security, internal administrative processing |
For special category data under Article 9 (health, biometric, genetic, trade union membership, and similar), a further condition from Article 9(2) must be met. Finnish employers frequently rely on Article 9(2)(b) (employment and social protection law obligations) when handling health-related employee data under the Act on the Protection of Privacy in Working Life.
Consent in the Employment Context
Finnish data protection practice treats consent with particular care in employment. The Data Protection Ombudsman and the Act on the Protection of Privacy in Working Life both recognize that the power imbalance between employer and employee makes genuinely voluntary consent difficult to establish. Consent is not a valid legal basis for employer processing of employee personal data unless the processing falls entirely outside the necessity framework of the workplace privacy law.
Data Subject Rights
Finnish data subjects hold all eight rights established by Chapter III of the GDPR. Controllers must respond to requests within one month, with a possible two-month extension for complex or numerous requests. The Data Protection Ombudsman has taken enforcement action against controllers that required data subjects to produce a personal identity code or other disproportionate identification to exercise access rights (Article 15), denied erasure requests without a legitimate ground under Article 17(3), or failed to provide information in clear and plain language as required by Articles 13 and 14.
Right of access (Article 15). The controller must provide a copy of all personal data being processed and supplementary information including the purposes of processing, the categories of data, the recipients or categories of recipients, and the envisaged retention periods.
Right to erasure (Article 17). Data subjects may request deletion when the data is no longer necessary for its original purpose, consent has been withdrawn, or the processing was unlawful. Exceptions apply for freedom of expression, legal obligations, and the establishment, exercise, or defence of legal claims.
Right to data portability (Article 20). Where processing is based on consent or contract and carried out by automated means, data subjects may receive their data in a structured, commonly used, machine-readable format and request its direct transmission to another controller.
Right to object (Article 21). Data subjects may object to processing based on legitimate interests or public task at any time on grounds relating to their particular situation. The controller must stop processing unless it demonstrates compelling legitimate grounds that override the data subject's interests.
Employee Privacy: The Strictest Rules in Europe
Finland's Act on the Protection of Privacy in Working Life (Laki yksityisyyden suojasta työelämässä, 759/2004) is widely regarded as the most restrictive statutory employee data protection regime in the European Union. It applies exclusively to the relationship between employers and employees and imposes obligations that go beyond what the GDPR requires.
The Necessity Requirement
The cornerstone of the Act is Section 3, which states that an employer may only process personal data that is directly necessary for the employment relationship and connected to managing the rights and obligations of the parties or to benefits provided by the employer. No exception applies even where the employee gives explicit consent. Finnish courts and the Data Protection Ombudsman have confirmed this consistently: the inherent power imbalance in employment means that employee consent cannot render non-necessary data processing lawful.
Email and Communications Monitoring
All communications transmitted to and from an employee's work email address carry constitutional confidentiality under Section 10 of the Finnish Constitution. Retrieving or opening an employee's messages outside the statutory conditions is punishable by a fine under Section 24 of the Act on the Protection of Privacy in Working Life. Where the conduct amounts to reading another person's messages, Criminal Code 38:3 (viestintäsalaisuuden loukkaus) applies instead, carrying a fine or up to two years' imprisonment, with up to three years for the aggravated form in 38:4.
Chapter 6 of the Act on the Protection of Privacy in Working Life, Sections 18 to 20, establishes narrowly defined conditions under which an employer may access or redirect an employee's work email. The prerequisites include: the employee is unexpectedly absent; the employer has reasonable grounds to believe that business-critical messages have been received; the email address is used exclusively for work purposes; and the employer has first attempted to contact the employee or the employee's designee. Even when these conditions are met, a designated person (not the employee's immediate supervisor) must conduct the access under procedural safeguards, and the employee must be informed as soon as possible.
Camera Surveillance
Section 16 of the Act on the Protection of Privacy in Working Life permits camera surveillance in workplaces for limited purposes: ensuring employee safety, protecting property, monitoring production processes, or preventing and investigating safety-threatening situations. Cameras may not be directed at a specific employee as the primary purpose. Surveillance of break rooms, changing rooms, washrooms, or other private spaces is prohibited. Employees and their representatives must be informed before any surveillance system is installed.
Drug Testing and Health Data
Sections 6-9 address drug testing. Employers may require a drug test only where the position involves tasks requiring special precision, reliability, or independent judgment, and only where safety, national security, the protection of trade secrets, or similar serious interests are at stake. Health data may be processed by only designated persons within the employer organization, and the list of authorized persons must be documented.
Background Checks
Section 5a permits credit checks only for positions that require special trustworthiness and fall into one of seven listed categories: power to make significant financial commitments for the employer or genuinely independent discretion in preparing them; an express duty to grant and supervise economically significant credit; access to trade secrets central to the employer or its customer that are specially protected; information-system rights allowing the transfer of the employer's or its customer's assets or the alteration of asset records, or system-administrator powers over such a system; handling significant sums of money, securities or valuables without direct supervision; guarding the employer's or its customer's property; and work that is mainly unsupervised in a private home. The same grounds apply where a current employee's duties change. General precautionary screening is not a sufficient justification, and the employer bears the cost of obtaining the credit data.
Data Protection Officer Requirements
Article 37 of the GDPR requires designation of a Data Protection Officer (DPO) for: (a) public authorities and bodies; (b) controllers or processors whose core activities involve large-scale, regular, and systematic monitoring of individuals; and (c) controllers or processors whose core activities involve large-scale processing of special category data.
In Finland, all public authorities are required to designate a DPO. The Data Protection Ombudsman has confirmed that "public authorities" includes municipalities, joint municipal authorities, state agencies, and entities exercising statutory public power.
Private sector organizations in Finland that must designate a DPO include healthcare providers, insurers, and social welfare service providers (large-scale special category data); advertising technology companies and operators of loyalty or targeting programs (large-scale systematic monitoring); and telecommunications companies and internet service providers. The DPO must be registered with the Data Protection Ombudsman's office through the authority's notification service.
Breach Notification
Finland applies the GDPR's two-tier breach notification framework without national modification. Under Article 33, a controller that becomes aware of a personal data breach likely to result in a risk to individuals' rights and freedoms must notify the Data Protection Ombudsman within 72 hours. Where a breach poses a high risk to the rights and freedoms of affected individuals, Article 34 requires the controller to notify those individuals directly, without undue delay, using clear and plain language describing the nature of the breach, likely consequences, and measures taken or proposed.
International Data Transfers

Finland follows the GDPR's Chapter V framework for transfers of personal data outside the EEA. The available transfer mechanisms include:
- Adequacy decisions. Commission adequacy decisions cover countries including Japan, South Korea, New Zealand, Israel, and the United Kingdom.
- EU-US Data Privacy Framework (DPF). The Commission adopted the DPF adequacy decision in July 2023, permitting transfers to certified US organizations. Finnish organizations relying on the DPF should verify certification status before each transfer, as certification must be renewed annually.
- Standard Contractual Clauses (SCCs). The 2021 SCCs remain the most widely used transfer mechanism for non-adequacy countries and require a transfer impact assessment documenting destination-country laws and any supplementary measures.
- Binding Corporate Rules (BCRs). Multinational groups may seek BCR approval from the Data Protection Ombudsman (where Finland is the lead authority) or from the competent lead supervisory authority under the one-stop-shop mechanism.
- Article 49 derogations. Explicit consent, contract necessity, vital interests, important public interest, and legal-claims derogations are available but narrowly construed. The Data Protection Ombudsman aligns with EDPB guidance treating them as exceptional rather than routine.
Fines and Penalties
Administrative Fines
The Sanctions Board may impose administrative fines under Article 83 of the GDPR. The two-tier structure applies:
- Lower tier (Article 83(4)). Fines up to EUR 10 million or 2 % of total worldwide annual turnover for violations of controller and processor obligations, supervisory authority obligations, and certification body obligations.
- Upper tier (Article 83(5)). Fines up to EUR 20 million or 4 % of total worldwide annual turnover for violations of basic processing principles (Articles 5-7, 9), data subject rights (Articles 12-22), third-country transfers (Articles 44-49), and non-compliance with supervisory authority orders.
Turnover figures are calculated at the level of the undertaking as a whole, not limited to the Finnish entity's revenue.
The Public-Sector Exemption (Section 24(4))
Those ceilings do not reach Finland's public sector. Section 24(4) of the Data Protection Act provides that an administrative fine cannot be imposed on state authorities, state enterprises, municipal authorities, independent public-law institutions, the offices of Parliament, the Office of the President of the Republic, or the Evangelical Lutheran Church and the Orthodox Church of Finland and their parishes, parish unions and other bodies.
Public-sector controllers remain fully bound by the GDPR. What changes is the toolkit: the Ombudsman relies on orders, reprimands and conditional fines (uhkasakko, Section 22) instead. Section 24(5) adds a ten-year limitation period, counted from the end of a continuing breach, after which no administrative fine may be imposed on anyone.
The exemption is live and contested. On 1 June 2026 the Helsinki Administrative Court quashed a EUR 1.1 million fine imposed on Yliopiston Apteekki, the pharmacy owned by the University of Helsinki, partly because it was unclear whether that entity could be fined at all. A government bill, HE 46/2026 vp, would extend administrative fines to authorities and public administration bodies at fixed maximum amounts well below the GDPR ceilings and scaled to the body's size and financial position. It is a bill before Parliament, not law.
Criminal Penalties
Section 26 of the Data Protection Act 1050/2018 is a signpost, not an offense-creating provision. It states that the penalty for a data protection offense (tietosuojarikos) is laid down in Chapter 38, Section 9 of the Criminal Code (39/1889), which Act 1051/2018 inserted. That offense carries a fine or up to one year's imprisonment and applies to a person acting intentionally or with gross negligence otherwise than as the GDPR controller or processor. Section 26 also points to Criminal Code 38:3 and 38:4 for breach of the confidentiality of communications and to 38:8 and 38:8a for computer intrusion.
Breaching the Act on the Protection of Privacy in Working Life is a separate matter. Its own Section 24 punishes an employer or an employer's representative who, among other things, retrieves messages contrary to Section 19 or opens them contrary to Section 20, and the penalty there is a fine only, unless a heavier penalty is laid down elsewhere in law. The imprisonment exposure comes from the Criminal Code offenses that Section 24 defers to. Reading another person's messages can amount to viestintäsalaisuuden loukkaus under Criminal Code 38:3, punishable by a fine or up to two years' imprisonment, or the aggravated form under 38:4, punishable by up to three years' imprisonment.
On 18 December 2025 the Helsinki Court of Appeal (R 23/1330) dismissed the tietosuojarikos charge against Vastaamo's former CEO. It held that failing to notify a breach under GDPR Article 33 is not a mode of conduct that satisfies the statutory elements of the offense, that the list of measures in Article 32(1)(a) is illustrative rather than mandatory, and that no unambiguous statutory duty had been shown from which criminal liability could be attached to a company's chief executive. The court expressly weighed the requirement that criminal law be precisely delimited.
Notable Enforcement Actions
Vastaamo psychotherapy centre (December 2021, fine EUR 608,000). The Sanctions Board imposed a EUR 608,000 fine on Vastaamo after a data breach exposed confidential therapy notes of approximately 36,000 patients. The violations included failure to maintain adequate security (Article 32), failure to notify the supervisory authority within 72 hours (Article 33), and deficiencies in accountability documentation (Article 5(2)). In April 2023 the Helsinki District Court convicted former CEO Ville Tapio of a data protection offense, imposing a three-month suspended sentence. On 18 December 2025 the Helsinki Court of Appeal (R 23/1330) unanimously dismissed the charge in full. It held that failing to notify a breach under GDPR Article 33 is not a mode of conduct covered by the data protection offense, that the list of security measures in Article 32(1)(a) is illustrative rather than mandatory, and that no unambiguous statutory requirement had been shown from which criminal liability could be attached to the company's chief executive.
Verkkokauppa.com (March 2024, fine now final at EUR 792,639). The Sanctions Board imposed a EUR 856,000 fine on Verkkokauppa.com Plc for failure to define retention periods for customer account data, which the company kept until a customer asked for deletion, in breach of Article 5(1)(e), and for requiring customer account registration as a condition of making an online purchase. The Helsinki Administrative Court later reduced the fine to EUR 792,639 on the basis of the company's most recent turnover and dismissed the rest of its appeal. On 12 June 2026 the Supreme Administrative Court left that outcome undisturbed (KHO 12.6.2026/1604), holding that a controller must set retention periods for the personal data it collects and cannot make the retention period depend on the customer's own deletion request, and that the Ombudsman's decision did not restrict the company's freedom of enterprise.
Posti Group OmaPosti service (November 2024, fine EUR 2.4 million, reversed November 2025). The Sanctions Board imposed a EUR 2.4 million fine on Posti Jakelu Oy for automatically creating an OmaPosti electronic mailbox for users without giving them the ability to decline that specific service component. The service had over 2 million registered users. In November 2025, the Helsinki Administrative Court reversed the fine, ruling that Posti was entitled under principles of freedom of enterprise and freedom of contract to bundle its digital services and had a lawful basis under Article 6(1)(b) for the mailbox processing. The court upheld a reprimand for insufficient transparency in customer information.
EU AI Act National Implementation: Act 1377/2025
The EU AI Act (Regulation 2024/1689) entered into force on 1 August 2024 and applies in phased stages, several of which Regulation (EU) 2026/1744, the Digital Omnibus on AI in force since 27 July 2026, has rescheduled. The prohibited practices have applied since 2 February 2025 and the general-purpose AI model rules since 2 August 2025. The Article 50 transparency duties still apply from 2 August 2026, with a grace period to 2 December 2026 for marking synthetic content produced by systems already on the market. The Annex III high-risk obligations now apply from 2 December 2027 and the Annex I product-embedded ones from 2 August 2028.
Finland enacted national supervisory legislation through Act 1377/2025 on the supervision of certain AI systems (laki eräiden tekoälyjärjestelmien valvonnasta), which entered into force on 1 January 2026.
Decentralized Supervision
Finland chose a decentralized supervision architecture. Rather than designating a single national AI authority, Act 1377/2025 allocates supervisory responsibility to the authorities already competent in each sector. Authorities responsible for road traffic, financial services, medical devices, product safety, digital infrastructure, and personal data protection each supervise AI systems within their domain.
Traficom as Single Contact Point
The Finnish Transport and Communications Agency (Traficom) is the market surveillance authority for the AI Act's Article 50 transparency obligations, except where a high-risk system's own competent market surveillance authority takes those obligations over, and it acts as Finland's single point of contact under Article 70(2) of the AI Act. General-purpose AI models are not supervised nationally at all. Article 88(1) gives the European Commission exclusive powers to supervise and enforce Chapter V, exercised through the AI Office.
A penalty-payment board (seuraamusmaksulautakunta) operates in connection with Traficom and imposes every administrative fine under Act 1377/2025, acting on a proposal from the competent sectoral market surveillance authority. There is no monetary threshold. The board may impose the fine as proposed, set it higher or lower, or impose none at all. Traficom nominates its chair and the Data Protection Ombudsman its vice-chair.
The Data Protection Ombudsman's AI Role
Act 1377/2025 makes the Office of the Data Protection Ombudsman the market surveillance authority for Annex III high-risk AI systems in biometrics (point 1), education (point 3), employment (point 4), creditworthiness assessment under point 5(b) outside the Financial Supervisory Authority's remit, law enforcement (point 6), migration and border control (point 7), and the administration of justice and democratic processes (point 8). Where a deployer of a high-risk AI system must conduct a fundamental-rights impact assessment under Article 27 of the EU AI Act and that assessment identifies personal data processing, the output must be reconciled with the GDPR's data protection impact assessment (Article 35). Finnish guidance indicates that organizations should conduct these assessments jointly rather than as separate documents.
Recent Developments (2024-2026)
Cybersecurity Act 124/2025 (April 2025). The Act implementing the NIS2 Directive entered into force, creating mandatory cybersecurity obligations and incident reporting requirements for operators of essential and important services. The Data Protection Ombudsman coordinates with the National Cyber Security Centre on incidents involving personal data breaches.
EU Data Act applicable from September 2025, Finnish implementing law in force from 1 January 2026. The EU Data Act (Regulation 2023/2854) became applicable on 12 September 2025. It covers data-sharing obligations for connected products and related services. Finland's implementing legislation, the Act on the Supervision of Data Management and Sharing (1148/2025), was confirmed by the President of the Republic on 5 December 2025 and entered into force on 1 January 2026. It makes Traficom the principal supervisory authority and the national data coordinator, with the Data Protection Ombudsman supervising the provisions that intersect with personal data protection.
Helsinki Administrative Court reverses EUR 2.4m Posti fine (November 2025). The court found that service bundling did not breach the GDPR's lawful-basis requirement, providing the first Finnish judicial guidance on freedom of enterprise as context for Article 6(1)(b) analysis.
Helsinki Court of Appeal dismisses the charge against Vastaamo's former CEO (18 December 2025). In R 23/1330 the court held that an Article 33 notification failure falls outside the statutory elements of the data protection offense, that Article 32(1)(a) sets out an illustrative rather than mandatory list of security measures, and that criminal liability cannot be derived against a chief executive without an unambiguous statutory duty. The court weighed the requirement that criminal law be precisely delimited.
Act 1377/2025 on AI supervision in force (1 January 2026). Traficom designated as single point of contact and as market surveillance authority for the Article 50 transparency obligations; the Data Protection Ombudsman and other sectoral authorities assume AI Act supervisory responsibilities in their domains.
EUR 100 million fine on Yango operator MLU B.V. (8 May 2026). In a joint decision led by the Dutch supervisory authority together with the Finnish Data Protection Ombudsman and the Norwegian authority, MLU B.V., the Yandex-group company responsible for the Yango taxi app's European data processing, was fined EUR 100 million for transferring users' personal data to Russia without adequate safeguards and ordered to stop those transfers. It is the first European supervisory decision assessing transfers to Russia. MLU B.V. may still object to the fine.
Helsinki Administrative Court quashes the EUR 1.1 million Yliopiston Apteekki fine (1 June 2026). The fine, imposed in June 2025 over online-pharmacy customer data passed to Google and Meta tracking services between 2018 and 2022, was set aside partly because it was unclear whether the pharmacy, owned by the University of Helsinki, could be fined at all under the Section 24(4) public-sector exemption. The reprimand for the security failings largely stood. The ruling is not yet final.
Supreme Administrative Court settles Verkkokauppa.com (12 June 2026). The court left the reduced EUR 792,639 fine undisturbed and confirmed that a controller cannot leave the retention period for personal data to the customer's own deletion request.
Bill HE 46/2026 vp before Parliament. The Government has proposed extending administrative fines to authorities and public administration bodies, at fixed maximum amounts substantially lower than the GDPR ceilings and scaled to the body's size and financial position. Until it passes, the Section 24(4) exemption stands.
Practical Compliance for Businesses Operating in Finland
Organizations operating in Finland face a compliance environment that is materially stricter than the GDPR baseline in several areas.
Employee monitoring audit. Review all employee monitoring systems against the Act on the Protection of Privacy in Working Life, not only the GDPR. Email access policies, location tracking systems, camera surveillance, and background check procedures must satisfy the necessity requirement under Section 3 of Act 759/2004. Practices lawful in other EU states may not be permissible in Finland.
Retention schedules. The Verkkokauppa.com fine, final at EUR 792,639 after the Supreme Administrative Court's ruling of 12 June 2026, illustrates the Sanctions Board's focus on defined retention periods. Every data category in a record of processing activities (Article 30) should carry a documented retention period and a deletion or anonymization trigger. Indefinite storage of customer data is a red flag.
Personal identity codes. Map all system outputs and printed documents that include the henkilötunnus. Remove it from outputs where alternative identifiers are sufficient. Processing the code without a statutory ground violates Section 29 of the Data Protection Act 1050/2018.
DPO registration. Public authorities and private-sector organizations meeting the Article 37 thresholds must designate and register a DPO with the Data Protection Ombudsman. Registration must be updated when the DPO changes.
AI systems inventory. With Act 1377/2025 in force from 1 January 2026, organizations deploying AI systems that may qualify as high-risk under Annex III of the EU AI Act should conduct a classification assessment and, where classification triggers obligations, prepare a fundamental-rights impact assessment aligned with the DPIA framework under Article 35 of the GDPR. Those Annex III obligations apply from 2 December 2027 following the Digital Omnibus on AI, so the inventory is the work to do now. The Article 50 transparency duties, including deepfake labelling, already apply.
Consent age gate. For digital services, verify that age-gating mechanisms prevent under-13 users from self-consenting and that parental consent mechanisms meet GDPR standards.
Watch out: Employee consent does not cure unlawful data processing in the Finnish employment context. If the data is not directly necessary for the employment relationship under Section 3 of Act 759/2004, no legal basis exists regardless of what the employee has signed. Finnish companies that imported consent-based employee monitoring practices from other EU jurisdictions have encountered enforcement action.
Disclaimer
This article provides general legal information about Finland's data privacy laws as of 10 September 2026 and is not legal advice. It covers the EU GDPR as applicable in Finland, the Finnish Data Protection Act 1050/2018, the Act on the Protection of Privacy in Working Life 759/2004, and Act 1377/2025 on the supervision of certain AI systems. Data protection laws change frequently. Consult a qualified attorney licensed in Finland for guidance on your specific situation.
Related Articles
Last updated: 10 September 2026. Statutes cited reflect their in-force versions as of 10 September 2026, including the amendments made to the Data Protection Act 1050/2018 by L 380/2026 (new Section 4(2), in force 1 September 2026) and to Act 759/2004 by L 945/2025 (Sections 4(3) and 21(1), in force 1 January 2026).
Frequently Asked Questions
What is Finland's primary data protection law beyond the GDPR?
Finland's primary national data protection legislation is the Data Protection Act (Tietosuojalaki 1050/2018), which entered into force on 1 January 2019. It supplements the GDPR with provisions on personal identity codes (Section 29), a digital consent age of 13 (Section 5), scientific research and archiving derogations (Sections 31 and 32), and a penal provision (Section 26) routing the data protection offense to Chapter 38, Section 9 of the Criminal Code. The Act on the Protection of Privacy in Working Life (759/2004) adds a separate layer for the employment context.
Who imposes GDPR fines in Finland?
GDPR administrative fines in Finland are imposed by the Sanctions Board (seuraamuskollegio), a collegial body consisting of the Data Protection Ombudsman and two Deputy Data Protection Ombudsmen. This three-official structure provides additional deliberation before significant penalties attach. Fines can reach EUR 10 million or 2 % of worldwide turnover for lower-tier violations and EUR 20 million or 4 % for upper-tier violations under Articles 83(4) and 83(5) of the GDPR respectively. Section 24(4) of the Data Protection Act exempts state and municipal authorities, independent public-law institutions, the offices of Parliament, the Office of the President and the Lutheran and Orthodox Churches from administrative fines entirely, leaving orders, reprimands and conditional fines as the tools against them. A pending bill, HE 46/2026 vp, would change that.
Can Finnish employers monitor employee emails?
Generally no. Work email communications are constitutionally protected as confidential under Section 10 of the Finnish Constitution. Retrieving or opening an employee's messages outside the statutory conditions is punishable by a fine under Section 24 of Act 759/2004, and reading another person's messages can amount to viestintäsalaisuuden loukkaus under Criminal Code 38:3, punishable by a fine or up to two years' imprisonment, with up to three years for the aggravated form in 38:4. Limited access is permitted only under the conditions in Sections 18 to 20 of Act 759/2004, which require unexpected employee absence, a reasonable belief that business-critical messages exist, exclusive work use of the address, and strict procedural safeguards.
Can employees consent to employer data processing that is not necessary for the employment relationship?
No. Section 3 of the Act on the Protection of Privacy in Working Life contains an absolute necessity requirement that cannot be overridden by employee consent. The law reflects the view that the inherent power imbalance in employment prevents genuinely voluntary consent. If the data is not directly necessary for the employment relationship, no legal basis for employer processing exists regardless of what the employee has signed.
What is Finland's digital consent age?
Finland set the digital consent age at 13 years under Section 5 of the Data Protection Act 1050/2018. Children aged 13 and older may independently consent to information society services. For children under 13, consent must be given or authorized by a parent or legal guardian. Finland chose the GDPR's minimum permissible threshold, the same as Denmark and Portugal.
Are there criminal penalties for data protection violations in Finland?
Yes. Section 26 of the Data Protection Act 1050/2018 cross-refers to the Criminal Code, where Chapter 38, Section 9 sets out the data protection offense (tietosuojarikos): a fine or imprisonment of up to one year for a person acting intentionally or with gross negligence otherwise than as the GDPR controller or processor. On 18 December 2025 the Helsinki Court of Appeal (R 23/1330) dismissed that charge against Vastaamo's former CEO, holding that a failure to notify under GDPR Article 33 does not satisfy the statutory elements of the offense and that no unambiguous statutory duty had been shown from which chief-executive criminal liability could be derived. Criminal liability may attach to individuals, in addition to administrative fines imposed on the organization.
How does Finland supervise AI systems under the EU AI Act?
Act 1377/2025, in force from 1 January 2026, establishes Finland's decentralized AI Act supervision framework. The Finnish Transport and Communications Agency (Traficom) supervises the Article 50 transparency obligations and is Finland's single point of contact under Article 70(2). General-purpose AI models are enforced by the European Commission through the AI Office under Article 88(1), not by any national authority. Sectoral authorities supervise AI within their own domains, with the Data Protection Ombudsman covering Annex III high-risk systems in biometrics, education, employment, law enforcement, migration and the administration of justice. A penalty-payment board (seuraamusmaksulautakunta) attached to Traficom imposes every fine under the Act on a proposal from the competent authority, with no monetary threshold.
What transfer mechanisms may Finnish organizations use to send personal data outside the EEA?
Finnish organizations may transfer personal data outside the EEA using European Commission adequacy decisions, the EU-US Data Privacy Framework for certified US organizations (since July 2023), Standard Contractual Clauses (2021 version) accompanied by a transfer impact assessment, Binding Corporate Rules approved by the relevant supervisory authority, or the Article 49 derogations where the specific conditions are met. The Data Protection Ombudsman treats Article 49 derogations as exceptional rather than routine.
What did the Helsinki Administrative Court decide in the Posti GDPR case?
In November 2025, the Helsinki Administrative Court reversed the EUR 2.4 million fine the Sanctions Board had imposed on Posti Jakelu Oy in November 2024. The court found that Posti was entitled under freedom of enterprise and freedom of contract to bundle its digital services into a single package and had a lawful basis under Article 6(1)(b) of the GDPR to process personal data connected to the automatically created OmaPosti mailbox. The court upheld a reprimand for insufficient transparency in informing customers.
Does the EU Data Act create new obligations for Finnish organizations?
Yes. The EU Data Act (Regulation 2023/2854) became applicable from 12 September 2025. It creates data-sharing obligations for manufacturers and providers of connected products and related services, and rights for users to access and share the data generated by those products. The Data Protection Ombudsman supervises Data Act provisions that intersect with personal data protection. Finland's implementing law, the Act on the Supervision of Data Management and Sharing (1148/2025), entered into force on 1 January 2026 and makes Traficom the main supervisory authority and national data coordinator.
Updates
Corrected the Finnish statute references throughout (the digital consent age is Section 5 of the Data Protection Act, the criminal offence is Section 26 pointing to Criminal Code Chapter 38 Section 9, and the employer email rules are Sections 18 to 20 of Act 759/2004), added the Section 24(4) rule that administrative fines cannot be imposed on Finnish public-sector bodies, corrected the employer email penalties (a fine under Act 759/2004, up to two years under Criminal Code 38:3), updated the Verkkokauppa.com fine to the final EUR 792,639 confirmed by the Supreme Administrative Court on 12 June 2026, restated what the Helsinki Court of Appeal actually held in the Vastaamo CEO case, removed two unsupported EU AI Act claims about Traficom and a EUR 300,000 fine threshold, and brought the enforcement, Data Act and AI Act sections up to September 2026.
Expanded from ~2,400 to ~6,200 words. Added: constitutional basis (s. 10), legal bases / consent, data subject rights, EU AI Act national implementation (Act 1377/2025, Traficom), DPO requirements, and expanded recent developments with 2024-2025 enforcement actions (Verkkokauppa.com, Posti, Vastaamo, and the Helsinki Court of Appeal ruling in the Vastaamo CEO case). Updated penalties section, cross-border transfers section, and compliance section. Set is_published = true. Several statements in that revision were found to be inaccurate and were corrected on 10 September 2026; see the entry of that date in this log.
Sources and References
- Office of the Data Protection Ombudsman – Legislation(tietosuoja.fi).gov
- Data Protection Act 1050/2018 – Finlex(finlex.fi).gov
- Ministry of Economic Affairs – Protection of Privacy at Work(tem.fi).gov
- Data Protection Ombudsman – Working Life FAQ(tietosuoja.fi).gov
- Finnish Government – National Supervision of EU AI Act(valtioneuvosto.fi).gov
- Ministry of Economic Affairs – National Supervision of EU AI Act(tem.fi).gov
- EDPB – Finnish SA Fine EUR 856,000 Verkkokauppa.com (2024)(edpb.europa.eu).gov
- EDPB – Finnish SA Fine EUR 2.4m Posti (2024)(edpb.europa.eu).gov
- Data Protection Ombudsman – Vastaamo Fine Decision(tietosuoja.fi).gov
- Data Protection Ombudsman – EU Data Act(tietosuoja.fi).gov
- GDPRhub – Finnish DPA Enforcement Tracker(gdprhub.eu)
- Tietosuojalaki 1050/2018, consolidated text (Finlex) – Sections 5, 24(4) and (5), 26, 27, 31 and 32, Chapter 3(finlex.fi).gov
- Laki yksityisyyden suojasta työelämässä 759/2004, consolidated text (Finlex) – Sections 5a, 16, 18 to 20 and 24(finlex.fi).gov
- Rikoslaki 39/1889, Chapter 38 (Finlex) – Section 3 viestintäsalaisuuden loukkaus, Section 4 aggravated form, Section 9 tietosuojarikos(finlex.fi).gov
- Laki eräiden tekoälyjärjestelmien valvonnasta 1377/2025 (Finlex) – Traficom as Article 50 market surveillance authority and Article 70(2) contact point, penalty-payment board(finlex.fi).gov
- HE 46/2026 vp – Government proposal to extend administrative fines to authorities and public administration bodies (Finlex)(finlex.fi).gov
- Laki yksityisyyden suojasta työelämässä annetun lain 4 ja 21 §:n muuttamisesta 945/2025 (Finlex)(finlex.fi).gov
- Data Protection Ombudsman – Supreme Administrative Court upheld the fine imposed on Verkkokauppa.com, reduced to EUR 792,639 (12 June 2026, KHO 12.6.2026/1604)(tietosuoja.fi).gov
- Data Protection Ombudsman – Administrative Court ruling on the Yliopiston Apteekki fine and the public-sector sanctions reform (2 June 2026)(tietosuoja.fi).gov
- Data Protection Ombudsman – EUR 100 million fine on Yango operator MLU B.V. for personal data transfers to Russia (8 May 2026)(tietosuoja.fi).gov
- Data Protection Ombudsman – Supreme Administrative Court rulings on Finland’s early GDPR fines, KHO:2023:81 and KHO:2023:82 (13 September 2023)(tietosuoja.fi).gov
- Helsinki Court of Appeal – charge of data protection offence against Vastaamo Oy’s former CEO dismissed, R 23/1330 (18 December 2025)(tuomioistuimet.fi).gov
- Helsinki Administrative Court – EUR 2.4 million fine on Posti Jakelu Oy over the OmaPosti service quashed, decision 6850/2025 (3 November 2025)(tuomioistuimet.fi).gov
- Finnish Government – Data Act implementing legislation confirmed 5 December 2025, in force 1 January 2026(valtioneuvosto.fi).gov
- Regulation (EU) 2024/1689 (AI Act), consolidated text as at 27 July 2026 – Article 70(2) and Article 88(1)(eur-lex.europa.eu).gov