What Is Data Protection Act 1050/2018?
Finland's current consolidated data-protection statute is the Data Protection Act 1050/2018, enacted on 5 December 2018 and in force from 1 January 2019. The current text records amendments 869/2020, 902/2020, 1112/2022, 239/2023, 1225/2023, 29/2024, and 437/2025. A further amendment, 380/2026, entered into force on 1 September 2026 and should be treated as part of the operative framework. GDPR Chapter III rights remain the baseline, subject to Finnish-specific qualifications for journalism, academic, artistic, and literary expression; scientific and historical research; statistics; public-interest archiving; information duties; access restrictions; authorities; and processing of the personal identity code. No general exemption removing all Chapter III rights was found. Finland's Constitution requires Acts to be published in Finnish and Swedish, and no official source was located establishing that one national-language version controls over the other. The Office of the Data Protection Ombudsman instructs individuals to contact the controller first and then submit a notification. Anonymous notifications are possible, although the notifier cannot then be contacted about the outcome. Data Protection Act §21 requires processing within three months or notification of an estimated decision date; the Office's approximately one-year figure is a target, not a fixed final-resolution deadline. GDPR fines are decided through a dedicated sanctions board, the seuraamuskollegio.
At a glance
- Full name
- Data Protection Act 1050/2018
- Short code
- Data Protection Act 1050/2018
- Jurisdiction
- Finland
- Enacted
- 2018
- Last major update
- Amendments 869/2020, 902/2020, 1112/2022, 239/2023, 1225/2023, 29/2024, and 437/2025 are recorded in the current consolidation; Act 380/2026 entered into force on 1 September 2026
- Regulator
- Office of the Data Protection Ombudsman
- Private right of action
- Limited
- Statutory citation
- Data Protection Act 1050/2018
Scope, who Data Protection Act 1050/2018 covers
Protected data
Data subject rights
Right to transparent information about processing
Right to collection-time information under Articles 13-14
Right of access under Article 15
Right to rectification under Article 16
Right to erasure under Article 17, subject to exceptions
Right to restriction of processing under Article 18
Right to data portability under Article 20
Right to object under Article 21
Safeguards concerning automated decision-making under Article 22
Right to submit a notification to the Office of the Data Protection Ombudsman, including anonymously
Notable features
Finland supplements GDPR with targeted rules for expression, research, statistics, archiving, authorities, public-interest confidentiality, and personal identity codes. The Office of the Data Protection Ombudsman and deputy Ombudsmen form a dedicated sanctions board for administrative fines. Finland publishes official Finnish and Swedish texts, while the Finlex English version is an unofficial translation; no official source was located establishing that one national-language version controls over the other. Act 380/2026 entered into force on 1 September 2026.
Enforcement & penalties
Regulator: Office of the Data Protection Ombudsman
Penalties: No separate Finnish-wide euro fine schedule applying to all controllers was located. Data Protection Act §24 adopts the GDPR Article 83 structure directly: up to €10 million or 2% of worldwide annual turnover for Article 83(4) infringements, and up to €20 million or 4% of worldwide annual turnover for Articles 83(5)-(6), whichever is higher. State authorities and enterprises, municipal authorities, independent public-law institutions, Parliament-related offices, the Office of the President, and specified Evangelical-Lutheran and Orthodox Church bodies are excluded from administrative fines. The sanctions board decides GDPR administrative fines through a collegial process.
Private right of action: An administrative-court appeal route is available if the Ombudsman does not process a GDPR Article 77 complaint within three months or provide an estimated decision date. A standalone private damages action was not identified; the administrative-court route should not be described as a general private right of action.
Relevance to data brokers
A Finland-specific general data-broker or public-record consumer deletion route was not located. The general GDPR erasure route applies through an Article 17 request to the relevant controller, subject to standard exceptions. The Credit Information Act provides sector-specific access and correction rights; the Population Information System Act and Positive Credit Register Act contain statutory purpose, disclosure, retention, and removal rules, but no general consumer deletion route equivalent to a universal broker opt-out was located.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
Is Finland’s current data-protection law fully reflected by the original 2018 text?+
No. The current consolidation records amendments through 437/2025, and Act 380/2026 entered into force on 1 September 2026. The original 2018 text should therefore not be treated as the complete operative framework.
How can I complain to Finland’s Data Protection Ombudsman?+
Contact the controller first, then submit a notification through the Office’s official route. Anonymous notifications are possible, although an anonymous notifier cannot later be contacted about the outcome. Section 21 requires processing within three months or notification of an estimated decision date; the Office’s approximately one-year figure is a target, not a fixed final-resolution deadline.
Does Finland have a dedicated data-broker deletion route?+
A Finland-specific general data-broker or public-record consumer deletion route was not located. The general route is a GDPR Article 17 request to the relevant controller, alongside sector-specific credit-information and registry mechanisms that do not amount to a universal broker opt-out.
Official sources & citations
Other international privacy regimes
Data Protection Act 1050/2018 sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
