The Finnish authority's 2025 activity report highlights the impact of artificial intelligence and geopolitics on data protection
The Finnish data protection authority has published its activity report for the year 2025, which highlights the impact of artificial intelligence and the geopolitical context on its work, as well as a notable increase in the number of cases handled.
In 2025, the authority recorded a significant increase in its activity with approximately 15,400 new cases, an increase of more than 2,000 compared to the previous year, and processed more than 15,030 files. This growth is partly explained by the update of the list of data protection officers. Notifications of personal data breaches remain the main category of cases, with more than 7,350 reports, bringing the total to over 40,000 since 2018. The most frequent incidents concerned phishing of M365 user accounts, unauthorized access to data, and, for the first time, breaches related to artificial intelligence tools. Three companies were subject to administrative fines for failures in processing security, notably in managing the modification processes of their systems.
To meet its missions, notably in monitoring artificial intelligence, the authority benefited from a budget increase of 2.35 million euros starting in 2026 and prepared a new organizational structure in 2025 to optimize the allocation of its resources. The procedures for processing breach notifications were improved, with the publication of a new form and a goal of future automation. The report emphasizes the growing importance of data sovereignty and the need for organizations, especially in the public sector, to identify risks related to digital dependency.
In 2025, the authority recorded a significant increase in its activity with approximately 15,400 new cases, an increase of more than 2,000 compared to the previous year, and processed more than 15,030 files. This growth is partly explained by the update of the list of data protection officers. Notifications of personal data breaches remain the main category of cases, with more than 7,350 reports, bringing the total to over 40,000 since 2018. The most frequent incidents concerned phishing of M365 user accounts, unauthorized access to data, and, for the first time, breaches related to artificial intelligence tools. Three companies were subject to administrative fines for failures in processing security, notably in managing the modification processes of their systems.
To meet its missions, notably in monitoring artificial intelligence, the authority benefited from a budget increase of 2.35 million euros starting in 2026 and prepared a new organizational structure in 2025 to optimize the allocation of its resources. The procedures for processing breach notifications were improved, with the publication of a new form and a goal of future automation. The report emphasizes the growing importance of data sovereignty and the need for organizations, especially in the public sector, to identify risks related to digital dependency.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire