Suomi.fi for Service Developers
Go directly to contents.
VAHTI best practices
Digital security risk management

To get the best help for your situation, first answer the questions on the guide's start page.

Data protection processes

What are data protection processes?

Data protection processes aim to ensure that

  • the risks related to data protection are minimised
  • the rights of data subjects are properly realised
  • the data protection requirements are fulfilled.

Risk management processes related to data protection also ensure that the processing activities, risk management measures, and measures related to preparedness and continuity management are up to date, known by the necessary parties, and practised.

Updated: 28/10/2024

Take stakeholders and service chains into consideration

As service chains can be quite long, it is important that risk management is comprehensive and extensive. Transfers and disclosures of personal data require that you consider stakeholders and service chains in the management of data protection risks.

The controller must

  • either manage not only the risks in their own operating environment but also the risks in the operating environments of stakeholders and suppliers, or
  • otherwise ensure that the stakeholders and processors involved in supply chains take into account the risks in their own and their subcontractors’ operating environments.

Updated: 28/10/2024

Make data protection requirements an obligation for suppliers in connection with competitive tendering

When arranging competitive tendering on information systems, include the data protection requirements so that your organisation does not incur any costs due to insufficient data protection.

For example, when your organisation calls for tenders for a system that is used in the processing of personal data,

  1. ensure that data protection has been adequately taken into account in the system’s requirement specifications
  2. conclude an agreement with the supplier in which you agree sufficiently on matters that require data protection.

Below you can find good practices for how to ensure data protection in connection with competitive tendering of systems.

Updated: 28/10/2024

Conduct a Data Protection Impact Assessment

Data protection regulation obliges operators processing personal data to take data protection matters into account in the processing of personal data. The Data Protection Impact Assessment (DPIA) is a way to fulfil this obligation.

The DPIA identifies and assesses risks to data subjects that may exist in the processing of personal data. An impact assessment is mandatory if the data subjects are exposed to an increased risk. Impact assessments must be carried out when the controller processes

biometric data
genetic data, or
location details.

The Data Protection Ombudsman maintains a list of data processing activities that require a Data Protection Impact Assessment from the controller. You can read the list of the processing activities on the website of the Office of the Data Protection OmbudsmanOpens in a new window.. Please note that the list of processing activities is not exhaustive.

Updated: 28/10/2024

Look after the rights of the data subject

Ensuring the implementation of data subjects’ rights is one of the most important means of ensuring the management of data protection risks. The implementation of data subjects’ rights requires

  • high-quality processing of personal data
  • operational development
  • ensuring data protection.

Once the implementation of data subjects’ rights has been ensured in accordance with the requirements, data protection risks can be considered fairly well managed.

Updated: 28/10/2024

Report deviations to your supervisor

When reporting deviations, follow the guide’s page Monitor, document and report risks.

Updated: 28/10/2024

Monitor process performance

The data protection environment is constantly changing: technology is developing, regulation is developing and increasing, and global political situations are changing. All of these affect the implementation of data protection, and the effectiveness and efficiency of data protection risk management processes must be monitored regularly.

Updated: 28/10/2024

Are you satisfied with the content on this page?

Checklist