Varaa keskustelu

— Tietosuoja

Ilmoituskanavarekisteri

Reaktin rekisterikohtainen tietosuojaseloste. Selosteessa kerrotaan henkilötietojen käsittelyn tarkoitus, oikeusperuste, säilytysaika ja rekisteröidyn oikeudet.

Kaikki tietosuojaselosteet

Rekisteri

Ilmoituskanavarekisteri

Rekisterinpitäjä

Reakt Direct S.L.

Yhteyshenkilö

Joonas Hyttinen
joonas.hyttinen@reakt.fi

Laadittu

2.10.2025

Käsittelyn oikeusperuste

Lakisääteinen velvoite

Henkilötietojen käsittelyn tarkoitus

Oikeusperusteena on ilmoituksen sisällön perusteella joko:

  • lakisääteinen velvoite (direktiivin alainen ilmoitettu tieto) tai
  • oikeutettu etu (direktiivin ulkopuolinen ilmoitettu tieto)

Tietojen käsittely perustuu ilmoittajansuojalakiin sekä ns. ”whistleblowdirektiiviin” ja niitä käsitellään väärinkäytösten, rikosten ja vastaavien ehkäisemiseksi sekä tutkimiseksi.

Oikeutetun edun peruste

Oikeutetun edun perusteena on rekisterinpitäjän ja rekisteröidyn merkityksellinen suhde: ilmoittaja on joko omaa henkilöstöä tai muuten whistleblowing-direktiivin mukainen sidosryhmäläinen suhteessa rekisterinpitäjään.

Kyseessä olevat henkilötietoryhmät

Oma henkilöstö sekä sidosryhmät ilmoittajansuojelulain mukaisesti. Ilmoitettavan nimi sekä muuta ilmoitettavan toimintaan liittyvää tietoa sekä ilmoittajan nimi, mikäli ilmoitusta ei ole tehty nimettömänä.

Käsittelyyn voi liittyä riski korkea riski annettavasta tiedosta johtuen. Riskejä on arvioitu tarkemmin ilmoituskanavarekisterin vaikutusten arvioinnissa, joka löytyy ”vaikutusten arvioinnit” osiosta Easy GDPR-palvelussa.

Vastaanottajat ja vastaanottajaryhmät

Rekisterinpitäjän oma henkilöstö sekä syvempää tutkintaa vaadittaessa siihen dedikoitu ulkoistuskumppani, jonka GDPR-valmiudet on tarkastettu ja jonka kanssa on tehty artikla 28 -mukaiset muut toimenpiteet.

Tietoja voidaan myös luovuttaa poliisille tai muulle viranomaiselle tilanteessa, joissa on tapahtunut tai epäillään tapahtuneen rikos.

Suostumus

Käsittely perustuu oikeutettuun etuun sekä lakisääteiseen velvoitteeseen, suostumusta ei tarvita.

Rekisterin tietosisältö

Rekisteri sisältää seuraavia tietoja:

  • Ilmoittajan nimi
  • Ilmoituksen kohteen nimi
  • Ilmoituksen aiheena olevaa ilmoittajan antamaa tietoa

Henkilötietoja, joilla selvästi ei ole merkitystä tietyn ilmoituksen käsittelyn kannalta, ei kerätä, tai jos niitä kerätään vahingossa, ne poistetaan ilman aiheetonta viivytystä.

Säännönmukaiset tietolähteet

Rekisteröidyltä itseltään, eli ilmoittajalta.

Henkilötietojen säilytysaika

Henkilörekisterin tietoja säilytetään niin kauan, kuin se on rekisterinpitäjän mahdollisen syyttömyystodistuksen kannalta välttämätöntä tai minkä laki määrittelee säilytysajaksi. Tämän jälkeen tiedot tuhotaan tietoturvallisesti.

Tietojen säännönmukaiset luovutukset

Rekisterin tietoja ei pääsääntöisesti luovuteta kolmansille osapuolille muuta kuin syvemmissä tutkintatilanteissa valikoiduille, GDPR-kelpoisille toimijoille joiden kanssa on toteutettu artikla 28 mukaiset toimenpiteet.

Tietojen siirto EU:n tai ETA:n ulkopuolelle

Rekisterin tietoja ei luovuteta EU:n tai ETA:n ulkopuolelle.

Rekisterin suojauksen periaatteet A: Manuaalinen aineisto

Ilmoituskanavarekisteriin liittyvä aineisto on pääasiassa vain sähköisessä muodossa ja tietoja käsitellään vain sähköisesti. Manuaalista aineistoa voi kuitenkin syntyä esimerkiksi suullisten tapaamisten yhteydessä kirjoitetuista muistioista tai vastaavista.

Pääsy Rekisterin tietoihin on vain niillä ja siinä laajuudessa kuin asian käsittely, valvominen tai muu ilmoitukseen liittyvän asian hoito edellyttää.

Rekisterin tietojen suojaamisessa ja käsittelyssä noudatetaan tietosuojalain säännöksiä ja periaatteita, viranomaisten määräyksiä sekä hyvää tietojenkäsittelytapaa.

Rekisterin suojauksen periaatteet B: Sähköinen aineisto

Pääsy rekisterin tietoihin on vain niillä ja siinä laajuudessa kuin asian käsittely, valvominen tai muu ilmoitukseen liittyvän asian hoito edellyttää. Rekisteriä säilytetään suojatulla palvelimella, joka sijaitsee Suomessa.

Rekisterin tietojen suojaamisessa ja käsittelyssä noudatetaan tietosuojalain säännöksiä ja periaatteita, viranomaisten määräyksiä sekä hyvää tietojenkäsittelytapaa.

Evästeet

Verkkosivut, joiden kautta ilmoituksia jätetään, voivat käyttää evästeitä. Sivuillamme vierailevalla käyttäjällä on mahdollisuus koska tahansa estää evästeiden käyttö muuttamalla niiden asetuksia evästebannerista.

Myös jotkut selainohjelmat mahdollistavat eväste-toiminnon poiskytkemisen ja jo tallennettujen evästeiden poistamisen. Evästeiden käytön estäminen saattaa vaikuttaa sivuston toiminnallisuuteen.

Automaattinen käsittely ja profilointi

Automaattista päätöksentekoa tai muutakaan arviointia henkilöistä ei ilmoituskanavatoiminnalla suoriteta, eikä rekisteröidylle aiheudu käsittelystä haittaa tai seurauksia.

Tarkastusoikeus eli oikeus saada pääsy henkilötietoihin

Ilmoituksen kohteena olevalla rekisteröidyllä ei ole tarkastusoikeutta tietoihin, jos tietojen antaminen voisi haitata epäiltyjen rikkomisten selvittämistä tai ilmoittajansuojan vaarantumisen.

Jos ilmoittamiseen käytetään puhelinlinjaa tai muuta ääniviestijärjestelmää, joka ei nauhoita keskustelua, on rekisterinpitäjällä oikeus dokumentoida suullinen ilmoitus ilmoituksen käsittelystä vastaavan henkilöstön jäsenen keskustelusta kirjoittaman tarkan pöytäkirjan muodossa. Ilmoittavalla henkilöllä on tällöin mahdollisuus tarkistaa, korjata ja hyväksyä allekirjoituksellaan keskustelusta laadittu pöytäkirja.

Oikeus siirtää tiedot järjestelmästä toiseen

Rekisteröidyillä ei ole oikeutta siirtää tietoja, jos tietojen antaminen voisi haitata epäiltyjen rikkomisten selvittämistä, käsittelyn oikeusperusteena on oikeutettu etu tai se saattaisi vaarantaa ilmoittajansuojan.

Oikeus vaatia tiedon korjaamista

Ilmoittajalla on mahdollisuus tarkistaa, korjata ja hyväksyä allekirjoituksellaan esimerkiksi keskustelusta laadittu selostus.

Korjauspyyntö voidaan myös evätä. Korjauspyynnön epäämisestä rekisterin vastuuhenkilö antaa kirjallisen todistuksen, jossa mainitaan syyt, joiden vuoksi korjauspyyntö on evätty. Asianomainen voi saattaa epäämisen tietosuojavaltuutetun ratkaistavaksi.

Rajoittamisoikeus

Rekisteröidyllä on oikeus pyytää tietojenkäsittelyn rajoittamista esimerkiksi jos rekisterissä olevat henkilötiedot ovat virheelliset, kunhan se ei haittaa epäiltyjen rikkomusten selvittämistä tai vaaranna ilmoittajansuojaa.Tällöin käsittelyä rajoitetaan, kunnes rekisterinpitäjä on varmistanut tietojen paikkansapitävyyden. Pyyntö tulee tehdä tunnistettavasta sähköpostiosoitteesta rekisterinpitäjän yhteyspisteeseen.

Vastustamisoikeus

Rekisteröidyillä ei ole oikeutta vastustaa käsittelyä, jos se voisi haitata epäiltyjen rikkomisten selvittämistä tai se mahdollisesti vaarantaisi ilmoittajansuojan.

Oikeus tehdä valitus valvontaviranomaiselle

Mikäli rekisteröity katsoo, että häntä koskevassa henkilötietojen käsittelyssä on rikottu tietosuoja-asetusta, niin rekisteröidyllä on oikeus tehdä kantelu valvontaviranomaiselle. Kantelun voi tehdä myös siinä jäsenvaltiossa, jossa rekisteröidyllä on vakinainen asuinpaikka tai työpaikka.

Valvontaviranomaisten yhteystiedot ovat:

Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid, Espanja, p. +34 901 100 099 / +34 912 663 517, www.aepd.es. Koska rekisterinpitäjä toimii myös Suomessa, kantelun voi tehdä myös tietosuojavaltuutetun toimistoon: Lintulahdenkuja 4, 00530 Helsinki, postiosoite PL 800, 00531 Helsinki, p. 029 566 6700, tietosuoja@om.fi, www.tietosuoja.fi.

Muut henkilötietojen käsittelyyn liittyvät oikeudet

Rekisteröidyllä on oikeus kieltää tietojensa luovuttaminen ja käsittely suoramainontaa ja muuta markkinointia varten, vaatia tietojen anonymisointia soveltuvin osin sekä oikeus tulla kokonaan unohdetuksi työsuhteen päätyttyä, ellei tämä voisi haitata epäiltyjen rikkomisten selvittämistä tai mahdollisesti vaarantaa ilmoittajansuojan.

Selosteen alkuperäiskieli on suomi. Ristiriitatilanteessa suomenkielinen versio on määräävä.

All privacy notices

Register

Whistleblowing channel register

Controller

Reakt Direct S.L.

Contact person

Joonas Hyttinen
joonas.hyttinen@reakt.fi

Drawn up

2.10.2025

Legal basis for processing

Legal obligation

Purpose of processing personal data

Depending on the content of the report, the legal basis is either:

  • a legal obligation (information reported within the scope of the Directive), or
  • legitimate interest (information reported outside the scope of the Directive)

The processing is based on the EU Whistleblower Directive (EU) 2019/1937 and the national legislation implementing it, and the data is processed in order to prevent and investigate misconduct, offences and similar matters.

Grounds for legitimate interest

The legitimate interest is based on a relevant relationship between the controller and the data subject: the reporting person is either a member of our own personnel or otherwise a stakeholder in relation to the controller within the meaning of the Whistleblower Directive.

Categories of personal data concerned

Our own personnel and stakeholders in accordance with whistleblower protection legislation. The name of the person reported on and other information relating to that person's activities, as well as the name of the reporting person if the report was not made anonymously.

The processing may involve a high risk due to the information provided. The risks have been assessed in more detail in the data protection impact assessment for the whistleblowing register, which can be found in the "impact assessments" section of the Easy GDPR service.

Recipients and categories of recipients

The controller's own personnel and, where a deeper investigation is required, a dedicated outsourcing partner whose GDPR capabilities have been verified and with whom the measures required by Article 28 have been agreed.

Data may also be disclosed to the police or another authority in situations where an offence has occurred or is suspected to have occurred.

Consent

The processing is based on legitimate interest and on a legal obligation; consent is not required.

Data content of the register

The register contains the following data:

  • The name of the reporting person
  • The name of the person the report concerns
  • Information provided by the reporting person concerning the subject of the report

Personal data that is clearly not relevant to the handling of a particular report is not collected, or, if collected inadvertently, is erased without undue delay.

Regular sources of data

From the data subject themselves, i.e. the reporting person.

Retention period for personal data

The data in the personal data register is retained for as long as is necessary for the controller's possible exoneration or for the retention period laid down by law. After that, the data is destroyed securely.

Regular disclosures of data

As a rule, data in the register is not disclosed to third parties other than, in deeper investigations, to selected GDPR-compliant operators with whom the measures required by Article 28 have been implemented.

Transfers of data outside the EU or EEA

Data in the register is not transferred outside the EU or the EEA.

Principles of protecting the register A: Manual material

Material relating to the whistleblowing register is mainly in electronic form only and the data is processed electronically only. Manual material may nevertheless arise, for example from memoranda written in connection with oral meetings or similar.

Access to the data in the register is limited to those persons, and to the extent, required by the handling and monitoring of the matter or the management of other matters relating to the report.

The protection and processing of the data in this register complies with the provisions and principles of data protection legislation, the requirements of the authorities and good data processing practice.

Principles of protecting the register B: Electronic material

Access to the data in the register is limited to those persons, and to the extent, required by the handling and monitoring of the matter or the management of other matters relating to the report. The register is kept on a protected server located in Finland.

The protection and processing of the data in this register complies with the provisions and principles of data protection legislation, the requirements of the authorities and good data processing practice.

Cookies

The websites through which reports are submitted may use cookies. A user visiting our site can prevent the use of cookies at any time by changing the settings in the cookie banner.

Some browsers also make it possible to switch off the cookie function and to delete cookies that have already been stored. Preventing the use of cookies may affect the functionality of the site.

Automated processing and profiling

No automated decision-making or other assessment of individuals is carried out through the whistleblowing channel, and the processing does not cause harm or consequences to the data subject.

Right of access to personal data

A data subject who is the subject of a report does not have a right of access to the data if providing the data could hinder the investigation of suspected breaches or jeopardise the protection of the reporting person.

If a telephone line or another voice messaging system that does not record the conversation is used for reporting, the controller has the right to document the oral report in the form of an accurate minute of the conversation written by the member of staff responsible for handling the report. The reporting person then has the opportunity to check, correct and approve the minute of the conversation by signing it.

Right to data portability

Data subjects do not have the right to data portability if providing the data could hinder the investigation of suspected breaches, if the legal basis for the processing is legitimate interest, or if it could jeopardise the protection of the reporting person.

Right to rectification

The reporting person has the opportunity to check, correct and approve by their signature, for example, a written account of the conversation.

A correction request may also be refused. If a correction request is refused, the person responsible for the register issues a written statement setting out the reasons for the refusal. The person concerned may refer the refusal to the data protection supervisory authority for a decision.

Right to restriction of processing

The data subject has the right to request the restriction of processing, for example if the personal data in the register is incorrect, provided that this does not hinder the investigation of suspected breaches or jeopardise the protection of the reporting person. Processing is then restricted until the controller has verified the accuracy of the data. The request must be made from an identifiable email address to the controller's contact point.

Right to object

Data subjects do not have the right to object to the processing if this could hinder the investigation of suspected breaches or could jeopardise the protection of the reporting person.

Right to lodge a complaint with a supervisory authority

If the data subject considers that the processing of personal data concerning them has infringed the General Data Protection Regulation, the data subject has the right to lodge a complaint with a supervisory authority. The complaint may also be lodged in the Member State in which the data subject has their habitual residence or place of work.

The contact details of the supervisory authorities are:

Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid, Spain, tel. +34 901 100 099 / +34 912 663 517, www.aepd.es. As the controller also operates in Finland, a complaint may also be lodged with the Office of the Data Protection Ombudsman, Lintulahdenkuja 4, 00530 Helsinki, postal address P.O. Box 800, 00531 Helsinki, tel. +358 29 566 6700, tietosuoja@om.fi, www.tietosuoja.fi.

Other rights relating to the processing of personal data

The data subject has the right to prohibit the disclosure and processing of their data for direct advertising and other marketing purposes, to require the anonymisation of the data where applicable, and to be forgotten entirely after the end of the employment relationship, unless this could hinder the investigation of suspected breaches or possibly jeopardise the protection of the reporting person.

The original language of this notice is Finnish. In the event of any discrepancy, the Finnish version prevails.

Todas las cláusulas informativas

Fichero

Fichero del canal de comunicaciones

Responsable del tratamiento

Reakt Direct S.L.

Persona de contacto

Joonas Hyttinen
joonas.hyttinen@reakt.fi

Fecha de elaboración

2.10.2025

Información básica sobre protección de datos

Responsable
Reakt Direct S.L.
Finalidad
En función del contenido de la comunicación, la base jurídica es:
Legitimación
Cumplimiento de una obligación legal
Destinatarios
El personal propio del responsable del tratamiento y, cuando se requiera una investigación más profunda, un socio de externalización dedicado a ello cuyas capacidades en materia de RGPD han sido verificadas y con el que se han acordado las medidas previstas en el artículo 28.
Derechos
Tiene derecho a acceder, rectificar y suprimir los datos, así como otros derechos (limitación, oposición y portabilidad) y a presentar una reclamación ante la AEPD, como se explica en la información adicional.

Puede consultar la información adicional y detallada sobre protección de datos a continuación.

Base jurídica del tratamiento

Obligación legal

Finalidad del tratamiento de los datos personales

En función del contenido de la comunicación, la base jurídica es:

  • una obligación legal (información comunicada dentro del ámbito de la Directiva), o
  • el interés legítimo (información comunicada fuera del ámbito de la Directiva)

El tratamiento se basa en la Directiva (UE) 2019/1937 relativa a la protección de las personas que informen sobre infracciones y en la normativa nacional que la transpone, y los datos se tratan con el fin de prevenir e investigar irregularidades, delitos y situaciones similares.

Fundamento del interés legítimo

El interés legítimo se fundamenta en la existencia de una relación pertinente entre el responsable del tratamiento y el interesado: la persona informante forma parte de nuestro propio personal o es, de otro modo, una parte interesada respecto del responsable del tratamiento en el sentido de la Directiva.

Categorías de datos personales tratados

Nuestro propio personal y las partes interesadas conforme a la normativa de protección de las personas informantes. El nombre de la persona objeto de la comunicación y otra información relativa a su actuación, así como el nombre de la persona informante si la comunicación no se ha realizado de forma anónima.

El tratamiento puede conllevar un riesgo alto debido a la información facilitada. Los riesgos se han evaluado con mayor detalle en la evaluación de impacto relativa al fichero del canal de comunicaciones, disponible en la sección "evaluaciones de impacto" del servicio Easy GDPR.

Destinatarios y categorías de destinatarios

El personal propio del responsable del tratamiento y, cuando se requiera una investigación más profunda, un socio de externalización dedicado a ello cuyas capacidades en materia de RGPD han sido verificadas y con el que se han acordado las medidas previstas en el artículo 28.

Los datos también pueden cederse a la policía o a otra autoridad en situaciones en las que se haya cometido o se sospeche que se ha cometido un delito.

Consentimiento

El tratamiento se basa en el interés legítimo y en una obligación legal; no se requiere consentimiento.

Contenido del fichero

El fichero contiene los siguientes datos:

  • El nombre de la persona informante
  • El nombre de la persona objeto de la comunicación
  • La información facilitada por la persona informante sobre el objeto de la comunicación

Los datos personales que claramente no resulten pertinentes para la tramitación de una comunicación concreta no se recogen o, si se recogen de forma accidental, se suprimen sin dilación indebida.

Fuentes habituales de los datos

Del propio interesado, es decir, de la persona informante.

Plazo de conservación de los datos personales

Los datos del fichero de datos personales se conservan durante el tiempo necesario para acreditar, en su caso, la ausencia de responsabilidad del responsable del tratamiento o durante el plazo de conservación que establezca la ley. Transcurrido ese plazo, los datos se destruyen de forma segura.

Cesiones habituales de datos

Por regla general, los datos del fichero no se ceden a terceros, salvo, en investigaciones más profundas, a operadores seleccionados que cumplen el RGPD y con los que se han implementado las medidas previstas en el artículo 28.

Transferencias de datos fuera de la UE o del EEE

Los datos del fichero no se transfieren fuera de la UE ni del EEE.

Principios de protección del fichero A: Material manual

El material relativo al fichero del canal de comunicaciones se encuentra principalmente solo en formato electrónico y los datos se tratan únicamente por medios electrónicos. No obstante, puede generarse material manual, por ejemplo actas redactadas con motivo de reuniones orales o similares.

El acceso a los datos del fichero se limita a las personas y en la medida en que lo exija la tramitación y el seguimiento del asunto o la gestión de otras cuestiones relacionadas con la comunicación.

En la protección y el tratamiento de los datos del fichero se observan las disposiciones y los principios de la normativa de protección de datos, las instrucciones de las autoridades y las buenas prácticas en el tratamiento de la información.

Principios de protección del fichero B: Material electrónico

El acceso a los datos del fichero se limita a las personas y en la medida en que lo exija la tramitación y el seguimiento del asunto o la gestión de otras cuestiones relacionadas con la comunicación. El fichero se conserva en un servidor protegido situado en Finlandia.

En la protección y el tratamiento de los datos del fichero se observan las disposiciones y los principios de la normativa de protección de datos, las instrucciones de las autoridades y las buenas prácticas en el tratamiento de la información.

Cookies

Los sitios web a través de los cuales se presentan las comunicaciones pueden utilizar cookies. El usuario que visita nuestro sitio puede impedir en cualquier momento el uso de cookies modificando su configuración en el banner de cookies.

Algunos navegadores permiten además desactivar la función de cookies y eliminar las cookies ya almacenadas. Impedir el uso de cookies puede afectar a la funcionalidad del sitio.

Tratamiento automatizado y elaboración de perfiles

A través del canal de comunicaciones no se realizan decisiones automatizadas ni ninguna otra evaluación de las personas, y el tratamiento no causa perjuicio ni consecuencias al interesado.

Derecho de acceso a los datos personales

El interesado que sea objeto de una comunicación no dispone de derecho de acceso a los datos si facilitarlos pudiera dificultar la investigación de las presuntas infracciones o poner en peligro la protección de la persona informante.

Si para comunicar se utiliza una línea telefónica u otro sistema de mensajería de voz que no grabe la conversación, el responsable del tratamiento tiene derecho a documentar la comunicación oral mediante un acta detallada de la conversación redactada por el miembro del personal responsable de su tramitación. En tal caso, la persona informante tiene la posibilidad de comprobar, rectificar y aprobar con su firma el acta de la conversación.

Derecho a la portabilidad de los datos

Los interesados no tienen derecho a la portabilidad de los datos si facilitarlos pudiera dificultar la investigación de las presuntas infracciones, si la base jurídica del tratamiento es el interés legítimo o si ello pudiera poner en peligro la protección de la persona informante.

Derecho de rectificación

La persona informante tiene la posibilidad de comprobar, rectificar y aprobar con su firma, por ejemplo, el acta redactada de la conversación.

La solicitud de rectificación también puede denegarse. Si se deniega una solicitud de rectificación, la persona responsable del fichero emite una declaración por escrito en la que se indican los motivos de la denegación. La persona interesada puede someter la denegación a la resolución de la autoridad de control en materia de protección de datos.

Derecho a la limitación del tratamiento

El interesado tiene derecho a solicitar la limitación del tratamiento, por ejemplo si los datos personales que constan en el fichero son inexactos, siempre que ello no dificulte la investigación de las presuntas infracciones ni ponga en peligro la protección de la persona informante. En tal caso, el tratamiento se limita hasta que el responsable del tratamiento haya verificado la exactitud de los datos. La solicitud debe realizarse desde una dirección de correo electrónico identificable al punto de contacto del responsable del tratamiento.

Derecho de oposición

Los interesados no tienen derecho a oponerse al tratamiento si ello pudiera dificultar la investigación de las presuntas infracciones o poner en peligro la protección de la persona informante.

Derecho a presentar una reclamación ante la autoridad de control

Si el interesado considera que el tratamiento de los datos personales que le conciernen ha infringido el Reglamento General de Protección de Datos, tiene derecho a presentar una reclamación ante una autoridad de control. La reclamación también puede presentarse en el Estado miembro en el que el interesado tenga su residencia habitual o su lugar de trabajo.

Los datos de contacto de las autoridades de control son:

Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid, tel. 901 100 099 / 912 663 517, www.aepd.es. Dado que el responsable del tratamiento opera también en Finlandia, la reclamación puede presentarse asimismo ante la Oficina del Defensor de la Protección de Datos (Tietosuojavaltuutetun toimisto), Lintulahdenkuja 4, 00530 Helsinki, apartado de correos 800, 00531 Helsinki, tel. +358 29 566 6700, tietosuoja@om.fi, www.tietosuoja.fi.

Otros derechos relacionados con el tratamiento de datos personales

El interesado tiene derecho a oponerse a la cesión y al tratamiento de sus datos con fines de publicidad directa y otras acciones de marketing, a exigir la anonimización de los datos cuando proceda y a ser olvidado por completo tras la finalización de la relación laboral, salvo que ello pudiera dificultar la investigación de las presuntas infracciones o poner en peligro la protección de la persona informante.

La lengua original de esta cláusula informativa es el finés. En caso de discrepancia, prevalecerá la versión finesa.