Skip to the content
Global Data RulesData governance rules, country by country

Finland

Part of the European Union, so bloc-wide rules apply here too. Checked yesterday.

The answer

Depends on your industryWork: HighEnforcement: Active

Finland has no general law forcing data to stay in the country. Personal data leaves under the ordinary European rules. Three walls override that: the state security network must sit in Finland, gambling systems must sit in Finland from July 2027, and health records released for research never leave a locked-down environment. The privacy regulator fines companies but cannot fine the government.

Data governance in Finland

The eight things that decide how you handle data about people in Finland. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. A company with no office in Finland is still caught if it offers goods or services to people in Finland or watches what they do here. That comes from the European privacy law, which applies directly. There is no revenue or headcount threshold to duck under. A company based outside Europe must name a representative inside Europe, and that representative does not have to be in Finland.

High confidenceBloc rulesNational rulesAppoint a local representative

Where the data is allowed to live

In general yes, on the normal European terms: inside Europe data moves freely, and it can go outside Europe once you have an approved country, a standard contract or another recognised safeguard. Finland adds no general residency rule of its own. But four areas are different. Gambling systems must be in Finland. The state's secure government network must be in Finland. Health and social records released for research stay locked inside an audited environment. And surveying the Finnish seabed or filming defence sites from the air needs a permit first.

High confidenceDepends on your industryAllowlistOnline gamingGovernmentHealth and social careMapping and locationTelecomsFinance

Sending data out of the country

The model is an approved-destinations list, run by the European Commission and not by Finland. Sending personal data to an approved country needs nothing extra. Sending it anywhere else needs a safeguard: usually the European standard contract, or approved group-wide rules for a company group. You are also expected to check whether local surveillance law in the destination undermines that paperwork. Finland adds no separate national permission step.

High confidenceAllowlistOfficial 'this country is safe' decisionStandard contract clausesApproved group rulesExplicit consentNeeded for a contract

The regulator, and whether it actually acts

The Office of the Data Protection Ombudsman, and it genuinely works. Anu Talus was reappointed Ombudsman for a five-year term starting on 1 November 2025. Fines are decided by a three-person panel of the Ombudsman and the deputy ombudsmen, and it has been issuing them: 1.8 million euros against a bank in September 2025, roughly two million US dollars. Separately, Finland's transport and communications agency runs cyber-incident supervision, the financial supervisor covers banks and insurers, and the police board licenses gambling.

High confidenceActiveRegulator

How long you must keep it — and when to delete it

Both directions apply. The floor: company accounts and books must be kept ten years after the financial year ends, and receipts and business correspondence six years. Telephone and internet connection records that certain operators keep for the police run 12 months, 9 months or 6 months depending on the service. The ceiling: personal data must be deleted once the purpose you collected it for has ended, and there is no fixed number for that. Where the two clash, the specific keeping duty in the sector law wins for as long as it lasts, and deletion follows once it expires.

High confidenceKeep data for a minimum periodDelete data after a periodKeep logs

If something goes wrong

Count three clocks, not one. If personal data leaks, you have 72 hours to tell the Data Protection Ombudsman. If you are a company covered by Finland's cybersecurity law, you have 24 hours for a first alert about a significant incident, 72 hours for a fuller report, and one month for the final report. If you are a telecoms operator, you must tell the transport and communications agency immediately about a significant security breach. The same event can start all three.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What catches people out

Five things that cost people their weekend. One: a child can agree to an online service at 13 in Finland, not 16, so a single European age setting will be wrong here. Two: employee monitoring is a criminal matter, not just a fine, and you must run a staff consultation before you switch it on. Three: you cannot fix an employment data problem with the worker's consent, because the necessity test cannot be waived. Four: the government cannot be fined, so if a Finnish public body loses your data your remedy is an order and a court claim, not a penalty. Five: surveying the seabed or filming defence sites from the air without a permit is a crime.

High confidenceGet a parent's consent for childrenCriminal liabilityEmployee dataChildren's dataMapping and survey data

What's changing next

Three dated changes. From January 2027 European rules ban cloud providers from charging customers to move their data out. On 1 July 2027 Finland's gambling monopoly ends, licences start, and the rule that gambling systems must sit in Finland begins to bite. And a bill put to parliament on 9 April 2026 would let the privacy regulator fine public bodies for the first time, at lower maximum amounts than for companies, with courts, parliamentary offices and national security bodies left out.

High confidenceProposedMake switching cloud provider possible

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries4 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Online gaming

Rahapelilaki

Act of parliament · 10/2026, 46 § (Pelijärjestelmien ja arvontalaitteiden sijainti)

Partly in forceNo — it stays put

Finland's new gambling law ends the state monopoly and opens a licensed market on 1 July 2027. Licensed operators must keep their gaming systems and draw devices in Finland, with two narrow escape routes: a supervision agreement between regulators, or remote verification access for the Finnish supervisor.

In force since 1 March 2026But only enforceable from 1 July 2027

Enforced by National Police Board

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence
Government

Laki julkisen hallinnon turvallisuusverkkotoiminnasta

Act of parliament · 10/2015, 5 §

In forceNo — it stays put

Finland's hardest localisation rule. The public administration security network that carries top state leadership and safety-critical communications must be state-owned or state-held, physically in Finland, with services produced, administered and supervised in Finland.

Enforced by Ministry of Finance

Transfer model: Not allowed

High confidence
Health and social care

Laki sosiaali- ja terveystietojen toissijaisesta käytöstä

Act of parliament · 552/2019

In forceNo — it stays put

Finnish health and social records reused for research, statistics, teaching, development or authority supervision are never handed over as a file. They are opened inside an audited secure environment, and only aggregated or approved results are exported.

Enforced by Health and Social Data Permit Authority

Transfer model: Approval each time · Accepted routes: Government sign-off needed

Medium confidence

Applies to every company2 rules

These bind you whatever business you are in, once the country's rules reach you.

Tietosuojalaki

Act of parliament · 1050/2018

In forceYes, with paperwork

Finland's national law on top of the European rules. It sets the age of digital consent at 13, gives fine decisions to a three-person panel, and bars fines against state bodies, councils, independent public-law institutions, parliamentary offices, the President's office and the national churches.

In force since 1 January 2019

Enforced by Office of the Data Protection Ombudsman

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules

High confidence

Kyberturvallisuuslaki

Act of parliament · 124/2025

In forceYes — store it anywhere

Finland's implementation of the European network and information security directive. It imposes no data localisation, but it does impose the tightest routine clocks in the Finnish stack: 24 hours for a first incident alert and 72 hours for a follow-up.

In force since 8 April 2025

Enforced by Finnish Transport and Communications Agency, including the National Cyber Security Centre

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Applies across the European Union1 rule

Written once for the whole bloc, and in force in every member country.

Yleinen tietosuoja-asetus (EU) 2016/679

Directly binding regulation · Regulation (EU) 2016/679

In forceYes, with paperwork

The European privacy rules apply in Finland directly. They do not require data to stay in Europe. They set conditions on data leaving: an approved destination, a standard contract, approved group rules or a narrow exception, plus a check on surveillance law in the destination.

In force since 24 May 2016But only enforceable from 25 May 2018

Enforced by Office of the Data Protection Ombudsman

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims, Someone's life is at risk, Important public interest

High confidence

Who you would hear from

  • Tietosuojavaltuutetun toimisto

    General data protection supervision; fines decided by a sanctions board of the Ombudsman and the deputy ombudsmen

    Fully staffed and issuing decisions. Anu Talus was reappointed Ombudsman for five years from 1 November 2025. A EUR 1.8 million fine against S-Bank was published on 10 September 2025 and administrative courts reviewed fine decisions in 2026. It cannot fine public authorities.

  • Liikenne- ja viestintävirasto Traficom / Kyberturvallisuuskeskus

    Telecoms regulation, network security, cyber incident reporting under the Cybersecurity Act

    Operating the NIS2 register of covered entities and receiving incident reports since 8 April 2025.

  • Finanssivalvonta

    Banks, payment institutions, insurers, securities markets; outsourcing and cloud supervision

  • Findata (Sosiaali- ja terveysalan tietolupaviranomainen)

    Data permits and secure processing environments for secondary use of health and social data

    Issuing data permits and binding regulations on secure processing environments, including regulation 1/2022.

  • Poliisihallitus

    Gambling licensing and supervision until 30 June 2027

    Had received 50 gambling licence applications by 8 June 2026.

  • Lupa- ja valvontavirasto

    Merged licensing and supervision agency operating since 1 January 2026; takes over gambling supervision on 1 July 2027

    The agency exists and operates, but its gambling powers do not start until 1 July 2027. Its own permanent web domain was not verified, so the link is to the government's announcement.

  • Valtiovarainministeriö

    Public administration information management, cloud policies, security network governance

  • Oikeusministeriö

    Data protection legislation and the 2026 proposal to extend fines to the public sector

  • Työsuojeluviranomaiset

    Enforce the Act on the Protection of Privacy in Working Life jointly with the Data Protection Ombudsman

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • Whether a secure processing environment used for Finnish health and social data may be physically located outside Finland or outside Europe

    The statute and the permit authority's published pages describe audit and access requirements but we could not open a text stating a geographic limit. The rule is therefore recorded as a control wall, not a location wall, at medium confidence.

  • Whether the transport and communications agency's technical regulations require retained telecoms records to be stored in Finland or in Europe

    The statute leaves technical implementation to the operator and to the agency's regulations. We read the statute but not every technical regulation issued under it, so a location condition could exist one level down.

  • The stage that the April 2026 bill on public-sector fines has reached in parliament as at 18 August 2026

    We confirmed the proposal and its content from the Ministry of Justice and the parliamentary proposals register, but not its current committee stage or a vote. It is recorded as proposed with no legal effect.

  • Maximum fine amounts proposed for public bodies in that bill

    The Ministry says they would be clearly lower than for the private sector but did not publish a figure in the announcement we could open.

  • How narrowly the gambling supervisor will read the two exceptions to the Finland-location rule for gaming systems

    No supervisory guidance has been published, and supervision moves to a different agency on 1 July 2027, so early practice is unknown.

  • Whether any separate Finnish rule restricts exporting seabed depth data or detailed mapping data once a survey permit has been granted

    We confirmed the permit requirement and its criminal sanction, but not a separate export restriction. Permit conditions are set case by case and are not published.

  • Any localisation requirement in Finnish banking, payments, insurance or securities rules

    None found, checked 18 August 2026. The financial supervisor's outsourcing rules require notification and supervisory access rather than location. We reviewed the general outsourcing rules but not every sector-specific regulation.

60-day cadence: three moving parts. The gambling localisation rule bites on 1 July 2027 with supervision changing hands the same day, the public-sector fines bill is live in parliament, and the telecoms retention regime is openly under review after European court rulings.

Freshness and refresh

Freshness

Checked yesterday — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Put this next to another country

Finland versus

Compare

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.