Finland Data Protection Act (Tietosuojalaki, 1050/2018)
Finland's Data Protection Act (Tietosuojalaki, 1050/2018) supplements the EU GDPR with national provisions. The Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto) oversees enforcement. The Act covers processing of special categories of data, national identification numbers (henkilötunnus), processing for research and statistics, the age of digital consent (13 years), and enforcement procedures. Finland also has sector-specific legislation including the Act on Electronic Communications Services and the Act on the Openness of Government Activities.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (27)
Chapter 1 - General Provisions
| Code | Title |
|---|---|
| 152FZ-1 | Scope of the Federal Law (Article 1) |
| 152FZ-2 | Purpose of the Federal Law (Article 2) |
| 152FZ-3 | Basic Terms (Article 3) |
| 152FZ-4 | Legislation on Personal Data (Article 4) |
| Art. 1 | Open Finance Implementation |
| Art. 2 | Consent Definition |
| Art. 3 | Objectives of Open Finance |
| Art. 4 | Participating Institutions |
| Art. 5 | Prohibited AI Practices |
| EPDPA-1 | Scope of Regulation (§1) |
| EPDPA-2 | Specifications for Application (§2) |
| EPDPA-3 | Application of Administrative Procedure Act (§3) |
| Sec. 1 | Short Title and Commencement |
| Sec. 2 | Interpretation |
| Sec. 3 | Scope and Application |
Chapter 2 - Legal Basis for Processing Personal Data
| Code | Title |
|---|---|
| Sec. 4 | Exemptions |
| Sec. 5 | Functions and Duties of Authority |
| Sec. 6 | Establishment of the Commission |
| Sec. 7 | Responsibilities of Organisation |
Chapter 3 - Data Protection Ombudsman and Expert Board
| Code | Title |
|---|---|
| Sec. 10 | Powers of the Commission |
| Sec. 11 | Deemed Consent |
| Sec. 8 | Functions of the Commission |
| Sec. 9 | Direct Marketing Consent |
Chapter 4 - Legal Remedies
| Code | Title |
|---|---|
| Sec. 12 | Independence |
| Sec. 13 | Appointment of Commissioner |
| Sec. 14 | Collection Without Consent |
| Sec. 15 | Duty to Register |
Chapter 5 - Specific Processing Situations
| Code | Title |
|---|---|
| Sec. 17 | Certificate of Registration |
| Sec. 27 | Duty to Conduct Assessment |
| Sec. 28 | Duty to Notify |
| Sec. 29 | Data Protection Council |
Chapter 6 - Penalties and Final Provisions
| Code | Title |
|---|---|
| Sec. 35 | Security of Processing |
| Sec. 36 | Right to Erasure |
| Sec. 37 | Financial Penalties |
| Sec. 38 | Right to Data Portability |
Children
| Code | Title |
|---|---|
| FI-DPA-004 | Minor Consent (Age 13) |
Documentation
| Code | Title |
|---|---|
| FI-DPA-006 | Records of Processing Activities (RoPA) |
Employment
| Code | Title |
|---|---|
| FI-DPA-010 | Employee Personal Data (Act on Privacy in Working Life) |
| FI-DPA-011 | Workplace Monitoring and Email Inspection |
Enforcement
| Code | Title |
|---|---|
| FI-DPA-021 | Administrative Fines and Sanctions Collegium |
Exemption
| Code | Title |
|---|---|
| FI-DPA-012 | Journalistic, Academic, Artistic and Literary Exemption |
Governance
| Code | Title |
|---|---|
| FI-DPA-005 | Data Protection Officer Appointment and Notification |
Incident
| Code | Title |
|---|---|
| FI-DPA-009 | Breach Notification to Tietosuojavaltuutettu |
Lawfulness
| Code | Title |
|---|---|
| FI-DPA-001 | Lawful Basis Determination Under GDPR Article 6 |
Marketing
| Code | Title |
|---|---|
| FI-DPA-016 | Direct Marketing and ePrivacy (SVTSL) |
National Identifier
| Code | Title |
|---|---|
| FI-DPA-003 | Personal Identity Code (Henkilotunnus) Processing |
Public Sector
| Code | Title |
|---|---|
| FI-DPA-022 | Public Sector Personal Data Handling |
Research
| Code | Title |
|---|---|
| FI-DPA-013 | Scientific and Historical Research Processing |
Rights
| Code | Title |
|---|---|
| FI-DPA-008 | Data Subject Rights Handling |
Risk Assessment
| Code | Title |
|---|---|
| FI-DPA-007 | Data Protection Impact Assessment (DPIA) |
Security
| Code | Title |
|---|---|
| FI-DPA-018 | Security of Processing (Article 32) |
Special Categories
| Code | Title |
|---|---|
| FI-DPA-002 | Processing of Special Category Data (Section 6) |
Supervisory Authority
| Code | Title |
|---|---|
| FI-DPA-020 | Cooperation with Tietosuojavaltuutettu |
Transfers
| Code | Title |
|---|---|
| FI-DPA-014 | International Transfers Outside EEA |
Transparency
| Code | Title |
|---|---|
| FI-DPA-019 | Transparency Notices in Finnish and Swedish |
Vendor
| Code | Title |
|---|---|
| FI-DPA-015 | Processor Engagement (Article 28 Contracts) |
ePrivacy
| Code | Title |
|---|---|
| FI-DPA-017 | Cookie and Tracking Consent |
Your Compliance Coverage
If you comply with Finland Data Protection Act (Tietosuojalaki, 1050/2018), you already cover:
GDPR
25%
14 controls mapped
Compare →EU Digital Markets Act
25%
14 controls mapped
Compare →EU AI Act
25%
14 controls mapped
Compare →+ 557 more: EU In Vitro Diagnostic Medical Devices Regulation (IVDR) (25%), eIDAS 2.0 - EU Digital Identity Regulation (25%)
See all 560 mapped frameworks ↓Maps to 560 other frameworks
Frequently Asked Questions
What is Finland Data Protection Act (Tietosuojalaki, 1050/2018)?
Finland Data Protection Act (Tietosuojalaki, 1050/2018) is a compliance framework from Finland with 27 domains and 57 controls. Finland's Data Protection Act (Tietosuojalaki, 1050/2018) supplements the EU GDPR with national provisions. The Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto) oversees enforcement. The Act covers processing of special categories of data, national identification numbers (henkilötunnus), processing for research and statistics, the age of digital consent (13 years), and enforcement procedures. Finland also has sector-specific legislation including the Act on Electronic Communications Services and the Act on the Openness of Government Activities. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Finland Data Protection Act (Tietosuojalaki, 1050/2018) have?
Finland Data Protection Act (Tietosuojalaki, 1050/2018) has 57 controls organised across 27 domains. The largest domains are Chapter 1 - General Provisions (15 controls), Chapter 2 - Legal Basis for Processing Personal Data (4 controls), Chapter 3 - Data Protection Ombudsman and Expert Board (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Finland Data Protection Act (Tietosuojalaki, 1050/2018) map to?
Finland Data Protection Act (Tietosuojalaki, 1050/2018) maps to 560 other compliance frameworks. The top mapping partners are GDPR (25% coverage), EU Digital Markets Act (25% coverage), EU AI Act (25% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Finland Data Protection Act (Tietosuojalaki, 1050/2018) compliance?
Start your Finland Data Protection Act (Tietosuojalaki, 1050/2018) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Finland Data Protection Act (Tietosuojalaki, 1050/2018) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 57 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 706 frameworks.
Get Started Free →Free forever — no credit card required