Finnish data-protection coordination with EU framework. GDPR (Regulation (EU) 2016/679): Tietosuojalaki supplements + does not duplicate GDPR; GDPR controls (Articles 5-7 + 12-22 + 25-32 + 33-34 + 44-49 + 83-84) apply directly + Tietosuojalaki adds Finnish derogations + specifications. EU NIS2 (Directive (EU) 2022/2555 + Finnish Cybersecurity Act 2024): essential + important entity registration + risk management + incident reporting + supervised by Traficom; coordinates with Tietosuojalaki for personal-data-related incidents. EU DSA (Digital Services Act Regulation (EU) 2022/2065): very-large-online-platform obligations + transparency reporting + risk assessment supervised by the Finnish Competition and Consumer Authority (Kilpailu- ja kuluttajavirasto, KKV) + the Tietosuojavaltuutettu for data protection aspects. EU DGA (Data Governance Act Regulation (EU) 2022/868): data-intermediation services + altruism organisations + supervised by Traficom + the Tietosuojavaltuutettu. EU eIDAS Revised (Regulation (EU) 2024/1183): European Digital Identity Wallet (EUDI) + qualified trust services + supervised by Traficom; the Tietosuojavaltuutettu addresses personal-data implications. AI ACT (Regulation (EU) 2024/1689): see Status control. EU FREEDOM OF EXPRESSION + JOURNALISM: the EU EMFA (European Media Freedom Act) + the Tietosuojalaki Section 27 journalism exemption together establish the freedom-of-expression-vs-data-protection balance.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.