Search
- Fess search
-
Data protection in the development and use of AI systems These pages have information on the requirements arising from data protection legislation that should be taken into account when artificial intelligence (AI) systems are developed and used. ...https://tietosuoja.fi/en/ai-systems-and-data-protection
-
Frequently asked questions about personal identity code Is it permitted to ask for the personal identity code when a guest checks into a hotel? Yes. According to the Act on Accommodation and Food Service Activities (308/2006), an accommodation pro...https://tietosuoja.fi/en/faq-personal-identity-code
-
Claiming damages for violations of the GDPR Data subjects are entitled to damages if a controller or processor of personal data violates the EU General Data Protection Regulation and the violation causes material or immaterial damage to the data s...https://tietosuoja.fi/en/claiming-damages
-
Regulation on political advertising and the powers of the Data Protection Ombudsman The EU regulation on the transparency and targeting of political advertising sets out rules on how political advertising may be targeted. The Data Protection Ombud...https://tietosuoja.fi/en/regulation-on-political-advertising
-
If you want to have your data rectified You have the right to demand the rectification of inaccurate personal data concerning you. The accuracy of your personal data is a part of your legal protection. You have the right to be evaluated on the bas...https://tietosuoja.fi/en/if-you-want-to-have-your-data-rectified
-
Scientific research FAQ Learn more about scientific research on our website Scientific research and data protection . The European Data Protection Board (EDPB) has published a first version of the guidelines for scientific research. The content of...https://tietosuoja.fi/en/faq-scientific-research
-
Everyone has the right to their own personal datahttps://tietosuoja.fi/en/private-persons
-
Data Protection Legislation General Data Protection Regulation (EUR-Lex) Data Protection Act (pdf, Finlex) Law Enforcement Directive (EUR-Lex) Law Enforcement Act Data Protection Act The Data Protection Act (1050/2018) specifies and supplements th...https://tietosuoja.fi/en/legislation
-
Annual report 2025 The annual report describes the year's most important data protection events, supervision measures in different sectors and presents the key figures for the Office's operations. Annual report of the Office of the Data Protection...https://tietosuoja.fi/en/annual-report-2025
-
Know your responsibility and build trusthttps://tietosuoja.fi/en/organisations
-
If you do not want your data processed In certain situations, you have the right to restrict the processing of your personal data. You can also object to the processing of your personal data if you do not want it processed at all. Personal data re...https://tietosuoja.fi/en/if-you-do-not-want-your-data-processed
-
Lawfulness, fairness and transparency The processing of personal data shall be lawful, fair and transparent. Lawfulness The processing of personal data must be done in compliance with the EU’s General Data Protection Regulation and other legislati...https://tietosuoja.fi/en/lawfulness-fairness-and-transparency
-
Know your rights The EU's General Data Protection Regulation sets down your rights when a company or organisation is processing your personal data. You have the right to obtain information on the processing of your personal data of access to your ...https://tietosuoja.fi/en/know-your-rights
-
The researcher’s data protection expertise Data protection tools are a necessary part of the researcher’s work and competence. Compliance with data protection regulations builds trust and lays the groundwork for future research. Data protection re...https://tietosuoja.fi/en/researchers-data-protection-expertise
-
Processors’ responsibilities Processors are governed by the General Data Protection Regulation if they are established in an EU Member State they are not established in an EU Member State but their personal data processing activities relate to the...https://tietosuoja.fi/en/processors-responsibilities
-
Transfer bases for authorities and the public sector Authorities and public organisations can transfer personal data to international organisations or the public bodies of third countries based on a European Commission decision on the adequacy of ...https://tietosuoja.fi/en/transfer-bases-for-authorities-and-the-public-sector
-
Telephone guidance Our telephone guidance service provides general guidance and support in matters involving data protection and lets you know if the case requires more detailed investigation and processing at our Office. In the first instance, tr...https://tietosuoja.fi/en/telephone-guidance
-
Data Protection Officer of the Office of the Data Protection Ombudsman The Data Protection Officer of the Office of the Data Protection Ombudsman acts as a contact person when the Office of the Data Protection Ombudsman processes your personal dat...https://tietosuoja.fi/en/data-protection-officer
-
If you would like to have your personal data transferred to another controller In certain situations, you have the right to receive your data and transfer them to another service provider. The right to data portability makes it easier for you to c...https://tietosuoja.fi/en/if-you-would-like-to-have-your-personal-data-transferred-to-another-controller
-
Frequently asked questions about genealogy What personal data can I process for purposes of genealogical research? The General Data Protection Regulation (GDPR) does not specify what personal data may be processed for genealogical purposes. The es...https://tietosuoja.fi/en/faq-genealogy
-
Brexit and the transfer of personal data to the UK When the transition period for the withdrawal from the EU ended, the United Kingdom lost all its rights and obligations as a Member State. Due to the withdrawal from the EU, data protection regula...https://tietosuoja.fi/en/brexit-and-the-transfer-of-personal-data-to-the-uk
-
When a competent authority processes your personal data The Act on the Processing of Personal Data in Criminal Matters and in Connection with Maintaining National Security sets down your rights when a competent authority processes your personal da...https://tietosuoja.fi/en/when-a-competent-authority-processes-your-personal-data
-
Accuracy of data The personal data being processed must be accurate and up to date. Inaccurate personal data must be rectified or erased without delay. The controller must confirm the accuracy of the personal data being kept by it. The verificatio...https://tietosuoja.fi/en/accuracy-of-data
-
Frequently asked questions about banking Are banks permitted to copy my ID? Yes. Banks have a statutory obligation to know and identify their customers. Among other things, this means that the bank must verify the customer’s identity in a reliable...https://tietosuoja.fi/en/faq-banking
-
Designating a data protection officer A data protection officer must be designated if your organisation processes sensitive data on a large scale monitors individuals regularly, systematically and on a large scale or your organisation is a public ...https://tietosuoja.fi/en/designating-a-data-protection-officer
-
Transfers on the basis of an adequacy decision Personal data can be transferred out of the European Union and European Economic Area if the European Commission has issued a decision on an adequate level of protection for personal data (‘adequacy d...https://tietosuoja.fi/en/transfers-on-the-basis-of-an-adequacy-decision
-
Frequently asked questions about the Digital Services Act (DSA) What kinds of operators are subject to the DSA's obligations? The obligations imposed by the Digital Services Act (DSA) apply to all online services, referred to as 'intermediary serv...https://tietosuoja.fi/en/digital-services-act-dsa-
-
Frequently asked questions regarding the adequacy decision concerning data protection in the United States For organisations What does the adequacy decision concerning the United States mean? The European Commission's decision on the adequacy of d...https://tietosuoja.fi/en/faq-adequacy-decision-concerning-data-protection-in-the-united-states
-
Accessibility statement of Tietosuoja.fi This accessibility statement applies to the website www.tietosuoja.fi and it was created on 22 September 2020. The statement has been updated on 20 January 2026. We are committed to providing accessibility ...https://tietosuoja.fi/en/accessibility-statement
-
Frequently asked questions about search engines How do I request that a search result be erased from a search engine? Contact the search engine directly to request the erasure of a search result. Out of the search engines, at least Google and Bing...https://tietosuoja.fi/en/faq-search-engines
-
Derogations for specific situations Article 49 of the General Data Protection Regulation provides for derogations for specific situations. They are a last-resort basis for data transfer, only applicable in exceptional cases . The transfer of data ...https://tietosuoja.fi/en/derogations-for-specific-situations
-
Processors A processor is an individual or an organisation that processes personal data on behalf of a controller. Processors operate according to the controller’s instructions and under its supervision. The controller determines the purposes and ...https://tietosuoja.fi/en/processors
-
Data protection officers A data protection officer is an expert within the organisation, who monitors the processing of personal data and provides advice on compliance with data protection regulations. The data protection officer monitors complian...https://tietosuoja.fi/en/data-protection-officers
-
The processing of personal data at the Office of the Data Protection Ombudsmanhttps://tietosuoja.fi/en/our-data-protection-policy
-
Scientific research and data protection Taking care of data protection builds trust in research subjects and is a requirement for the success of any study. It is essential to plan the processing of personal data for its entire lifespan before the ...https://tietosuoja.fi/en/scientific-research-and-data-protection
-
Rights of the data subject When a controller processes personal data, it must take appropriate measures to ensure that the data protection rights of data subjects are fulfilled. Controllers are also required facilitate the exercise of the data sub...https://tietosuoja.fi/en/rights-of-the-data-subject
-
Purpose limitation The purpose of processing personal data must be planned and defined clearly before the start of processing. Personal data may only be collected and processed for a specific and lawful purpose. The data may not be processed in a ...https://tietosuoja.fi/en/purpose-limitation
-
Frequently asked questions about the internet Is the controller entitled to publish personal data from its personal data file on its website? Personal data stored in a personal data file may only be published on the internet with the consent of th...https://tietosuoja.fi/en/faq-internet
-
Find out whether the Data Protection Ombudsman can help you What do you want to do? I want to obtain information on the processing of my personal data. I want access to my personal data I want to rectify my personal data. I want to erase my person...https://tietosuoja.fi/en/en/find-out-whether-the-data-protection-ombudsman-can-help-you-rights
-
Choosing the processing basis and ensuring its lawfulness in scientific research As a rule, the controller is free to choose the basis for processing that is most applicable to the implementation of the study. The processing of special categories ...https://tietosuoja.fi/en/choosing-the-processing-basis-and-ensuring-its-lawfulness
-
Lecture requests The Office of the Data Protection Ombudsman’s experts can be invited to give lectures at training events held by stakeholders and other organisations. As a rule, such lectures are subject to a fee. The fees are based on the Act on...https://tietosuoja.fi/en/lecture-requests
-
Current issues From the Data Protection Ombudsman: data protection regulations must be observed when using smart glasses Publication date: 26.8.2026 Annual report of the Office of the Data Protection Ombudsman 2025: Artificial intelligence and wor...https://tietosuoja.fi/en/current-issues
-
European cooperation The Office of the Data Protection Ombudsman is an active member of the European Data Protection Board (EDPB). The EDPB promotes cooperation between European data protection authorities and the consistent application of data pr...https://tietosuoja.fi/en/european-cooperation
-
Controller's legitimate interests The processing of personal data can sometimes be justified due to the legitimate interests of the controller or a third party. The use of legitimate interests as a basis for processing requires particularly carefu...https://tietosuoja.fi/en/controller-s-legitimate-interests
-
Accountability in scientific research The controller must be prepared to demonstrate that data protection regulations have been taken into account in the study. Researchers must document the implementation of data-protection principles and other p...https://tietosuoja.fi/en/accountability-in-scientific-research
-
Defining the research scheme and purpose for processing personal data Processing personal data for purposes of scientific research must comply with the requirement of purpose limitation. The purpose of processing personal data must be planned and ...https://tietosuoja.fi/en/defining-the-research-scheme-and-purpose-for-processing-personal-data
-
Data protection principles The data protection principles must always be observed when processing personal data . The controller must also be able to demonstrate the effective implementation of the data protection principles in the processing of p...https://tietosuoja.fi/en/data-protection-principles
-
Declaration of Data Protection Officer Purpose of processing The purpose of processing the personal data of Data Protection Officers is to enable communication between the supervisory authority and the Data Protection Officers of controllers and p...https://tietosuoja.fi/en/declaration-of-data-protection-officer
-
Duties of the Data Protection Ombudsman supervising compliance with data protection legislation and other laws concerning the processing of personal data promoting awareness of the risks, rules, safeguards, obligations and rights related to the pr...https://tietosuoja.fi/en/duties
-
Data breach notification Purpose of processing If a personal data breach can cause a risk to the rights and freedoms of natural persons, the supervisory authority must be notified. In Finland, the Office of the Data Protection Ombudsman functions ...https://tietosuoja.fi/en/data-breach-notification
-
Office of the Data Protection Ombudsman The Office of the Data Protection Ombudsman safeguards your data protection rights The Data Protection Ombudsman is a national supervisory authority which supervises the compliance with data protection legis...https://tietosuoja.fi/en/office-of-the-data-protection-ombudsman
-
Minimisation of data Personal data may only be processed when necessary for the purposes of the processing. The personal data being processed must be appropriate , i.e. data that can be used to fulfil a specified purpose of processing relevant , i...https://tietosuoja.fi/en/minimisation-of-data
-
Risk assessment and data protection planning Controllers have a responsibility to assess the risks relating to the processing of personal data every time they are about to process personal data. A risk assessment allows controllers to plan the ste...https://tietosuoja.fi/en/risk-assessment-and-data-protection-planning
-
Codes of Conduct Codes of conduct are sector-specific guidelines on the application of data protection legislation. They are intended to help organisations comply with data protection requirements with concrete and practical instructions. By commi...https://tietosuoja.fi/en/codes-of-conduct
-
Storage limitation Personal data may only be stored for as long as necessary for the purposes of processing. The controller must plan and be able to justify the storage time of the personal data. The storage times of personal data must also be doc...https://tietosuoja.fi/en/storage-limitation
-
Lifespan of personal data processing, data protection principles and the protection of data in scientific research If processing of personal data is necessary for the implementation of the study, the lifespan of the processing must be planned from...https://tietosuoja.fi/en/lifespan-of-personal-data-processing-data-protection-principles-and-the-protection-of-data
-
Binding corporate rules Binding Corporate Rules (BCR) refer to common binding rules on the transfer of personal data to third countries within companies in the same group of undertakings or group of enterprises engaged in a joint economic activity...https://tietosuoja.fi/en/binding-corporate-rules
-
Notification to the Data Protection Ombudsman Concerning your rights Data protection rights help you manage your data. If you would like to exercise your rights, first contact the company or organisation that is processing your data, i.e. the cont...https://tietosuoja.fi/en/notification-to-the-data-protection-ombudsman
-
Transfers of personal data out of the European Economic Area Transferring personal data out of the EEA requires an appropriate basis for the transfer and compliance with the other requirements imposed by data protection legislation. This page desc...https://tietosuoja.fi/en/transfers-of-personal-data-out-of-the-eea
-
26.8.2026 | The growing popularity of smart glasses has raised new concerns about privacy. Users of the glasses must be aware of the risks and rules relating to data protection, says Data Protection Ombudsman Anu Talus. EU data protection authorities are currently working on a common approach to smart glasses and data protection.https://tietosuoja.fi/en/-/from-the-data-protection-ombudsman-data-protection-regulations-must-be-observed-when-using-smart-glasses