Tietosuojavaltuutettu
Office of the Data Protection Ombudsman
Measured Finnish enforcer focused on lawful basis, telecoms, and employee privacy.
15months
Employment, Telecom, Healthcare
Enforcement Cases (10)
Mehiläinen Oy
technologyThe Ombudsman fined Mehiläinen for inadequate governance over processor access to patient systems and insufficient audit logging under GDPR Articles 28 and 32.
€210,000.0
DNA Oyj
technologyThe authority found deficiencies in customer authentication and disclosure controls that risked unauthorized access to subscriber data under GDPR Articles 25 and 32.
€95,000.0
Kela
technologyThe Ombudsman sanctioned Finland's social insurance institution over insufficient access restrictions to sensitive benefits data, citing GDPR Articles 5, 24 and 32.
€140,000.0
Wolt Enterprises Oy
technologyThe authority examined Wolt's customer and courier data processing, highlighting transparency and lawful-basis issues around profiling and service analytics under GDPR Articles 6, 13 and 22.
€110,000.0
City of Espoo
technologyThe Ombudsman criticized Espoo for excessive retention of student welfare records and incomplete information notices, implicating GDPR Articles 5 and 13.
€70,000.0
Sanoma Media Finland
technologyThe authority reviewed cookie and advertising consent flows and found insufficient granularity and transparency under GDPR Articles 5, 6, 7 and ePrivacy-related requirements.
€85,000.0
HUS Helsinki University Hospital
technologyThe Ombudsman sanctioned HUS over unauthorized internal access to patient records and insufficient monitoring of user activity, engaging GDPR Articles 5, 24 and 32.
€300,000.0
Telia Finland Oyj
technologyThe authority found Telia's direct-marketing consent and objection handling insufficient, citing GDPR Articles 6, 7, 12 and 21.
€250,000.0
Yliopiston Apteekki
technologyThe Ombudsman fined a pharmacy operator for inadequate access controls and retention practices affecting prescription and customer data under GDPR Articles 5 and 32.
€180,000.0
Posti Group Oyj
technologyFinland's Data Protection Ombudsman sanctioned Posti for excessive employee location and work-performance monitoring without adequate lawful basis or transparency, implicating GDPR Articles 5, 6 and 13.
€100,000.0