country: Finland framework: GDPR region: EU language: fi version: 2024-06 status: published last_updated: 2025-06-30 source_verified: true authority: Tietosuojavaltuutetun toimisto – Office of the Data Protection Ombudsman notes: - Finland enforces GDPR alongside the Finnish Data Protection Act (Tietosuojalaki 1050/2018). - The Office of the Data Protection Ombudsman provides national guidance particularly in education, social services, employment, and biometric use. categories: - name: Full Name type: direct_identifier subtype: personal_name required_masking: true tags: - pii citations: - regulation: GDPR article: 4(1) category_tags: - core - identity - name: Email Address type: direct_identifier subtype: digital_contact required_masking: true tags: - pii citations: - regulation: GDPR article: 4(1) category_tags: - core - contact - name: Phone Number type: direct_identifier subtype: telecom_contact required_masking: true tags: - pii citations: - regulation: GDPR article: 4(1) category_tags: - core - contact - name: IP Address type: indirect_identifier subtype: network_identifier required_masking: true tags: - tracking citations: - regulation: GDPR recital: '30' - authority: Tietosuojavaltuutettu guideline: Verkkoseuranta ja evästeet url: https://tietosuoja.fi/evasteet category_tags: - digital - behavioral - name: Henkilötunnus (Finnish Personal Identity Code) type: national_identifier subtype: government_id required_masking: true tags: - pii - national_id - government_id citations: - regulation: GDPR article: '87' - national_law: Tietosuojalaki 1050/2018 section: 29 § description: Restricts processing of the Finnish identity code to specific legal bases category_tags: - identity - sensitive - name: Health Data (patient information, diagnoses, care history) type: special_category subtype: health required_masking: true tags: - phi - sensitive citations: - regulation: GDPR article: 9(1) - authority: Tietosuojavaltuutettu guideline: Tietosuoja sosiaali- ja terveydenhuollossa url: https://tietosuoja.fi/sosiaali-ja-terveydenhuolto category_tags: - health - sensitive - name: Biometric Data (fingerprint, iris, voice recognition) type: special_category subtype: biometric required_masking: true tags: - biometric - sensitive citations: - regulation: GDPR article: 9(1) category_tags: - biometric - sensitive - name: Location Data (transport logs, GPS, mobile tracking) type: behavioral subtype: geolocation required_masking: true tags: - tracking citations: - regulation: GDPR article: 4(1) category_tags: - tracking - digital - name: Cookie Identifiers / Device Fingerprints type: indirect_identifier subtype: device_id required_masking: true tags: - tracking - online_identifier - pii citations: - regulation: GDPR recital: '30' - authority: Tietosuojavaltuutettu guideline: Evästeiden käyttö verkkopalveluissa url: https://tietosuoja.fi/evasteet category_tags: - tracking - digital - name: Employment Records (working hours, HR reviews, contracts) type: contextual_identifier subtype: hr_data required_masking: true tags: - pii - hr_data - employment_contracts citations: - regulation: GDPR article: '88' - national_law: Tietosuojalaki 1050/2018 section: 4 luku description: Addresses personal data processing in the context of employment category_tags: - employment - sensitive