Finland
Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Finland — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Finland has no general law forcing data to stay in the country. Personal data leaves under the ordinary European rules. Three things override that. The state security network must sit in Finland. Gambling systems must sit in Finland from July 2027. And health records released for research never leave a locked-down environment. The privacy regulator fines companies but cannot fine the government.
Data governance in Finland
The eight things that decide how you handle data about people in Finland. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. A company with no office in Finland is still covered if it offers goods or services to people in Finland. The same applies if it watches what people do here. That comes from the European privacy law, which applies directly. There is no revenue or staff-count level below which you are free. A company based outside Europe must name a representative inside Europe. That representative does not have to be in Finland.
- What you have to do here:
- Appoint a representative
Three layers stack here. The first is the European General Data Protection Regulation, Regulation (EU) 2016/679. It sets who is covered and the duty to name a representative in Europe. The second is the Finnish Data Protection Act 1050/2018, which adds to the European rules rather than replacing them. The third is Finland's Cybersecurity Act 124/2025. That law brings the European Union's second network and information security directive into Finnish law, and it reaches further than most people expect. It covers a cloud provider, data centre operator, managed service provider, online marketplace, search engine or social platform whose main European office or European representative is in Finland. It also covers an operator with no European office and no European representative at all, if it simply offers services in Finland. Employment adds a further layer. The Act on the Protection of Privacy in Working Life 759/2004 applies to anyone employing people in Finland, whatever the employer's nationality.
Sources
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation), Articles 3 and 27
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceFinlex, Ministry of Justice open data serviceKyberturvallisuuslaki 124/2025, 6 § (lainkäyttövalta ja alueellisuus)
opendata.finlex.fi
“Jos toimija ei ole sijoittautunut Euroopan unionin jäsenvaltioon tai asettanut NIS 2 -direktiivin 26 artiklan 3 kohdassa tarkoitettua nimettyä edustajaa ja toimija tarjoaa palveluita Suomessa, toimija kuuluu tämän lain soveltamisalaan.”
Link checked 18 August 2026
- Official sourceFinlexTietosuojalaki 1050/2018 (Finnish Data Protection Act)
finlex.fi
Link checked 18 August 2026
Where the data is allowed to live
Yes in general, on the normal European terms. Inside Europe data moves freely. It can go outside Europe once you have an approved country, a standard contract or another recognised protection. Finland adds no general rule of its own about data staying in the country. But four areas are different. Gambling systems must be in Finland. The state's secure government network must be in Finland. Health and social records released for research stay locked inside an audited environment. And surveying the Finnish seabed, or filming defence sites from the air, needs a permit first.
Industry by industry, verified on 18 August 2026. GAMBLING. data must stay in the country from 1 July 2027. The new Gambling Act 10/2026 says the gaming systems and draw devices of licence holders must be in Finland. There are two ways out. The operator is licensed in another state whose regulator has signed a supervision agreement with the Finnish supervisor. Or the operator lets the Finnish supervisor check the system remotely. Fifty licence applications were already in by 8 June 2026. GOVERNMENT SECURITY NETWORK. data must stay in the country Act 10/2015 requires the equipment rooms and equipment directly connected to the public administration security network to be owned or held by the Finnish state. They must be in Finland. The services must be produced in Finland. Administration and supervision must happen in Finland. There is a narrow exception where it is operationally necessary. HEALTH, REUSE FOR RESEARCH. data must stay in the country in effect. Under Act 552/2019, person-level data released for research, statistics, teaching, development or official supervision is not handed over as a file. It is opened inside a secure environment run by the data permit authority, or by an audited outside provider. Only results come out. HEALTH, DIRECT CARE. data can leave only if conditions are met Patient records can be shared with a foreign care provider through Finland's national contact point, with the patient's consent. We found no rule about where the data must be stored. MAPPING AND SEABED. data can leave only if conditions are met The Territorial Surveillance Act 755/2000 makes three things an offence without a permit. Surveying the shape or make-up of the seabed in Finnish waters. Running low-altitude airborne geophysical surveys. And recording defence-significant sites from the air. Once you have a permit, the permit's conditions govern the data. BANKING, PAYMENTS, INSURANCE, SECURITIES. data can leave only if conditions are met We found no rule forcing data to stay in the country. The Finnish Financial Supervisory Authority's outsourcing rules require advance notice of major outsourcing, and continuous access for the supervisor. For outsourcing outside Europe you must also show that the host country's law lets the supervisor get the information it needs. The European Union's digital operational resilience rules sit on top, and they too do not force data to stay in any country. TELECOMS. data can leave only if conditions are met Call and connection records kept for the police under Act 917/2014 must be kept for 12, 9 or 6 months, depending on the service. We found no rule requiring those records to be held in Finland or in Europe. That is a real difference from some neighbouring countries. GOVERNMENT CLOUD IN GENERAL. data can leave only if conditions are met Finland's public administration cloud policies were last updated in 2024. They are guidance, not law. Security-classified material is the real limit. The higher classification levels need approved environments rather than ordinary public cloud. EDUCATION, DEFENCE PROCUREMENT, ARTIFICIAL INTELLIGENCE. We found no separate Finnish rule forcing data to stay in the country, checked 18 August 2026, medium confidence.
Sources
- Official sourceFinlex, Ministry of Justice open data serviceRahapelilaki 10/2026, 46 § — Pelijärjestelmien ja arvontalaitteiden sijainti
opendata.finlex.fi
“Yksinoikeustoimiluvanhaltijan ja rahapelitoimiluvanhaltijan pelijärjestelmien ja arvontalaitteiden on sijaittava Suomessa.”
Link checked 18 August 2026
- Official sourceFinlex, Ministry of Justice open data serviceLaki julkisen hallinnon turvallisuusverkkotoiminnasta 10/2015, 5 §
opendata.finlex.fi
“De utrustningsutrymmen och den utrustning som direkt hör samman med säkerhetsnätet ska finnas i Finland och tjänsterna ska produceras i Finland.”
Link checked 18 August 2026
- Official sourceFinlex, Ministry of Justice open data serviceLaki sosiaali- ja terveystietojen toissijaisesta käytöstä 552/2019, 20 § — tietoturvallinen käyttöympäristö
opendata.finlex.fi
Link checked 18 August 2026
- Official sourceFinlex, Ministry of Justice open data serviceAluevalvontalaki 755/2000, 12–14 § ja 44 § — luvanvarainen merenpohjan ja ilmasta tapahtuva tutkiminen
opendata.finlex.fi
“Suomen aluevesillä ei saa ilman lupaa harjoittaa merenpohjan tai sen sisustan muodon, rakenteen tai koostumuksen selvittämistä geologisilla tai geofyysisillä tutkimuksilla.”
Link checked 18 August 2026
- Official sourceFinanssivalvonta (Financial Supervisory Authority)FIN-FSA Regulations and guidelines 1/2012, Outsourcing (version in force from 1 September 2023)
finanssivalvonta.fi
“In case of cross-border outsourcing to a non-EEA state, clarification of whether the host country's legal framework will permit the FIN-FSA to obtain information needed to supervise.”
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2018/1807 on the free flow of non-personal data
eur-lex.europa.eu
Link checked 18 August 2026
What to do: Check your own industry against the restricted list before you pick a hosting region.
Sending data out of the country
You can only send data freely to approved countries. The European Commission keeps that list, not Finland. Sending personal data to an approved country needs nothing extra. Sending it anywhere else needs a protection in place. That is usually the European standard contract, or approved group-wide rules for a company group. You are also expected to check whether surveillance law in the destination country undermines that paperwork. Finland adds no separate national permission step.
- Ways to send data out:
- Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Explicit consent · Needed for a contract
The approved list has entries and is current as at 18 August 2026. It covers Andorra, Argentina, Brazil (new, 26 January 2026, and mutual), Canada for commercial organisations, Faroe Islands, Guernsey, Isle of Man, Israel, Japan, Jersey, New Zealand, South Korea (first review confirmed 23 July 2026), Switzerland, the United Kingdom (renewed 19 December 2025, running to 2031), Uruguay, the United States for organisations signed up to the EU-US Data Privacy Framework, and the European Patent Organisation. None has been withdrawn or suspended. The 2021 standard contract clauses are still the ones you use. The promised extra clauses, for recipients already covered by the European rules directly, are still not adopted. Group-wide internal rules are still available. The narrow one-off exceptions cannot be used for routine or bulk transfers. The United States route is under pressure. A court challenge is on appeal. On 31 July 2026 the European Data Protection Board formally asked the Commission to examine whether recent changes in the United States affect the decision. It has not been suspended. One Finnish quirk. The Data Protection Ombudsman may ask the Helsinki Administrative Court to send a question to the European Union court. The question is whether an approval decision is lawful.
Sources
- Official sourceEuropean CommissionAdequacy decisions — current list
commission.europa.eu
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionCommission Implementing Decision (EU) 2021/914 — standard contractual clauses
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceFinlex, Ministry of Justice open data serviceTietosuojalaki 1050/2018, 23 § — komission päätökset
opendata.finlex.fi
Link checked 18 August 2026
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
The regulator, and whether it actually acts
The Office of the Data Protection Ombudsman, and it works. Anu Talus was reappointed Ombudsman for a five-year term starting on 1 November 2025. Fines are decided by a three-person panel of the Ombudsman and the deputy ombudsmen. It has been issuing them. In September 2025 it fined a bank 1.8 million euros, roughly two million US dollars. Other bodies enforce too. Finland's transport and communications agency supervises cyber incidents. The financial supervisor covers banks and insurers. The police board licenses gambling.
We rate enforcement an active regulator, not aggressive. The regulator issues a steady stream of decisions. Its fines are appealed to and reviewed by the administrative courts. But the number of cases and the amounts are moderate by European standards. The system clearly works. The Supreme Administrative Court has ruled on how fines are set, and upheld a fine against the postal operator. On 1 June 2026 the Helsinki Administrative Court cancelled a 1.1 million euro fine against University Pharmacy, while upholding most of the findings behind it. There is a large gap. Finnish law says a fine cannot be imposed on state authorities, state enterprises, municipal authorities, independent public-law institutions, parliamentary offices, the President's office or the two national churches. So the public sector is supervised, ordered and criticised, but not fined. The government proposed on 9 April 2026 to change this. Cyber supervision is split by industry. The Finnish Transport and Communications Agency and its National Cyber Security Centre are the main bodies. Gambling is licensed and supervised by the National Police Board until 30 June 2027. After that it passes to the new Finnish Licensing and Supervisory Agency.
Sources
- Official sourceOffice of the Data Protection OmbudsmanS-Bank fined EUR 1.8 million for a data security vulnerability, 10 September 2025
tietosuoja.fi
Link checked 18 August 2026
- Official sourceOffice of the Data Protection OmbudsmanHelsinki Administrative Court decision on the University Pharmacy fine, 1 June 2026
tietosuoja.fi
Link checked 18 August 2026
- Official sourceOffice of the Data Protection OmbudsmanAnu Talus reappointed Data Protection Ombudsman for five years from 1 November 2025
tietosuoja.fi
Link checked 18 August 2026
- Official sourceFinlex, Ministry of Justice open data serviceTietosuojalaki 1050/2018, 24 § — sanctions board and the public-sector exemption
opendata.finlex.fi
“Seuraamusmaksua ei voida määrätä valtion viranomaisille, valtion liikelaitoksille, kunnallisille viranomaisille, itsenäisille julkisoikeudellisille laitoksille, eduskunnan virastoille, tasavallan presidentin kanslialle.”
Link checked 18 August 2026
- Official sourcePoliisihallitus (National Police Board)National Police Board — 50 gambling licence applications received, 8 June 2026
poliisi.fi
Link checked 18 August 2026
How long you must keep it — and when to delete it
There are both minimum and maximum keep-times. The minimums: company accounts and books must be kept ten years after the financial year ends. Receipts and business correspondence must be kept six years. Telephone and internet connection records that certain operators keep for the police run 12 months, 9 months or 6 months, depending on the service. The maximum: personal data must be deleted once the purpose you collected it for has ended. There is no fixed number for that. Where the two clash, the specific keep-time in the industry law wins for as long as it lasts. You delete once it expires.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period · Keep logs
The Accounting Act 1336/1997 sets both the keep-times and Finland's only general rule about where records sit. That rule is light. The records must be kept so that an authority or an auditor can inspect them from Finland without undue delay. That allows storage abroad with a working access path. It does not require a copy in Finland. Telecoms records kept for the police under Act 917/2014 run 12 months for mobile telephony and text messaging, 9 months for internet access, and 6 months for internet telephony. The clock starts at the communication. Message content and web-browsing records are left out. Under the health reuse law, access logs for a data permit are deleted or archived 12 years after the permit ends. The general duty to delete comes from the European rule that you keep data no longer than you need it. Finland does not put a number on that.
Sources
- Official sourceFinlex, Ministry of Justice open data serviceKirjanpitolaki 1336/1997, 2 luku 9 ja 10 § — storage and retention of accounting material
opendata.finlex.fi
“Tilinpäätös, kirjanpidot, tositteet ja muu kirjanpitoaineisto on säilytettävä huolellisesti ... siten, että niiden tarkastelu Suomesta käsin on mahdollista viranomaiselle ja tilintarkastajalle ilman aiheetonta viivettä.”
Link checked 18 August 2026
- Official sourceFinlex, Ministry of Justice open data serviceLaki sähköisen viestinnän palveluista 917/2014, 157 § — retention periods for authority purposes
opendata.finlex.fi
“Edellä 2 momentin 1 kohdassa tarkoitettujen palvelujen tietoja on säilytettävä 12 kuukautta, 2 momentin 3 kohdassa tarkoitetun palvelun tietoja 9 kuukautta ja 2 momentin 2 kohdassa tarkoitettujen palvelujen tietoja 6 kuukautta.”
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679, Article 5(1)(e) — storage limitation
eur-lex.europa.eu
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
There are three separate deadlines. If personal data leaks, you have 72 hours to tell the Data Protection Ombudsman. If you are a company covered by Finland's cybersecurity law, you have 24 hours for a first alert about a significant incident. Then 72 hours for a fuller report. Then one month for the final report. If you are a telecoms operator, you must tell the transport and communications agency immediately about a significant security breach. The same event can start all three.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
The 24-hour and 72-hour cyber deadlines come from the Cybersecurity Act 124/2025. That law brings the European Union's second network and information security directive into Finnish law, and has applied since 8 April 2025. A trust service provider has a shorter version. Its follow-up report is due within 24 hours, not 72. If an incident runs on, an interim report is due within one month of the follow-up report. The telecoms deadline is in Act 917/2014. It is written as 'without delay' rather than as a number of hours, which means faster than 24 hours. The privacy deadline is the European 72-hour rule. You must also tell affected individuals without undue delay where the risk to them is high. The notices go to different bodies. Personal data goes to the Ombudsman. Cyber incidents go to your industry's named supervisor. Telecoms incidents go to the transport and communications agency.
Sources
- Official sourceFinlex, Ministry of Justice open data serviceKyberturvallisuuslaki 124/2025, 11–13 § — incident reporting deadlines
opendata.finlex.fi
“Ensi-ilmoitus on tehtävä 24 tunnin kuluessa merkittävän poikkeaman havaitsemisesta ja jatkoilmoitus 72 tunnin kuluessa merkittävän poikkeaman havaitsemisesta.”
Link checked 18 August 2026
- Official sourceLiikenne- ja viestintävirasto TraficomTraficom — Cybersecurity Act approved, NIS2 obligations from 8 April 2025
traficom.fi
Link checked 18 August 2026
- Official sourceFinlex, Ministry of Justice open data serviceLaki sähköisen viestinnän palveluista 917/2014, 275 § — häiriöilmoitukset
opendata.finlex.fi
“Teleyrityksen on ilmoitettava viipymättä Liikenne- ja viestintävirastolle, jos sen palveluun kohdistuu tai sitä uhkaa merkittävä tietoturvaloukkaus.”
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679, Articles 33 and 34 — breach notification
eur-lex.europa.eu
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things cost people their weekend. One: a child can agree to an online service at 13 in Finland, not 16. A single European age setting will be wrong here. Two: employee monitoring is a criminal matter, not just a fine. You must run a staff consultation before you switch it on. Three: you cannot fix an employment data problem with the worker's consent. The necessity test cannot be waived. Four: the government cannot be fined. If a Finnish public body loses your data, your remedy is an order and a court claim, not a penalty. Five: surveying the seabed, or filming defence sites from the air, without a permit is a crime.
- What you have to do here:
- Get a parent's consent for children
- What it costs if you get it wrong:
- Criminal liability
(1) The age of 13 comes from the Finnish Data Protection Act 1050/2018. (2) and (3) come from the Act on the Protection of Privacy in Working Life 759/2004. It says the necessity requirement cannot be set aside with the employee's consent. It says the employer must collect personal data mainly from the employee. You need consent to collect it elsewhere. There are narrow exceptions for credit and criminal record checks. Collecting employee data falls inside the staff consultation procedure required by law. The Act makes a list of breaches a crime, punishable by a fine for the employer or the employer's representative. It also points to the Criminal Code for the more serious offences about personal data, unlawful access, covert surveillance and breach of confidence. Enforcement is shared between the occupational safety and health authorities and the Data Protection Ombudsman. That double-headed supervisor is unusual. (4) is the public-sector exemption in the Data Protection Act. (5) is the Territorial Surveillance Act 755/2000. There is a sixth, less dramatic point. Bulk release of Population Information System data abroad is decided by the population register authority, not by the recipient's contract.
Sources
- Official sourceFinlex, Ministry of Justice open data serviceTietosuojalaki 1050/2018, 5 § — age limit for information society services
opendata.finlex.fi
“lapsen henkilötietojen käsittely on lainmukaista, jos lapsi on vähintään 13-vuotias.”
Link checked 18 August 2026
- Official sourceFinlex, Ministry of Justice open data serviceLaki yksityisyyden suojasta työelämässä 759/2004, 3, 4, 22 ja 24 §
opendata.finlex.fi
“Tarpeellisuusvaatimuksesta ei voida poiketa työntekijän suostumuksella.”
Link checked 18 August 2026
- Official sourceFinlex, Ministry of Justice open data serviceAluevalvontalaki 755/2000, 44 § — rangaistussäännökset
opendata.finlex.fi
Link checked 18 August 2026
- Official sourceFinlex, Ministry of Justice open data serviceLaki väestötietojärjestelmästä ja Digi- ja väestötietoviraston varmennepalveluista 661/2009, 47 §
opendata.finlex.fi
Link checked 18 August 2026
What's changing next
Three dated changes. From January 2027 European rules ban cloud providers from charging customers to move their data out. On 1 July 2027 Finland's gambling monopoly ends and licences start. The rule that gambling systems must sit in Finland begins then too. And a bill put to parliament on 9 April 2026 would let the privacy regulator fine public bodies for the first time. The maximum amounts would be lower than for companies. Courts, parliamentary offices and national security bodies would be left out.
- What you have to do here:
- Make switching cloud provider possible
Powers and reviews to watch, because they can move without a new law. First, the rule that gambling systems must sit in Finland has two escape routes, and the supervisor decides how narrowly to read them. That decides whether it is a real ban or a paperwork step. The supervisor also changes on 1 July 2027, from the National Police Board to the new Finnish Licensing and Supervisory Agency. The new body may read them differently. Second, Finland's rules on keeping telephone and internet records for the police are under review. The Ministry of Transport and Communications is reviewing them, after European court rulings. A working paper went out for comment in 2024 and no bill has followed. So the current keep-times stand, but the design is openly unsettled. Third, the exception in the security network law that allows equipment abroad 'where operationally necessary' has no published threshold. Fourth, at European level the United States transfer route is under formal review. The European Data Protection Board wrote to the Commission about it on 31 July 2026. Suspending it would hit Finnish exporters immediately. We did not confirm where the public-sector fines bill stood in parliament on 18 August 2026. Treat it as proposed, not as law.
Sources
- Official sourceFinlexGovernment proposal GP 46/2026 — amending the sanctions provisions of the Data Protection Act
finlex.fi
Link checked 18 August 2026
- Official sourceOikeusministeriö (Ministry of Justice)Ministry of Justice — administrative fines to be extended to the public sector, 9 April 2026
oikeusministerio.fi
“Seuraamusmaksuja ei voitaisi määrätä muun muassa tuomioistuimille”
Link checked 18 August 2026
- Official sourceFinlex, Ministry of Justice open data serviceRahapelilaki 10/2026, 106 § — voimaantulo
opendata.finlex.fi
“Tämä laki tulee voimaan 1 päivänä heinäkuuta 2027. Lain 2 ja 9 luku, 43 §:n 3 momentti sekä 44, 57, 63 ja 64 § tulevat voimaan kuitenkin jo 1 päivänä maaliskuuta 2026.”
Link checked 18 August 2026
- Official sourceLiikenne- ja viestintäministeriöMinistry of Transport and Communications — assessment memorandum on retention of electronic communications traffic data
lvm.fi
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2023/2854 (Data Act) — zero cloud switching charges from 12 January 2027
eur-lex.europa.eu
Link checked 18 August 2026
What to do: Diarise 1 July 2027 — that is the date this changes.
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries4 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Online gaming data rules
Official name: Rahapelilaki · 10/2026, 46 § (Pelijärjestelmien ja arvontalaitteiden sijainti) · Act of parliament
Finland's new gambling law ends the state monopoly and opens a licensed market on 1 July 2027. Licensed operators must keep their gaming systems and draw devices in Finland. There are two narrow ways out. Either the regulators sign a supervision agreement. Or the Finnish supervisor gets remote access to check the system.
That is a long gap: the duty is real law today, but no penalty can follow until 1 July 2027. A contract you sign can still hold you to it from day one — and government contracts often do.
Enforced by National Police Board
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the country — from 1 July 2027Gaming systems and draw devices must be in Finland. There are two exceptions. The operator is licensed in a state whose regulator has signed a supervision agreement with the Finnish supervisor. Or the operator gives the Finnish supervisor remote access to check the system.
- Register or notifyYou need a licence. Applications opened in 2026. Fifty had been filed by 8 June 2026.
- Appoint a representativeAn operator with no home or office in the European Economic Area must have a representative based in the European Economic Area.
What it costs if you get it wrong
- Loss of your licenceBreach of licence conditions
- Fixed maximum finePenalty payment imposed by the Market Court on the supervisor's application
Sources
- Official sourceFinlex, Ministry of Justice open data serviceRahapelilaki 10/2026, 46 § ja 106 §
opendata.finlex.fi
“Yksinoikeustoimiluvanhaltijan ja rahapelitoimiluvanhaltijan pelijärjestelmien ja arvontalaitteiden on sijaittava Suomessa.”
Link checked 18 August 2026
- Official sourcePoliisihallitusNational Police Board — gambling licence applications, 8 June 2026
poliisi.fi
Link checked 18 August 2026
Telecoms rules
Official name: Laki julkisen hallinnon turvallisuusverkkotoiminnasta · 10/2015, 5 § · Act of parliament
Finland's strictest rule about where data must sit. The public administration security network carries top state leadership and safety-critical communications. It must be owned or held by the state. It must be physically in Finland. Its services must be produced, administered and supervised in Finland.
Enforced by Ministry of Finance
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the countryEquipment rooms and equipment directly connected to the security network must be in Finland. The services must be produced in Finland. Administration and supervision must be carried out in Finland. Equipment may sit abroad only where operationally necessary.
- Hold a security certificateHigh preparedness and high security requirements, set in law or under it.
Sources
- Official sourceFinlex, Ministry of Justice open data serviceLaki julkisen hallinnon turvallisuusverkkotoiminnasta 10/2015, 5 §
opendata.finlex.fi
“De utrustningsutrymmen och den utrustning som direkt hör samman med säkerhetsnätet ska finnas i Finland och tjänsterna ska produceras i Finland. Administreringen av och tillsynen över utrustningsutrymmena, utrustningen och tjänsteproduktionen ska skötas i Finland.”
Link checked 18 August 2026
- Official sourceValtiovarainministeriö (Ministry of Finance)Ministry of Finance — use of cloud services in public administration (policies updated 2024, guidance not law)
vm.fi
Link checked 18 August 2026
Health and social care data must stay in the country
Official name: Laki sosiaali- ja terveystietojen toissijaisesta käytöstä · 552/2019 · Act of parliament
Finnish health and social records reused for research, statistics, teaching, development or official supervision are never handed over as a file. They are opened inside an audited secure environment. Only summary or approved results are exported.
Enforced by Health and Social Data Permit Authority
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Register or notifyYou need a data permit from the health and social data permit authority before any reuse.
- Keep the data in the countryPerson-level data is opened inside a secure environment run by the permit authority, or by an audited outside provider. You reach it through a secure access service. Only results leave, through a controlled export step.
- Independent auditOutside secure environments must be assessed against the permit authority's binding requirements, regulation 1/2022.
- Keep logs — 12 yearsUsage logs are deleted or archived 12 years after the data permit ends.
What it costs if you get it wrong
- Order to stopWithdrawal of the data permit
Sources
- Official sourceFinlex, Ministry of Justice open data serviceLaki sosiaali- ja terveystietojen toissijaisesta käytöstä 552/2019, 17 ja 20 §
opendata.finlex.fi
“Tietolupaan perustuva tietoaineisto luovutetaan luvansaajan käsiteltäväksi aina 20 §:ssä tarkoitettuun tietoturvalliseen käyttöympäristöön 17 §:ssä tarkoitetun tietoturvallisen käyttöpalvelun välityksellä, ellei siitä ole muodostettu aggregoitua tilastotietoa.”
Link checked 18 August 2026
- Official sourceFindata, Health and Social Data Permit AuthorityFindata — binding regulations, including regulation 1/2022 on requirements for other providers' secure processing environments
findata.fi
Link checked 18 August 2026
Telecoms rules (Telecoms)
Official name: Laki sähköisen viestinnän palveluista · 917/2014, 157, 158 ja 275 § · Act of parliament
Named Finnish telecoms operators must keep connection records for the police for 12, 9 or 6 months, depending on the service. We found no rule requiring those records to be held in Finland or in Europe. So the limits here are about keeping the data and securing it, not about where it sits.
Enforced by Finnish Transport and Communications Agency, including the National Cyber Security Centre
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What you have to do
- Keep data for a minimum period — 1 yearMobile telephony and text messaging records, for named operators chosen by the Ministry of the Interior.
- Keep data for a minimum period — 9 monthsInternet access service records.
- Keep data for a minimum period — 6 monthsInternet telephony records. Message content and web-browsing records are left out of this duty.
- Report cyber incidentsSignificant security breaches must be reported to the transport and communications agency without delay.
- Secure the data
What it costs if you get it wrong
- Criminal liability: FineElectronic communications data protection infringement, for example unlawful handling of traffic or location data
Sources
- Official sourceFinlex, Ministry of Justice open data serviceLaki sähköisen viestinnän palveluista 917/2014, 157, 158, 275 ja 347 §
opendata.finlex.fi
“Säilytysvelvollinen yritys päättää tietojen säilyttämisen teknisestä toteuttamisesta.”
Link checked 18 August 2026
- Official sourceLiikenne- ja viestintäministeriöMinistry of Transport and Communications — review of the traffic data retention regime after EU court case law
lvm.fi
Link checked 18 August 2026
Applies to every company2 rules
These bind you whatever business you are in, once the country's rules reach you.
Data rules
Official name: Tietosuojalaki · 1050/2018 · Act of parliament
Finland's national law on top of the European rules. It sets the age of digital consent at 13. It gives fine decisions to a three-person panel. And it bars fines against state bodies, councils, independent public-law institutions, parliamentary offices, the President's office and the national churches.
Enforced by Office of the Data Protection Ombudsman
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What you have to do
- Get a parent's consent for children — applies at: under 13A child of 13 or over can agree to an online service themselves. Below 13, a parent or guardian must agree.
- Appoint a data protection officer
- Secure the data
What it costs if you get it wrong
- Percentage of global turnover: €20 million or 4% of worldwide group turnover — about $23 millionDecided by a sanctions board of the Ombudsman and the deputy ombudsmen, sitting three-strong
- Criminal liability: Fine or imprisonment under the Criminal CodeData protection offence, unlawful access, breach of confidentiality
Sources
- Official sourceFinlex, Ministry of Justice open data serviceTietosuojalaki 1050/2018, consolidated text
opendata.finlex.fi
“Seuraamusmaksua ei voida määrätä valtion viranomaisille, valtion liikelaitoksille, kunnallisille viranomaisille, itsenäisille julkisoikeudellisille laitoksille, eduskunnan virastoille, tasavallan presidentin kanslialle.”
Link checked 18 August 2026
- Official sourceFinlexTietosuojalaki 1050/2018 (Finlex landing page)
finlex.fi
Link checked 18 August 2026
Breach reporting rules
Official name: Kyberturvallisuuslaki · 124/2025 · Act of parliament
Finland's version of the European network and information security directive. It does not force data to stay in any country. But it sets the tightest routine deadlines in Finnish law: 24 hours for a first incident alert, and 72 hours for a follow-up.
Enforced by Finnish Transport and Communications Agency, including the National Cyber Security Centre
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Report cyber incidents — within 24 hoursFirst alert within 24 hours of noticing a significant incident. A trust service provider's follow-up report is also due within 24 hours.
- Report cyber incidents — within 72 hoursFollow-up report within 72 hours of noticing. Final report within one month; interim report within one month for a long-running incident.
- Secure the dataSteps to manage your risks, with named management responsibility.
- Register or notifyCovered organisations must sign up to the supervisor's register.
- Appoint a representativeCertain digital service providers with no office in the European Union must name a representative in the Union.
What it costs if you get it wrong
- Percentage of global turnoverFailure to meet risk management or reporting duties, under the NIS2 framework
- Order to stopSupervisory orders and, for essential entities, temporary bans on management responsibilities
Sources
- Official sourceFinlex, Ministry of Justice open data serviceKyberturvallisuuslaki 124/2025, 6 ja 11–13 §
opendata.finlex.fi
“Ensi-ilmoitus on tehtävä 24 tunnin kuluessa merkittävän poikkeaman havaitsemisesta ja jatkoilmoitus 72 tunnin kuluessa merkittävän poikkeaman havaitsemisesta.”
Link checked 18 August 2026
- Official sourceLiikenne- ja viestintävirasto TraficomTraficom — Cybersecurity Act obligations in force from 8 April 2025
traficom.fi
Link checked 18 August 2026
Applies across the European Union1 rule
Written once for the whole bloc, and in force in every member country.
Europe's main privacy law
Official name: Yleinen tietosuoja-asetus (EU) 2016/679 · Regulation (EU) 2016/679 · Directly binding regulation
The European privacy rules apply in Finland directly. They do not require data to stay in Europe. They set conditions on data leaving. You need an approved destination, a standard contract, approved group rules or a narrow exception. You also need a check on surveillance law in the destination country.
Enforced by Office of the Data Protection Ombudsman
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims, To save someone’s life, Important public interest
What you have to do
- Tell people what you do
- Keep records of how you use data
- Secure the data
- Assess high-risk projects
- Written vendor contract
- Put a transfer safeguard in place
- Report breaches to the regulator — within 72 hours
- Tell affected people
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Limit automated decisions
- Appoint a data protection officer — applies at: Public bodies, large-scale monitoring, large-scale sensitive data
- Appoint a representative — applies at: Controllers and processors with no establishment in the European Union
- Delete data after a period
What it costs if you get it wrong
- Percentage of global turnover: €20 million or 4% of worldwide group turnover, whichever is higher — about $23 millionBasic principles, individual rights, unlawful transfers, defying a regulator order
- Percentage of global turnover: €10 million or 2% of worldwide group turnover, whichever is higher — about $12 millionController and processor duties such as security, records and impact assessments
- Order to stopOrder to stop processing or to suspend flows to a third country
- Claims by individualsCompensation claim by an affected individual
Sources
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679, Chapter V
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceEuropean Data Protection BoardEuropean Data Protection Board guidelines and recommendations
edpb.europa.eu
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
Whether a secure processing environment used for Finnish health and social data may be physically located outside Finland or outside Europe
We could not confirm whether the secure research environment must be physically in Finland. The law and the permit authority's published pages describe audit and access requirements. We could not find a text setting a geographic limit. So we record this as a control on access, not a rule about location, at medium confidence.
Whether the transport and communications agency's technical regulations require retained telecoms records to be stored in Finland or in Europe
We could not confirm whether a location condition sits in the technical rules. The law leaves technical detail to the operator and to the agency's own regulations. We read the law but not every technical regulation issued under it.
The stage that the April 2026 bill on public-sector fines has reached in parliament as at 18 August 2026
We could not confirm how far the public-sector fines bill has got. We confirmed the proposal and its content from the Ministry of Justice and the parliamentary proposals register. We did not confirm its current committee stage or any vote. We record it as proposed, with no legal effect.
Maximum fine amounts proposed for public bodies in that bill
We could not confirm the maximum fines proposed for public bodies. The Ministry says they would be clearly lower than for private companies. It did not publish a figure in the announcement we could open.
How narrowly the gambling supervisor will read the two exceptions to the Finland-location rule for gaming systems
We could not confirm how the gambling location rule will be applied. No supervisory guidance has been published. Supervision also moves to a different agency on 1 July 2027, so early practice is unknown.
Whether any separate Finnish rule restricts exporting seabed depth data or detailed mapping data once a survey permit has been granted
We could not confirm whether seabed and aerial survey data faces a separate export restriction. We confirmed the permit requirement and the criminal penalty behind it. Permit conditions are set case by case and are not published.
Any localisation requirement in Finnish banking, payments, insurance or securities rules
We found no financial rule forcing data to stay in the country, checked 18 August 2026. The financial supervisor's outsourcing rules require notice and supervisor access rather than a location. We reviewed the general outsourcing rules but not every industry-specific regulation.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.