The fine sits alongside a broader enforcement escalation: 2024 administrative fines from the Office of the Data Protection Ombudsman reached a record annual total of EUR 2.4 million, the largest to date in Finland, and the Government has now submitted proposal HE 46/2026 vp to Parliament, which if enacted would for the first time allow administrative fines to be imposed on public-sector controllers and processors, a category previously shielded from monetary GDPR penalties.
Other Developments
Two new sectoral supervisory regimes under Traficom. Finland's national EU Data Act implementing legislation was confirmed on 5 December 2025 and entered into force on 1 January 2026, designating Traficom, not the Data Protection Ombudsman, as data coordinator and principal supervisor, while personal-data processing under the Data Act remains within Ombudsman competence. On the same date, Finland's national AI Act implementation, the Act on the Supervision of Certain AI Systems, entered into force, again naming Traficom as the central contact point and establishing a National Sanctions Board able to impose fines up to EU AI Act maximums; Phase 2 provisions covering regulatory sandboxes and a high-risk AI register are expected around 2 August 2026.
Direct-marketing guidance updated. The Office of the Data Protection Ombudsman updated its FAQs on direct marketing, emphasising information-disclosure duties toward data subjects and the obligation to honour opt-out requests.
Cross-Monitor Connections
The new Traficom-administered supervisory regimes for the EU Data Act and the national AI Act implementation touch directly on the artificial-intelligence monitor's territory, given the AI Act supervision structure and its fining powers up to EU AI Act maximums. The proposed extension of GDPR fines to public-sector bodies under HE 46/2026 vp, if enacted, would also be of interest to financial-integrity's assessment of Finnish institutional accountability structures, though no financial-integrity-specific claim links to it this cycle.
Outlook
Whether HE 46/2026 vp is enacted, extending GDPR fines to Finnish public-sector controllers, remains open; if it passes, it would remove a longstanding gap in Finland's enforcement architecture. Phase 2 of the national AI Act supervision regime, covering regulatory sandboxes and the high-risk AI register, is expected around 2 August 2026 and will be the next concrete test of Traficom's new AI-supervisory role. The record 2024 fine total and the confirmed Verkkokauppa.com appellate outcome together suggest an Ombudsman and Sanctions Board increasingly willing to pursue and defend significant financial penalties, a trend worth tracking into the next enforcement cycle.
Standing brief · as of 23 August 2026
Written before the update above. Where they differ, the update is the more recent position.
Lead Signal
Finland's data protection enforcement environment tightened materially this cycle, anchored by the Supreme Administrative Court's June 2026 affirmance of a fine of approximately 795,000 euro against Verkkokauppa.com for failing to define a data storage period for online-purchase data. Confirmed at the level of Finland's highest administrative court, the fine converts what had been an administrative-level enforcement position into a durable judicial precedent on retention-period compliance. The case matters beyond its size because it establishes that failure to define a retention period is treated as a chargeable violation with real financial consequence, not merely a documentation gap, and it is understood to sit alongside a broader escalation in Finnish enforcement activity across multiple modules this cycle.
Other Developments
A financial-sector security fine. The Data Protection Ombudsman fined Aktia Bank Plc approximately 865,000 euro for a security flaw, under GDPR Article 32, in its electronic identification service. The fine is a material controller/processor-duties enforcement event, and its size relative to the Suomen Numerokeskus fine below suggests Finnish enforcement calibrates penalty severity to the sensitivity of the underlying processing.
A cross-border transfer finding. The Data Protection Ombudsman found insufficient protection of personal data in Finnish government cloud services, particularly data transferred to the United States. This is an active-scrutiny signal that persists despite the continued operation of the EU-US Data Privacy Framework, suggesting that adequacy-mechanism coverage at the framework level does not, in the regulator's assessment, eliminate the need for adequate transfer-impact-assessment practice at the level of individual public-sector cloud deployments.
A modest access-right fine. The Ombudsman fined Suomen Numerokeskus 5,000 euro for failing to provide access to call recordings, a violation of GDPR Articles 15(1) and 15(3). Though modest in size, the fine is a further data-subject-rights enforcement data point this cycle, reinforcing that access-right failures are a live enforcement category alongside the larger security and retention cases above.
Regulator powers expansion. Finland has proposed legislation strengthening the EU Data Act that grants Traficom supervisory powers and sanctioning authority, effective 1 January 2026, expected to run concurrently with the Data Protection Ombudsman's existing competence. This is enacted-not-yet-effective legislation as of this cycle, and its practical delineation from the Ombudsman's remit is not yet detailed in available evidence.
Direct-marketing guidance. The Data Protection Ombudsman updated its FAQs on direct marketing, emphasising information disclosure and the honouring of opt-out requests. This is a guidance-level update rather than a binding rule change, and should be read as clarifying existing obligations rather than introducing new ones.
Cross-Monitor Connections
The government-cloud transfer finding touches on cross-border data-flow architecture also of interest to the world-payments and financial-integrity monitors, insofar as public-sector cloud dependency on United States providers intersects with broader questions of jurisdictional data control; readers tracking those monitors should treat this as a related but separately analysed signal, not a re-analysis performed here. The Traficom powers expansion sits adjacent to the crypto monitor's supervisory-architecture tracking given Traficom's broader digital-infrastructure remit, though no crypto-specific finding is asserted from this cycle's evidence, and this brief does not extend its analysis into that domain.
Outlook
Finland's enforcement trajectory is escalating rather than stabilising: the Supreme Administrative Court's affirmance of the Verkkokauppa.com fine, read together with the Aktia Bank security fine and the Suomen Numerokeskus access-right fine, signals a durable pattern of enforcement spanning retention-period, security-of-processing and access-right failures within a single cycle. The Traficom powers expansion, effective 1 January 2026, is worth watching for how concurrent competence between Traficom and the Ombudsman is delineated in practice once the provisions take effect. The government-cloud US-transfer finding also bears watching for whether it prompts a broader transfer-impact-assessment review across the Finnish public sector, given that the finding was made despite the continued operation of the EU-US Data Privacy Framework.