Search

Your search for 'Information' returned 407 results
Fess search
  1. Accessibility statement of Tietosuoja.fi This accessibility statement applies to the website www.tietosuoja.fi and it was created on 22 September 2020. The statement has been updated on 20 January 2026. We are committed to providing accessibility ...
    https://tietosuoja.fi/en/accessibility-statement
  2. Frequently asked questions about genealogy What personal data can I process for purposes of genealogical research? The General Data Protection Regulation (GDPR) does not specify what personal data may be processed for genealogical purposes. The es...
    https://tietosuoja.fi/en/faq-genealogy
  3. Transfer bases for authorities and the public sector Authorities and public organisations can transfer personal data to international organisations or the public bodies of third countries based on a European Commission decision on the adequacy of ...
    https://tietosuoja.fi/en/transfer-bases-for-authorities-and-the-public-sector
  4. Designating a data protection officer A data protection officer must be designated if your organisation processes sensitive data on a large scale monitors individuals regularly, systematically and on a large scale or your organisation is a public ...
    https://tietosuoja.fi/en/designating-a-data-protection-officer
  5. The researcher’s data protection expertise Data protection tools are a necessary part of the researcher’s work and competence. Compliance with data protection regulations builds trust and lays the groundwork for future research. Data protection re...
    https://tietosuoja.fi/en/researchers-data-protection-expertise
  6. Transfers on the basis of an adequacy decision Personal data can be transferred out of the European Union and European Economic Area if the European Commission has issued a decision on an adequate level of protection for personal data (‘adequacy d...
    https://tietosuoja.fi/en/transfers-on-the-basis-of-an-adequacy-decision
  7. Frequently asked questions about the Digital Services Act (DSA) What kinds of operators are subject to the DSA's obligations? The obligations imposed by the Digital Services Act (DSA) apply to all online services, referred to as 'intermediary serv...
    https://tietosuoja.fi/en/digital-services-act-dsa-
  8. Know your rights The EU's General Data Protection Regulation sets down your rights when a company or organisation is processing your personal data. You have the right to obtain information on the processing of your personal data of access to your ...
    https://tietosuoja.fi/en/know-your-rights
  9. Lawfulness, fairness and transparency The processing of personal data shall be lawful, fair and transparent. Lawfulness The processing of personal data must be done in compliance with the EU’s General Data Protection Regulation and other legislati...
    https://tietosuoja.fi/en/lawfulness-fairness-and-transparency
  10. Everyone has the right to their own personal data
    https://tietosuoja.fi/en/private-persons
  11. If you want to have your data rectified You have the right to demand the rectification of inaccurate personal data concerning you. The accuracy of your personal data is a part of your legal protection. You have the right to be evaluated on the bas...
    https://tietosuoja.fi/en/if-you-want-to-have-your-data-rectified
  12. Telephone guidance Our telephone guidance service provides general guidance and support in matters involving data protection and lets you know if the case requires more detailed investigation and processing at our Office. In the first instance, tr...
    https://tietosuoja.fi/en/telephone-guidance
  13. Data Protection Officer of the Office of the Data Protection Ombudsman The Data Protection Officer of the Office of the Data Protection Ombudsman acts as a contact person when the Office of the Data Protection Ombudsman processes your personal dat...
    https://tietosuoja.fi/en/data-protection-officer
  14. Claiming damages for violations of the GDPR Data subjects are entitled to damages if a controller or processor of personal data violates the EU General Data Protection Regulation and the violation causes material or immaterial damage to the data s...
    https://tietosuoja.fi/en/claiming-damages
  15. Right to restriction of processing The data subject can request the controller to restrict the processing of personal data concerning him or her. The restriction of processing means that, in addition to storage, the personal data subject to the re...
    https://tietosuoja.fi/en/right-to-restriction-of-processing
  16. Personal data breaches What is a personal data breach? A personal data breach means an event leading to the destruction, loss, alteration or unauthorised disclosure of, or access to, personal data. Examples of personal data breaches include lost d...
    https://tietosuoja.fi/en/personal-data-breaches
  17. If you do not want your data processed In certain situations, you have the right to restrict the processing of your personal data. You can also object to the processing of your personal data if you do not want it processed at all. Personal data re...
    https://tietosuoja.fi/en/if-you-do-not-want-your-data-processed
  18. Frequently asked questions about banking Are banks permitted to copy my ID? Yes. Banks have a statutory obligation to know and identify their customers. Among other things, this means that the bank must verify the customer’s identity in a reliable...
    https://tietosuoja.fi/en/faq-banking
  19. Brexit and the transfer of personal data to the UK When the transition period for the withdrawal from the EU ended, the United Kingdom lost all its rights and obligations as a Member State. Due to the withdrawal from the EU, data protection regula...
    https://tietosuoja.fi/en/brexit-and-the-transfer-of-personal-data-to-the-uk
  20. Registry You can enquire after matters concerning instituting and pending a case from the registry of the Office of the Data Protection Ombudsman. This kind of enquiries are for example how should a case be sent to the Office of the Data Protectio...
    https://tietosuoja.fi/en/registry
  21. Processors’ responsibilities Processors are governed by the General Data Protection Regulation if they are established in an EU Member State they are not established in an EU Member State but their personal data processing activities relate to the...
    https://tietosuoja.fi/en/processors-responsibilities
  22. When a competent authority processes your personal data The Act on the Processing of Personal Data in Criminal Matters and in Connection with Maintaining National Security sets down your rights when a competent authority processes your personal da...
    https://tietosuoja.fi/en/when-a-competent-authority-processes-your-personal-data
  23. Annual report 2025 The annual report describes the year's most important data protection events, supervision measures in different sectors and presents the key figures for the Office's operations. Annual report of the Office of the Data Protection...
    https://tietosuoja.fi/en/annual-report-2025
  24. If you would like to have your personal data transferred to another controller In certain situations, you have the right to receive your data and transfer them to another service provider. The right to data portability makes it easier for you to c...
    https://tietosuoja.fi/en/if-you-would-like-to-have-your-personal-data-transferred-to-another-controller
  25. Data protection in the development and use of AI systems These pages have information on the requirements arising from data protection legislation that should be taken into account when artificial intelligence (AI) systems are developed and used. ...
    https://tietosuoja.fi/en/ai-systems-and-data-protection
  26. Have you been subjected to a decision based solely on automated processing? You have the right to demand human involvement in decisions that concern you. Some decisions concerning you can be made automatically. This means that humans are not invol...
    https://tietosuoja.fi/en/have-you-been-subjected-to-a-decision-based-solely-on-automated-processing
  27. Data Protection Legislation General Data Protection Regulation (EUR-Lex) Data Protection Act (pdf, Finlex) Law Enforcement Directive (EUR-Lex) Law Enforcement Act Data Protection Act The Data Protection Act (1050/2018) specifies and supplements th...
    https://tietosuoja.fi/en/legislation
  28. Minimisation of personal data in scientific research The necessity of personal data for scientific research must be assessed at the earliest possible stage. Efforts must be made to minimise the processing of personal data. Both the amount and natu...
    https://tietosuoja.fi/en/minimisation-of-personal-data
  29. Record of processing activities Record of processing activities is a written description of organisations personal data processing. The obligation to draw up a record of processing activities applies to all organisations with more than 250 employe...
    https://tietosuoja.fi/en/record-of-processing-activities
  30. Regulation on political advertising and the powers of the Data Protection Ombudsman The EU regulation on the transparency and targeting of political advertising sets out rules on how political advertising may be targeted. The Data Protection Ombud...
    https://tietosuoja.fi/en/regulation-on-political-advertising
  31. Destruction, anonymisation or archiving of data at the conclusion of research When a study ends, the controller must ensure that data is appropriately destroyed, anonymised or archived. Data protection regulations specify a lifespan for personal d...
    https://tietosuoja.fi/en/destruction-anonymisation-or-archiving-of-data
  32. Know your responsibility and build trust
    https://tietosuoja.fi/en/organisations
  33. Scientific research FAQ Learn more about scientific research on our website Scientific research and data protection . Does scientific research always require consent for the processing of personal data? No. Personal data can be processed for resea...
    https://tietosuoja.fi/en/faq-scientific-research
  34. Frequently asked questions about personal identity code Is it permitted to ask for the personal identity code when a guest checks into a hotel? Yes. According to the Act on Accommodation and Food Service Activities (308/2006), an accommodation pro...
    https://tietosuoja.fi/en/faq-personal-identity-code
  35. Data protection for children and youth A lot of information called personal data is collected on you when you use the internet, social media or the apps on your phone, or play video games. Personal data is also collected for your hobbies and at sc...
    https://tietosuoja.fi/en/children-s-data-protection
  36. When is the processing of personal data permitted? Legal bases for processing personal data The processing of personal data always requires a legal basis, which must be determined before the start of processing. Once the processing of personal dat...
    https://tietosuoja.fi/en/when-is-the-processing-of-personal-data-permitted
  37. What rights do data subjects have in different situations? Not all of the rights of the data subject can be exercised in all situations, depending on factors such as the basis for the processing of personal data. Some of the rights of the data sub...
    https://tietosuoja.fi/en/what-rights-do-data-subjects-have-in-different-situations
  38. Rights of the data subject in scientific research The rights of the data subject arising from the basis for processing should be considered at the planning stage of the study. Research subjects must be informed of how their personal data will be p...
    https://tietosuoja.fi/en/rights-of-the-data-subject-in-scientific-research
  39. Carrying out an impact assessment 1. Draw up a systematic description of the envisaged processing operations and the purposes of the processing Draw up a description of the nature, scope, context and purposes of the processing of personal data. Id...
    https://tietosuoja.fi/en/carrying-out-an-impact-assessment
  40. EU digital and data regulation The EU's digital and data regulation facilitate the movement of data within the EU, create clear and fair rules for data use and promote compliance with privacy, data protection and competition rules. Digital and dat...
    https://tietosuoja.fi/en/eu-digital-and-data-regulation