[codicts-css-switcher id=”346″]

Global Law Experts Logo
criminal liability data breaches finland

When Can Executives Be Criminally Prosecuted for Data Breaches in Finland (2026), What Boards & Gcs Must Know

By Global Law Experts
– posted 2 hours ago

Criminal liability data breaches finland is now a live boardroom concern, not an abstract legal question, as the 2026 enforcement landscape sharpens the personal exposure of directors, CEOs and general counsel after a cyber incident. Stronger cross-agency cooperation between Finland’s prosecutors, the Data Protection Ombudsman and the National Cyber Security Centre, layered on top of the EU NIS2 framework as implemented in national law, has raised the probability that serious incidents will trigger criminal scrutiny of individuals, not only administrative action against the company.

This article sets out, in practical terms, when executives face genuine criminal risk in Finland, how individual and corporate exposure differ, what reporting duties bite after an incident, and the concrete steps a board and its GC should take within the first hours and days. It takes a clear position where boards need one, and it ends with a decision framework you can apply under pressure.

Quick answer: when can executives be prosecuted?

Executives face realistic criminal exposure in Finland in a narrow but important set of circumstances. The following scenarios are where personal risk is highest:

  • Deliberate concealment or obstruction. Where an executive suppresses evidence, falsifies logs, or misleads investigators or regulators after a breach.
  • Directed or knowingly approved wrongdoing. Where a senior individual authorised, instructed or knowingly permitted the acts that caused the breach or the mishandling of data.
  • Criminal acts against data or trade secrets. Where the incident involves theft of trade secrets, unauthorised access, or data theft in which the executive personally participated.
  • Gross negligence causing serious harm. Where an offence’s threshold is met by gross negligence, for example, ignoring known, material security failures that foreseeably caused serious harm.

Immediate board takeaway. Preserve evidence, avoid wide internal circulation of blame, notify regulators where required, engage external forensic and criminal counsel early, and document every decision contemporaneously.

Legal framework, offences that arise from data breaches

Understanding criminal liability data breaches finland starts with three overlapping legal regimes: the Finnish Criminal Code, the GDPR as supplemented by the national Data Protection Act, and the NIS2 cybersecurity regime as implemented in Finnish law. Each carries different thresholds, enforcement authorities and consequences, and they frequently run in parallel after a single incident.

Relevant Finnish statutes (Criminal Code provisions)

The primary source of individual criminal exposure is the Finnish Criminal Code (Rikoslaki, 39/1889, as amended). It contains the offences prosecutors typically reach for after a cyber incident: unauthorised access to information systems and computer intrusion, offences relating to the violation and misuse of business secrets, property and fraud-type offences, and offences concerning the falsification or destruction of evidence and interference with the administration of justice. The Criminal Code applies to natural persons, which is why an executive’s own conduct, a signed-off decision, a directive to delete records, an email instructing staff not to report, becomes the centre of gravity in any prosecution.

Because these are individual offences, the analysis turns on what a specific person knew, decided or concealed, rather than on the company’s aggregate posture. The Criminal Code also provides for corporate criminal liability (corporate fines) in defined circumstances.

GDPR, the Finnish Data Protection Act & DPA powers

The GDPR (Regulation (EU) 2016/679) and the Finnish Data Protection Act (Tietosuojalaki, 1050/2018) govern the data-protection dimension. The Data Protection Ombudsman is the national supervisory authority and exercises administrative enforcement powers, corrective orders and, together with the sanctions board, administrative fines. Crucially, GDPR enforcement is primarily administrative against the controlling entity, not criminal against the individual. The interaction matters: a failure that produces an administrative GDPR fine for the company can, on the same facts, expose an individual to criminal liability where deliberate concealment or gross negligence is present.

Personal criminal exposure in the data context is therefore better understood as a criminal track running alongside the DPA’s administrative track, rather than as a route of enforcement within the GDPR itself. Note also that the Data Protection Act (section 26) contains a separate data protection offence provision covering certain intentional or grossly negligent conduct.

NIS2 / sectoral reporting & administrative enforcement

Directive (EU) 2022/2555 (NIS2), transposed into Finnish law through national cybersecurity legislation, imposes incident-reporting and cybersecurity risk-management obligations on essential and important entities across critical sectors. NIS2 raises board-level expectations for cyber risk management and channels sectoral incident reporting through competent national authorities, with the National Cyber Security Centre Finland (NCSC-FI, part of Traficom) providing guidance and reporting channels. NIS2 enforcement is administrative, but a failure to report, or an attempt to hide an incident from sectoral regulators, can feed the criminal narrative where obstruction is alleged.

When can individual executives be criminally prosecuted?

This is the question boards most want answered, and the honest answer is that criminal liability data breaches finland attaches to individuals only where specific culpability can be proven. Administrative failure alone does not create personal criminal liability.

Threshold tests (mens rea / negligence / intent)

Finnish criminal offences require a defined mental element. Most serious offences, violation of business secrets, interference with the administration of justice, falsification of records, unauthorised access, require intent. Some offences can be committed through gross negligence, a materially higher bar than ordinary carelessness. This distinction is the executive’s first line of defence and the prosecutor’s first hurdle. A director who relied in good faith on competent security officers, followed expert advice, and did not know of a material unaddressed risk is in a very different position from one who was warned repeatedly, did nothing, and then instructed staff to stay silent.

Individual actions, decisions, sign-offs, and, above all, contemporaneous communications, are the evidence that determines which side of the threshold an executive falls.

Typical offences used in practice

In practice, prosecutors examining a data breach tend to build a case around a recognisable cluster of offences:

  • Business secret violation and data misappropriation. Where confidential data or trade secrets are misappropriated by cyber means, and an individual participated in or directed the taking.
  • Computer intrusion / unauthorised access. Where an individual accessed or facilitated access to systems without authorisation.
  • Negligent handling causing harm. Where gross negligence in the processing or protection of data foreseeably produced serious harm.
  • Interference with a regulatory or criminal inquiry. Deliberately impeding an investigation after the incident.
  • Falsifying or destroying records. Altering logs, backdating documents, or deleting evidence, often the most aggravating conduct of all.

Ransomware incidents deserve particular attention: where a ransomware attack involves the exfiltration and misappropriation of data, or where the response involves concealment, the matter can move from an administrative incident into criminal territory, focused on the individuals who directed the response.

Who prosecutors target and why, practical indicators

Prosecutors do not pursue executives at random. They follow the evidence, and the practical indicators that draw individual scrutiny are consistent: a documented warning that was ignored; an email or message showing an intent to mislead; a decision to delay or avoid notification for reputational reasons; deletion of logs after the incident became known; and personal involvement in, or direct authorisation of, the conduct that caused the breach. Where none of these markers exists, the matter usually remains an administrative one against the entity.

Side-by-side comparison, criminal liability data breaches finland: executive vs company

The single most useful tool for a board assessing exposure is a clear matrix separating individual criminal risk from corporate administrative and criminal risk. The two tracks have different legal bases, thresholds, enforcers and consequences, and they demand different responses.

Dimension Executive (individual) prosecution Company (legal person) exposure
Legal basis Criminal Code provisions applied to natural persons (intrusion, business secret violation, negligence, obstruction, falsification) Administrative enforcement under GDPR and NIS2; corporate criminal liability (corporate fine) in limited cases
Typical allegations Data or business secret misappropriation, computer intrusion, negligent processing causing serious harm, obstruction, cover-up GDPR accountability failures, corrective orders, administrative fines; systemic organisational failure
Threshold Proof of intent or gross negligence depending on the offence; individual decisions and communications are decisive Lower administrative threshold for GDPR fines; corporate criminal liability typically needs organisational failure attributable to the entity
Evidence used Emails, directives, sign-offs, failure to implement known measures, forensic timelines, witness testimony Audit trails, policies, logs, absence of DPIAs, governance failures, failure to notify DPA/NCSC
Enforcement authority Public prosecutors; criminal courts Data Protection Ombudsman (administrative); prosecutors for corporate offences; NCSC-FI/sectoral regulators for incident handling
Penalties Imprisonment, fines, criminal record, and, where the relevant offence permits, disqualification from business activity Administrative fines up to EUR 20m or 4% of total worldwide annual turnover (whichever is higher) under GDPR, corrective measures, reputational and contractual fallout
Notification impact Failure to report or deliberate concealment can aggravate a prosecution Failure to notify can draw administrative fines; timely cooperation mitigates
Timing / limitation Varies by offence; early counsel engagement is critical because evidence and witness accounts form quickly Administrative timelines differ; DPA investigations often run in parallel with criminal probes
Typical defences Lack of intent, reliance on expert advice, delegation to competent officers, absence of gross negligence Demonstrable compliance programme, timely notification, documented mitigation and remediation
Practical board steps Consider suspension of implicated executives, preserve evidence, engage criminal counsel, limit wide internal circulation of blame Notify DPA/NCSC where required, commission external forensic review, minute remediation steps

Read the table as a triage tool. The left column is a criminal-defence problem centred on the conduct and communications of named individuals; the right column is a compliance and remediation problem centred on the organisation’s systems and documentation. A board’s instinct after an incident is often to consolidate everything into a single internal narrative, but doing so can blur the two tracks and manufacture admissions that harm both. The disciplined approach is to protect individuals’ criminal position (evidence preservation, restrained communications, early counsel) while simultaneously discharging the company’s regulatory duties (notification, cooperation, documented remediation). Where the facts are mixed, both tracks must be managed in parallel and coordinated by counsel.

Notification, reporting and co-operation duties after an incident

Post-incident reporting duties are where criminal liability data breaches finland and administrative exposure most obviously intersect. Getting notification right protects the company; getting it wrong, or worse, deliberately avoiding it, can convert an administrative problem into a criminal one.

GDPR DPA notification thresholds & timing (72 hours)

Under the GDPR, a controller must notify the Data Protection Ombudsman of a personal data breach without undue delay and, where feasible, not later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of individuals. Where the breach is likely to result in a high risk, affected data subjects must also be informed without undue delay. The 72-hour clock is a hard operational benchmark and boards should treat it as such. Corporate cyber incident reporting in Finland begins here: the notification decision must be made quickly, documented, and grounded in the risk assessment rather than in reputational preference.

NCSC / sectoral incident reporting

Essential and important entities within NIS2 scope carry sectoral incident-reporting obligations channelled through competent national authorities, with NCSC-FI providing guidance and reporting channels. These duties are distinct from GDPR notification and may apply even where no personal data is affected. Under the NIS2 regime, an early warning is generally expected within a short window of becoming aware of a significant incident, followed by a more detailed notification, in line with the timelines set in the applicable legislation and authority guidance. Boards in regulated and critical sectors should map their reporting obligations before an incident, not during one.

Prosecutor/regulator engagement and preserving privilege

Cooperation with regulators is generally mitigating on the administrative side. But cooperation must be managed so that it does not inadvertently prejudice the legal position of individuals on the criminal side. The correct sequence is to preserve evidence first, obtain legal advice on what must be disclosed and when, and then engage regulators through counsel. Timely, honest engagement is protective; freelance disclosure by stressed executives is dangerous.

Investigations & evidence, how board and GC actions change criminal exposure

The board’s own conduct in the hours and days after discovery is one of the largest variables in criminal liability data breaches finland. Handled well, an internal investigation preserves the truth and protects legitimate interests. Handled badly, it creates the very evidence a prosecutor needs.

Internal investigations: preserving confidentiality and chain of custody

An internal investigation into a data breach in Finland should be structured from the outset to protect the confidentiality of legal advice and maintain a defensible chain of custody. That means engaging external counsel to direct the investigation where appropriate, ensuring forensic images and logs are captured and preserved before any remediation overwrites them, and controlling who has access to sensitive findings. Chain of custody is not a technicality: if evidence is altered, lost or handled loosely, it undermines both the company’s defence and any attempt to attribute wrongdoing correctly, and it can itself look like an attempt to interfere with an investigation.

Communication policies and the risk of admission

Every internal memo, public statement and chat message written after an incident is potential evidence. Careless internal communications that assign blame, speculate about fault, or characterise conduct as deliberate can become the centrepiece of a prosecution against a named individual. Boards should route substantive analysis of causation and culpability through legally privileged channels where available, keep operational communications factual, and align external statements with counsel before release.

When to escalate to external counsel and forensic experts

Escalate early. The moment there is any indication of deliberate concealment, business secret misappropriation, unauthorised access, or senior involvement in the conduct that caused the breach, external criminal counsel and independent forensic experts should be instructed. Early escalation is cheaper than late escalation and, more importantly, it shapes the evidence record while it is still forming rather than trying to repair it afterwards.

Practical mitigation, governance & insurance steps for boards and GCs

Preparation and disciplined execution are the most reliable ways to reduce criminal liability data breaches finland at the individual level. The following phased checklist is designed for use under pressure:

  • Immediate (first 72 hours). Convene the incident team; preserve forensic evidence and logs; assess the GDPR notification threshold and notify the DPA within 72 hours where required; assess NIS2/sectoral reporting duties; instruct external counsel and forensic experts; consider suspending implicated staff where there is credible evidence of wrongdoing; and control internal and external communications.
  • Short term (first 30 days). Complete the forensic timeline; document all decisions in board minutes; notify affected data subjects where high risk exists; cooperate with regulators through counsel; and maintain confidentiality discipline across the investigation.
  • Medium term (post-incident remediation). Remediate the root cause; document remediation as evidence of good faith; review governance and reporting lines; update the incident-response plan; and conduct a lessons-learned review under legal advice.

On insurance and indemnities, boards should confirm the scope of directors’ and officers’ (D&O) cover for defence costs arising from cyber incidents, understand any exclusions for deliberate or criminal conduct, and check the interaction between D&O cover and company indemnities. Insurance funds a defence; it does not cure culpability, and cover typically will not respond to proven intentional criminal acts.

Recent enforcement trends & illustrative context (2024–2026)

The direction of travel into 2026 is clear. The Data Protection Ombudsman continues to exercise its administrative powers actively, and the pattern across enforcement is that concealment and non-cooperation tend to aggravate outcomes while prompt notification and documented remediation tend to mitigate them. The NIS2 era has raised board-level accountability for cyber governance in critical sectors, and NCSC-FI’s role in incident handling has strengthened cross-agency coordination. Practitioners expect this coordination between the DPA, NCSC-FI and prosecutors to increase the likelihood that serious incidents involving concealment, business secret misappropriation or gross negligence are examined for individual criminal exposure, not merely for administrative fines.

The likely practical effect is that sectors handling large volumes of sensitive personal data and critical-infrastructure operators face the highest combined administrative and criminal scrutiny. None of this changes the underlying legal test, but it changes the probability that the test is applied to individuals.

Key takeaways for boards & GCs, a decision framework

Boards need a decision, not a hedge. Use the following framework to choose your track immediately after an incident:

  • Choose “immediate criminal counsel + preserve evidence” when: there is evidence of deliberate concealment, falsified logs, or communications showing intent to mislead investigators; the incident involves misappropriation of business secrets or clear criminal acts such as ransomware with data exfiltration or unauthorised access; or senior executives directed or knowingly approved the decisions that caused the breach.
  • Choose “focus on regulatory reporting & remediation” when: the breach results from systemic governance failures with no evidence linking executive intent; and notification to the DPA or NCSC-FI is required and prompt cooperation can mitigate fines.
  • Choose “parallel track: criminal & regulatory strategy” when: the facts are mixed, possible negligence combined with potential criminal acts, in which case counsel should coordinate the criminal-defence and regulatory-cooperation workstreams and preserve confidentiality of advice throughout.

The recommendation is unambiguous: where the markers of intent, concealment or misappropriation are present, treat the matter as a criminal problem from the first hour and structure everything else around that. Where they are absent, run a clean, well-documented regulatory and remediation response. Where you cannot yet tell, assume the parallel track and instruct counsel to keep both options open. Managing criminal liability data breaches finland well is ultimately about discipline in the first 72 hours, preserving evidence, restraining communications, and getting the right advice before the record hardens.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Annastiina Latvasaho at Salingre Attorneys, a member of the Global Law Experts network.

Sources

  1. Finnish Criminal Code (Rikoslaki 39/1889), Finlex
  2. General Data Protection Regulation (EU) 2016/679, EUR-Lex
  3. Finnish Data Protection Act (Tietosuojalaki 1050/2018), Finlex
  4. Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto)
  5. National Cyber Security Centre Finland (NCSC-FI), Traficom
  6. Directive (EU) 2022/2555 (NIS2), EUR-Lex
  7. European Union Agency for Cybersecurity (ENISA)

FAQs

When can a CEO be personally prosecuted for a data breach in Finland?
A CEO faces personal prosecution when prosecutors can prove the individual committed or knowingly authorised a criminal act, with intent or, for some offences, gross negligence, or interfered with an investigation. Administrative failure by the company alone does not establish personal criminal liability; the case turns on the CEO’s own decisions, communications and knowledge.
Failing to notify the Data Protection Ombudsman is primarily an administrative GDPR breach that exposes the company to fines. However, deliberate concealment of an incident, or active interference with a regulatory or criminal inquiry, can cross into criminal territory and aggravate an individual’s position.
Board members can face criminal exposure where individual culpability, intent or gross negligence, is proven, and penalties may include fines and imprisonment, with disqualification from business activity available for certain offences and circumstances under Finnish law. Where no individual culpability exists, exposure is usually administrative or contractual rather than criminal.
To reduce criminal liability data breaches finland at the individual level, preserve forensic evidence, consider suspending implicated staff where there is credible evidence, engage external forensic and criminal counsel, notify the DPA and NCSC-FI where required, control internal and external communications, and document every decision contemporaneously.
They run in parallel. GDPR fines are administrative and imposed on the company; criminal prosecution focuses on the personal culpability of individuals. Cooperation and remediation can reduce administrative fines but will not, by themselves, prevent a criminal charge where intent or gross negligence is present.

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

When Can Executives Be Criminally Prosecuted for Data Breaches in Finland (2026), What Boards & Gcs Must Know

Send welcome message

Custom Message