← Regulators
GDPR EU 2016/679 Finland

Who is Tietosuojavaltuutettu: Finland's Data Protection Ombudsman

Tietosuojavaltuutetun toimisto is Finland's GDPR supervisory authority — one of the oldest in Europe (1987). What it does, how the collegial Sanctions Board works, why its head also chairs the EU's data-protection board (EDPB), and the €2.4M Posti fine that the Helsinki Administrative Court later annulled.

If you received a letter from Tietosuojavaltuutetun toimisto, saw it mentioned in GDPR fine news, or are just trying to figure out who regulates privacy in Finland — this is a profile of the body, with every fact sourced. Spoiler: the office is one of the oldest data-protection authorities in Europe, and the person currently running it is also chairing the EU-wide body that coordinates all national data-protection authorities (DPAs).

Quick facts

  • Finnish name: Tietosuojavaltuutetun toimisto
  • English name: Office of the Data Protection Ombudsman
  • Founded: 1987 — established by Henkilörekisterilaki 471/1987 (the Personal Data Files Act, Finland’s first personal-data law)
  • Data Protection Ombudsman: Anu Talus — first appointed 1 November 2020, reappointed by the Government on 27 June 2025 for a second five-year term running 1 November 2025 — 31 October 2030
  • Deputy Ombudsmen (members of the Sanctions Board): Heljä-Tuulia Pihamaa (since 22 March 2021), Annina Hautala (since 1 September 2022)
  • Headcount: ~65 specialists
  • Mandate: GDPR + national Tietosuojalaki 1050/2018 + privacy provisions of the Information Society Code
  • Largest GDPR fine ever imposed: €2,400,000 against Posti Jakelu Oy on 13 November 2024 (Articles 5, 6, 13, 25 GDPR — unlawful electronic-mailbox enrolment) — annulled in full by the Helsinki Administrative Court on 3 November 2025; the transparency reprimand and corrective order remain in force, only the fine itself was struck down
  • Bonus: the Ombudsman also serves as Chair of the European Data Protection Board (since 25 May 2023)
  • Website: tietosuoja.fi

What “Tietosuojavaltuutettu” actually means

Tietosuojavaltuutetun toimisto translates literally as Office of the Data Protection Ombudsman — and that is what the authority calls itself in English. In English-language coverage three forms appear interchangeably: “the Finnish Data Protection Ombudsman”, “the Finnish DPA”, or simply Tietosuojavaltuutettu (which is the ombudsman herself; toimisto is her office).

Finland never settled on a short acronym the way France did with CNIL or Estonia with AKI — texts use the full name, “the Ombudsman”, or “the DPA”. For brevity below: “the ombudsman”.

Every EU country has such a body — in GDPR’s own language they are supervisory authorities. To anchor expectations:

  • AKI — Andmekaitse Inspektsioon in Estonia
  • CNIL in France
  • BfDI in Germany (plus one DPA per federal state)
  • DPC in Ireland (the famous one — Meta, Google and Apple’s EU HQs are all in Ireland)
  • Garante in Italy
  • AEPD in Spain
  • Datatilsynet in Norway and Denmark
  • IMY in Sweden (formerly Datainspektionen — see history below)

The Finnish ombudsman is the local equivalent, scaled to a country of 5,650,152 people (Statistics Finland, end of April 2026).

The Finns were doing data protection before it was cool

The position of Tietosuojavaltuutettu has existed in Finland since 1987, established by Henkilörekisterilaki 471/1987 — the Personal Data Files Act, Finland’s first national personal-data law (the law and the office on Finlex, the official Finnish legal gazette).

For context:

  • Finland joined the EU only in 1995
  • The first European data protection directive (95/46/EC) — also 1995
  • GDPR — 2018

So Finland had a national data protection ombudsman eight years before joining the EU and eight years before the EU’s first data protection directive. This isn’t EU-driven implementation — it’s a Nordic tradition that the EU later overlaid GDPR on top of.

For comparison, Sweden’s equivalent is even older: Datainspektionen was established by Datalagen of 11 May 1973 — the world’s first national data protection law, in force from 1 July 1974. The Swedish authority renamed itself to IMY (Integritetsskyddsmyndigheten) on 1 January 2021. Finland’s ombudsman therefore isn’t the oldest in Europe but solidly in the “first wave” — alongside France’s CNIL (1978) and decades ahead of Estonia’s AKI (founded 15 February 1999).

What the ombudsman actually does

Per the office’s own description, the ombudsman supervises compliance with data protection legislation. By section, what that means in practice.

1. GDPR and Tietosuojalaki supervision

Tietosuojalaki 1050/2018 is Finland’s Data Protection Act, the national companion to GDPR. GDPR is a directly applicable EU regulation; Tietosuojalaki adds Finland-specific bits: procedures, journalism and scientific-research carve-outs, fining provisions, and special rules for processing the personal identity code (henkilötunnus).

The ombudsman:

  • receives and investigates complaints from individuals and companies
  • runs proactive audits
  • issues orders to fix violations
  • imposes administrative fines via the Sanctions Board (see below)
  • publishes guidance on how GDPR applies in the Finnish context
  • maintains the register of Data Protection Officers at Finnish organisations

2. Electronic communications privacy

The ombudsman also covers privacy in electronic communications — what at the EU level falls under the ePrivacy directive (the 2002 EU directive, separate from GDPR, that governs tracking technologies on websites, telecom metadata, and the privacy of phone-call and SMS data; the same directive that requires “we use cookies” banners). The Finnish implementation lives in the Information Society Code (Laki sähköisen viestinnän palveluista). If a Finnish telecom or website drops trackers without consent, that is the ombudsman’s home turf.

3. EU-level coordination

This is where Finland punches above its weight: the Chair of the EDPB (European Data Protection Board) is the Finnish ombudsman herself, Anu Talus.

EDPB is the EU-wide body coordinating all national DPAs across the EEA. It issues binding guidelines, resolves cross-border disputes via Article 65 GDPR decisions, and effectively sets the direction of European privacy enforcement for years at a time. Talus was elected Chair on 25 May 2023 for a five-year term — meaning her current EDPB mandate runs to 2028, during which she simultaneously runs the Finnish authority and chairs the EU-wide one.

For a country of 5.65 million people, this is unusual. Estonia’s AKI, Lithuania’s VDAI or Latvia’s DVI have never seriously contended for the EDPB chair.

Leadership

The current ombudsman is Anu Talus, a lawyer by training (Doctor of Laws, University of Helsinki). Before her current role she spent over a decade at Finland’s Ministry of Justice as Senior Adviser, where she led the national implementation of GDPR.

  • 1 May 2019 — took office as Deputy Data Protection Ombudsman (apulaistietosuojavaltuutettu) following appointment by the Government on 25 April 2019
  • 1 November 2020 — Data Protection Ombudsman, succeeding Reijo Aarnio, who had held the post since 1997 (23 consecutive years)
  • 25 May 2023 — elected Chair of the EDPB (five-year term)
  • 27 June 2025 — Government reappointed her for a second five-year ombudsman term running 1 November 2025 — 31 October 2030

Interesting contrast with Estonia: AKI’s Director General is also appointed for five-year terms, but turnover is more frequent. In Finland, Aarnio sat for 23 years and that was considered normal. Institutional stability as a value in itself.

Structure: the Sanctions Board as a collegial mini-tribunal

This is arguably the biggest structural difference from neighbouring DPAs.

In most DPAs, fines are imposed either by the director personally or by a board of commissioners voting in plenary. In Finland it works differently: the Seuraamuskollegio (Sanctions Board) is a three-person collegial body — the ombudsman herself plus the two deputy ombudsmen. The ombudsman chairs.

Current members:

  • Anu Talus, Data Protection Ombudsman (chair)
  • Heljä-Tuulia Pihamaa, Deputy Data Protection Ombudsman (since 22 March 2021)
  • Annina Hautala, Deputy Data Protection Ombudsman (since 1 September 2022)

Per the office’s description: “The Data Protection Ombudsman and the Deputy Data Protection Ombudsmen form the Sanctions Board, which is tasked with imposing administrative fines in accordance with the General Data Protection Regulation.” Maximum fine — the GDPR ceiling: €20 million or 4% of global annual turnover.

Important date: the Sanctions Board first exercised its fining powers on 18 May 2020 — i.e. Finland began actually enforcing GDPR with administrative fines exactly two years after the regulation took effect (more on those first cases below). Estonia’s AKI only acquired that ability against legal entities after the November 2023 Penal Code reform. Finland cleared this hurdle on day one, with no need for legislative repair.

Beyond the Sanctions Board, the office also has an Expert Board — an independent advisory body issuing opinions on tricky data protection questions. Current term: 1 May 2024 – 30 April 2027. Members: Riikka Koulu (Chair), Sami Kivivasara (Vice Chair), Riikka Rosendahl, Kimmo Rousku, Tommi Toivola.

Resources

By the office’s current descriptionabout 65 specialists. For context: in 2019, per the personnel-and-finances page, the office employed 46 people. So headcount has grown by roughly 40% over five years — tracking the Europe-wide GDPR-complaints surge.

The caseload is heavy for that size. In 2024 the office opened 13,284 new cases and closed 13,291, and — as for several years running — personal-data-breach notifications were the single largest category, at 7,152 (Annual Report 2024). Since GDPR took effect, more than 30,000 breach notifications have been filed in total.

For sense of scale:

  • Finland: ~65 DPA staff over 5.65M population = ~11.5 per million inhabitants
  • Estonia: AKI has 34 civil service positions over 1.36M = ~25 per million (proportionally larger but in absolute terms much smaller)
  • Ireland: DPC, the routing point for Meta/Google/Apple cases, runs close to 250 staff over 5.3M population — deliberately oversized to handle cross-border one-stop-shop work

The Finnish ratio is typical for a country whose DPA actively works local complaints but isn’t the funnel point for global big-tech enforcement.

Enforcement: from €100,000 to €2,400,000

The first fines (18 May 2020)

The Sanctions Board imposed administrative fines for the first time on 18 May 2020 — three companies on the same day, marking Finland’s transition from advisory to enforcement mode:

  • Posti Oy (the Finnish postal service) — €100,000 for failing to inform data subjects (the people whose data is being processed — under GDPR every individual has rights regarding their own data) of their rights regarding change-of-address notifications (EDPB record)
  • Kymen Vesi Oy (a regional water utility) — €16,000 for not conducting a Data Protection Impact Assessment (DPIA) — a formal risk-analysis document required by GDPR Article 35 before launching any high-risk processing activity, in this case tracking employee location data
  • A third (unnamed) employer was fined €12,500 for collecting unnecessary personal data from job applicants and employees, including information on religious beliefs, health, possible pregnancy, and family status

These three cases established the operational pattern: not headline-grabbing amounts, but administered systematically, with detailed reasoning and a focus on transparency, lawful basis, and DPIAs. Subsequent fines through 2021–2023 followed the same template at low six-figure scales.

Verkkokauppa.com (€792,639 — reduced by the court, upheld by the Supreme Court June 2026)

On 6 March 2024 the Sanctions Board imposed a €856,000 fine on online retailer Verkkokauppa.com Oyj (ombudsman press release; EDPB record). Two violations:

  • the company required customers to register an account in order to make an online purchase. This breaches the data minimisation principle (GDPR Article 5(1)(c) — companies must collect only the personal data they actually need; you don’t need an account to take a payment and ship a parcel)
  • it stored customer-account data indefinitely, with no defined retention period. This breaches the storage limitation principle (Article 5(1)(e) GDPR — personal data must be kept only as long as necessary for its purpose, then deleted)

Verkkokauppa.com appealed. In February 2025 the Helsinki Administrative Court largely rejected the appeal — the underlying violations were upheld — but reduced the fine to €792,639 based on revised revenue figures (ess.fi / Uutissuomalainen, 26 February 2025). The company appealed further, and on 12 June 2026 the Supreme Administrative Court (KHO) upheld the reduced fine (decision KHO 12.6.2026/1604), confirming that Verkkokauppa.com had been obliged to define retention periods for the personal data it collected — which makes the €792,639 penalty final (Data Protection Ombudsman).

Posti €2,400,000 (November 2024 — annulled by court November 2025)

On 13 November 2024 the Sanctions Board imposed a €2,400,000 fine on Posti Jakelu Oy — at the time, Finland’s largest-ever GDPR penalty (EDPB record). Violations: Articles 5, 6, 13, and 25 GDPR.

The substance: Posti automatically created electronic mailboxes (OmaPosti) for customers without obtaining separate consent and bundled the mailbox with other postal services so customers couldn’t refuse it independently. Personal documents — including invoices and sensitive medical records — were forwarded to those automatically-created OmaPosti accounts. Some customers did not actively use OmaPosti or had refused digital mail communication; their documents were still rerouted there. The decision flagged “an automatically activated selector function and a pre-ticked checkbox” as canonical examples of unlawful processing under GDPR’s transparency, consent and data-protection-by-design rules.

The court reversal (3 November 2025). Posti appealed. On 3 November 2025 the Helsinki Administrative Court annulled the entire €2.4M fine (Helsinki Administrative Court decision 6850/2025), ruling that “Posti is entitled, based on freedom of enterprise and freedom of contract, to bundle its digital services into a single service package.” Because the Sanctions Board had grounded the fine solely on the absence of a lawful processing basis, once the court accepted that contract-necessity could justify the bundling, the entire penalty fell away. The transparency reprimand and corrective order about insufficient information on OmaPosti’s creation were left in force — Posti is still required to fix the disclosures, just without the monetary sanction. The decision can in principle be appealed to the Supreme Administrative Court (KHO); as of writing, no public KHO record exists.

Even after the reversal, the case is notable for two reasons:

  1. Posti Jakelu Oy is part of the same Posti Group that was fined €100,000 in 2020 — the first ever Finnish GDPR fine. Five years later, the same group was hit with a 24× higher penalty by the same regulator for a different but related transparency failure — only for the courts to reset the meter on what counts as lawful service-bundling. (That first €100,000 fine, by contrast, was litigated all the way up and upheld by the Supreme Administrative Court on 12 September 2023 (Data Protection Ombudsman) — so the small fine held while the big one fell.)
  2. The court’s reasoning sets a meaningful precedent for the rest of Europe: a national DPA cannot simply assume that bundling digital services with physical ones is unlawful — it has to do the contract-necessity analysis under GDPR Article 6(1)(b) before reaching for fines. After this decision, the largest fine actually standing in Finland is the €792,639 Verkkokauppa.com fine — reduced by the Helsinki Administrative Court and confirmed final by the Supreme Administrative Court on 12 June 2026.

For up-to-date numbers, see the office’s annual reports and the enforcementtracker.com registry (filter Country → Finland). In aggregate, Finland’s enforcement volume sits below CNIL, Garante or the Irish DPC, but is more systematic than the neighbouring Baltic DPAs.

How to contact the ombudsman

  • File a complaint — via the form on tietosuoja.fi. Free of charge.
  • Email and postal address — current contact details under “Yhteystiedot” / “Contact us”.
  • Processing times — typically 30 days, extendable to four months in complex cases (an EU-wide GDPR requirement, not Finland-specific).

You can complain about any organisation processing your personal data in violation of GDPR or Tietosuojalaki. If the respondent is headquartered in another EU country, the ombudsman will route the case through the EDPB one-stop-shop mechanism.

How the Finnish ombudsman differs from neighbouring DPAs

To summarise in three points:

1. Older than most EU peers. The institution dates from 1987, eight years before the EU’s first data protection directive. Not implementation of supranational law — a domestic Nordic tradition.

2. Collegial fining via the Sanctions Board. A fining decision is taken by three people — ombudsman plus two deputies. Not by a single director, not by a large plenary commission. Reduces the risk of arbitrariness while moving faster than committee-driven DPAs.

3. No “Estonia-style” problem fining legal entities. The Sanctions Board began issuing administrative GDPR fines on 18 May 2020 — two years after the regulation took effect, with no Penal Code amendment required. Estonia’s AKI only got the same ability after the November 2023 reform.

And as a bonus — the current EDPB Chair sits in the Finnish office. So when the EDPB issues its next binding pan-European guideline, the Finnish ombudsman’s signature is on it.

What this means for you

If you run a business that handles Finnish personal data: the Finnish ombudsman’s track record reads as a list of patterns to avoid — making customers register an account when a one-off transaction would do (Verkkokauppa.com), enrolling people into digital services they didn’t ask for (Posti OmaPosti), tracking employees without a documented DPIA (Kymen Vesi). The cleanest mental model: ask for the minimum data you actually need, set a retention period and stick to it, and don’t pre-tick anything for the user.

If you’re a Finnish resident wanting to file a complaint: the complaint form on tietosuoja.fi is free, processed in 30 days (extendable to four months for complex cases). If the company is headquartered abroad in the EU, the ombudsman will hand the case to that country’s DPA via the EDPB one-stop-shop.

If you’re a journalist or researcher: the Sanctions Board’s reasoned decisions tend to be the cleanest, most-cited GDPR fining decisions in Europe — partly because three people sign each one, partly because Finland’s procedural tradition is to publish detailed reasoning. They’re a good source even when your story isn’t about Finland.

TL;DR

Tietosuojavaltuutetun toimisto is one of Europe’s oldest data protection authorities — established in 1987, eight years before Finland joined the EU. Structurally distinctive: a three-person collegial Sanctions Board (ombudsman plus two deputies) imposes administrative fines, in operation since 18 May 2020. The headline penalty was €2,400,000 against Posti (13 November 2024) for unlawful OmaPosti electronic-mailbox enrolment — but the Helsinki Administrative Court annulled the fine in full on 3 November 2025 on contract-necessity / service-bundling grounds, leaving the €792,639 Verkkokauppa.com sanction — upheld by the Supreme Administrative Court on 12 June 2026 — as Finland’s largest fine actually standing. The current ombudsman, Anu Talus, also chairs the EDPB through her current 5-year term ending in 2028, giving Finland disproportionate weight in EU privacy enforcement. If your business touches Finnish data, this is a serious regulator without the teething problems of its smaller neighbours.

Sources