Suomi.fi for Service Developers
Go directly to contents.
VAHTI best practices
Digital security risk management

To get the best help for your situation, first answer the questions on the guide's start page.

Provide training and assess the implementation of data protection

The management is responsible for ensuring adequate training and monitoring the implementation of data protection

It is the senior management’s responsibility to ensure that sufficient training on data protection and data protection risks is available for the staff. The management is also responsible for ensuring that the implementation of data protection is planned and documented and that its implementation is also monitored in a documented manner.

Updated: 29/10/2024

Ensure adequate training for the entire organisation

Management and employees must be familiar with their own roles and areas of responsibility in the processing of personal data and data protection. Training is one of the organisational means mentioned in data protection regulation that ensures that data protection is implemented.

Therefore, ensure that the management and employees of the organisation

  • have received sufficient training on data protection and data protection risks
  • are aware of up-to-date instructions related to data protection and data protection risks.

Updated: 29/10/2024

Assess success and develop activities

By assessing and measuring the development of data protection work, you can identify data protection risks to which the organisation must primarily allocate resources. The development of data protection and its assessment must be documented and the documentation maintained appropriately.

Data protection poses risks to the organisation the same as all other functions. Processes related to data protection should therefore be regularly

  • planned
  • documented
  • implemented
  • assessed and
  • updated.

Updated: 29/10/2024

Are you satisfied with the content on this page?

Checklist