Home
Web Hosting
Domains FAQ
Resources
About Contact Client Portal
Guides ยท ยท 15 min read

Finnish Hosting Law: Privacy, Retention and e-Evidence

ยท 15 min read

Finnish hosting law is often reduced to vague claims about strong privacy and GDPR. Reputation is not protection, so this page names the laws that actually apply to a Finnish host, explains what each one covers, and is direct about where the protection stops.

There is also a date worth putting in your calendar. On 18 August 2026, the EU e-Evidence Regulation becomes applicable, and it changes how quickly a prosecutor in one member state can reach a hosting provider in another. Finland is in the EU, so this applies here directly.

Finnish hosting law: the rules that actually apply

Finnish hosting law is not one statute. It is a stack of data protection, communications, criminal procedure, cybersecurity and intelligence rules, and each layer does something different.

  • The GDPR applies directly. It is an EU regulation, so it is law in Finland without national implementation.
  • The Data Protection Act 1050/2018 (tietosuojalaki) entered into force on 1 January 2019 and repealed the old Personal Data Act 523/1999. It supplements the GDPR in the areas where member states retain discretion, and it sets out the powers of the national supervisory authority.
  • The Act on Electronic Communications Services 917/2014 (laki sähköisen viestinnän palveluista, also known as the Information Society Code) governs the confidentiality of electronic communications. This is the law that matters most to a hosting provider.
  • The Act on the Processing of Personal Data in Criminal Matters 1054/2018 covers processing by authorities for law enforcement and national security purposes.
  • The Cybersecurity Act 124/2025 (kyberturvallisuuslaki) entered into force on 8 April 2025, implementing the EU NIS2 Directive. It adds risk management and incident reporting duties for operators in the sectors it covers, which include cloud computing and data centre services where the scope and establishment tests are met. The same package amended Act 917/2014.

Enforcement of data protection sits with the Office of the Data Protection Ombudsman (tietosuojavaltuutetun toimisto), supported by two deputy ombudsmen with equivalent powers and an expert board that issues opinions on request. GDPR fine ceilings apply, up to 20 million euro or 4 percent of global annual turnover, whichever is higher.

Constitutional protection, and the 2018 amendment

Section 10 of the Constitution of Finland states that the secrecy of correspondence, telephony and other confidential communications is inviolable. That is a constitutional guarantee, not a statutory one, which places it above ordinary legislation.

It was, however, amended. A new subsection entered into force on 15 October 2018, allowing limitations on the secrecy of confidential communications to be laid down by ordinary act where necessary for gathering intelligence on military operations or other activities that pose a serious threat to national security. The amendment was a precondition for the intelligence legislation that followed a year later. Any honest description of Finnish privacy law has to include this, because the constitutional protection is real but it is no longer absolute.

Confidentiality of communications covers hosting, not just telecoms

When the Information Society Code took effect on 1 January 2015, it consolidated ten separate acts and did something significant for hosting customers. It extended the statutory duty to protect the confidentiality of communications beyond traditional telephone and network operators to intermediaries of electronic communications services generally.

Under Finnish hosting law, a provider owes confidentiality over the messages and traffic data it intermediates as a matter of statute, not merely as a matter of contract. The Act also restricts what may be done with traffic data and requires providers to describe what they process and for how long. A privacy policy can be rewritten by the company that published it. A statutory duty cannot. Traficom supervises compliance.

Data retention, and who it actually applies to

This is the point most jurisdiction comparisons get wrong, in both directions. Finland has a mandatory data retention regime, but ordinary web hosting and VPS hosting are not themselves within its scope. Section 157 of Act 917/2014 applies to telecommunications operators individually designated by the Ministry of the Interior, and only to the categories of communications services specified in the law, covering telephone, messaging, internet telephony and internet access data.

Three limits are built into that provision:

  • Only a telecommunications operator (teleyritys), meaning a provider of publicly available communications networks or communications services, can be designated at all.
  • Providers of minor significance are excluded from designation by the text of the section itself.
  • Designation is company-specific rather than automatic. A provider is covered only if the Ministry of the Interior has expressly designated it under section 157, and designations are made on aggregate market share and the geographic coverage of the services.

The associated regulation also does not create new categories of data. It extends the storage period for data that designated operators already retain for their own purposes, such as customer management and billing records. Retained data may be used only in investigating offences that permit telecommunications monitoring, following the same procedure.

For a VPS or shared hosting customer, the practical consequence of Finnish hosting law is straightforward. A provider offering only ordinary hosting is not required by section 157 to create a government-mandated archive of website or VPS activity. Whatever logs exist, exist because the provider chose to keep them. Log retention is a policy decision, which is exactly why it is worth reading before you buy.

The EU backdrop reinforces this. The Court of Justice struck down the Data Retention Directive in 2014, and in Tele2 Sverige and later judgments held that general and indiscriminate retention of traffic and location data is precluded, allowing only targeted retention limited to what is strictly necessary.

The intelligence legislation, without the spin

Finland enacted civilian intelligence legislation that entered into force on 1 June 2019, alongside the Act on Military Intelligence 590/2019. This is the part that privacy hosting marketing tends to skip.

The entirely new powers created by the package are intelligence gathering on specific locations, copying of a message, interruption of the delivery of a message for copying, and network traffic intelligence. Network traffic intelligence permits technical collection and processing of data communications crossing the Finnish border. Civilian intelligence powers are exercised by the Finnish Security and Intelligence Service and can be used abroad in defined circumstances.

The safeguards are meaningful and worth stating accurately. Network traffic intelligence requires a court decision, not an internal authorisation. Oversight is carried out by the Intelligence Ombudsman and by Parliament's Intelligence Oversight Committee. The Ministry of the Interior has a reform project underway to update civilian intelligence legislation, so this area is not settled.

Two things are true at once. Finland is not generally identified as a participant in the groupings commonly called the Five Eyes, Nine Eyes or Fourteen Eyes. Finland also has a modern, court supervised signals intelligence capability focused on cross-border traffic. Any provider telling you Finland has no state collection capability is selling you a story rather than a jurisdiction.

How Finnish hosting law handles copyright complaints

Finland is not subject to the US Digital Millennium Copyright Act, but that does not mean copyright complaints are irrelevant until a court becomes involved. Finnish hosting law includes its own notice procedure for hosted material, carried into the Information Society Code from the earlier legislation on information society services. A qualifying notice can require a host to block access to the material identified, with a counter-notice route available to the customer. Compelled disclosure of subscriber information and court-ordered blocking follow separate judicial procedures under the Copyright Act 404/1961.

  • Section 60a allows a rightsholder to petition the Market Court (markkinaoikeus) for an order compelling disclosure of the contact information of a subscriber whose connection was used to make protected material available to the public.
  • Case law has narrowed this. Disclosure requires infringement that is significant in extent, assessed on the quantity of material, the duration and the nature of the works, and later Market Court practice tightened the test further so that the individual whose identity is sought must have significantly infringed rather than merely appearing in a large swarm.
  • Sections 60c and 60e provide for discontinuation orders and blocking orders directed at intermediaries.

The jurisdictional point that matters is who decides what. A complaint does not, by itself, compel the disclosure of a customer's identity. That takes a court order, and the court applies a proportionality test. We covered the wider comparison in DMCA takedowns and hosting jurisdiction.

What changes on 18 August 2026

Regulation (EU) 2023/1543, the e-Evidence Regulation, becomes applicable on 18 August 2026 in every EU member state except Denmark. Its companion, Directive (EU) 2023/1544, had a transposition deadline of 18 February 2026.

The change is structural. A judicial authority in one member state will be able to send a European Production Order or a European Preservation Order directly to a service provider in another member state, without routing the request through mutual legal assistance and, in many cases, without the provider's own national authorities being involved beforehand. Hosting providers, cloud operators, domain registrars and registries are explicitly in scope.

The thresholds differ by data category:

Data category When an order may be issued
Subscriber data, and data requested solely to identify a user Any criminal offence, or execution of a custodial sentence of at least four months. A public prosecutor may issue.
Traffic data and content data Offences punishable in the issuing state by a custodial sentence of a maximum of at least three years, or a listed set of offences covering terrorism, child sexual abuse material, non-cash payment fraud and certain cybercrime. Must be issued or validated by a judge or court.

Production orders must generally be executed within ten days, and within eight hours in emergency cases. A preservation order requires the recipient to freeze the specified data without delay for 60 days, extendable by a further 30 days if production is being sought.

Providers operating across EU borders must designate an establishment or appoint a legal representative to receive and execute orders. The requirement also reaches providers incorporated outside the EU when they offer covered services in the Union. A provider established in one member state and serving only that same state is excluded from the Directive's representative requirement. The Regulation requires member states to provide effective financial penalties of up to 2 percent of the provider's worldwide annual turnover for specified failures to comply, and national law may also provide criminal penalties where applicable.

Finland has now adopted the national legislation needed to support the package. Acts 436/2026, 437/2026 and 438/2026 were approved in May 2026, covering the Finnish procedure, designated establishments and legal representatives, and enforcement of the applicable penalties. Under the Finnish framework, issuing and validation powers are divided between designated pre-trial investigation officials, prosecutors and courts, depending on the type of order and data requested. Traficom acts as the central authority for provider designations and legal representatives. Worth noting for anyone reading Finland as a jurisdiction: Finland voted against final adoption of the Regulation in Council and filed a statement that the notification mechanism and its grounds for refusal were insufficient.

The honest reading is that the e-Evidence framework narrows the gap between EU hosting jurisdictions. Finnish hosting law still shapes confidentiality, logging and national procedure, but choosing one EU country over another changes less about who can order what than it used to. What e-Evidence does not change is how much data exists to be produced in the first place. That remains the variable you actually control. If you are weighing a non-EU option, our companion piece on Swiss data protection law for hosting covers the other side, and Finland vs Switzerland hosting sets the two against each other directly.

What a Finnish host can actually be made to hand over

A legal order can only reach data that exists. That reduces to four questions.

  • What did signup collect? If the account record is an email address and a password, that is the subscriber data. There is no identity document to produce because none was ever requested.
  • How was it paid for? Card and bank payments create records with the processor and financial institution, and may also pass identifying transaction details to the hosting provider. A Monero payment does not create the same public transaction trail as Bitcoin, or the same conventional identity record as a card or bank payment, although the host will still retain its own invoice and account record.
  • What logs are kept, and for how long? Absent a designation under section 157, this is set by provider policy rather than statute.
  • Who controls the disk? On an unmanaged VPS the provider holds the underlying image. Full disk encryption managed inside your own VM raises the cost of a cold image considerably, but a running VM holds its keys in memory on hardware the operator controls, so encryption at rest is a real mitigation rather than an absolute one. On shared hosting the files sit on a server the provider administers, so the ceiling is lower by design.

We went through this in more detail in anonymous VPS: what it actually hides.

How this works at Packetra

Our Finnish infrastructure sits under the framework described above, and we try to hold the minimum that the framework can reach.

  • Signup requires an email address and a password. KYC is never requested at any stage.
  • Bitcoin and Monero payments run through our own self-hosted BTCPay Server, so no third-party payment processor sits in the payment path for those methods. Card, PayPal and Wise remain available for customers who prefer them.
  • Packetra has not been designated as a storage-obligated telecommunications operator under section 157, and we do not retain traffic data on behalf of authorities.
  • In providing its hosting services, Packetra treats the confidentiality and processing restrictions in Act 917/2014 as applicable to the communications it intermediates.
  • We act on valid legal orders from competent authorities. We do not disclose customer identity in response to informal requests. Copyright notices are handled under the applicable Finnish statutory procedure, while compelled disclosure of subscriber information requires a valid court order.
  • Our acceptable use policy is public and we do not pretend it does not exist. Tor exit nodes are not permitted in either location, and torrents, P2P and adult content are not permitted in Finland. VPN operation is explicitly allowed and needs no separate approval.

For the wider case on the jurisdiction, see why Finland makes sense for privacy-focused hosting and our comparison of the best hosting providers in Finland for 2026.

Frequently asked questions

What is Finnish hosting law?

Finnish hosting law is not a single statute. It is the combination of the GDPR, the Data Protection Act 1050/2018, the confidentiality of communications rules in the Act on Electronic Communications Services 917/2014, the Cybersecurity Act 124/2025, the Copyright Act 404/1961, the 2019 intelligence legislation, and the EU e-Evidence framework that applies from 18 August 2026. Each governs a different part of what a hosting provider must protect and what it can be compelled to produce.

Does Finland have mandatory data retention for hosting providers?

Finnish hosting law includes a retention regime, but ordinary web and VPS hosting fall outside it. Section 157 of the Act on Electronic Communications Services applies only to telecommunications operators individually designated by the Ministry of the Interior, and only to the communications services specified in the law. Providers of minor significance cannot be designated. A hosting provider that has not been designated keeps logs as a matter of its own policy, not statutory duty.

Is Finland part of the Fourteen Eyes?

Finland is not generally identified as a participant in the groupings commonly called the Five Eyes, Nine Eyes or Fourteen Eyes. That is a narrower statement than it is often made to sound. Finland does operate its own civilian and military intelligence capability, including court-authorised network traffic intelligence on cross-border communications, under legislation in force since 2019.

Which law is the Finnish data protection law?

The Data Protection Act 1050/2018, in force since 1 January 2019, which supplements the GDPR. For hosting specifically, the Act on Electronic Communications Services 917/2014 is equally important because it carries the confidentiality of communications obligations that apply to intermediaries.

Does the DMCA apply to Finnish hosting?

No. Finland has its own statutory notice procedure for hosted material, and copyright enforcement otherwise runs through the Copyright Act 404/1961 and the Market Court. Disclosure of subscriber contact details under section 60a requires a court order and a showing of significant infringement, rather than a form submission.

What does the e-Evidence Regulation mean for me as a customer?

From 18 August 2026, a judicial authority in any participating EU member state can send production and preservation orders straight to your hosting provider, with a ten day deadline in standard cases and eight hours in emergencies. Subscriber data can be sought for any criminal offence. Traffic and content data require an offence carrying a maximum custodial sentence of at least three years, or a listed serious offence, and judicial issue or validation. Finland adopted its supporting national legislation in May 2026.

Does GDPR make my hosting private?

No. The GDPR governs how companies process personal data and gives you rights against them. It does not restrain criminal process. A provider can be fully GDPR compliant and still be required to produce data under a valid order. Jurisdiction and data minimisation do the work the GDPR does not.

Finnish VPS hosting, no KYC, Monero accepted.

KVM virtualisation, full root access, dedicated IPv4, DDoS protection and unmetered bandwidth on the 1 Gbit line, running in Finland under the framework described above. Signup requires only an email address and password, with no identity documents at any stage. View Finland Cloud VPS plans.

This article is general information about Finnish and EU law, current as of August 2026, and is not legal advice. Legislation in this area is actively changing, particularly the ongoing reform of Finnish civilian intelligence legislation.

Need Reliable Hosting?

Privacy-focused, anonymous, and built for people who value their data.