Finland
NSA Tier B partner and NATO member folded into Europol, Schengen, Prüm and Nordic (NORDEFCO and NB8) sharing, with the C-Lion1 cable cut twice in five weeks and a US pact opening 15 military bases
Overview
EU Member State: Finland is subject to the GDPR. For the EU framework, see the EU Framework page.
In 2019, Finland enacted Intelligence Acts enabling cross-border traffic interception by Supo and the FDIA, legislation that required a constitutional amendment passed by two-thirds supermajority across two parliamentary terms, demonstrating how even strong constitutional privacy protections are amended when national security demands arise. Finland joined NATO on April 4, 2023 (31st member), nearly doubling the alliance’s Russian border (1,340 km). A US Defense Cooperation Agreement grants access to 15 Finnish military bases (in force September 2024). NSA Tier B partner. The C-Lion1 submarine cable was severed twice in five weeks (November–December 2024); the Eagle S tanker damaged five undersea cables on December 25, 2024.[1][2]
Finland’s outward data-sharing runs through its alliances and treaties, each detailed below. It is an NSA Tier B partner (targetable by NSA collection, unlike Five Eyes members) and, since 2023, a NATO member bound to the United States by a Defense Cooperation Agreement; it cooperates through NORDEFCO and the Nordic-Baltic Eight. It is a party to the 1959 Council of Europe Mutual Assistance Convention and the Budapest Convention on Cybercrime, belongs to the Schengen and Prüm frameworks and to Europol and the European Investigation Order, and cooperates on mutual legal assistance with the United States (through the EU-US instrument), Canada, Australia, and its Nordic neighbours. These are the channels through which the domestic protections described below are, in practice, bypassed.[13][14][15][16][17]
International Data Sharing Agreements
Mutual Legal Assistance
EU Member States (26 countries): Finland (an EU member since January 1, 1995) cooperates with the other EU states through the EU Convention on Mutual Assistance in Criminal Matters (2000), the Schengen Convention, and the European Investigation Order, which enables binding cross-border evidence requests.
European Convention on Mutual Assistance in Criminal Matters (1959, ETS 30): This Council of Europe instrument and its Additional Protocols apply between Finland and all other parties; the Ministry of Justice is Finland’s Central Authority. As of July 2026 it has 51 parties: all 46 Council of Europe member states (Albania, Andorra, Armenia, Austria, Azerbaijan, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Georgia, Germany, Greece, Hungary, Iceland, Ireland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Montenegro, the Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye, Ukraine, and the United Kingdom) plus five non-members (Chile, Israel, Mongolia, the Republic of Korea, and the Russian Federation).[13]
Convention on Cybercrime (the Budapest Convention, 2001, ETS 185): Finland is a party to the Council of Europe’s cybercrime convention, which governs the expedited preservation and cross-border disclosure of stored computer and subscriber data. As of July 2026 it has 82 parties: 45 Council of Europe member states (every one of the 46 except Ireland, which has signed but not ratified), namely Albania, Andorra, Armenia, Austria, Azerbaijan, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Georgia, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Montenegro, the Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye, Ukraine, and the United Kingdom; together with 37 non-member states: Argentina, Australia, Benin, Brazil, Cabo Verde, Cameroon, Canada, Chile, Colombia, Costa Rica, Côte d’Ivoire, the Dominican Republic, Ecuador, Fiji, Ghana, Grenada, Israel, Japan, Kiribati, Mauritius, Morocco, New Zealand, Nigeria, Panama, Papua New Guinea, Paraguay, Peru, the Philippines, Rwanda, São Tomé and Príncipe, Senegal, Sierra Leone, Sri Lanka, Tonga, Tunisia, the United States, and Vanuatu.[14]
Bilateral mutual legal assistance: Finland has no separate bilateral MLAT with the United States; US cooperation runs through the EU-US MLA instrument (in force February 1, 2010). Finland does hold bilateral MLA treaties with Canada and Australia, and under Nordic cooperation uses direct authority-to-authority contact, the Nordic Arrest Warrant, and uniform norms for extradition and sentence transfer with Denmark, Iceland, Norway, and Sweden. The full set of Finland’s bilateral treaties is searchable in the Finlex treaty series (Valtiosopimukset).[9]
Defense and Intelligence Cooperation
NATO (since April 2023). US-Finland DCA (in force September 2024): US forces access to 15 Finnish bases. NSA Tier B “Focused Cooperation.” NORDEFCO (Nordic Defence Cooperation; five members: Denmark, Finland, Iceland, Norway, and Sweden; Finland 2025 chair, revised MoU May 2025).[18] NB8 (the Nordic-Baltic Eight: Denmark, Estonia, Finland, Iceland, Latvia, Lithuania, Norway, and Sweden).[19] X-Road: Federated data exchange with Estonia (since February 2018, via NIIS). EU-US Umbrella Agreement, SWIFT/TFTP, PNR. Interpol I-24/7. Egmont Group.[10]
EU Law Enforcement Cooperation
SIS II: Real-time query and alert sharing across the Schengen Area (29 states: Austria, Belgium, Bulgaria, Croatia, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, the Netherlands, Norway, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden, and Switzerland).[15] Prüm: Automated DNA, fingerprint, and vehicle-registration exchange; the framework binds 31 states (all 27 EU members plus the non-EU Schengen associates Iceland, Liechtenstein, Norway, and Switzerland); Prüm II (2024) adds facial images and police records.[16]
Europol
As an EU member state, Finland is one of the 27 EU members that constitute Europol, the EU Agency for Law Enforcement Cooperation (Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, and Sweden). Europol also holds operational agreements permitting personal-data exchange with 17 non-EU states (Albania, Australia, Bosnia and Herzegovina, Canada, Colombia, Georgia, Iceland, Liechtenstein, Moldova, Monaco, Montenegro, North Macedonia, Norway, Serbia, Switzerland, Ukraine, and the United States) and cooperates with US law enforcement including the FBI, so Finnish person data flowing through Europol is reachable onward.[17]
The Privacy Backdoor Effect
- NSA Tier B: Focused cooperation; Finnish persons targetable
- Intelligence Acts 2019: Cross-border cable interception authorised by constitutional amendment
- US DCA: 15 military bases with US force presence and intelligence-sharing implications
- EU Framework: Finnish data in SIS II, Prüm, EIO accessible to 27 EU states
- MLAT/CoE Conventions: the US (via the EU-US instrument), the 51 parties to the 1959 Convention and the 82 parties to the Budapest Convention can request data through MLA channels
- Cable vulnerability: C-Lion1 cut twice; Eagle S damaged five cables; hybrid warfare targeting interceptable infrastructure
Club de Berne and the Counter Terrorism Group
Finland’s Supo takes part in the Club de Berne (founded 1969), the forum of the heads of the domestic intelligence and security services of the 27 EU member states (Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, and Sweden) together with Norway and Switzerland. The Club is a broad, all-source intelligence-sharing body, not a counterterrorism-specific one; its separate offshoot, the Counter Terrorism Group (CTG), created in September 2001, shares terrorism intelligence among the same services plus the United Kingdom and has run a joint operational platform in The Hague with a common database and real-time information system since 2016.[20]
Surveillance and Intelligence
Intelligence Agencies
Supo (Suojelupoliisi, ~584 employees): Finland’s only civilian intelligence service, under Ministry of Interior. 2024 assessment: Russia treats Finland as a “hostile country.” FDIA (Finnish Defence Intelligence Agency, operational since 2014): Combined SIGINT, GEOINT, IMINT. Houses the Viestikoekeskus (Intelligence Research Centre) monitoring Russian Armed Forces electromagnetic emissions.[4][5]
Intelligence Acts 2019
Required a constitutional amendment (two-thirds supermajority across two parliamentary terms) to enable cross-border cable traffic interception by Supo and the FDIA. Oversight: Intelligence Ombudsman (Kimmo Hakonen, since May 2019, reappointed May 2024) supervises legality with inspection powers; Parliamentary Intelligence Oversight Committee provides political scrutiny.[1]
Internet Infrastructure and Cable Security
FICIX (founded 1993, one of world’s oldest IXPs) operates three exchanges (Espoo, Helsinki, Oulu). C-Lion1 (1,173 km, 120 Tbps, Helsinki-Rostock): severed twice in five weeks: November 18 (Yi Peng 3 with Russian captain investigated, Swedish EEZ) and December 25 (Gulf of Finland, 60 km from Helsinki). Eagle S tanker (Russia shadow fleet) dragged its anchor across the Gulf, damaging Estlink 2 power cable and FEC-1/FEC-2 telecom cables (December 25). Finnish Police Karhu unit boarded by helicopter; captain charged. NATO launched Baltic Sentry (January 14, 2025). Google Hamina data centre: EUR 4.5B+ cumulative investment.[6][7]
EU cable-security build-out (2026): Under its submarine-cable security toolbox the European Commission funded the first two Regional Cable Hubs, with Finland coordinating the Baltic Sea hub (EUR 2.5 million) alongside Denmark, Germany, Estonia, Latvia, and Sweden, to link national security operations centres and cross-border threat detection for subsea infrastructure. A EUR 20 million pilot financed cable-repair modules for the Baltic in spring 2026, followed by a EUR 40 million call to expand European repair capacity. The planned Amber Cable system (Finland, Estonia, Latvia, Lithuania, Poland, Denmark) pairs new capacity with integrated sensing to detect interference along the route. The security rationale is genuine, but the same build-out concentrates monitoring capability on the region’s traffic arteries.[21]
Recent Developments
Eagle S / Estlink 2 (December 25, 2024): Shadow fleet tanker damaged five cables including Estlink 2 power and FEC-1/FEC-2 telecom. Captain charged. EUR 60M+ repair costs.[7]
C-Lion1 Severed Twice (November–December 2024): Yi Peng 3 incident (November 18) and separate Gulf of Finland incident (December 25).[6]
NATO Baltic Sentry (January 2025): Multi-domain maritime surveillance in response to cable incidents.[11]
Eastern Border Closed: All Finland-Russia land crossings closed since December 2023. Pushback law enacted July 2024 amid Russian weaponised migration.[12]
Privacy Framework
The Office of the Data Protection Ombudsman is headed by Anu Talus, who simultaneously chairs the EDPB (since May 2023). Age of consent: 13. State authorities are exempt from GDPR administrative fines. Notable enforcement: S-Pankki EUR 1.8M (banking app security flaw, September 2025). The Data Protection Act (1050/2018) supplements the GDPR; the Coercive Measures Act (806/2011) governs surveillance for criminal investigations; the Act on Electronic Communications Services (917/2014) addresses telecom privacy.[3]
Data Retention
Information Society Code Section 157: telephony/SMS 12 months, other electronic communications 9 months, internet access 6 months. No content retention. Four designated providers based on market share. Following Tele2 Sverige, Finland revised to require case-by-case access review.[8]
Pending Legislation
- EU AI Act national implementation: most AI Act rules apply from August 2, 2026; Finland is designating competent authorities and the Data Protection Ombudsman’s role for AI matters intersecting with personal data.
- Traficom communications-network security rules: updated 2026 regulation expands critical-network security obligations, including to 5G base stations, tightening control over telecom infrastructure.
- Data Act supervision: the Data Protection Ombudsman has been designated to supervise Data Act provisions intersecting with personal data, with implementing arrangements phasing in through 2026.
- NIS2 (Cybersecurity Act 124/2025): in force, with sector obligations and supervisory practice continuing to develop.
