Search
- Fess search
-
Undantag från den registrerades rättigheter i samband med vetenskaplig eller historisk forskning eller statistikföring Bestämmelser om den registrerades rättigheter som tillämpas på behandling av personuppgifter finns i dataskyddsförordningens kap...https://tietosuoja.fi/sv/undantag-fran-den-registrerades-rattigheter
-
Behandling av personuppgifter om dataskyddsombud Personuppgiftsansvariga och personuppgiftsbiträden ska anmäla dataskyddsombudets kontaktuppgifter till vår byrå. Anmälan kan göras på den blankett som finns på vår webbplats eller genom att lämna ko...https://tietosuoja.fi/sv/behandling-av-personuppgifter-om-dataskyddsombud
-
Lagenlighet, korrekthet och transparens Behandlingen av personuppgifter ska vara lagenlig, korrekt och transparent. Lagenlighet Vid behandling av personuppgifter ska EU:s allmänna dataskyddsförordning och övrig lagstiftning om behandling av person...https://tietosuoja.fi/sv/lagenlighet-korrekthet-och-transparens
-
Vanliga frågor om coronaviruset och dataskydd Vad avses med hälsouppgifter? Hälsouppgifter syftar till uppgifter som beskriver personens hälsotillstånd, sjukdom, funktionshinder eller vårdåtgärder. Hälsouppgifterna ingår särskilda kategorier av pe...https://tietosuoja.fi/sv/coronavirus
-
Känn ditt ansvar och bygg upp ett förtroendehttps://tietosuoja.fi/sv/organisationer
-
Uträttande av ärenden på plats på dataombudsmannens byrå Anhängiggörande av ärendet På vår webbplats finns det e-blanketter, med vilka en kund kan inleda ärenden som hör till dataskyddsmyndighetens verksamhetsfält ( läs mer om uträttande av ärende...https://tietosuoja.fi/sv/utrattande-av-arenden-pa-plats
-
Automatiskt beslutsfattande och profilering Vad avses med profilering? Profilering innebär automatisk behandling av personuppgifter, där en människa personliga egenskaper bedöms. Med profilering avses analys eller förutsägelser av särdrag som gäll...https://tietosuoja.fi/sv/automatiskt-beslutsfattande-och-profilering
-
Kontrollera uppgifter som den behöriga myndigheten behandlar Den behöriga myndigheten är skyldig att informera dig om den behandlar information om dig. Du har om du så vill möjlighet att granska vilka personuppgifter som gäller dig olika personupp...https://tietosuoja.fi/sv/kontrollera-uppgifter-som-den-behoriga-myndigheten-behandlar
-
Dataskydd vid utveckling och användning av AI-system På den här sidan finns information om kraven i dataskyddslagstiftningen som ska beaktas i utvecklingen och användningen av system för artificiell intelligens. Anvisningarna är inte uttömmande, u...https://tietosuoja.fi/sv/ai-system-och-dataskydd
-
Registratorskontor Från dataombudsmannens byrås registratorskontor kan du fråga om anhängiggörande och anhängighet av ett ärende, till exempel hur kan man skicka ett ärende till dataombudsmannens byrå om ett ärende är anhängig i dataombudsmannens ...https://tietosuoja.fi/sv/registratorskontor
-
Uträttande av ärenden elektroniskt Hur ett ärende inleds elektroniskt Dataombudsmannens byrå använder elektroniska blanketter som fungerar i Statens center för informations- och kommunikationsteknik Valtoris tjänst Turvalomake. Blanketterna fylls ...https://tietosuoja.fi/sv/utrattande-av-arenden-elektroniskt
-
Dataförordningen och dataombudsmannens behörighet I EU:s dataförordning (Data Act, DA) föreskrivs hur data från uppkopplade produkter kan delas. Förordningen började till stor del tillämpas 12.9.2025. Dataombudsmannens byrå övervakar att lagstiftn...https://tietosuoja.fi/sv/dataforordningen
-
Vanliga frågor om informationssystem Kan ett företags kund få logguppgifter med stöd av rätten till tillgång? I artikel 15 i allmänna dataskyddsförordningen föreskrivs om den registrerades rätt att få tillgång till uppgifter som gäller honom eller...https://tietosuoja.fi/sv/vanliga-fragor-informationssystem
-
Om du drabbas av en personuppgiftsincident På denna sida hittar du anvisningar om hur du ska förfara om du drabbats av en personuppgiftsincident. Granska först vilka uppgifter om dig som eventuellt kommit i en utomståendes händer . Agera snabbt i ...https://tietosuoja.fi/sv/om-du-drabbas-av-en-personuppgiftsincident
-
Uträttande av ärenden per telefon med dataombudsmannens byrå Uppgifter som behandlas i samband med ärenden som uträttas per telefon Telefonväxel Växeln vid dataombudsmannens byrå förmedlar samtal till tjänstemännen på dataombudsmannens byrå. Vad g...https://tietosuoja.fi/sv/utrattande-av-arenden-per-telefon
-
Behandling av ärenden som hör till vår behörighet Behandling av personuppgifter i anknytning till ärenden som hör till vår behörighet De ärenden som inletts vid dataombudsmannens byrå registreras i ärendehanteringen. I ärendehanteringen antecknas ...https://tietosuoja.fi/sv/behandling-av-arenden-som-hor-till-var-behorighet
-
Dataskyddsrättigheter och rättsskydd Du kan begära att dataombudsmannens byrå tillgodoser dina följande dataskyddsrättigheter. Rätten att få information om behandlingen av personuppgifter Du har rätt att få veta för vilka syften och på vilket sätt...https://tietosuoja.fi/sv/dina-dataskyddsrattigheter-och-rattsskyddet
-
Vilka rättigheter har den registrerade i olika situationer? En registrerad kan inte utöva alla sina rättigheter i alla situationer. Situationen påverkas till exempel av på vilken grund personuppgifter behandlas. En del av den registrerades rättigh...https://tietosuoja.fi/sv/vilka-rattigheter-har-den-registrerade-i-olika-situationer
-
Berätta om behandlingen för den registrerade Kraven för informationspraxis för personuppgiftsansvariga fastställs i den allmänna dataskyddsförordningen. Dataombudsmannens byrå uppmuntrar de olika branscherna att skapa gemensam informationspraxis t...https://tietosuoja.fi/sv/beratta-om-behandlingen-for-den-registrerade
-
Har du underrättats om behandlingen av dina uppgifter? Du har rätt att få information om för vilket syfte dina personuppgifter samlas in och hur de behandlas. Ett företag, en myndighet eller ett samfund som samlar in personuppgifter, kallas för pe...https://tietosuoja.fi/sv/har-du-underrattats-om-behandlingen-av-dina-uppgifter
-
12.1.2024 | Internet platforms and other digital services will have new obligations when the application of the EU's Digital Services Act begins on 17 February 2024. The purpose of the new Act is to reduce illegal content and increase the transparency of services.https://tietosuoja.fi/en/-/new-obligations-for-digital-operators-the-goal-is-safer-and-more-open-online-services
-
EU:s bestämmelser om digitalisering och data EU:s reglering om digitalisering och data främjar hur data rör sig inom EU, skapar tydliga och rättvisa regler för användningen av data samt främjar iakttagandet av reglerna om integritetsskydd, datasky...https://tietosuoja.fi/sv/eu-s-bestammelser-om-digitalisering-och-data
-
16.2.2024 | The Digital Services Act (DSA), which will be applied in mid-February, aims to secure the position of users of digital services, such as various online communities and marketplaces. If you report suspected illegal content in the future, the service provider must deal with the matter and inform you of its solution. If you produce content or act as a seller through an online platform, you have the right to receive information and justifications about any kind of restriction of the use of service.https://tietosuoja.fi/en/-/the-new-regulations-for-digital-services-come-into-effect-this-is-how-the-user-s-position-improves
-
18.3.2024 | The Sanctions Board of the Office of the Data Protection Ombudsman has imposed an administrative fine of 856,000 euros on Verkkokauppa.com Oyj because the company had not specified the storage period of its online shop customer accounts. In addition, Verkkokauppa.com's practice of requiring the creation of a customer account for making online purchases violated data protection provisions.https://tietosuoja.fi/en/-/administrative-fine-imposed-on-verkkokauppa.com-for-failing-to-define-storage-period-of-customer-data-requiring-customers-to-register-was-also-illegal
-
4.6.2025 | The Sanctions Board of the Office of the Data Protection Ombudsman issued a EUR 1,100,000 administrative fine against the pharmacy company Yliopiston Apteekki because of data protection shortcomings found in the pharmacy’s online shop related to the use of tracking services. Data on the customers’ use of the online shop was leaked to tracking service companies through the website’s analytics tools and tracking technology.https://tietosuoja.fi/en/-/yliopiston-apteekki-fined-for-online-shop-data-protection-shortcomings
-
25.6.2025 | ANNUAL REPORT OF THE OFFICE OF THE DATA PROTECTION OMBUDSMAN OF FINLAND 2024 ANNUAL REPORT OF THE OFFICE OF THE DATA PROTECTION OMBUDSMAN OF FINLAND 2024 3 Contents The Office of the Data Protection Ombudsman safeguards the rights and freedoms of ...https://tietosuoja.fi/documents/6927448/242571942/3%20TSV%20Annual%20Report%202024%20saavutettava.pdf/c49babc0-430a-77ec-aea2-95d5cebd2885?t=1750846070262
-
25.2.2025 | The EU's Digital Services Act imposes obligations on digital service providers to improve the transparency and security of their services. Last year, authorities in Finland received nearly 80 complaints about suspected breaches of the Digital Services Act, and the EU Commission has launched several investigations into digital waste. The act, which improves users' rights, has been fully in force for one year as of February 2025.https://tietosuoja.fi/en/-/digital-services-act-in-force-for-a-year-nearly-80-complaints-to-authorities-in-finland-in-2024
-
5.3.2025 | This year, the European data protection authorities will examine how organisations are exercising the right of individuals to have their personal data erased. Thirty-two data protection supervisory authorities from across Europe are participating in the joint inquiry. The Office of the Data Protection Ombudsman will investigate the situation in Finland through an anonymous survey of data controllers.https://tietosuoja.fi/en/-/office-of-the-data-protection-ombudsman-to-examine-the-exercise-of-the-right-to-erasure-as-part-of-an-eu-wide-measure
-
25.4.2025 | The Data Protection Ombudsman has approved two applications by Nokia for binding corporate rules (so-called BCRs). BCRs are legally binding rules for the transfer of personal data within a group of enterprises. They allow companies in the same group to transfer personal data between each other outside the EU and EEA countries.https://tietosuoja.fi/en/-/data-protection-ombudsman-confirms-nokia-s-bcr-rules-for-international-data-transfers
-
4.7.2025 | On 1–2 July, the European Data Protection Board met in Helsinki for a two-day high level meeting to discuss common outlines for future work. In the statement issued at the meeting, the data protection authorities agreed on new measures to facilitate compliance with data protection regulations, to increase dialogue with stakeholders and to develop cooperation between authorities in different sectors.https://tietosuoja.fi/en/-/edpb-issues-helsinki-statement-support-and-clarity-for-small-and-medium-sized-actors
-
16.10.2025 | The Office of the Data Protection Ombudsman has assessed the practices of the Government ICT Centre Valtori, the Digital and Population Data Services Agency and the Tax Administration in the use of cloud services in 2022. The assessment found that an adequate level of data protection had not been ensured for personal data transferred to the United States through the cloud service provided by Valtori.https://tietosuoja.fi/en/-/office-of-the-data-protection-ombudsman-government-cloud-services-must-meet-data-protection-requirements
-
6.8.2025 | We have put together answers to frequently asked questions about alcohol and drug testing in the workplace on our website. We also added information on what employers should consider when collecting personal data from employees and job applicants.https://tietosuoja.fi/en/-/we-completed-the-guidance-on-the-alcohol-testing-of-employees-and-processing-of-personal-data-in-the-workplace
-
20.10.2025 | The Office of the Data Protection Ombudsman has made changes to the online form for notifying personal data breaches. The revised form will be published on Monday, 27 October 2025 at 8.00 a.m. The aim is to streamline the processing of notifications.https://tietosuoja.fi/en/-/the-revised-online-form-for-notifying-data-breaches-will-be-published-next-week
-
30.1.2026 | On Thursday 29 January 2026, the Government appointed Heljä-Tuulia Pihamaa, Master of Laws, to the post of Deputy Data Protection Ombudsman for the next five-year term of office, starting on 22 March. Pihamaa has been serving as Deputy Data Protection Ombudsman since March 2021.https://tietosuoja.fi/en/-/helja-tuulia-pihamaa-continues-as-deputy-data-protection-ombudsman
-
25.3.2026 | The Sanctions Board of the Office of the Data Protection Ombudsman has imposed a fine of EUR 5,000 on Suomen Numerokeskus Oy, as the company systematically failed to comply with customers’ right to access recordings of customer calls. The company also deleted the call recordings despite requests from customers to review them.https://tietosuoja.fi/en/-/suomen-numerokeskus-fined-for-failing-to-provide-call-recordings
-
Impact assessment Impact assessments are designed to identify, evaluate and control risks involved in the processing of personal data. They are designed to be a continuous process for identifying and controlling risks. Impact assessments must be c...https://tietosuoja.fi/en/impact-assessments
-
19.3.2026 | This year, European data protection authorities will investigate how well organisations comply with the transparency and information obligations related to personal data processing. Data protection authorities from 25 countries across Europe will take part in the action.https://tietosuoja.fi/en/-/the-office-of-the-data-protection-ombudsman-to-investigate-the-transparency-of-personal-data-processing-as-part-of-eu-wide-action
-
12.6.2026 | The Supreme Administrative Court has enforced the decision of the Office of the Data Protection Ombudsman and the Sanctions Board of the Data Protection Ombudsman concerning the operations of Verkkokauppa.com Plc. The company violated data protection provisions by failing to specify the storage periods for customer account data.https://tietosuoja.fi/en/-/supreme-administrative-court-upholds-the-administrative-fine-imposed-on-verkkokauppa.com-for-data-protection-violations
-
The review and approval of codes of conduct at the Office of the Data Protection Ombudsman The Office of the Data Protection Ombudsman reviews and approves national codes of conduct applied in Finland. The criteria for the content of codes of cond...https://tietosuoja.fi/en/the-review-and-approval-of-codes-of-conduct
-
14.7.2026 | The annual report of the Office of the Data Protection Ombudsman describes the most important data protection events of the year, supervisory work in different sectors and performance indicators. Last year was marked by an increase in the use of artificial intelligence, the transforming legislative field and the debate on the competitiveness of the EU.https://tietosuoja.fi/en/-/annual-report-of-the-office-of-the-data-protection-ombudsman-2025-artificial-intelligence-and-world-politics-were-highlighted-in-data-protection-work
-
10.7.2026 | ANNUAL REPORT OF THE OFFICE OF THE DATA PROTECTION OMBUDSMAN OF FINLAND 2025 ANNUAL REPORT OF THE OFFICE OF THE DATA PROTECTION OMBUDSMAN OF FINLAND 2025 3 Contents The Office of the Data Protection Ombudsman safeguards the rights and freedoms of ...https://tietosuoja.fi/documents/6927448/267659444/TSV%20Annual%20Report%202025%20saavutettava.pdf/2f0bc5fe-b5bd-f5cd-6110-cca70019fede?t=1783669724217
-
Right to data portability The data subject has the right to receive the personal data that he or she has provided to a controller in a structured, commonly used and machine-readable format and, if desired, transmit that data to another controller....https://tietosuoja.fi/en/right-to-data-portability
-
Processing involving several EU countries If your organisation operates in more than one EU country, you need to find out which country’s supervisory authority you are meant to deal with. This data protection authority is called the lead superviso...https://tietosuoja.fi/en/processing-involving-several-eu-countries
-
List compiled by the Office of the Data Protection Ombudsman of processing operations which require data protection impact assessment (DPIA) Updated 21.12.2018 Article 35 (1) GDPR requires a DPIA when the processing activity is likely to result in...https://tietosuoja.fi/en/list-of-processing-operations-which-require-dpia
-
Roles and responsibilities for processing personal data in scientific research A research project can involve a variety of parties in different roles. Personal data may be processed for research purposes by one or more research organizations, pers...https://tietosuoja.fi/en/roles-and-responsibilities-for-processing-personal-data
-
Transfers of personal data out of the European Economic Area Transferring personal data out of the EEA requires an appropriate basis for the transfer and compliance with the other requirements imposed by data protection legislation. This page desc...https://tietosuoja.fi/en/transfers-of-personal-data-out-of-the-eea
-
Notification to the Data Protection Ombudsman Concerning your rights Data protection rights help you manage your data. If you would like to exercise your rights, first contact the company or organisation that is processing your data, i.e. the cont...https://tietosuoja.fi/en/notification-to-the-data-protection-ombudsman
-
Binding corporate rules Binding Corporate Rules (BCR) refer to common binding rules on the transfer of personal data to third countries within companies in the same group of undertakings or group of enterprises engaged in a joint economic activity...https://tietosuoja.fi/en/binding-corporate-rules
-
Codes of Conduct Codes of conduct are sector-specific guidelines on the application of data protection legislation. They are intended to help organisations comply with data protection requirements with concrete and practical instructions. By commi...https://tietosuoja.fi/en/codes-of-conduct
-
Storage limitation Personal data may only be stored for as long as necessary for the purposes of processing. The controller must plan and be able to justify the storage time of the personal data. The storage times of personal data must also be doc...https://tietosuoja.fi/en/storage-limitation
-
Lifespan of personal data processing, data protection principles and the protection of data in scientific research If processing of personal data is necessary for the implementation of the study, the lifespan of the processing must be planned from...https://tietosuoja.fi/en/lifespan-of-personal-data-processing-data-protection-principles-and-the-protection-of-data
-
Risk assessment and data protection planning Controllers have a responsibility to assess the risks relating to the processing of personal data every time they are about to process personal data. A risk assessment allows controllers to plan the ste...https://tietosuoja.fi/en/risk-assessment-and-data-protection-planning
-
Minimisation of data Personal data may only be processed when necessary for the purposes of the processing. The personal data being processed must be appropriate , i.e. data that can be used to fulfil a specified purpose of processing relevant , i...https://tietosuoja.fi/en/minimisation-of-data
-
Office of the Data Protection Ombudsman The Office of the Data Protection Ombudsman safeguards your data protection rights The Data Protection Ombudsman is a national supervisory authority which supervises the compliance with data protection legis...https://tietosuoja.fi/en/office-of-the-data-protection-ombudsman
-
Data breach notification Purpose of processing If a personal data breach can cause a risk to the rights and freedoms of natural persons, the supervisory authority must be notified. In Finland, the Office of the Data Protection Ombudsman functions ...https://tietosuoja.fi/en/data-breach-notification
-
Duties of the Data Protection Ombudsman supervising compliance with data protection legislation and other laws concerning the processing of personal data promoting awareness of the risks, rules, safeguards, obligations and rights related to the pr...https://tietosuoja.fi/en/duties
-
Data protection principles The data protection principles must always be observed when processing personal data . The controller must also be able to demonstrate the effective implementation of the data protection principles in the processing of p...https://tietosuoja.fi/en/data-protection-principles
-
European cooperation The Office of the Data Protection Ombudsman is an active member of the European Data Protection Board (EDPB). The EDPB promotes cooperation between European data protection authorities and the consistent application of data pr...https://tietosuoja.fi/en/european-cooperation
-
Choosing the processing basis and ensuring its lawfulness in scientific research As a rule, the controller is free to choose the basis for processing that is most applicable to the implementation of the study. The processing of special categories ...https://tietosuoja.fi/en/choosing-the-processing-basis-and-ensuring-its-lawfulness
-
Controller's legitimate interests The processing of personal data can sometimes be justified due to the legitimate interests of the controller or a third party. The use of legitimate interests as a basis for processing requires particularly carefu...https://tietosuoja.fi/en/controller-s-legitimate-interests