FineME
Run assessment
Back to Authorities
BalancedFI

Tietosuojavaltuutettu

Office of the Data Protection Ombudsman

Measured Finnish enforcer focused on lawful basis, telecoms, and employee privacy.

Avg. Investigation

15months

Enforcement Intensity
Priority Sectors

Employment, Telecom, Healthcare

Official Website

Enforcement Cases (10)

Mehiläinen Oy

technology
TIETOSUOJAVALTUUTETTU2024

The Ombudsman fined Mehiläinen for inadequate governance over processor access to patient systems and insufficient audit logging under GDPR Articles 28 and 32.

€210,000.0

DNA Oyj

technology
TIETOSUOJAVALTUUTETTU2023

The authority found deficiencies in customer authentication and disclosure controls that risked unauthorized access to subscriber data under GDPR Articles 25 and 32.

€95,000.0

Kela

technology
TIETOSUOJAVALTUUTETTU2023

The Ombudsman sanctioned Finland's social insurance institution over insufficient access restrictions to sensitive benefits data, citing GDPR Articles 5, 24 and 32.

€140,000.0

Wolt Enterprises Oy

technology
TIETOSUOJAVALTUUTETTU2023

The authority examined Wolt's customer and courier data processing, highlighting transparency and lawful-basis issues around profiling and service analytics under GDPR Articles 6, 13 and 22.

€110,000.0

City of Espoo

technology
TIETOSUOJAVALTUUTETTU2022

The Ombudsman criticized Espoo for excessive retention of student welfare records and incomplete information notices, implicating GDPR Articles 5 and 13.

€70,000.0

Sanoma Media Finland

technology
TIETOSUOJAVALTUUTETTU2022

The authority reviewed cookie and advertising consent flows and found insufficient granularity and transparency under GDPR Articles 5, 6, 7 and ePrivacy-related requirements.

€85,000.0

HUS Helsinki University Hospital

technology
TIETOSUOJAVALTUUTETTU2022

The Ombudsman sanctioned HUS over unauthorized internal access to patient records and insufficient monitoring of user activity, engaging GDPR Articles 5, 24 and 32.

€300,000.0

Telia Finland Oyj

technology
TIETOSUOJAVALTUUTETTU2021

The authority found Telia's direct-marketing consent and objection handling insufficient, citing GDPR Articles 6, 7, 12 and 21.

€250,000.0

Yliopiston Apteekki

technology
TIETOSUOJAVALTUUTETTU2021

The Ombudsman fined a pharmacy operator for inadequate access controls and retention practices affecting prescription and customer data under GDPR Articles 5 and 32.

€180,000.0

Posti Group Oyj

technology
TIETOSUOJAVALTUUTETTU2020

Finland's Data Protection Ombudsman sanctioned Posti for excessive employee location and work-performance monitoring without adequate lawful basis or transparency, implicating GDPR Articles 5, 6 and 13.

€100,000.0