Search

Your search for 'agreements' returned 59 results
Fess search
  1. Transfer bases for authorities and the public sector Authorities and public organisations can transfer personal data to international organisations or the public bodies of third countries based on a European Commission decision on the adequacy of ...
    https://tietosuoja.fi/en/transfer-bases-for-authorities-and-the-public-sector
  2. Binding corporate rules Binding Corporate Rules (BCR) refer to common binding rules on the transfer of personal data to third countries within companies in the same group of undertakings or group of enterprises engaged in a joint economic activity...
    https://tietosuoja.fi/en/binding-corporate-rules
  3. Children's data protection rights Every child and young person has the right to data protection. If you have questions about how your personal data are used, you can contact the Office of the Data Protection Ombudsman. Your personal data include f...
    https://tietosuoja.fi/en/children-s-data-protection
  4. Demonstrate your compliance with data protection regulations Compliance with the provisions of the General Data Protection Regulation (GDPR) is required when processing personal data. Accountability means that the controller must be able to demons...
    https://tietosuoja.fi/en/accountability
  5. Telephone guidance Our telephone guidance service provides general guidance and support in matters involving data protection and lets you know if the case requires more detailed investigation and processing at our Office. In the first instance, tr...
    https://tietosuoja.fi/en/telephone-guidance
  6. Processing of special categories of personal data As a rule, the processing of personal data belonging to special categories is prohibited. Such data reveals the person’s ethnic origin political opinions religion or philosophical beliefs trade uni...
    https://tietosuoja.fi/en/processing-of-special-categories-of-personal-data
  7. Roles and responsibilities for processing personal data in scientific research A research project can involve a variety of parties in different roles. Personal data may be processed for research purposes by one or more research organizations, pers...
    https://tietosuoja.fi/en/roles-and-responsibilities-for-processing-personal-data
  8. Carrying out an impact assessment 1. Draw up a systematic description of the envisaged processing operations and the purposes of the processing Draw up a description of the nature, scope, context and purposes of the processing of personal data. Id...
    https://tietosuoja.fi/en/carrying-out-an-impact-assessment
  9. Impact assessment Impact assessments are designed to identify, evaluate and control risks involved in the processing of personal data. They are designed to be a continuous process for identifying and controlling risks. Impact assessments must be c...
    https://tietosuoja.fi/en/impact-assessments
  10. Consent of the data subject Consent is one possible legal basis for processing personal data. Consent gives the data subjects the opportunity to monitor the processing of their personal data and influence it by withdrawing their consent. Requireme...
    https://tietosuoja.fi/en/consent-of-the-data-subject
  11. Frequently asked questions about working life What personal data on employees and job applicants can an employer process? The employer may only process personal data that is directly necessary with regard to the employee's employment relationship,...
    https://tietosuoja.fi/en/faq-working-life
  12. Frequently asked questions about health care Rectifying patient records How can I rectify my patient records? If there are errors in your patient records, you can ask for their rectification. The rectification request is made to the health care un...
    https://tietosuoja.fi/en/faq-health-care
  13. 25.4.2025 | The Data Protection Ombudsman has approved two applications by Nokia for binding corporate rules (so-called BCRs). BCRs are legally binding rules for the transfer of personal data within a group of enterprises. They allow companies in the same group to transfer personal data between each other outside the EU and EEA countries.
    https://tietosuoja.fi/en/-/data-protection-ombudsman-confirms-nokia-s-bcr-rules-for-international-data-transfers
  14. Brexit and the transfer of personal data to the UK When the transition period for the withdrawal from the EU ended, the United Kingdom lost all its rights and obligations as a Member State. Due to the withdrawal from the EU, data protection regula...
    https://tietosuoja.fi/en/brexit-and-the-transfer-of-personal-data-to-the-uk
  15. Processors A processor is an individual or an organisation that processes personal data on behalf of a controller. Processors operate according to the controller’s instructions and under its supervision. The controller determines the purposes and ...
    https://tietosuoja.fi/en/processors
  16. Safeguards to supplement transfer tools The level of protection for personal data must be essentially equivalent to that guaranteed within the EU when transferring data to international organisations and third countries outside the European Econom...
    https://tietosuoja.fi/en/safeguards-to-supplement-transfer-tools
  17. When is the processing of personal data permitted? Legal bases for processing personal data The processing of personal data always requires a legal basis, which must be determined before the start of processing. Once the processing of personal dat...
    https://tietosuoja.fi/en/when-is-the-processing-of-personal-data-permitted
  18. Registry You can enquire after matters concerning instituting and pending a case from the registry of the Office of the Data Protection Ombudsman. This kind of enquiries are for example how should a case be sent to the Office of the Data Protectio...
    https://tietosuoja.fi/en/registry
  19. If you would like to have your personal data transferred to another controller In certain situations, you have the right to receive your data and transfer them to another service provider. The right to data portability makes it easier for you to c...
    https://tietosuoja.fi/en/if-you-would-like-to-have-your-personal-data-transferred-to-another-controller
  20. The right to rectification Data subjects have the right to demand the rectification of inaccurate personal data concerning them and to have incomplete personal data completed. How quickly is the controller required to reply to the data subject’s r...
    https://tietosuoja.fi/en/right-to-rectification