Finland
Part of the European Union, so bloc-wide rules apply here too. Checked yesterday.
The answer
Finland has no general law forcing data to stay in the country. Personal data leaves under the ordinary European rules. Three walls override that: the state security network must sit in Finland, gambling systems must sit in Finland from July 2027, and health records released for research never leave a locked-down environment. The privacy regulator fines companies but cannot fine the government.
Data governance in Finland
The eight things that decide how you handle data about people in Finland. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. A company with no office in Finland is still caught if it offers goods or services to people in Finland or watches what they do here. That comes from the European privacy law, which applies directly. There is no revenue or headcount threshold to duck under. A company based outside Europe must name a representative inside Europe, and that representative does not have to be in Finland.
Layer 1 is Regulation (EU) 2016/679, whose Article 3 sets the territorial reach and whose Article 27 sets the representative duty. Layer 2 is the Finnish Data Protection Act 1050/2018, which supplements rather than replaces it. Finland's separate Cybersecurity Act 124/2025, which implements the EU NIS2 directive, reaches further than most people expect: its section 6 catches a cloud provider, data centre operator, managed service provider, online marketplace, search engine or social platform whose EU main establishment or EU representative is in Finland, and also catches an operator with no EU establishment and no EU representative at all if it simply offers services in Finland. Employment is a third layer: the Act on the Protection of Privacy in Working Life 759/2004 applies to anyone employing people in Finland, whatever the employer's nationality.
Sources
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation), Articles 3 and 27
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceFinlex, Ministry of Justice open data serviceKyberturvallisuuslaki 124/2025, 6 § (lainkäyttövalta ja alueellisuus)
opendata.finlex.fi
“Jos toimija ei ole sijoittautunut Euroopan unionin jäsenvaltioon tai asettanut NIS 2 -direktiivin 26 artiklan 3 kohdassa tarkoitettua nimettyä edustajaa ja toimija tarjoaa palveluita Suomessa, toimija kuuluu tämän lain soveltamisalaan.”
Link checked 18 August 2026
- Official sourceFinlexTietosuojalaki 1050/2018 (Finnish Data Protection Act)
finlex.fi
Link checked 18 August 2026
Where the data is allowed to live
In general yes, on the normal European terms: inside Europe data moves freely, and it can go outside Europe once you have an approved country, a standard contract or another recognised safeguard. Finland adds no general residency rule of its own. But four areas are different. Gambling systems must be in Finland. The state's secure government network must be in Finland. Health and social records released for research stay locked inside an audited environment. And surveying the Finnish seabed or filming defence sites from the air needs a permit first.
Sector by sector, verified on 18 August 2026. GAMBLING — data must stay in the country from 1 July 2027. Section 46 of the new Gambling Act 10/2026 says the gaming systems and draw devices of an exclusive-right licence holder and of a gambling licence holder must be located in Finland. Two escape hatches: the operator is licensed in another state whose regulator has signed a supervision agreement with the Finnish supervisor, or the operator lets the Finnish supervisor verify the system remotely. Fifty licence applications were already in by 8 June 2026. GOVERNMENT SECURITY NETWORK — data must stay in the country. Section 5 of Act 10/2015 requires the equipment rooms and equipment directly connected to the public administration security network to be owned or held by the Finnish state, to be located in Finland, for the services to be produced in Finland, and for administration and supervision to be carried out in Finland. There is a narrow exception where operationally necessary. HEALTH, SECONDARY USE — data must stay in the country in practice. Under Act 552/2019 an individual-level dataset released for research, statistics, teaching, development or authority supervision is not handed over as a file. It is opened inside a secure processing environment run by the data permit authority or by an audited third party, and only results come out. HEALTH, DIRECT CARE — data can leave with paperwork. Patient records can be shared with a foreign care provider through Finland's national contact point with the patient's consent. No storage-location rule was found. MAPPING AND SEABED — data can leave with paperwork. The Territorial Surveillance Act 755/2000 makes it an offence to survey the shape or composition of the seabed in Finnish waters, to run low-altitude airborne geophysical surveys, or to record defence-significant sites from the air, without a permit. Once a permit exists, the data itself is governed by the permit's conditions. BANKING, PAYMENTS, INSURANCE, SECURITIES — data can leave with paperwork. No localisation found. The Finnish Financial Supervisory Authority's outsourcing rules require advance notification of material outsourcing and continuous supervisory access, and for outsourcing outside Europe they require you to show the host country's law lets the supervisor get the information it needs. The EU digital operational resilience rules sit on top and also impose no localisation. TELECOMS — data can leave with paperwork. Call and connection records kept for the police under Act 917/2014 must be retained for 12, 9 or 6 months depending on the service. No provision was found requiring those records to be held in Finland or in Europe, which is a real difference from some neighbours. GOVERNMENT CLOUD GENERALLY — data can leave with paperwork. Finland's public administration cloud policies, last updated in 2024, are guidance and not law. Security-classified material is the constraint: the higher classification levels need approved environments rather than ordinary public cloud. EDUCATION, DEFENCE PROCUREMENT, ARTIFICIAL INTELLIGENCE — no separate Finnish localisation rule found, checked 18 August 2026, confidence medium.
Sources
- Official sourceFinlex, Ministry of Justice open data serviceRahapelilaki 10/2026, 46 § — Pelijärjestelmien ja arvontalaitteiden sijainti
opendata.finlex.fi
“Yksinoikeustoimiluvanhaltijan ja rahapelitoimiluvanhaltijan pelijärjestelmien ja arvontalaitteiden on sijaittava Suomessa.”
Link checked 18 August 2026
- Official sourceFinlex, Ministry of Justice open data serviceLaki julkisen hallinnon turvallisuusverkkotoiminnasta 10/2015, 5 §
opendata.finlex.fi
“De utrustningsutrymmen och den utrustning som direkt hör samman med säkerhetsnätet ska finnas i Finland och tjänsterna ska produceras i Finland.”
Link checked 18 August 2026
- Official sourceFinlex, Ministry of Justice open data serviceLaki sosiaali- ja terveystietojen toissijaisesta käytöstä 552/2019, 20 § — tietoturvallinen käyttöympäristö
opendata.finlex.fi
Link checked 18 August 2026
- Official sourceFinlex, Ministry of Justice open data serviceAluevalvontalaki 755/2000, 12–14 § ja 44 § — luvanvarainen merenpohjan ja ilmasta tapahtuva tutkiminen
opendata.finlex.fi
“Suomen aluevesillä ei saa ilman lupaa harjoittaa merenpohjan tai sen sisustan muodon, rakenteen tai koostumuksen selvittämistä geologisilla tai geofyysisillä tutkimuksilla.”
Link checked 18 August 2026
- Official sourceFinanssivalvonta (Financial Supervisory Authority)FIN-FSA Regulations and guidelines 1/2012, Outsourcing (version in force from 1 September 2023)
finanssivalvonta.fi
“In case of cross-border outsourcing to a non-EEA state, clarification of whether the host country's legal framework will permit the FIN-FSA to obtain information needed to supervise.”
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2018/1807 on the free flow of non-personal data
eur-lex.europa.eu
Link checked 18 August 2026
Sending data out of the country
The model is an approved-destinations list, run by the European Commission and not by Finland. Sending personal data to an approved country needs nothing extra. Sending it anywhere else needs a safeguard: usually the European standard contract, or approved group-wide rules for a company group. You are also expected to check whether local surveillance law in the destination undermines that paperwork. Finland adds no separate national permission step.
The list is populated and current as at 18 August 2026: Andorra, Argentina, Brazil (new, 26 January 2026, mutual), Canada for commercial organisations, Faroe Islands, Guernsey, Isle of Man, Israel, Japan, Jersey, New Zealand, South Korea (first review confirmed 23 July 2026), Switzerland, the United Kingdom (renewed 19 December 2025, running to 2031), Uruguay, the United States for organisations self-certified under the EU-US Data Privacy Framework, and the European Patent Organisation. None has been withdrawn or suspended. The 2021 standard contractual clauses remain the operative set; the promised extra clauses for importers already directly caught by the European rules are still not adopted. Binding corporate rules remain available. The narrow one-off exceptions are not a basis for routine or bulk transfers. The US framework is under pressure: a court challenge is on appeal, and on 31 July 2026 the European Data Protection Board formally asked the Commission to examine whether recent changes in the United States affect the decision's validity. It has not been suspended. One Finnish quirk: the Data Protection Ombudsman may ask the Helsinki Administrative Court to refer a question to the EU court about whether an approval decision is lawful.
Sources
- Official sourceEuropean CommissionAdequacy decisions — current list
commission.europa.eu
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionCommission Implementing Decision (EU) 2021/914 — standard contractual clauses
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceFinlex, Ministry of Justice open data serviceTietosuojalaki 1050/2018, 23 § — komission päätökset
opendata.finlex.fi
Link checked 18 August 2026
The regulator, and whether it actually acts
The Office of the Data Protection Ombudsman, and it genuinely works. Anu Talus was reappointed Ombudsman for a five-year term starting on 1 November 2025. Fines are decided by a three-person panel of the Ombudsman and the deputy ombudsmen, and it has been issuing them: 1.8 million euros against a bank in September 2025, roughly two million US dollars. Separately, Finland's transport and communications agency runs cyber-incident supervision, the financial supervisor covers banks and insurers, and the police board licenses gambling.
Enforcement rating the regulator is active, not aggressive: the regulator issues a steady stream of decisions and its fines are appealed to and reviewed by the administrative courts, but the volume and the values are moderate by European standards. Evidence of a working system: the Supreme Administrative Court has ruled on the fine framework and upheld a fine against the postal operator; on 1 June 2026 the Helsinki Administrative Court annulled a 1.1 million euro fine against University Pharmacy while upholding most of the underlying findings. There is a large hole. Finnish law says a fine cannot be imposed on state authorities, state enterprises, municipal authorities, independent public-law institutions, parliamentary offices, the President's office or the two national churches. So the public sector is supervised, ordered and criticised, but not fined. The government proposed on 9 April 2026 to change this. Cybersecurity supervision is split by sector, with the Finnish Transport and Communications Agency and its National Cyber Security Centre as the main body. Gambling is licensed and supervised by the National Police Board until 30 June 2027, after which it passes to the new Finnish Licensing and Supervisory Agency.
Sources
- Official sourceOffice of the Data Protection OmbudsmanS-Bank fined EUR 1.8 million for a data security vulnerability, 10 September 2025
tietosuoja.fi
Link checked 18 August 2026
- Official sourceOffice of the Data Protection OmbudsmanHelsinki Administrative Court decision on the University Pharmacy fine, 1 June 2026
tietosuoja.fi
Link checked 18 August 2026
- Official sourceOffice of the Data Protection OmbudsmanAnu Talus reappointed Data Protection Ombudsman for five years from 1 November 2025
tietosuoja.fi
Link checked 18 August 2026
- Official sourceFinlex, Ministry of Justice open data serviceTietosuojalaki 1050/2018, 24 § — sanctions board and the public-sector exemption
opendata.finlex.fi
“Seuraamusmaksua ei voida määrätä valtion viranomaisille, valtion liikelaitoksille, kunnallisille viranomaisille, itsenäisille julkisoikeudellisille laitoksille, eduskunnan virastoille, tasavallan presidentin kanslialle.”
Link checked 18 August 2026
- Official sourcePoliisihallitus (National Police Board)National Police Board — 50 gambling licence applications received, 8 June 2026
poliisi.fi
Link checked 18 August 2026
How long you must keep it — and when to delete it
Both directions apply. The floor: company accounts and books must be kept ten years after the financial year ends, and receipts and business correspondence six years. Telephone and internet connection records that certain operators keep for the police run 12 months, 9 months or 6 months depending on the service. The ceiling: personal data must be deleted once the purpose you collected it for has ended, and there is no fixed number for that. Where the two clash, the specific keeping duty in the sector law wins for as long as it lasts, and deletion follows once it expires.
Accounting Act 1336/1997 chapter 2 sets both the retention periods and Finland's only general storage-location style rule, and it is a light one: the records must be kept so that an authority or an auditor can inspect them from Finland without undue delay. That permits storage abroad with a working access path, and does not require a copy in Finland. Retained telecoms records under Act 917/2014 section 157 are 12 months for mobile telephony and text messaging, 9 months for internet access, and 6 months for internet telephony, counted from the communication event, and the content of messages and web-browsing records are excluded. Under the secondary-use health law, access logs for a data permit are deleted or archived 12 years after the permit ends. The general deletion duty comes from the European storage-limitation principle, which Finland does not put a number on.
Sources
- Official sourceFinlex, Ministry of Justice open data serviceKirjanpitolaki 1336/1997, 2 luku 9 ja 10 § — storage and retention of accounting material
opendata.finlex.fi
“Tilinpäätös, kirjanpidot, tositteet ja muu kirjanpitoaineisto on säilytettävä huolellisesti ... siten, että niiden tarkastelu Suomesta käsin on mahdollista viranomaiselle ja tilintarkastajalle ilman aiheetonta viivettä.”
Link checked 18 August 2026
- Official sourceFinlex, Ministry of Justice open data serviceLaki sähköisen viestinnän palveluista 917/2014, 157 § — retention periods for authority purposes
opendata.finlex.fi
“Edellä 2 momentin 1 kohdassa tarkoitettujen palvelujen tietoja on säilytettävä 12 kuukautta, 2 momentin 3 kohdassa tarkoitetun palvelun tietoja 9 kuukautta ja 2 momentin 2 kohdassa tarkoitettujen palvelujen tietoja 6 kuukautta.”
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679, Article 5(1)(e) — storage limitation
eur-lex.europa.eu
Link checked 18 August 2026
If something goes wrong
Count three clocks, not one. If personal data leaks, you have 72 hours to tell the Data Protection Ombudsman. If you are a company covered by Finland's cybersecurity law, you have 24 hours for a first alert about a significant incident, 72 hours for a fuller report, and one month for the final report. If you are a telecoms operator, you must tell the transport and communications agency immediately about a significant security breach. The same event can start all three.
The 24-hour and 72-hour cyber clocks come from the Cybersecurity Act 124/2025 section 11, which implements the EU NIS2 directive and has applied since 8 April 2025. A trust service provider has a shorter version: its follow-up report is due within 24 hours, not 72. If an incident is long-running, an interim report is due within one month of the follow-up report. The telecoms clock is in Act 917/2014 section 275 and is written as 'without delay' rather than as a number of hours, which in practice means faster than 24 hours. The privacy clock is the European 72-hour rule, plus telling affected individuals without undue delay where the risk to them is high. Notifications go to different bodies: the Ombudsman for personal data, the sector's designated supervisor for cyber incidents, and the transport and communications agency for telecoms.
Sources
- Official sourceFinlex, Ministry of Justice open data serviceKyberturvallisuuslaki 124/2025, 11–13 § — incident reporting deadlines
opendata.finlex.fi
“Ensi-ilmoitus on tehtävä 24 tunnin kuluessa merkittävän poikkeaman havaitsemisesta ja jatkoilmoitus 72 tunnin kuluessa merkittävän poikkeaman havaitsemisesta.”
Link checked 18 August 2026
- Official sourceLiikenne- ja viestintävirasto TraficomTraficom — Cybersecurity Act approved, NIS2 obligations from 8 April 2025
traficom.fi
Link checked 18 August 2026
- Official sourceFinlex, Ministry of Justice open data serviceLaki sähköisen viestinnän palveluista 917/2014, 275 § — häiriöilmoitukset
opendata.finlex.fi
“Teleyrityksen on ilmoitettava viipymättä Liikenne- ja viestintävirastolle, jos sen palveluun kohdistuu tai sitä uhkaa merkittävä tietoturvaloukkaus.”
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679, Articles 33 and 34 — breach notification
eur-lex.europa.eu
Link checked 18 August 2026
What catches people out
Five things that cost people their weekend. One: a child can agree to an online service at 13 in Finland, not 16, so a single European age setting will be wrong here. Two: employee monitoring is a criminal matter, not just a fine, and you must run a staff consultation before you switch it on. Three: you cannot fix an employment data problem with the worker's consent, because the necessity test cannot be waived. Four: the government cannot be fined, so if a Finnish public body loses your data your remedy is an order and a court claim, not a penalty. Five: surveying the seabed or filming defence sites from the air without a permit is a crime.
(1) Age 13 comes from the Finnish Data Protection Act 1050/2018 section 5. (2) and (3) come from the Act on the Protection of Privacy in Working Life 759/2004: section 3 says the necessity requirement cannot be departed from with the employee's consent; section 4 says the employer must collect personal data primarily from the employee and needs consent to collect it elsewhere, with narrow exceptions for credit and criminal record checks; collecting employee data falls inside the statutory co-operation procedure; section 24 makes a list of breaches a criminal offence punishable by a fine for the employer or the employer's representative, and points onward to the Criminal Code for the more serious personal data, unlawful access, covert surveillance and breach of confidentiality offences. Section 22 gives enforcement jointly to the occupational safety and health authorities and the Data Protection Ombudsman, which is an unusual double-headed supervisor. (4) is the public-sector exemption in section 24 of the Data Protection Act. (5) is the Territorial Surveillance Act 755/2000 sections 12 to 14 and 44. A sixth, less dramatic one: bulk disclosure of Population Information System data abroad is decided by the population register authority rather than by the recipient's contract.
Sources
- Official sourceFinlex, Ministry of Justice open data serviceTietosuojalaki 1050/2018, 5 § — age limit for information society services
opendata.finlex.fi
“lapsen henkilötietojen käsittely on lainmukaista, jos lapsi on vähintään 13-vuotias.”
Link checked 18 August 2026
- Official sourceFinlex, Ministry of Justice open data serviceLaki yksityisyyden suojasta työelämässä 759/2004, 3, 4, 22 ja 24 §
opendata.finlex.fi
“Tarpeellisuusvaatimuksesta ei voida poiketa työntekijän suostumuksella.”
Link checked 18 August 2026
- Official sourceFinlex, Ministry of Justice open data serviceAluevalvontalaki 755/2000, 44 § — rangaistussäännökset
opendata.finlex.fi
Link checked 18 August 2026
- Official sourceFinlex, Ministry of Justice open data serviceLaki väestötietojärjestelmästä ja Digi- ja väestötietoviraston varmennepalveluista 661/2009, 47 §
opendata.finlex.fi
Link checked 18 August 2026
What's changing next
Three dated changes. From January 2027 European rules ban cloud providers from charging customers to move their data out. On 1 July 2027 Finland's gambling monopoly ends, licences start, and the rule that gambling systems must sit in Finland begins to bite. And a bill put to parliament on 9 April 2026 would let the privacy regulator fine public bodies for the first time, at lower maximum amounts than for companies, with courts, parliamentary offices and national security bodies left out.
Dormant switches to watch, because they can move without a fresh law. First, the location rule for gambling systems has two discretionary escape hatches, and how narrowly the supervisor reads them will decide whether it is a genuine wall or a paperwork step; the supervisor also changes hands on 1 July 2027, from the National Police Board to the new Finnish Licensing and Supervisory Agency, and the new body may read them differently. Second, Finland's rules on keeping telephone and internet records for the police are under review by the Ministry of Transport and Communications following European court rulings; a working paper went out for comment in 2024 and no bill has followed, so the current periods stand but the design is openly unsettled. Third, the exception in the security network law that allows equipment abroad 'where operationally necessary' has no published threshold. Fourth, at European level the US transfer route is under formal scrutiny after the European Data Protection Board wrote to the Commission on 31 July 2026; a suspension there would hit Finnish exporters immediately. The status of the public-sector fines bill in parliament on 18 August 2026 was not confirmed, so treat it as proposed and not as law.
Sources
- Official sourceFinlexGovernment proposal GP 46/2026 — amending the sanctions provisions of the Data Protection Act
finlex.fi
Link checked 18 August 2026
- Official sourceOikeusministeriö (Ministry of Justice)Ministry of Justice — administrative fines to be extended to the public sector, 9 April 2026
oikeusministerio.fi
“Seuraamusmaksuja ei voitaisi määrätä muun muassa tuomioistuimille”
Link checked 18 August 2026
- Official sourceFinlex, Ministry of Justice open data serviceRahapelilaki 10/2026, 106 § — voimaantulo
opendata.finlex.fi
“Tämä laki tulee voimaan 1 päivänä heinäkuuta 2027. Lain 2 ja 9 luku, 43 §:n 3 momentti sekä 44, 57, 63 ja 64 § tulevat voimaan kuitenkin jo 1 päivänä maaliskuuta 2026.”
Link checked 18 August 2026
- Official sourceLiikenne- ja viestintäministeriöMinistry of Transport and Communications — assessment memorandum on retention of electronic communications traffic data
lvm.fi
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2023/2854 (Data Act) — zero cloud switching charges from 12 January 2027
eur-lex.europa.eu
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries4 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Rahapelilaki
Act of parliament · 10/2026, 46 § (Pelijärjestelmien ja arvontalaitteiden sijainti)
Finland's new gambling law ends the state monopoly and opens a licensed market on 1 July 2027. Licensed operators must keep their gaming systems and draw devices in Finland, with two narrow escape routes: a supervision agreement between regulators, or remote verification access for the Finnish supervisor.
Enforced by National Police Board
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the country — from 1 July 2027Gaming systems and draw devices must be in Finland unless the operator is licensed in a state whose regulator has signed a supervision agreement with the Finnish supervisor, or the operator gives the Finnish supervisor remote verification access.
- Register or notifyLicence required. Applications opened in 2026; 50 had been filed by 8 June 2026.
- Appoint a local representativeAn operator with no home or establishment in the European Economic Area must have a representative domiciled in the European Economic Area.
What it costs if you get it wrong
- Loss of your licenceBreach of licence conditions
- Fixed maximum finePenalty payment imposed by the Market Court on the supervisor's application
Sources
- Official sourceFinlex, Ministry of Justice open data serviceRahapelilaki 10/2026, 46 § ja 106 §
opendata.finlex.fi
“Yksinoikeustoimiluvanhaltijan ja rahapelitoimiluvanhaltijan pelijärjestelmien ja arvontalaitteiden on sijaittava Suomessa.”
Link checked 18 August 2026
- Official sourcePoliisihallitusNational Police Board — gambling licence applications, 8 June 2026
poliisi.fi
Link checked 18 August 2026
Laki julkisen hallinnon turvallisuusverkkotoiminnasta
Act of parliament · 10/2015, 5 §
Finland's hardest localisation rule. The public administration security network that carries top state leadership and safety-critical communications must be state-owned or state-held, physically in Finland, with services produced, administered and supervised in Finland.
Enforced by Ministry of Finance
Transfer model: Not allowed
What it makes you do
- Keep the data in the countryEquipment rooms and equipment directly connected to the security network must be in Finland, services must be produced in Finland, and administration and supervision must be carried out in Finland. Equipment may sit abroad only where operationally necessary.
- Hold a security certificateHigh preparedness and high security requirements set in or under law.
Sources
- Official sourceFinlex, Ministry of Justice open data serviceLaki julkisen hallinnon turvallisuusverkkotoiminnasta 10/2015, 5 §
opendata.finlex.fi
“De utrustningsutrymmen och den utrustning som direkt hör samman med säkerhetsnätet ska finnas i Finland och tjänsterna ska produceras i Finland. Administreringen av och tillsynen över utrustningsutrymmena, utrustningen och tjänsteproduktionen ska skötas i Finland.”
Link checked 18 August 2026
- Official sourceValtiovarainministeriö (Ministry of Finance)Ministry of Finance — use of cloud services in public administration (policies updated 2024, guidance not law)
vm.fi
Link checked 18 August 2026
Laki sosiaali- ja terveystietojen toissijaisesta käytöstä
Act of parliament · 552/2019
Finnish health and social records reused for research, statistics, teaching, development or authority supervision are never handed over as a file. They are opened inside an audited secure environment, and only aggregated or approved results are exported.
Enforced by Health and Social Data Permit Authority
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Register or notifyA data permit from the health and social data permit authority is required before any secondary use.
- Keep the data in the countryIndividual-level data is opened inside a secure processing environment run by the permit authority, or by an audited third-party provider, and reached through a secure access service. Only results leave, through a controlled export step.
- Independent auditThird-party secure environments must be assessed against the permit authority's binding requirements, regulation 1/2022.
- Keep logs — 12 yearsUse logs are deleted or archived 12 years after the data permit ends.
What it costs if you get it wrong
- Order to stopWithdrawal of the data permit
Sources
- Official sourceFinlex, Ministry of Justice open data serviceLaki sosiaali- ja terveystietojen toissijaisesta käytöstä 552/2019, 17 ja 20 §
opendata.finlex.fi
“Tietolupaan perustuva tietoaineisto luovutetaan luvansaajan käsiteltäväksi aina 20 §:ssä tarkoitettuun tietoturvalliseen käyttöympäristöön 17 §:ssä tarkoitetun tietoturvallisen käyttöpalvelun välityksellä, ellei siitä ole muodostettu aggregoitua tilastotietoa.”
Link checked 18 August 2026
- Official sourceFindata, Health and Social Data Permit AuthorityFindata — binding regulations, including regulation 1/2022 on requirements for other providers' secure processing environments
findata.fi
Link checked 18 August 2026
Laki sähköisen viestinnän palveluista
Act of parliament · 917/2014, 157, 158 ja 275 §
Named Finnish telecoms operators must keep connection records for the police for 12, 9 or 6 months depending on the service. No provision was found requiring those records to be held in Finland or in Europe, so the constraint is retention and security rather than location.
Enforced by Finnish Transport and Communications Agency, including the National Cyber Security Centre
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What it makes you do
- Keep data for a minimum period — 1 yearMobile telephony and text messaging records, for named operators designated by the Ministry of the Interior.
- Keep data for a minimum period — 9 monthsInternet access service records.
- Keep data for a minimum period — 6 monthsInternet telephony records. Message content and web-browsing records are excluded from the duty.
- Report cyber incidentsSignificant security breaches must be reported to the transport and communications agency without delay.
- Secure the data
What it costs if you get it wrong
- Criminal liability: FineElectronic communications data protection infringement, for example unlawful handling of traffic or location data
Sources
- Official sourceFinlex, Ministry of Justice open data serviceLaki sähköisen viestinnän palveluista 917/2014, 157, 158, 275 ja 347 §
opendata.finlex.fi
“Säilytysvelvollinen yritys päättää tietojen säilyttämisen teknisestä toteuttamisesta.”
Link checked 18 August 2026
- Official sourceLiikenne- ja viestintäministeriöMinistry of Transport and Communications — review of the traffic data retention regime after EU court case law
lvm.fi
Link checked 18 August 2026
Applies to every company2 rules
These bind you whatever business you are in, once the country's rules reach you.
Tietosuojalaki
Act of parliament · 1050/2018
Finland's national law on top of the European rules. It sets the age of digital consent at 13, gives fine decisions to a three-person panel, and bars fines against state bodies, councils, independent public-law institutions, parliamentary offices, the President's office and the national churches.
Enforced by Office of the Data Protection Ombudsman
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What it makes you do
- Get a parent's consent for children — applies at: under 13A child of 13 or over can agree to an online service themselves. Below 13, a parent or guardian must agree.
- Appoint a data protection officer
- Secure the data
What it costs if you get it wrong
- Percentage of global turnover: €20 million or 4% of worldwide group turnover — about $23 millionDecided by a sanctions board of the Ombudsman and the deputy ombudsmen, sitting three-strong
- Criminal liability: Fine or imprisonment under the Criminal CodeData protection offence, unlawful access, breach of confidentiality
Sources
- Official sourceFinlex, Ministry of Justice open data serviceTietosuojalaki 1050/2018, consolidated text
opendata.finlex.fi
“Seuraamusmaksua ei voida määrätä valtion viranomaisille, valtion liikelaitoksille, kunnallisille viranomaisille, itsenäisille julkisoikeudellisille laitoksille, eduskunnan virastoille, tasavallan presidentin kanslialle.”
Link checked 18 August 2026
- Official sourceFinlexTietosuojalaki 1050/2018 (Finlex landing page)
finlex.fi
Link checked 18 August 2026
Kyberturvallisuuslaki
Act of parliament · 124/2025
Finland's implementation of the European network and information security directive. It imposes no data localisation, but it does impose the tightest routine clocks in the Finnish stack: 24 hours for a first incident alert and 72 hours for a follow-up.
Enforced by Finnish Transport and Communications Agency, including the National Cyber Security Centre
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Report cyber incidents — within 24 hoursFirst alert within 24 hours of noticing a significant incident. A trust service provider's follow-up report is also due within 24 hours.
- Report cyber incidents — within 72 hoursFollow-up report within 72 hours of noticing. Final report within one month; interim report within one month for a long-running incident.
- Secure the dataRisk management measures, with management responsibility.
- Register or notifyEntities must enrol in the supervisor's register of covered operators.
- Appoint a local representativeCertain digital service providers with no European Union establishment must name a representative in the Union.
What it costs if you get it wrong
- Percentage of global turnoverFailure to meet risk management or reporting duties, under the NIS2 framework
- Order to stopSupervisory orders and, for essential entities, temporary bans on management responsibilities
Sources
- Official sourceFinlex, Ministry of Justice open data serviceKyberturvallisuuslaki 124/2025, 6 ja 11–13 §
opendata.finlex.fi
“Ensi-ilmoitus on tehtävä 24 tunnin kuluessa merkittävän poikkeaman havaitsemisesta ja jatkoilmoitus 72 tunnin kuluessa merkittävän poikkeaman havaitsemisesta.”
Link checked 18 August 2026
- Official sourceLiikenne- ja viestintävirasto TraficomTraficom — Cybersecurity Act obligations in force from 8 April 2025
traficom.fi
Link checked 18 August 2026
Applies across the European Union1 rule
Written once for the whole bloc, and in force in every member country.
Yleinen tietosuoja-asetus (EU) 2016/679
Directly binding regulation · Regulation (EU) 2016/679
The European privacy rules apply in Finland directly. They do not require data to stay in Europe. They set conditions on data leaving: an approved destination, a standard contract, approved group rules or a narrow exception, plus a check on surveillance law in the destination.
Enforced by Office of the Data Protection Ombudsman
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims, Someone's life is at risk, Important public interest
What it makes you do
- Tell people what you do
- Keep records of processing
- Secure the data
- Assess high-risk projects
- Written vendor contract
- Put a transfer safeguard in place
- Report breaches to the regulator — within 72 hours
- Tell affected people
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Limit automated decisions
- Appoint a data protection officer — applies at: Public bodies, large-scale monitoring, large-scale sensitive data
- Appoint a local representative — applies at: Controllers and processors with no establishment in the European Union
- Delete data after a period
What it costs if you get it wrong
- Percentage of global turnover: €20 million or 4% of worldwide group turnover, whichever is higher — about $23 millionBasic principles, individual rights, unlawful transfers, defying a regulator order
- Percentage of global turnover: €10 million or 2% of worldwide group turnover, whichever is higher — about $12 millionController and processor duties such as security, records and impact assessments
- Order to stopOrder to stop processing or to suspend flows to a third country
- Claims by individualsCompensation claim by an affected individual
Sources
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679, Chapter V
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceEuropean Data Protection BoardEuropean Data Protection Board guidelines and recommendations
edpb.europa.eu
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
Whether a secure processing environment used for Finnish health and social data may be physically located outside Finland or outside Europe
The statute and the permit authority's published pages describe audit and access requirements but we could not open a text stating a geographic limit. The rule is therefore recorded as a control wall, not a location wall, at medium confidence.
Whether the transport and communications agency's technical regulations require retained telecoms records to be stored in Finland or in Europe
The statute leaves technical implementation to the operator and to the agency's regulations. We read the statute but not every technical regulation issued under it, so a location condition could exist one level down.
The stage that the April 2026 bill on public-sector fines has reached in parliament as at 18 August 2026
We confirmed the proposal and its content from the Ministry of Justice and the parliamentary proposals register, but not its current committee stage or a vote. It is recorded as proposed with no legal effect.
Maximum fine amounts proposed for public bodies in that bill
The Ministry says they would be clearly lower than for the private sector but did not publish a figure in the announcement we could open.
How narrowly the gambling supervisor will read the two exceptions to the Finland-location rule for gaming systems
No supervisory guidance has been published, and supervision moves to a different agency on 1 July 2027, so early practice is unknown.
Whether any separate Finnish rule restricts exporting seabed depth data or detailed mapping data once a survey permit has been granted
We confirmed the permit requirement and its criminal sanction, but not a separate export restriction. Permit conditions are set case by case and are not published.
Any localisation requirement in Finnish banking, payments, insurance or securities rules
None found, checked 18 August 2026. The financial supervisor's outsourcing rules require notification and supervisory access rather than location. We reviewed the general outsourcing rules but not every sector-specific regulation.
60-day cadence: three moving parts. The gambling localisation rule bites on 1 July 2027 with supervision changing hands the same day, the public-sector fines bill is live in parliament, and the telecoms retention regime is openly under review after European court rulings.
Freshness and refresh
Freshness
Checked yesterday — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Put this next to another country
Finland versus
Compare