Suomi.fi for Service Developers
Go directly to contents.

Data protection

Data Exchange Layer's privacy statement

The Suomi.fi Data Exchange Layer provides a secure way to transfer data between organisations, enabling the construction of reliable service collections for citizens, companies and public authorities. The API Catalogue is a service directory, which presents the organisations that have joined the Suomi.fi Data Exchange Layer and the services they are offering through the Data Exchange Layer.

You can browse and download data in the API Catalogue without registration. Publishing and updating data in the API Catalogue requires registration in the Suomi.fi Data Exchange Layer.

1. Controller and contact persons

Digital and Population Data Services Agency
Lintulahdenkuja 2, FI-00530 Helsinki
P.O. Box 123, FI-00531 Helsinki
Telephone (switchboard) +358 295 536 000
Email kirjaamo(at)dvv.fi

Contact person in register-related matters

Anssi Ahlberg, Chief Specialist
Lintulahdenkuja 2, FI-00530 Helsinki
Telephone (switchboard) +358 295 536 000
Email kirjaamo(at)dvv.fi

Pasi Ahola, Chief Specialist
Lintulahdenkuja 2, FI-00530 Helsinki
Telephone (switchboard) +358 295 536 000
Email kirjaamo(at)dvv.fi

2. Data Protection Officer

Telephone (switchboard) +358 295 536 000
Email tietosuoja@dvv.fi

The data kept in the registers is processed to identify the customer organisations of the service and their e-services and to ensure information secure processing of personal data in the Suomi.fi services of the Digital and Population Data Services Agency, to investigate errors and to investigate any misuse and data breaches. The data can also be used to determine the extent to which the service is used, cost monitoring and distribution, and for statistical purposes.

Personal data kept in the registers of the Suomi.fi Data Exchange Layer is processed under sections 3 and 4 of the Act on Common Administrative E-Service Support Services (Support Services Act; 571/2016) to manage and develop access rights, customer relationships and services. 

Personal data is processed as part of the provision of the Digital and Population Data Services Agency’s statutory services, i.e. on the basis of Article 6(1)(c) of the General Data Protection Regulation of the EU, in order to comply with the controller’s statutory obligations.

An event log is kept on the actions taken by logged-in users. The data in the event log will be used, where necessary, for the retrospective investigation of data processing activities that have taken place in the service and actions taken by the user.

4. Personal data retention period

The controller must keep the data of the customer register, system administrator register and the event log for five (5) years from the date on which the use of the service ends (section 13(2) of the Support Services Act).

The Digital and Population Data Services Agency has estimated that with regard to event data, a five-year (5) retention period is necessary, when taking into consideration the most common limitation periods for offences related to the processing of personal data and the limitation period for offences in office, which is five years.

5. Personal data to be processed

The following details of the organisation’s contact person are entered in the customer register: 

  • name
  • telephone number
  • email address

The following details are entered in the system administrator register:

  • ID
  • user ID
  • name (optional)
  • email address
  • organisation membership
  • subsystem administrators (name and email address)

The following details are entered in the feedback form:

  • name
  • email address
  • date and time the feedback was sent

6. Standard sources of information

The data from the customer register and the system administrator register is obtained through the organisation’s own notification or when the organisation registers for the service. Data Exchange Layer transactions as well as the data repositories and services connected to the Data Exchange Layer are also used as data sources for the register.

For the feedback form, the data is obtained via the individual’s own notification.

7. Disclosure of data

As a rule, no information is disclosed to third parties. If the matter concerns a service provided by the public authorities and requires a response to the customer, the email address or the phone number and, if necessary, the contact content data are forwarded to the appropriate public authorities.

8. Transferring data outside the EU or the EEA

Personal data will not be transferred outside the EU or EEA countries or to international organisations.

9. Automated decision-making

Personal data will not be used for automated decision-making.

10. Data subject’s rights

Right of access

You have the right to gain access to your personal data and check its content. The written request must be submitted to the Digital and Population Data Services Agency’s registry. Be prepared to provide proof of identity.

Right to rectification

You have the right to correct your personal data when you observe that it is inaccurate or incorrect. Submit the written request to the registry’s contact person. In the request for revision, state the information to be corrected and its exact change or addition. Be prepared to provide proof of identity.

Limitations to the rights of the data subject

Most of the services provided by the Digital and Population Data Services Agency are based on compliance with the controller's statutory obligation or on the performance of a duty of public interest or the exercise of public authority. In these cases, you cannot request that your personal data be deleted or transferred to another system, and, as a rule, you cannot oppose the processing of your personal data.

11. Right to lodge a complaint with the supervisory authority

If you feel that your personal data is being processed unlawfully, you can file a complaint with the Office of the Data Protection Ombudsman.

Office of the Data Protection Ombudsman
Street address Lintulahdenkuja 4, 00530 Helsinki, Finland
Postal address P.O. Box 800, 00531 Helsinki
Email tietosuoja(at)om.fi
Switchboard +358 29 566 6700
Registry +358 29 566 6768

For more information on filing a complaint, see the Office of the Data Protection Ombudsman website at https://tietosuoja.fi/en/Opens in a new window..

12. Other information 

The privacy statement of the Suomi.fi Data Exchange Layer can be viewed on the service website and at the registry of the Digital and Population Data Services Agency.

Read more about the general data protection information provided by the Digital and Population Data Services Agency at https://dvv.fi/en/data-protectionOpens in a new window..


Updated: 15/10/2024

Are you satisfied with the content on this page?