Tukes + Tietosuojavaltuutettu + GDPR, what do I need to comply with in Finland?
Three Finnish supervisory bodies to know:
- Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman), Finland’s GDPR regulator. Less aggressive than France’s CNIL but still active. Cookie-consent guidance follows EDPB (no pre-ticked boxes, granular per-purpose, equal prominence for “Reject all” vs “Accept all”).
- Tietosuojalaki 1050/2018, the Finnish Data Protection Act, layered on top of GDPR. Adds rules around employee data, health data, and Finnish-specific DSAR routing.
- Tukes (Turvallisuus- ja kemikaalivirasto), the Finnish Safety and Chemicals Agency. Regulates product safety, CE marking, electrical safety, REACH (chemicals), toy safety. Important if you sell electronics, cosmetics, children’s products, or chemical goods online. Tukes runs market surveillance, pulls products that don’t meet EU + Finnish safety standards. Not a data-protection authority, that’s Tietosuojavaltuutettu.
- KKV (Kilpailu- ja kuluttajavirasto, Competition and Consumer Authority), consumer protection. 14-day cooling-off period (EU rule), price-display rules, distance-selling protections.
Magento implementation: we ship Cookiebot / Iubenda (with Finnish + Swedish translations) wired into Magento’s cookie API, banner copy reviewed against EDPB + Tietosuojavaltuutettu guidance, and the standard Finnish 14-day return form embedded in the customer account area.