Cybersecurity 2026

FINLAND Law and Practice Contributed by: Rosa Lång, Joona Linner, Toni Tainio and Oliver Lönnblad, Lieke Attorneys Ltd

would constitute the primary means of demonstrat - ing the conformity of those products with the applica - ble cybersecurity requirements and of ensuring their access to the EU internal market. In the context of public procurement, contracting authorities and entities may require certified ICT prod - ucts, services or processes as part of their procure - ment procedures. The NIS 2 Directive further permits (but does not oblige) member states and the Commis - sion to impose such requirements on entities falling within its scope. 6. Cybersecurity in Other Regulations 6.1 Cybersecurity and Data Protection Regulatory Framework for Data Protection The main source of personal data protection legisla - tion in Finland is the GDPR. This is supplemented by the Finnish Data Protection Act (1050/2018, Tietosuo- jalaki ), the Act on Electronic Communications Services (917/2014, Laki sähköisen viestinnän palveluista ) and the Act on the Protection of Privacy in Working Life (759/2004, Laki yksityisyyden suojasta työelämässä ). Cybersecurity Obligations The GDPR includes three types of cybersecurity-relat - ed obligations: • obligations on ensuring the security of personal data processing; • notification obligations in cases of personal data breaches; and • principles of information security-based processing of personal data. Security of personal data processing The GDPR includes multiple requirements for ensuring the security of personal data processing. The central obligation is ensuring the integrity and confidentiality of processing. Further specific obligations include risk management, data protection by design and default, and requirements for security of processing – namely, Articles 5 (1)(f), 25, 28 32, 33, 34 and 35. In particu - lar, the GDPR requires controllers and processors to implement appropriate technical and organisational

measures to ensure a level of security appropriate to the risk, including, where appropriate: • the pseudonymisation and encryption of personal data; • the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services; • the ability to restore the availability of and access to personal data in a timely manner in the event of an incident; and • a process for regularly testing, assessing and evaluating the effectiveness of such measures. Notification obligations The GDPR requires controllers to notify the competent authority (the Data Protection Ombudsman in Finland) and data subjects of personal data breaches. A per - sonal data breach is defined as a breach of security leading to the accidental or unlawful destruction, loss, alteration or unauthorised disclosure of, or access to, personal data. The notification to the Data Protection Ombudsman must be made within 72 hours after becoming aware of the breach, unless the controller is able to dem - onstrate that the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. The notification must include at least: • a description of the nature of the breach including, where possible, the categories and approximate number of data subjects and personal data records concerned; • the name and contact details of the data protection officer or other contact point; • a description of the likely consequences of the breach; and • a description of the measures taken or proposed to address the breach and mitigate its possible adverse effects. A breach must also be communicated to data sub - jects without undue delay if it is likely to result in a high risk to the rights and freedoms of natural persons, and if none of the exceptions under Article 34 (3) of the GDPR apply. The communication to data subjects must describe the nature of the breach in clear and

108 CHAMBERS.COM

Powered by