Skip to the content
Global Data RulesData governance rules, country by country

Finland

Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Finland — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: HighEnforcement: Active

Finland has no general law forcing data to stay in the country. Personal data leaves under the ordinary European rules. Three things override that. The state security network must sit in Finland. Gambling systems must sit in Finland from July 2027. And health records released for research never leave a locked-down environment. The privacy regulator fines companies but cannot fine the government.

Data governance in Finland

The eight things that decide how you handle data about people in Finland. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. A company with no office in Finland is still covered if it offers goods or services to people in Finland. The same applies if it watches what people do here. That comes from the European privacy law, which applies directly. There is no revenue or staff-count level below which you are free. A company based outside Europe must name a representative inside Europe. That representative does not have to be in Finland.

What you have to do here:
Appoint a representative

Where the data is allowed to live

Yes in general, on the normal European terms. Inside Europe data moves freely. It can go outside Europe once you have an approved country, a standard contract or another recognised protection. Finland adds no general rule of its own about data staying in the country. But four areas are different. Gambling systems must be in Finland. The state's secure government network must be in Finland. Health and social records released for research stay locked inside an audited environment. And surveying the Finnish seabed, or filming defence sites from the air, needs a permit first.

What to do: Check your own industry against the restricted list before you pick a hosting region.

Sending data out of the country

You can only send data freely to approved countries. The European Commission keeps that list, not Finland. Sending personal data to an approved country needs nothing extra. Sending it anywhere else needs a protection in place. That is usually the European standard contract, or approved group-wide rules for a company group. You are also expected to check whether surveillance law in the destination country undermines that paperwork. Finland adds no separate national permission step.

Ways to send data out:
Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Explicit consent · Needed for a contract

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

The regulator, and whether it actually acts

The Office of the Data Protection Ombudsman, and it works. Anu Talus was reappointed Ombudsman for a five-year term starting on 1 November 2025. Fines are decided by a three-person panel of the Ombudsman and the deputy ombudsmen. It has been issuing them. In September 2025 it fined a bank 1.8 million euros, roughly two million US dollars. Other bodies enforce too. Finland's transport and communications agency supervises cyber incidents. The financial supervisor covers banks and insurers. The police board licenses gambling.

How long you must keep it — and when to delete it

There are both minimum and maximum keep-times. The minimums: company accounts and books must be kept ten years after the financial year ends. Receipts and business correspondence must be kept six years. Telephone and internet connection records that certain operators keep for the police run 12 months, 9 months or 6 months, depending on the service. The maximum: personal data must be deleted once the purpose you collected it for has ended. There is no fixed number for that. Where the two clash, the specific keep-time in the industry law wins for as long as it lasts. You delete once it expires.

What you have to do here:
Keep data for a minimum period · Delete data after a period · Keep logs

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

There are three separate deadlines. If personal data leaks, you have 72 hours to tell the Data Protection Ombudsman. If you are a company covered by Finland's cybersecurity law, you have 24 hours for a first alert about a significant incident. Then 72 hours for a fuller report. Then one month for the final report. If you are a telecoms operator, you must tell the transport and communications agency immediately about a significant security breach. The same event can start all three.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things cost people their weekend. One: a child can agree to an online service at 13 in Finland, not 16. A single European age setting will be wrong here. Two: employee monitoring is a criminal matter, not just a fine. You must run a staff consultation before you switch it on. Three: you cannot fix an employment data problem with the worker's consent. The necessity test cannot be waived. Four: the government cannot be fined. If a Finnish public body loses your data, your remedy is an order and a court claim, not a penalty. Five: surveying the seabed, or filming defence sites from the air, without a permit is a crime.

What you have to do here:
Get a parent's consent for children
What it costs if you get it wrong:
Criminal liability

What's changing next

Three dated changes. From January 2027 European rules ban cloud providers from charging customers to move their data out. On 1 July 2027 Finland's gambling monopoly ends and licences start. The rule that gambling systems must sit in Finland begins then too. And a bill put to parliament on 9 April 2026 would let the privacy regulator fine public bodies for the first time. The maximum amounts would be lower than for companies. Courts, parliamentary offices and national security bodies would be left out.

What you have to do here:
Make switching cloud provider possible

What to do: Diarise 1 July 2027 — that is the date this changes.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries4 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Online gaming

Online gaming data rules

Official name: Rahapelilaki · 10/2026, 46 § (Pelijärjestelmien ja arvontalaitteiden sijainti) · Act of parliament

Partly in forceNo — it stays put

Finland's new gambling law ends the state monopoly and opens a licensed market on 1 July 2027. Licensed operators must keep their gaming systems and draw devices in Finland. There are two narrow ways out. Either the regulators sign a supervision agreement. Or the Finnish supervisor gets remote access to check the system.

In force since 1 March 2026In force now, but not enforced until 1 July 2027

That is a long gap: the duty is real law today, but no penalty can follow until 1 July 2027. A contract you sign can still hold you to it from day one — and government contracts often do.

Enforced by National Police Board

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Government

Telecoms rules

Official name: Laki julkisen hallinnon turvallisuusverkkotoiminnasta · 10/2015, 5 § · Act of parliament

In forceNo — it stays put

Finland's strictest rule about where data must sit. The public administration security network carries top state leadership and safety-critical communications. It must be owned or held by the state. It must be physically in Finland. Its services must be produced, administered and supervised in Finland.

Enforced by Ministry of Finance

How this country controls where data goes: Not allowed

Health and social care

Health and social care data must stay in the country

Official name: Laki sosiaali- ja terveystietojen toissijaisesta käytöstä · 552/2019 · Act of parliament

In forceNo — it stays put

Finnish health and social records reused for research, statistics, teaching, development or official supervision are never handed over as a file. They are opened inside an audited secure environment. Only summary or approved results are exported.

Enforced by Health and Social Data Permit Authority

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Not fully verified — see “What we're not sure about” below.

Applies to every company2 rules

These bind you whatever business you are in, once the country's rules reach you.

Data rules

Official name: Tietosuojalaki · 1050/2018 · Act of parliament

In forceYes, with paperwork

Finland's national law on top of the European rules. It sets the age of digital consent at 13. It gives fine decisions to a three-person panel. And it bars fines against state bodies, councils, independent public-law institutions, parliamentary offices, the President's office and the national churches.

In force since 1 January 2019

Enforced by Office of the Data Protection Ombudsman

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules

Breach reporting rules

Official name: Kyberturvallisuuslaki · 124/2025 · Act of parliament

In forceYes — store it anywhere

Finland's version of the European network and information security directive. It does not force data to stay in any country. But it sets the tightest routine deadlines in Finnish law: 24 hours for a first incident alert, and 72 hours for a follow-up.

In force since 8 April 2025

Enforced by Finnish Transport and Communications Agency, including the National Cyber Security Centre

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Applies across the European Union1 rule

Written once for the whole bloc, and in force in every member country.

Europe's main privacy law

Official name: Yleinen tietosuoja-asetus (EU) 2016/679 · Regulation (EU) 2016/679 · Directly binding regulation

In forceYes, with paperwork

The European privacy rules apply in Finland directly. They do not require data to stay in Europe. They set conditions on data leaving. You need an approved destination, a standard contract, approved group rules or a narrow exception. You also need a check on surveillance law in the destination country.

In force since 24 May 2016Enforced from 25 May 2018

Enforced by Office of the Data Protection Ombudsman

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims, To save someone’s life, Important public interest

Who you would hear from

  • Tietosuojavaltuutetun toimisto

    General data protection supervision; fines decided by a sanctions board of the Ombudsman and the deputy ombudsmen

    Fully staffed and issuing decisions. Anu Talus was reappointed Ombudsman for five years from 1 November 2025. A 1.8 million euro fine against S-Bank was published on 10 September 2025. Administrative courts reviewed fine decisions in 2026. It cannot fine public authorities.

  • Liikenne- ja viestintävirasto Traficom / Kyberturvallisuuskeskus

    Telecoms regulation, network security, cyber incident reporting under the Cybersecurity Act

    Running the register of organisations covered by the European Union's second network and information security directive. It has been receiving incident reports since 8 April 2025.

  • Finanssivalvonta

    Banks, payment institutions, insurers, securities markets; outsourcing and cloud supervision

  • Findata (Sosiaali- ja terveysalan tietolupaviranomainen)

    Data permits and secure processing environments for secondary use of health and social data

    Issuing data permits and binding rules on secure environments, including regulation 1/2022.

  • Poliisihallitus

    Gambling licensing and supervision until 30 June 2027

    Had received 50 gambling licence applications by 8 June 2026.

  • Lupa- ja valvontavirasto

    Merged licensing and supervision agency operating since 1 January 2026; takes over gambling supervision on 1 July 2027

    The agency exists and operates. Its gambling powers do not start until 1 July 2027. We could not verify its own permanent web address, so the link goes to the government's announcement.

  • Valtiovarainministeriö

    Public administration information management, cloud policies, security network governance

  • Oikeusministeriö

    Data protection legislation and the 2026 proposal to extend fines to the public sector

  • Työsuojeluviranomaiset

    Enforce the Act on the Protection of Privacy in Working Life jointly with the Data Protection Ombudsman

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • Whether a secure processing environment used for Finnish health and social data may be physically located outside Finland or outside Europe

    We could not confirm whether the secure research environment must be physically in Finland. The law and the permit authority's published pages describe audit and access requirements. We could not find a text setting a geographic limit. So we record this as a control on access, not a rule about location, at medium confidence.

  • Whether the transport and communications agency's technical regulations require retained telecoms records to be stored in Finland or in Europe

    We could not confirm whether a location condition sits in the technical rules. The law leaves technical detail to the operator and to the agency's own regulations. We read the law but not every technical regulation issued under it.

  • The stage that the April 2026 bill on public-sector fines has reached in parliament as at 18 August 2026

    We could not confirm how far the public-sector fines bill has got. We confirmed the proposal and its content from the Ministry of Justice and the parliamentary proposals register. We did not confirm its current committee stage or any vote. We record it as proposed, with no legal effect.

  • Maximum fine amounts proposed for public bodies in that bill

    We could not confirm the maximum fines proposed for public bodies. The Ministry says they would be clearly lower than for private companies. It did not publish a figure in the announcement we could open.

  • How narrowly the gambling supervisor will read the two exceptions to the Finland-location rule for gaming systems

    We could not confirm how the gambling location rule will be applied. No supervisory guidance has been published. Supervision also moves to a different agency on 1 July 2027, so early practice is unknown.

  • Whether any separate Finnish rule restricts exporting seabed depth data or detailed mapping data once a survey permit has been granted

    We could not confirm whether seabed and aerial survey data faces a separate export restriction. We confirmed the permit requirement and the criminal penalty behind it. Permit conditions are set case by case and are not published.

  • Any localisation requirement in Finnish banking, payments, insurance or securities rules

    We found no financial rule forcing data to stay in the country, checked 18 August 2026. The financial supervisor's outsourcing rules require notice and supervisor access rather than a location. We reviewed the general outsourcing rules but not every industry-specific regulation.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.