Search

Your search for 'health' returned 82 results
Fess search
  1. Frequently asked questions about health care Rectifying patient records How can I rectify my patient records? If there are errors in your patient records, you can ask for their rectification. The rectification request is made to the health care un...
    https://tietosuoja.fi/en/faq-health-care
  2. Frequently asked questions on data protection and the coronavirus What does health data mean? Health data refers to information about an individual’s health, diseases, disability or treatment. Health data belongs to the special categories of perso...
    https://tietosuoja.fi/en/coronavirus-covid-19
  3. Frequently asked questions about working life What personal data on employees and job applicants can an employer process? The employer may only process personal data that is directly necessary with regard to the employee's employment relationship,...
    https://tietosuoja.fi/en/faq-working-life
  4. Processing of special categories of personal data As a rule, the processing of personal data belonging to special categories is prohibited. Such data reveals the person’s ethnic origin political opinions religion or philosophical beliefs trade uni...
    https://tietosuoja.fi/en/processing-of-special-categories-of-personal-data
  5. This section provides answers to common questions.
    https://tietosuoja.fi/en/frequently-asked-questions
  6. Telephone guidance Our telephone guidance service provides general guidance and support in matters involving data protection and lets you know if the case requires more detailed investigation and processing at our Office. In the first instance, tr...
    https://tietosuoja.fi/en/telephone-guidance
  7. Impact assessment Impact assessments are designed to identify, evaluate and control risks involved in the processing of personal data. They are designed to be a continuous process for identifying and controlling risks. Impact assessments must be c...
    https://tietosuoja.fi/en/impact-assessments
  8. Find out whether the Data Protection Ombudsman can help you Is the violation you have noticed related to The processing of personal data The publicity or confidentiality of a document The actions of authorities in your case The confidentiality of ...
    https://tietosuoja.fi/en/find-out-whether-the-data-protection-ombudsman-can-help-you-violation
  9. When is the processing of personal data permitted? Legal bases for processing personal data The processing of personal data always requires a legal basis, which must be determined before the start of processing. Once the processing of personal dat...
    https://tietosuoja.fi/en/when-is-the-processing-of-personal-data-permitted
  10. Frequently asked questions about personal identity code Is it permitted to ask for the personal identity code when a guest checks into a hotel? Yes. According to the Act on Accommodation and Food Service Activities (308/2006), an accommodation pro...
    https://tietosuoja.fi/en/faq-personal-identity-code
  11. Right of access Data subjects have the right to receive confirmation from the controller on whether or not the controller is processing personal data that concerns them. The data subjects thus have the opportunity to evaluate and ensure the legali...
    https://tietosuoja.fi/en/right-of-access
  12. Choosing the processing basis and ensuring its lawfulness in scientific research As a rule, the controller is free to choose the basis for processing that is most applicable to the implementation of the study. The processing of special categories ...
    https://tietosuoja.fi/en/choosing-the-processing-basis-and-ensuring-its-lawfulness
  13. Accuracy of data The personal data being processed must be accurate and up to date. Inaccurate personal data must be rectified or erased without delay. The controller must confirm the accuracy of the personal data being kept by it. The verificatio...
    https://tietosuoja.fi/en/accuracy-of-data
  14. Processors A processor is an individual or an organisation that processes personal data on behalf of a controller. Processors operate according to the controller’s instructions and under its supervision. The controller determines the purposes and ...
    https://tietosuoja.fi/en/processors
  15. Automated decision-making and profiling What does profiling mean? Profiling means the automated processing of personal data for evaluating the personal aspects of an individual. In particular, profiling refers to the analysis or prediction of aspe...
    https://tietosuoja.fi/en/automated-decision-making-and-profiling
  16. The Digital Services Act and powers of the Data Protection Ombudsman in the monitoring of online platforms The EU Digital Services Act (DSA) imposes obligations on digital service providers, such as online platforms, to improve the transparency an...
    https://tietosuoja.fi/en/digital-services-act
  17. Regulation on political advertising and the powers of the Data Protection Ombudsman The EU regulation on the transparency and targeting of political advertising sets out rules on how political advertising may be targeted. The Data Protection Ombud...
    https://tietosuoja.fi/en/regulation-on-political-advertising
  18. Data protection for children and youth A lot of information called personal data is collected on you when you use the internet, social media or the apps on your phone, or play video games. Personal data is also collected for your hobbies and at sc...
    https://tietosuoja.fi/en/children-s-data-protection
  19. Processing involving several EU countries If your organisation operates in more than one EU country, you need to find out which country’s supervisory authority you are meant to deal with. This data protection authority is called the lead superviso...
    https://tietosuoja.fi/en/processing-involving-several-eu-countries
  20. Guidelines of the European Data Protection Board The European Data Protection Board (EDPB) is responsible for the uniform application of the EU's General Data Protection Regulation and the Data Protection Directive applying to police and criminal ...
    https://tietosuoja.fi/en/guidelines-of-the-european-data-protection-board
  21. Frequently asked questions about phone calls Are individuals allowed to record their own telephone conversations? Citizens have the right to record telephone calls in which they are the caller or receiver. Finland’s Constitution gives the right to...
    https://tietosuoja.fi/en/faq-phone-calls
  22. Data Act and powers of the Data Protection Ombudsman The EU Data Act (DA) sets out how data generated by connected products can be shared. Most of the regulation became applicable on 12 September 2025. The Office of the Data Protection Ombudsman m...
    https://tietosuoja.fi/en/data-act
  23. Frequently asked questions about elections On this page, you will find answers to frequently asked questions about election advertising and data protection. See also: Frequently asked questions about direct marketing Information on the EU regulati...
    https://tietosuoja.fi/en/faq-elections
  24. Right to data portability The data subject has the right to receive the personal data that he or she has provided to a controller in a structured, commonly used and machine-readable format and, if desired, transmit that data to another controller....
    https://tietosuoja.fi/en/right-to-data-portability
  25. Frequently asked questions about genealogy What personal data can I process for purposes of genealogical research? The General Data Protection Regulation (GDPR) does not specify what personal data may be processed for genealogical purposes. The es...
    https://tietosuoja.fi/en/faq-genealogy
  26. EU digital and data regulation The EU's digital and data regulation facilitate the movement of data within the EU, create clear and fair rules for data use and promote compliance with privacy, data protection and competition rules. Digital and dat...
    https://tietosuoja.fi/en/eu-digital-and-data-regulation
  27. Electronic services at the Office of the Data Protection Ombudsman Instituting a case electronically The Office of the Data Protection Ombudsman uses electronic forms implemented with the Government ICT Centre's (Valtori) Turvalomake (Secure Form)...
    https://tietosuoja.fi/en/electronic-services-at-our-office
  28. Carrying out an impact assessment 1. Draw up a systematic description of the envisaged processing operations and the purposes of the processing Draw up a description of the nature, scope, context and purposes of the processing of personal data. Id...
    https://tietosuoja.fi/en/carrying-out-an-impact-assessment
  29. Consent of the data subject Consent is one possible legal basis for processing personal data. Consent gives the data subjects the opportunity to monitor the processing of their personal data and influence it by withdrawing their consent. Requireme...
    https://tietosuoja.fi/en/consent-of-the-data-subject
  30. Lifespan of personal data processing, data protection principles and the protection of data in scientific research If processing of personal data is necessary for the implementation of the study, the lifespan of the processing must be planned from...
    https://tietosuoja.fi/en/lifespan-of-personal-data-processing-data-protection-principles-and-the-protection-of-data
  31. Right to erasure In certain cases, the data subject has the right to have the controller erase data concerning him or her without undue delay. This right is also known as the right to be forgotten. The controller is obligated to erase the personal...
    https://tietosuoja.fi/en/right-to-erasure
  32. 10.7.2026 | ANNUAL REPORT OF THE OFFICE OF THE DATA PROTECTION OMBUDSMAN OF FINLAND 2025 ANNUAL REPORT OF THE OFFICE OF THE DATA PROTECTION OMBUDSMAN OF FINLAND 2025 3 Contents The Office of the Data Protection Ombudsman safeguards the rights and freedoms of ...
    https://tietosuoja.fi/documents/6927448/267659444/TSV%20Annual%20Report%202025%20saavutettava.pdf/2f0bc5fe-b5bd-f5cd-6110-cca70019fede?t=1783669724217
  33. Processors’ responsibilities Processors are governed by the General Data Protection Regulation if they are established in an EU Member State they are not established in an EU Member State but their personal data processing activities relate to the...
    https://tietosuoja.fi/en/processors-responsibilities
  34. Data protection in the development and use of AI systems These pages have information on the requirements arising from data protection legislation that should be taken into account when artificial intelligence (AI) systems are developed and used. ...
    https://tietosuoja.fi/en/ai-systems-and-data-protection
  35. Annual report 2025 The annual report describes the year's most important data protection events, supervision measures in different sectors and presents the key figures for the Office's operations. Annual report of the Office of the Data Protection...
    https://tietosuoja.fi/en/annual-report-2025
  36. 6.8.2025 | We have put together answers to frequently asked questions about alcohol and drug testing in the workplace on our website. We also added information on what employers should consider when collecting personal data from employees and job applicants.
    https://tietosuoja.fi/en/-/we-completed-the-guidance-on-the-alcohol-testing-of-employees-and-processing-of-personal-data-in-the-workplace
  37. 16.10.2025 | The Office of the Data Protection Ombudsman has assessed the practices of the Government ICT Centre Valtori, the Digital and Population Data Services Agency and the Tax Administration in the use of cloud services in 2022. The assessment found that an adequate level of data protection had not been ensured for personal data transferred to the United States through the cloud service provided by Valtori.
    https://tietosuoja.fi/en/-/office-of-the-data-protection-ombudsman-government-cloud-services-must-meet-data-protection-requirements
  38. 4.6.2025 | The Sanctions Board of the Office of the Data Protection Ombudsman issued a EUR 1,100,000 administrative fine against the pharmacy company Yliopiston Apteekki because of data protection shortcomings found in the pharmacy’s online shop related to the use of tracking services. Data on the customers’ use of the online shop was leaked to tracking service companies through the website’s analytics tools and tracking technology.
    https://tietosuoja.fi/en/-/yliopiston-apteekki-fined-for-online-shop-data-protection-shortcomings
  39. 25.6.2025 | ANNUAL REPORT OF THE OFFICE OF THE DATA PROTECTION OMBUDSMAN OF FINLAND 2024 ANNUAL REPORT OF THE OFFICE OF THE DATA PROTECTION OMBUDSMAN OF FINLAND 2024 3 Contents The Office of the Data Protection Ombudsman safeguards the rights and freedoms of ...
    https://tietosuoja.fi/documents/6927448/242571942/3%20TSV%20Annual%20Report%202024%20saavutettava.pdf/c49babc0-430a-77ec-aea2-95d5cebd2885?t=1750846070262
  40. 12.1.2024 | Internet platforms and other digital services will have new obligations when the application of the EU's Digital Services Act begins on 17 February 2024. The purpose of the new Act is to reduce illegal content and increase the transparency of services.
    https://tietosuoja.fi/en/-/new-obligations-for-digital-operators-the-goal-is-safer-and-more-open-online-services
  41. 31.7.2023 | ANNUAL REPORT OF THE OFFICE OF THE DATA PROTECTION OMBUDSMAN 2022 ANNUAL REPORT OF THE OFFICE OF THE DATA PROTECTION OMBUDSMAN 2022 3 Contents The Office of the Data Protection Ombudsman safeguards the rights and freedoms of individuals with regar...
    https://tietosuoja.fi/documents/6927448/169954657/TSV+Annual+Report+2022.pdf/503a9466-d89c-8e63-016f-cfc018d8bc70/TSV+Annual+Report+2022.pdf?t=1690784905744
  42. 12.3.2020 | Data protection legislation does not restrict public health measures or the prevention of infectious diseases, but must still be taken into account in the processing of personal data. Public and private organisations have begun taking measures to limit the spread of coronavirus COVID-19 and mitigate its effects. Some of these measures may involve the processing of personal data.
    https://tietosuoja.fi/en/-/tietosuoja-ja-koronaviruksen-leviamisen-hillitseminen
  43. 22.4.2020 | The European Data Protection Board’s guidelines concern the processing of health data for purposes of scientific research related to the COVID-19 disease and the use of location data and contact tracing applications.
    https://tietosuoja.fi/en/-/euroopan-tietosuojaneuvosto-antoi-ohjeita-koronapandemiaan-liittyvasta-henkilotietojen-kasittelysta
  44. 15.2.2022 | The Office of the Data Protection Ombudsman will participate in a coordinated enforcement action of the European Data Protection Board along with 22 other supervisory authorities. The purpose of the action is to investigate use of cloud-based services in the public sector. The action of the EDPB was launched on 15 February.
    https://tietosuoja.fi/en/-/the-office-of-the-data-protection-ombudsman-launches-an-investigation-into-the-use-of-cloud-based-services-in-the-public-sector-as-a-part-of-a-coordinated-action-of-european-supervisory-authorities
  45. 22.4.2020 | The European Data Protection Board’s guidelines concern the processing of health data for purposes of scientific research related to the COVID-19 disease and the use of location data and contact tracing applications.
    https://tietosuoja.fi/en/-/european-data-protection-board-issues-guidelines-on-personal-data-processing-related-to-the-coronavirus-pandemic
  46. 23.3.2020 | The Office of the Data Protection Ombudsman has compiled answers to the most common questions concerning data protection and the coronavirus epidemic. The FAQ is published on the Office’s website, and its topics include the publication of coronavirus statistics, the definition of health data and the employer’s confidentiality obligation. The FAQ will be updated as required.
    https://tietosuoja.fi/en/-/tietosuojavaltuutetun-toimisto-julkaisi-vastauksia-kysymyksiin-koronaviruksesta-ja-tietosuojasta
  47. 7.12.2022 | ANNUAL REPORT OF THE OFFICE OF THE DATA PROTECTION OMBUDSMAN 2021 2 ANNUAL REPORT OF THE OFFICE OF THE DATA PROTECTION OMBUDSMAN 2021 3 Contents The Office of the Data Protection Ombudsman safeguards the rights and freedoms of individuals with reg...
    https://tietosuoja.fi/documents/6927448/142648058/1+TSV+Annual+Report+2021.pdf/e2a55868-8c05-cf3f-f794-6f5d28aada13?t=1670403332297
  48. Anvisningar av Europeiska dataskyddsstyrelsen Europeiska dataskyddsstyrelsen ansvarar för en harmoniserad tillämpning inom Europeiska Unionen av EU:s allmänna dataskyddsförordning och dataskyddsdirektivet, som gäller för polis- och strafrättsmyndi...
    https://tietosuoja.fi/sv/anvisningar-av-europeiska-dataskyddsstyrelsen
  49. Euroopan tietosuojaneuvoston ohjeet Euroopan tietosuojaneuvosto vastaa EU:n yleisen tietosuoja-asetuksen ja poliisi- ja rikosoikeusviranomaisia koskevan tietosuojadirektiivin yhdenmukaisesta soveltamisesta Euroopan unionissa. Tietosuojaneuvosto ju...
    https://tietosuoja.fi/euroopan-tietosuojaneuvoston-ohjeet
  50. 13.8.2024 | ANNUAL REPORT OF THE OFFICE OF THE DATA PROTECTION OMBUDSMAN 2023 ANNUAL REPORT OF THE OFFICE OF THE DATA PROTECTION OMBUDSMAN 2023 3 Contents The Office of the Data Protection Ombudsman safeguards the rights and freedoms of individuals with regar...
    https://tietosuoja.fi/documents/6927448/218217127/TSV%20Annual%20Report%202023.pdf/a28dce67-82b2-61d2-f565-071180b61a0c?t=1723542778239
  51. 19.5.2023 | Adopted Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679 Version 2.0 4 June 2019 Adopted 2 Version history Version 2.0 4 June 2019 Adoption of the Guidelines after public consultation Version 1.0 12 February 20...
    https://tietosuoja.fi/documents/6927448/8316711/edpb_guidelines_201901_v2.0_codesofconduct_en.pdf/1bfbe4c4-1b50-4010-02c6-e403273e7ff0?t=1684499604192
  52. 20.6.2019 | Adopted Guidelines 1/2018 on certification and identifying certification criteria in accordance with Articles 42 and 43 of the Regulation Version 3.0 4 June 2019 2 Adopted Version history Version 3.0 4 June 2019 Inclusion of Annex 2 (version 2.0 o...
    https://tietosuoja.fi/documents/6927448/8316711/Guidelines_1_2018_certification_criteria_en.pdf/c1d683da-2be4-6d63-b34b-113108eeed77/Guidelines_1_2018_certification_criteria_en.pdf.pdf?t=1561032081000
  53. 31.5.2018 | ARTICLE 29 DATA PROTECTION WORKING PARTY This Working Party was set up under Article 29 of Directive 95/46/EC. It is an independent European advisory body on data protection and privacy. Its tasks are described in Article 30 of Directive 95/46/EC ...
    https://tietosuoja.fi/documents/6927448/8316711/Guidelines+on+Data+Protection+Officers/64ea8efe-10c8-4c45-aba1-890414fd6b34?t=1527768610000
  54. 20.6.2019 | Adopted Guidelines 1/2018 on certification and identifying certification criteria in accordance with Articles 42 and 43 of the Regulation Version 3.0 4 June 2019 2 Adopted Version history Version 3.0 4 June 2019 Inclusion of Annex 2 (version 2.0 o...
    https://tietosuoja.fi/documents/6927448/8316711/Guidelines_1_2018_certification_criteria_en.pdf/c1d683da-2be4-6d63-b34b-113108eeed77?t=1561032081000
  55. 31.5.2018 | ARTICLE 29 DATA PROTECTION WORKING PARTY This Working Party was set up under Article 29 of Directive 95/46/EC. It is an independent European advisory body on data protection and privacy. Its tasks are described in Article 30 of Directive 95/46/EC ...
    https://tietosuoja.fi/documents/6927448/8316711/Guidelines+on+Data+Protection+Officers/64ea8efe-10c8-4c45-aba1-890414fd6b34/Guidelines+on+Data+Protection+Officers.pdf?t=1527768610000
  56. 6.8.2018 | ARTICLE 29 DATA PROTECTION WORKING PARTY This Working Party was set up under Article 29 of Directive 95/46/EC. It is an independent European advisory body on data protection and privacy. Its tasks are described in Article 30 of Directive 95/46/EC ...
    https://tietosuoja.fi/documents/6927448/8316711/Guidelines+on+Data+Protection+Impact+Assessment.pdf/def06c04-03f9-4505-99d2-709243ef2d35?t=1533551916000
  57. 20.6.2019 | Adopted Guidelines 1/2018 on certification and identifying certification criteria in accordance with Articles 42 and 43 of the Regulation Version 3.0 4 June 2019 2 Adopted Version history Version 3.0 4 June 2019 Inclusion of Annex 2 (version 2.0 o...
    https://tietosuoja.fi/documents/6927448/8316711/Guidelines_1_2018_certification_criteria_en.pdf/c1d683da-2be4-6d63-b34b-113108eeed77/Guidelines_1_2018_certification_criteria_en.pdf.pdf/Guidelines_1_2018_certification_criteria_en.pdf.pdf?t=1561032081000
  58. 17.12.2020 | ANNUAL REPORT OFFICE OF THE DATA PROTECTION OMBUDSMAN 2019 2 ANNUAL REPORT OFFICE OF THE DATA PROTECTION OMBUDSMAN 2019 3 Contents The Office of the Data Protection Ombudsman safeguards the rights and freedoms of individuals with regard to the pro...
    https://tietosuoja.fi/documents/6927448/10717840/Annual+Report+Office+of+the+Data+Protection+Ombudsman+2019.pdf/ddfeac75-fe58-851e-6036-eab0a326cbd9?t=1608209824830
  59. 16.7.2019 | Adopted 1 Recommendation 01/2019 on the draft list of the European Data Protection Supervisor regarding the processing operations subject to the requirement of a data protection impact assessment (Article 39.4 of Regulation (EU) 2018/1725) Adopted...
    https://tietosuoja.fi/documents/6927448/8316711/Recommendation+1_2019_dpia_list/1badb0e4-e6e1-c46d-3572-8e8ea3b22b70?t=1563277198000
  60. 19.5.2023 | Page 1 of 16 Adopted - After public consultation Guidelines 04/2021 on Codes of Conduct as tools for transfers Version 2.0 Adopted on 22 February 2022 Page 2 of 16 Adopted - After public consultation Version history Version 2.0 22 February 2022 Ad...
    https://tietosuoja.fi/documents/6927448/8316711/edpb_guidelines_codes_conduct_transfers_after_public_consultation_en_1.pdf/bfcfe5a5-f926-f6ca-2dd3-f7f611239135?t=1684499603006