FINLAND Law and Practice Contributed by: Rosa Lång, Joona Linner, Toni Tainio and Oliver Lönnblad, Lieke Attorneys Ltd
important or essential across various sectors. Most of the obligations set out in the Act apply to both impor - tant and essential entities, with the distinction relating predominantly to the supervisory measures available to the authorities and the severity of applicable sanc - tions. Most small and micro-enterprises (maximum turnover of EUR10 million and fewer than 50 employees) are excluded from the scope of the Cybersecurity Act. However, if an entity has partner enterprises or linked enterprises, as defined in Commission Recommen - dation 2003/361/EC, said entity may fall within the scope of the Cybersecurity Act even if its individual turnover and personnel numbers are below the appli - cable thresholds. Certain entities are subject to the requirements of the Cybersecurity Act regardless of their size, including: • providers of public electronic communications networks or publicly available electronic communi - cations services; • trust service providers; • top-level domain name registry operators; • DNS service providers; and • entities designated as critical under the Act on the Protection of Infrastructure Critical to Society and Improvement of Resilience (310/2025). For these so-called “CER-critical entities”, the Act on the Protection of Infrastructure Critical to Society and Improvement of Resilience is applied in parallel to the Cybersecurity Act. It applies to entities that are considered critical to society due to, for exam - ple, the crucial nature of their services for maintain - ing vital societal functions or their role in operating critical infrastructure in Finland, or a significant risk of adverse effects on the provision of critical services if they were to be subject to an incident. However, enti - ties do not need to make this assessment themselves; rather, the competent authorities make this designa - tion and are required to do so by 17 July 2026. In addition, the Cybersecurity Act applies to an entity regardless of its size if it carries out activities referred to in Annex I or II, or if it is an entity referred to in those Annexes, and if:
• it provides a service that is essential for the main - tenance of critical societal or economic functions and that is not provided by other entities; • a disruption to the service it provides could have a significant impact on public order, public safety or public health; • a disruption to the service it provides could cause a significant systemic risk, particularly in sectors where such a disruption could have cross-border effects; or • it is critical due to its particular importance at national or regional level for the sector or type of service concerned, or for other interdependent sectors in any EU member state. According to the Cybersecurity Act, more detailed guidelines on the designation of critical entities can be issued in secondary legislation (a Government Decree). At the time of writing, no such decree has been issued, and therefore the interpretation of the criteria for size-independent critical entities remains uncertain. Activities in the areas of national or public security, defence or law enforcement, including the prevention, investigation, detection and prosecution of criminal offences, are excluded from the scope of the Cyber - security Act. Instead of the Cybersecurity Act, Chapter 4a of the Act on Information Management in Public Adminis - tration (906/2019) applies to most public authorities. However, certain entities fall largely outside the scope of cybersecurity regulation, including courts, universi - ties, organs connected to the Parliament, the Office of the President of the Republic and various authorities involved in defence or the criminal justice system. Sectors in Scope of the Cybersecurity Act The sectors within the scope of the Cybersecurity Act and the respective sector-specific competent authori - ties are listed below. Highly critical sectors (Annex I to the Cybersecurity Act) The following sectors are deemed to be highly critical, and are subject to the oversight of the listed authority:
101 CHAMBERS.COM
Powered by FlippingBook