Finland Data Protection Act (Tietosuojalaki, 1050/2018)
Finland's Data Protection Act (Tietosuojalaki, 1050/2018) supplements the EU GDPR with national provisions. The Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto) oversees enforcement. The Act covers processing of special categories of data, national identification numbers (henkilötunnus), processing for research and statistics, the age of digital consent (13 years), and enforcement procedures. Finland also has sector-specific legislation including the Act on Electronic Communications Services and the Act on the Openness of Government Activities.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (6)
Chapter 1 — General Provisions
| Code | Title |
|---|---|
| 152FZ-1 | Scope of the Federal Law (Article 1) |
| 152FZ-2 | Purpose of the Federal Law (Article 2) |
| 152FZ-3 | Basic Terms (Article 3) |
| 152FZ-4 | Legislation on Personal Data (Article 4) |
| Art. 1 | Open Finance Implementation |
| Art. 2 | Consent Definition |
| Art. 3 | Objectives of Open Finance |
| Art. 4 | Participating Institutions |
| Art. 5 | Legal Recognition of Data Messages |
| EPDPA-1 | Scope of Regulation (§1) |
| EPDPA-2 | Specifications for Application (§2) |
| EPDPA-3 | Application of Administrative Procedure Act (§3) |
| Sec. 1 | Short Title and Commencement |
| Sec. 2 | Interpretation |
| Sec. 3 | Scope and Application |
Chapter 2 — Legal Basis for Processing Personal Data
| Code | Title |
|---|---|
| Sec. 4 | Exemptions |
| Sec. 5 | Functions and Duties of Authority |
| Sec. 6 | Establishment of the Commission |
| Sec. 7 | Responsibilities of Organisation |
Chapter 3 — Data Protection Ombudsman and Expert Board
| Code | Title |
|---|---|
| Sec. 10 | Powers of the Commission |
| Sec. 11 | Deemed Consent |
| Sec. 8 | Functions of the Commission |
| Sec. 9 | Direct Marketing Consent |
Chapter 4 — Legal Remedies
| Code | Title |
|---|---|
| Sec. 12 | Independence |
| Sec. 13 | Appointment of Commissioner |
| Sec. 14 | Collection Without Consent |
| Sec. 15 | Duty to Register |
Chapter 5 — Specific Processing Situations
| Code | Title |
|---|---|
| Sec. 17 | Certificate of Registration |
| Sec. 27 | Duty to Conduct Assessment |
| Sec. 28 | Duty to Notify |
| Sec. 29 | Data Protection Council |
Chapter 6 — Penalties and Final Provisions
| Code | Title |
|---|---|
| Sec. 35 | Security of Processing |
| Sec. 36 | Right to Erasure |
| Sec. 37 | Financial Penalties |
| Sec. 38 | Right to Data Portability |
Maps to 534 other frameworks
Frequently Asked Questions
What is Finland Data Protection Act (Tietosuojalaki, 1050/2018)?
Finland Data Protection Act (Tietosuojalaki, 1050/2018) is a compliance framework from Finland with 6 domains and 35 controls. Finland's Data Protection Act (Tietosuojalaki, 1050/2018) supplements the EU GDPR with national provisions. The Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto) oversees enforcement. The Act covers processing of special categories of data, national identification numbers (henkilötunnus), processing for research and statistics, the age of digital consent (13 years), and enforcement procedures. Finland also has sector-specific legislation including the Act on Electronic Communications Services and the Act on the Openness of Government Activities. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Finland Data Protection Act (Tietosuojalaki, 1050/2018) have?
Finland Data Protection Act (Tietosuojalaki, 1050/2018) has 35 controls organised across 6 domains. The largest domains are Chapter 1 — General Provisions (15 controls), Chapter 2 — Legal Basis for Processing Personal Data (4 controls), Chapter 3 — Data Protection Ombudsman and Expert Board (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Finland Data Protection Act (Tietosuojalaki, 1050/2018) map to?
Finland Data Protection Act (Tietosuojalaki, 1050/2018) maps to 534 other compliance frameworks. The top mapping partners are EU Digital Markets Act (40% coverage), EU In Vitro Diagnostic Medical Devices Regulation (IVDR) (40% coverage), eIDAS 2.0 — EU Digital Identity Regulation (40% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Finland Data Protection Act (Tietosuojalaki, 1050/2018) compliance?
Start your Finland Data Protection Act (Tietosuojalaki, 1050/2018) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Finland Data Protection Act (Tietosuojalaki, 1050/2018) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 35 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required