Search

Your search for 'data protection officers' returned 223 results
Fess search
  1. Have you been affected by a personal data breach? This page contains instructions for people who have been affected by a personal data breach. If you have been affected by a personal data breach, first check what data about you could have been dis...
    https://tietosuoja.fi/en/have-you-been-affected-by-a-personal-data-breach
  2. Destruction, anonymisation or archiving of data at the conclusion of research When a study ends, the controller must ensure that data is appropriately destroyed, anonymised or archived. Data protection regulations specify a lifespan for personal d...
    https://tietosuoja.fi/en/destruction-anonymisation-or-archiving-of-data
  3. If you would like to have your data erased In certain situations, you have the right to request the controller to erase the personal data concerning you. Personal data refers to information by which you can be identified. A company, authority or c...
    https://tietosuoja.fi/en/if-you-would-like-to-have-all-of-your-data-erased
  4. 12.6.2026 | The Supreme Administrative Court has enforced the decision of the Office of the Data Protection Ombudsman and the Sanctions Board of the Data Protection Ombudsman concerning the operations of Verkkokauppa.com Plc. The company violated data protection provisions by failing to specify the storage periods for customer account data.
    https://tietosuoja.fi/en/-/supreme-administrative-court-upholds-the-administrative-fine-imposed-on-verkkokauppa.com-for-data-protection-violations
  5. Roles and responsibilities for processing personal data in scientific research A research project can involve a variety of parties in different roles. Personal data may be processed for research purposes by one or more research organizations, pers...
    https://tietosuoja.fi/en/roles-and-responsibilities-for-processing-personal-data
  6. Transfers of personal data out of the European Economic Area Transferring personal data out of the EEA requires an appropriate basis for the transfer and compliance with the other requirements imposed by data protection legislation. This page desc...
    https://tietosuoja.fi/en/transfers-of-personal-data-out-of-the-eea
  7. Defining the research scheme and purpose for processing personal data Processing personal data for purposes of scientific research must comply with the requirement of purpose limitation. The purpose of processing personal data must be planned and ...
    https://tietosuoja.fi/en/defining-the-research-scheme-and-purpose-for-processing-personal-data
  8. The right to obtain information on the processing of personal data Data subjects have the right to be informed of the collection and processing of their personal data. The processing of personal data shall be done in a transparent manner. Data sub...
    https://tietosuoja.fi/en/the-right-to-obtain-information-on-the-processing-of-personal-data
  9. What rights do data subjects have in different situations? Not all of the rights of the data subject can be exercised in all situations, depending on factors such as the basis for the processing of personal data. Some of the rights of the data sub...
    https://tietosuoja.fi/en/what-rights-do-data-subjects-have-in-different-situations
  10. Have you been notified of the processing of your personal data? You have the right to obtain information on the purpose for which your personal data is collected and how it is processed. A company, authority or corporation processing your personal...
    https://tietosuoja.fi/en/have-you-been-notified-of-the-processing-of-your-personal-data
  11. Erasure of data and restriction of processing when the controller is a competent authority In certain situations, the competent authority must erase data concerning you at its own initiative. Personal data must be erased if processing is not neces...
    https://tietosuoja.fi/en/erasure-of-data-and-restriction-of-processing
  12. If you would like to have your personal data transferred to another controller In certain situations, you have the right to receive your data and transfer them to another service provider. The right to data portability makes it easier for you to c...
    https://tietosuoja.fi/en/if-you-would-like-to-have-your-personal-data-transferred-to-another-controller
  13. The right to obtain information on the processing of personal data by a competent authority You have the right to obtain information on the purpose for which a competent authority collects your personal data and on how it is processed. The authori...
    https://tietosuoja.fi/en/right-to-obtain-information-on-the-processing-of-personal-data
  14. 19.3.2026 | This year, European data protection authorities will investigate how well organisations comply with the transparency and information obligations related to personal data processing. Data protection authorities from 25 countries across Europe will take part in the action.
    https://tietosuoja.fi/en/-/the-office-of-the-data-protection-ombudsman-to-investigate-the-transparency-of-personal-data-processing-as-part-of-eu-wide-action
  15. When your personal data are processed in the Schengen Information System or the Visa Information System The Schengen Information System (SIS) and the joint Visa Information System (VIS) of the EU countries are information exchange systems used as ...
    https://tietosuoja.fi/en/when-your-personal-data-are-processed-in-the-schengen-information-system-or-the-visa-information-system
  16. Derogating from the rights of data subjects in the context of scientific or historical research or for statistical purposes Chapter III of the General Data Protection Regulation provides for the rights of the data subject applied to the processing...
    https://tietosuoja.fi/en/derogating-from-the-rights-of-data-subjects
  17. 16.10.2025 | The Office of the Data Protection Ombudsman has assessed the practices of the Government ICT Centre Valtori, the Digital and Population Data Services Agency and the Tax Administration in the use of cloud services in 2022. The assessment found that an adequate level of data protection had not been ensured for personal data transferred to the United States through the cloud service provided by Valtori.
    https://tietosuoja.fi/en/-/office-of-the-data-protection-ombudsman-government-cloud-services-must-meet-data-protection-requirements
  18. 30.3.2026 | The Deputy Data Protection Ombudsman has determined that the credit information company Dun & Bradstreet Finland’s practice of allowing individuals to only check their credit information for free once per year is not compliant with data protection legislation. Several deficiencies were also found in the company’s practices for responding to personal data requests.
    https://tietosuoja.fi/en/-/deputy-data-protection-ombudsman-individuals-must-be-able-to-access-their-credit-information-for-free
  19. 30.1.2026 | On Thursday 29 January 2026, the Government appointed Heljä-Tuulia Pihamaa, Master of Laws, to the post of Deputy Data Protection Ombudsman for the next five-year term of office, starting on 22 March. Pihamaa has been serving as Deputy Data Protection Ombudsman since March 2021.
    https://tietosuoja.fi/en/-/helja-tuulia-pihamaa-continues-as-deputy-data-protection-ombudsman
  20. 25.4.2025 | The Data Protection Ombudsman has approved two applications by Nokia for binding corporate rules (so-called BCRs). BCRs are legally binding rules for the transfer of personal data within a group of enterprises. They allow companies in the same group to transfer personal data between each other outside the EU and EEA countries.
    https://tietosuoja.fi/en/-/data-protection-ombudsman-confirms-nokia-s-bcr-rules-for-international-data-transfers