Search

Your search for 'Information' returned 405 results
Fess search
  1. Brexit and the transfer of personal data to the UK When the transition period for the withdrawal from the EU ended, the United Kingdom lost all its rights and obligations as a Member State. Due to the withdrawal from the EU, data protection regula...
    https://tietosuoja.fi/en/brexit-and-the-transfer-of-personal-data-to-the-uk
  2. Accuracy of data The personal data being processed must be accurate and up to date. Inaccurate personal data must be rectified or erased without delay. The controller must confirm the accuracy of the personal data being kept by it. The verificatio...
    https://tietosuoja.fi/en/accuracy-of-data
  3. Designating a data protection officer A data protection officer must be designated if your organisation processes sensitive data on a large scale monitors individuals regularly, systematically and on a large scale or your organisation is a public ...
    https://tietosuoja.fi/en/designating-a-data-protection-officer
  4. Accessibility statement of Tietosuoja.fi This accessibility statement applies to the website www.tietosuoja.fi and it was created on 22 September 2020. The statement has been updated on 20 January 2026. We are committed to providing accessibility ...
    https://tietosuoja.fi/en/accessibility-statement
  5. Frequently asked questions regarding the adequacy decision concerning data protection in the United States For organisations What does the adequacy decision concerning the United States mean? The European Commission's decision on the adequacy of d...
    https://tietosuoja.fi/en/faq-adequacy-decision-concerning-data-protection-in-the-united-states
  6. Frequently asked questions about the Digital Services Act (DSA) What kinds of operators are subject to the DSA's obligations? The obligations imposed by the Digital Services Act (DSA) apply to all online services, referred to as 'intermediary serv...
    https://tietosuoja.fi/en/digital-services-act-dsa-
  7. Transfers on the basis of an adequacy decision Personal data can be transferred out of the European Union and European Economic Area if the European Commission has issued a decision on an adequate level of protection for personal data (‘adequacy d...
    https://tietosuoja.fi/en/transfers-on-the-basis-of-an-adequacy-decision
  8. Derogations for specific situations Article 49 of the General Data Protection Regulation provides for derogations for specific situations. They are a last-resort basis for data transfer, only applicable in exceptional cases . The transfer of data ...
    https://tietosuoja.fi/en/derogations-for-specific-situations
  9. Processors A processor is an individual or an organisation that processes personal data on behalf of a controller. Processors operate according to the controller’s instructions and under its supervision. The controller determines the purposes and ...
    https://tietosuoja.fi/en/processors
  10. Frequently asked questions about search engines How do I request that a search result be erased from a search engine? Contact the search engine directly to request the erasure of a search result. Out of the search engines, at least Google and Bing...
    https://tietosuoja.fi/en/faq-search-engines
  11. Data protection officers A data protection officer is an expert within the organisation, who monitors the processing of personal data and provides advice on compliance with data protection regulations. The data protection officer monitors complian...
    https://tietosuoja.fi/en/data-protection-officers
  12. Scientific research and data protection Taking care of data protection builds trust in research subjects and is a requirement for the success of any study. It is essential to plan the processing of personal data for its entire lifespan before the ...
    https://tietosuoja.fi/en/scientific-research-and-data-protection
  13. Frequently asked questions about the internet Is the controller entitled to publish personal data from its personal data file on its website? Personal data stored in a personal data file may only be published on the internet with the consent of th...
    https://tietosuoja.fi/en/faq-internet
  14. Purpose limitation The purpose of processing personal data must be planned and defined clearly before the start of processing. Personal data may only be collected and processed for a specific and lawful purpose. The data may not be processed in a ...
    https://tietosuoja.fi/en/purpose-limitation
  15. Rights of the data subject When a controller processes personal data, it must take appropriate measures to ensure that the data protection rights of data subjects are fulfilled. Controllers are also required facilitate the exercise of the data sub...
    https://tietosuoja.fi/en/rights-of-the-data-subject
  16. The processing of personal data at the Office of the Data Protection Ombudsman
    https://tietosuoja.fi/en/our-data-protection-policy
  17. Current issues Supreme Administrative Court upholds the administrative fine imposed on Verkkokauppa.com for data protection violations Publication date: 12.6.2026 Deputy Data Protection Ombudsman: individuals must be able to access their credit in...
    https://tietosuoja.fi/en/current-issues
  18. Find out whether the Data Protection Ombudsman can help you What do you want to do? I want to obtain information on the processing of my personal data. I want access to my personal data I want to rectify my personal data. I want to erase my person...
    https://tietosuoja.fi/en/en/find-out-whether-the-data-protection-ombudsman-can-help-you-rights
  19. Choosing the processing basis and ensuring its lawfulness in scientific research As a rule, the controller is free to choose the basis for processing that is most applicable to the implementation of the study. The processing of special categories ...
    https://tietosuoja.fi/en/choosing-the-processing-basis-and-ensuring-its-lawfulness
  20. Controller's legitimate interests The processing of personal data can sometimes be justified due to the legitimate interests of the controller or a third party. The use of legitimate interests as a basis for processing requires particularly carefu...
    https://tietosuoja.fi/en/controller-s-legitimate-interests
  21. Lecture requests The Office of the Data Protection Ombudsman’s experts can be invited to give lectures at training events held by stakeholders and other organisations. As a rule, such lectures are subject to a fee. The fees are based on the Act on...
    https://tietosuoja.fi/en/lecture-requests
  22. Accountability in scientific research The controller must be prepared to demonstrate that data protection regulations have been taken into account in the study. Researchers must document the implementation of data-protection principles and other p...
    https://tietosuoja.fi/en/accountability-in-scientific-research
  23. European cooperation The Office of the Data Protection Ombudsman is an active member of the European Data Protection Board (EDPB). The EDPB promotes cooperation between European data protection authorities and the consistent application of data pr...
    https://tietosuoja.fi/en/european-cooperation
  24. Defining the research scheme and purpose for processing personal data Processing personal data for purposes of scientific research must comply with the requirement of purpose limitation. The purpose of processing personal data must be planned and ...
    https://tietosuoja.fi/en/defining-the-research-scheme-and-purpose-for-processing-personal-data
  25. Declaration of Data Protection Officer Purpose of processing The purpose of processing the personal data of Data Protection Officers is to enable communication between the supervisory authority and the Data Protection Officers of controllers and p...
    https://tietosuoja.fi/en/declaration-of-data-protection-officer
  26. Duties of the Data Protection Ombudsman supervising compliance with data protection legislation and other laws concerning the processing of personal data promoting awareness of the risks, rules, safeguards, obligations and rights related to the pr...
    https://tietosuoja.fi/en/duties
  27. Data breach notification Purpose of processing If a personal data breach can cause a risk to the rights and freedoms of natural persons, the supervisory authority must be notified. In Finland, the Office of the Data Protection Ombudsman functions ...
    https://tietosuoja.fi/en/data-breach-notification
  28. Data protection principles The data protection principles must always be observed when processing personal data . The controller must also be able to demonstrate the effective implementation of the data protection principles in the processing of p...
    https://tietosuoja.fi/en/data-protection-principles
  29. 17.1.2023 | The Deputy Data Protection Ombudsman has issued a reprimand to the libraries of the cities of Helsinki, Espoo, Vantaa and Kauniainen for infringements of data protection legislation in the processing of personal data. The websites of the Capital Region's Helmet libraries have used tracking technologies that may have conveyed data on, for example, the books and other materials searched for by users to third parties. Personal data has also been unlawfully transferred to the United States.
    https://tietosuoja.fi/en/-/deputy-data-protection-ombudsman-issues-reprimand-for-conveying-library-search-information-to-us-based-google
  30. Office of the Data Protection Ombudsman The Office of the Data Protection Ombudsman safeguards your data protection rights The Data Protection Ombudsman is a national supervisory authority which supervises the compliance with data protection legis...
    https://tietosuoja.fi/en/office-of-the-data-protection-ombudsman
  31. Minimisation of data Personal data may only be processed when necessary for the purposes of the processing. The personal data being processed must be appropriate , i.e. data that can be used to fulfil a specified purpose of processing relevant , i...
    https://tietosuoja.fi/en/minimisation-of-data
  32. Risk assessment and data protection planning Controllers have a responsibility to assess the risks relating to the processing of personal data every time they are about to process personal data. A risk assessment allows controllers to plan the ste...
    https://tietosuoja.fi/en/risk-assessment-and-data-protection-planning
  33. Storage limitation Personal data may only be stored for as long as necessary for the purposes of processing. The controller must plan and be able to justify the storage time of the personal data. The storage times of personal data must also be doc...
    https://tietosuoja.fi/en/storage-limitation
  34. Lifespan of personal data processing, data protection principles and the protection of data in scientific research If processing of personal data is necessary for the implementation of the study, the lifespan of the processing must be planned from...
    https://tietosuoja.fi/en/lifespan-of-personal-data-processing-data-protection-principles-and-the-protection-of-data
  35. Codes of Conduct Codes of conduct are sector-specific guidelines on the application of data protection legislation. They are intended to help organisations comply with data protection requirements with concrete and practical instructions. By commi...
    https://tietosuoja.fi/en/codes-of-conduct
  36. Binding corporate rules Binding Corporate Rules (BCR) refer to common binding rules on the transfer of personal data to third countries within companies in the same group of undertakings or group of enterprises engaged in a joint economic activity...
    https://tietosuoja.fi/en/binding-corporate-rules
  37. Notification to the Data Protection Ombudsman Concerning your rights Data protection rights help you manage your data. If you would like to exercise your rights, first contact the company or organisation that is processing your data, i.e. the cont...
    https://tietosuoja.fi/en/notification-to-the-data-protection-ombudsman
  38. Transfers of personal data out of the European Economic Area Transferring personal data out of the EEA requires an appropriate basis for the transfer and compliance with the other requirements imposed by data protection legislation. This page desc...
    https://tietosuoja.fi/en/transfers-of-personal-data-out-of-the-eea
  39. 10.7.2026 | ANNUAL REPORT OF THE OFFICE OF THE DATA PROTECTION OMBUDSMAN OF FINLAND 2025 ANNUAL REPORT OF THE OFFICE OF THE DATA PROTECTION OMBUDSMAN OF FINLAND 2025 3 Contents The Office of the Data Protection Ombudsman safeguards the rights and freedoms of ...
    https://tietosuoja.fi/documents/6927448/267659444/TSV%20Annual%20Report%202025%20saavutettava.pdf/2f0bc5fe-b5bd-f5cd-6110-cca70019fede?t=1783669724217
  40. List compiled by the Office of the Data Protection Ombudsman of processing operations which require data protection impact assessment (DPIA) Updated 21.12.2018 Article 35 (1) GDPR requires a DPIA when the processing activity is likely to result in...
    https://tietosuoja.fi/en/list-of-processing-operations-which-require-dpia