Cybersecurity 2026

FINLAND Law and Practice Contributed by: Rosa Lång, Joona Linner, Toni Tainio and Oliver Lönnblad, Lieke Attorneys Ltd

Cybersecurity and Data Protection The General Data Protection Regulation (Regulation (EU) 2016/679) (GDPR) sets out extensive rules for the processing of personal data in organisations. The Data Protection Act (1050/2018, Tietosuojalaki ) complements the GDPR, as do special data protec - tion provisions in many other acts. These instruments specify and ensure the effective implementation of the GDPR. The Act on the Processing of Client Data in Healthcare and Social Welfare (703/2023, Laki sosiaali- ja tervey- denhuollon asiakastietojen käsittelystä ) (the “Client Data Act”) applies to data processing and information systems in the healthcare and social welfare sectors, supplementing the requirements set out in the Finnish Data Protection Act and the GDPR. The Act on the Secondary Use of Health and Social Data (552/2019, Laki sosiaali- ja terveystietojen toissi- jaisesta käytöstä ) facilitates the effective and safe pro - cessing of, and access to, personal social and health data for steering, supervision, research, statistics and development in the health and social sectors. The Act on Electronic Communications Services (917/2014, Laki sähköisen viestinnän palveluista ) applies to electronic communications service provid - ers. It ensures the quality, safety and reliability of com - munication networks and services, as well as promot - ing fair competition and confidentiality and privacy in electronic communication. Other Relevant Legislation Applicable in Finland The Artificial Intelligence Act) (Regulation (EU) 2024/1689) (the “AI Act”) creates a unified EU frame - work with risk-based classifications to ensure the safety and trustworthiness of AI systems. The CER Directive (Directive (EU) 2022/2557) has been implemented in national legislation, as described below. The Act on the Protection of Infrastructure Critical to Society and Improvement of Resilience (310/2025, Laki yhteiskunnan kriittisen infrastruktuurin suojaamis- esta ja häiriönsietokyvyn parantamisesta ) implements

the CER Directive. The Act strengthens societal crisis resilience and national safety by ensuring the uninter - rupted functioning of the most essential services. Enti - ties considered critical actors under this Act are auto - matically subject to the Cybersecurity Act. The Act extends risk management obligations beyond infor - mation and communication networks to also cover the physical environment relating to critical infrastructure. The Criminal Code (39/1889, Rikoslaki ) contains penal provisions concerning cybercrimes, including, for example, Chapter 38 on data and communications offences and Chapter 35, Sections 3a–3c on criminal damage to data. The eIDAS Regulation (Regulation (EU) No 910/2014) establishes the regulatory framework for electronic identification and trust services within the EU. The regulation ensures secure electronic transactions across member states and sets standards for elec - tronic signatures and other trust services. In summary, the Cybersecurity Act sets out minimum cybersecurity requirements, but more specific require - ments imposed by other regulations may be applied in addition to or instead of the Cybersecurity Act. Chap - ter 4a of the Act on Information Management in Pub - lic Administration implements NIS 2 directive require - ments for public administration entities; for such entities, this provision applies instead of the national Cybersecurity Act. DORA applies primarily to financial sector entities instead of the national Cybersecurity Act, creating a sector-specific regulatory framework. The GDPR, Data Protection Act and cybersecurity legislation overlap particularly regarding data security breaches. Criminal law provisions, particularly in the Criminal Code, complement cybersecurity regulation by establishing criminal liability for cybercrimes such as data breaches, unauthorised access to information systems, and disruption of information systems. 1.3 Cybersecurity Regulators The competent authorities enforcing cybersecurity legislation are quite fragmented. The authorities are outlined below, grouped by the statutes or topics they enforce; certain authorities with unique mandates are presented separately.

99 CHAMBERS.COM

Powered by