Cybersecurity 2026

FINLAND Law and Practice Contributed by: Rosa Lång, Joona Linner, Toni Tainio and Oliver Lönnblad, Lieke Attorneys Ltd

• Cybersecurity Act: the Transport and Communica - tions Agency (Traficom), the Energy Authority, the Finnish Safety and Chemicals Agency (Tukes), the Finnish Supervisory Agency, the Economic Devel - opment Centres, the Finnish Food Authority and the Finnish Medicines Agency (Fimea) supervise compliance with the Cybersecurity Act within their respective sectors. These authorities have the right to obtain information, conduct inspections and require actors to conduct a safety audit. Their enforcement powers include imposing penalty payments, enforcing compliance and suspending non-compliant activities, restricting persons from acting in the management of essential entities, and proposing an administrative fine. The final decision on an administrative fine is made by the Adminis - trative Fine Board operating under the Ministry of Transport and Communications. The same authori - ties also supervise compliance with the Act on the Protection of Infrastructure Critical to Society and Improvement of Resilience, but their enforcement powers under that Act are limited to penalty pay - ments, enforced compliance and non-compliance fees. • The Computer Security Incident Response Team (CSIRT), operating under the National Cyber Secu - rity Centre Finland (NCSC-FI) of Traficom, monitors and analyses cyber threats and vulnerabilities, and provides cybersecurity information and support. The CSIRT does not supervise entities subject to the Cybersecurity Act, and its activities are accord - ingly organised separately from the supervisory functions described above. Its activities are based on trust and voluntary security breach notifications. The CSIRT may use non-intrusive methods to con - duct vulnerability assessments on networks and IT systems connected to the general communications network, and its responsibilities include responding to incident notifications, assisting notifying enti - ties and, where necessary, conducting technical investigations of serious security breaches. It also participates in maintaining national cybersecurity situational awareness and issues early warnings, alerts and notifications. The supportive role of the CSIRT is also recognised in the Cybersecurity Act, which provides that information voluntarily dis - closed to the CSIRT may not, without consent from the disclosing party, be used in criminal investiga -

tions or administrative or other decision-making directed at the disclosing party. • Traficom is the competent authority for public authorities under Chapter 4a of the Act on Infor - mation Management in Public Administration. Its supervisory powers are similar to those of the competent authorities under the Cybersecurity Act. Enforcement powers include issuing a formal notice, requiring the publication of details of non- compliance and imposing penalty fines. • DORA: the Financial Supervisory Authority is the competent authority under DORA. It has informa - tion and investigation powers and can impose penalties and administrative fines, as well as give public warnings for non-compliance. • GDPR and data protection: the Data Protection Ombudsman is the competent authority under the GDPR and national data protection legislation. It has the right to obtain information and conduct investigations, and the ability to impose penalty payments and administrative fines. • The Finnish Supervisory Agency supervises infor - mation systems and wellbeing applications under the Client Data Act. It can conduct investigations and request information, and its enforcement pow - ers include prohibiting the use of non-compliant systems and penalty payments. • CRA: Traficom is the main competent author - ity under the Act on Electronic Communications Services and the CRA, as well as the certification authority under the EU Cybersecurity Act. The supervisory and enforcement powers under the Act on Electronic Communications Services largely correspond to the powers of competent authori - ties under the Cybersecurity Act, while the powers under the CRA are similar to general market sur - veillance powers (see 4.2 Key Obligations Under Legislation ). 2. Critical Infrastructure Cybersecurity Regulation 2.1 Scope of Critical Infrastructure Cybersecurity Regulation The regulation on cybersecurity for critical infra - structure is primarily set out in the Cybersecurity Act (124/2025), which applies to entities considered

100 CHAMBERS.COM

Powered by