Search

Your search for 'Information' returned 404 results
Fess search
  1. Accuracy of data The personal data being processed must be accurate and up to date. Inaccurate personal data must be rectified or erased without delay. The controller must confirm the accuracy of the personal data being kept by it. The verificatio...
    https://tietosuoja.fi/en/accuracy-of-data
  2. Accessibility statement of Tietosuoja.fi This accessibility statement applies to the website www.tietosuoja.fi and it was created on 22 September 2020. The statement has been updated on 20 January 2026. We are committed to providing accessibility ...
    https://tietosuoja.fi/en/accessibility-statement
  3. Frequently asked questions about genealogy What personal data can I process for purposes of genealogical research? The General Data Protection Regulation (GDPR) does not specify what personal data may be processed for genealogical purposes. The es...
    https://tietosuoja.fi/en/faq-genealogy
  4. Processors’ responsibilities Processors are governed by the General Data Protection Regulation if they are established in an EU Member State they are not established in an EU Member State but their personal data processing activities relate to the...
    https://tietosuoja.fi/en/processors-responsibilities
  5. When a competent authority processes your personal data The Act on the Processing of Personal Data in Criminal Matters and in Connection with Maintaining National Security sets down your rights when a competent authority processes your personal da...
    https://tietosuoja.fi/en/when-a-competent-authority-processes-your-personal-data
  6. Lawfulness, fairness and transparency The processing of personal data shall be lawful, fair and transparent. Lawfulness The processing of personal data must be done in compliance with the EU’s General Data Protection Regulation and other legislati...
    https://tietosuoja.fi/en/lawfulness-fairness-and-transparency
  7. If you would like to have your personal data transferred to another controller In certain situations, you have the right to receive your data and transfer them to another service provider. The right to data portability makes it easier for you to c...
    https://tietosuoja.fi/en/if-you-would-like-to-have-your-personal-data-transferred-to-another-controller
  8. Annual report 2025 The annual report describes the year's most important data protection events, supervision measures in different sectors and presents the key figures for the Office's operations. Annual report of the Office of the Data Protection...
    https://tietosuoja.fi/en/annual-report-2025
  9. Transfer bases for authorities and the public sector Authorities and public organisations can transfer personal data to international organisations or the public bodies of third countries based on a European Commission decision on the adequacy of ...
    https://tietosuoja.fi/en/transfer-bases-for-authorities-and-the-public-sector
  10. Designating a data protection officer A data protection officer must be designated if your organisation processes sensitive data on a large scale monitors individuals regularly, systematically and on a large scale or your organisation is a public ...
    https://tietosuoja.fi/en/designating-a-data-protection-officer
  11. Everyone has the right to their own personal data
    https://tietosuoja.fi/en/private-persons
  12. If you want to have your data rectified You have the right to demand the rectification of inaccurate personal data concerning you. The accuracy of your personal data is a part of your legal protection. You have the right to be evaluated on the bas...
    https://tietosuoja.fi/en/if-you-want-to-have-your-data-rectified
  13. The researcher’s data protection expertise Data protection tools are a necessary part of the researcher’s work and competence. Compliance with data protection regulations builds trust and lays the groundwork for future research. Data protection re...
    https://tietosuoja.fi/en/researchers-data-protection-expertise
  14. Know your rights The EU's General Data Protection Regulation sets down your rights when a company or organisation is processing your personal data. You have the right to obtain information on the processing of your personal data of access to your ...
    https://tietosuoja.fi/en/know-your-rights
  15. Data Protection Legislation General Data Protection Regulation (EUR-Lex) Data Protection Act (pdf, Finlex) Law Enforcement Directive (EUR-Lex) Law Enforcement Act Data Protection Act The Data Protection Act (1050/2018) specifies and supplements th...
    https://tietosuoja.fi/en/legislation
  16. Right to restriction of processing The data subject can request the controller to restrict the processing of personal data concerning him or her. The restriction of processing means that, in addition to storage, the personal data subject to the re...
    https://tietosuoja.fi/en/right-to-restriction-of-processing
  17. Know your responsibility and build trust
    https://tietosuoja.fi/en/organisations
  18. Regulation on political advertising and the powers of the Data Protection Ombudsman The EU regulation on the transparency and targeting of political advertising sets out rules on how political advertising may be targeted. The Data Protection Ombud...
    https://tietosuoja.fi/en/regulation-on-political-advertising
  19. Scientific research FAQ Learn more about scientific research on our website Scientific research and data protection . Does scientific research always require consent for the processing of personal data? No. Personal data can be processed for resea...
    https://tietosuoja.fi/en/faq-scientific-research
  20. Telephone guidance Our telephone guidance service provides general guidance and support in matters involving data protection and lets you know if the case requires more detailed investigation and processing at our Office. In the first instance, tr...
    https://tietosuoja.fi/en/telephone-guidance
  21. Destruction, anonymisation or archiving of data at the conclusion of research When a study ends, the controller must ensure that data is appropriately destroyed, anonymised or archived. Data protection regulations specify a lifespan for personal d...
    https://tietosuoja.fi/en/destruction-anonymisation-or-archiving-of-data
  22. Frequently asked questions about personal identity code Is it permitted to ask for the personal identity code when a guest checks into a hotel? Yes. According to the Act on Accommodation and Food Service Activities (308/2006), an accommodation pro...
    https://tietosuoja.fi/en/faq-personal-identity-code
  23. Data Protection Officer of the Office of the Data Protection Ombudsman The Data Protection Officer of the Office of the Data Protection Ombudsman acts as a contact person when the Office of the Data Protection Ombudsman processes your personal dat...
    https://tietosuoja.fi/en/data-protection-officer
  24. When is the processing of personal data permitted? Legal bases for processing personal data The processing of personal data always requires a legal basis, which must be determined before the start of processing. Once the processing of personal dat...
    https://tietosuoja.fi/en/when-is-the-processing-of-personal-data-permitted
  25. Claiming damages for violations of the GDPR Data subjects are entitled to damages if a controller or processor of personal data violates the EU General Data Protection Regulation and the violation causes material or immaterial damage to the data s...
    https://tietosuoja.fi/en/claiming-damages
  26. Personal data breaches What is a personal data breach? A personal data breach means an event leading to the destruction, loss, alteration or unauthorised disclosure of, or access to, personal data. Examples of personal data breaches include lost d...
    https://tietosuoja.fi/en/personal-data-breaches
  27. If you do not want your data processed In certain situations, you have the right to restrict the processing of your personal data. You can also object to the processing of your personal data if you do not want it processed at all. Personal data re...
    https://tietosuoja.fi/en/if-you-do-not-want-your-data-processed
  28. Pseudonymised and anonymised data Pseudonymised personal data Pseudonymisation means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific person without the use of additional information...
    https://tietosuoja.fi/en/pseudonymised-and-anonymised-data
  29. Carrying out an impact assessment 1. Draw up a systematic description of the envisaged processing operations and the purposes of the processing Draw up a description of the nature, scope, context and purposes of the processing of personal data. Id...
    https://tietosuoja.fi/en/carrying-out-an-impact-assessment
  30. Registry You can enquire after matters concerning instituting and pending a case from the registry of the Office of the Data Protection Ombudsman. This kind of enquiries are for example how should a case be sent to the Office of the Data Protectio...
    https://tietosuoja.fi/en/registry
  31. Have you been notified of the processing of your personal data? You have the right to obtain information on the purpose for which your personal data is collected and how it is processed. A company, authority or corporation processing your personal...
    https://tietosuoja.fi/en/have-you-been-notified-of-the-processing-of-your-personal-data
  32. Data protection in the development and use of AI systems These pages have information on the requirements arising from data protection legislation that should be taken into account when artificial intelligence (AI) systems are developed and used. ...
    https://tietosuoja.fi/en/ai-systems-and-data-protection
  33. Visiting the Office of the Data Protection Ombudsman Instituting a case Our website contains electronic forms for instituting cases falling within the competence of the data protection authorities ( read more on our office’s electronic services )....
    https://tietosuoja.fi/en/visiting-the-office
  34. Frequently asked questions about Data Protection Officers More information about data protection officers and instructions for organisations and managers that have designated a data protection officer Do the Data Protection Officer's name and cont...
    https://tietosuoja.fi/en/faq-dpos
  35. Frequently asked questions about phone calls Are individuals allowed to record their own telephone conversations? Citizens have the right to record telephone calls in which they are the caller or receiver. Finland’s Constitution gives the right to...
    https://tietosuoja.fi/en/faq-phone-calls
  36. Frequently asked questions about elections On this page, you will find answers to frequently asked questions about election advertising and data protection. See also: Frequently asked questions about direct marketing Information on the EU regulati...
    https://tietosuoja.fi/en/faq-elections
  37. Right to erasure In certain cases, the data subject has the right to have the controller erase data concerning him or her without undue delay. This right is also known as the right to be forgotten. The controller is obligated to erase the personal...
    https://tietosuoja.fi/en/right-to-erasure
  38. Processor's record of processing activities Organisations are obligated to draw up a written description of their personal data processing. This description is called a record of processing activities. The obligation to draw up a record of process...
    https://tietosuoja.fi/en/processor-s-record-of-processing-activities
  39. Record of processing activities Record of processing activities is a written description of organisations personal data processing. The obligation to draw up a record of processing activities applies to all organisations with more than 250 employe...
    https://tietosuoja.fi/en/record-of-processing-activities
  40. This section provides answers to common questions.
    https://tietosuoja.fi/en/frequently-asked-questions