- News
National Data Protection Act enters into force on January 1, 2019
The EU's General Data Protection Regulation, or GDPR It entered into force on May 25, 2018, and, in principle, applies to all processing of personal data. Under the national leeway provided for in the General Data Protection Regulation, member states were required to enact their own laws, and the Finnish Parliament has now ratified these laws on its part, as the national Data Protection Act comes into effect. This is supplementary legislation that must be applied in conjunction with the General Data Protection Regulation. From Finland’s perspective, the Data Protection Act establishes certain exceptions and clarifications to the EU’s General Data Protection Regulation. These include, for example, the reconciliation of freedom of expression and the protection of personal data, the provision of information society services directly to children, and regulations concerning certain specific groups of individuals. The processing of personal data concerning specific categories of individuals may occur, for example, in connection with insurance activities, trade union membership, or services organized and provided by health and social welfare service providers. To safeguard freedom of speech—for example, in journalism—exceptions and exemptions are also provided for, which, among other things, limit individuals’ right to access information concerning themselves. Exceptions also apply to research, archiving, and statistics. In Finland, it was decided that a child must be at least 13 years old to be directly provided with information society services. Children younger than this must have parental consent to use any social media services that require the provision of personal data. The responsibility for ensuring that consent has been obtained lies with the service provider, i.e., the data controller. The EU regulation allowed for an age range of 13 to 16 years. All official duties required by the General Data Protection Regulation are centralized under the Data Protection Ombudsman. The Sanctions Board to be established within the Office of the Data Protection Ombudsman has the authority to impose administrative fines for violations of the regulations. These fines range from a minimum of 10 million euros or 2% of total global turnover to a maximum of 20 million euros or 4% of total global turnover. The Data Protection Ombudsman also has access to less severe enforcement options. It is worth noting that administrative fines cannot be imposed on public authorities or public administration organizations. The Data Protection Act also contains a provision regarding the protection of the whistleblower’s identity. This means that the identity of a person reporting a suspected violation of the regulations must be kept confidential if, based on the circumstances, it can be assessed that disclosure would cause harm to the whistleblower. The Data Protection Act and related legislative amendments also include provisions regarding data protection offenses. Such an offense may occur if a person employed by a data controller unlawfully accesses personal data contrary to its intended purpose. The penalty may include a fine or imprisonment for up to one year. The turn of the year is a good time to review your company’s data protection practices and ensure compliance with both the EU General Data Protection Regulation (GDPR) and the national Data Protection Act. Protect also has expertise in GDPR matters, and we are happy to support companies in ensuring compliance.