Blog/Guides
Background checks and candidate privacy in Finland: what employers should know
Finnish law limits you to data that is directly necessary for the employment relationship — and consent does not widen that. What you may check, what you may not, and who pays.

The instinct when hiring is to find out as much as possible. Finnish law runs the other way: you may hold only what is directly necessary for the employment relationship — and asking the candidate’s permission does not widen that.
That last point is the one that catches people. As the Occupational Safety and Health Administration puts it, the necessity requirement cannot be departed from even with the employee’s consent. A consent form does not turn an impermissible check into a permissible one. It is not a key.
The rules sit in the Act on the Protection of Privacy in Working Life (759/2004), which runs alongside the General Data Protection Regulation (GDPR) rather than being replaced by it.
- You may hold only data that is directly necessary for the employment relationship — the candidate’s consent does not widen that.
- Outdated, incorrect or unnecessary data may not be retained, and data must be collected primarily from the candidate themselves.
- A credit check needs both particular trustworthiness and an opportunity for unlawful financial gain, plus at least one of seven listed job elements, and only for a candidate already selected.
- You always pay for a drug test, and you can only require one from the candidate already selected — never at application or interview stage.
- Drug testing needs a written substance abuse programme and roles cleared through the co-operation procedure before you can require a certificate.
- Health data may only be handled for sick pay, verifying an absence, or at the employee’s own request — you may not keep a register of it.
What counts as “directly necessary”?
Data connected to managing the rights and obligations of the parties, to benefits you provide, or to the special nature of the duties. Everything outside that is off limits, consent or no consent.
- Decide in advance. When planning the collection you must define why the data is necessary for performing the task and for what purpose it is collected. The assessment is made separately in each case.
- Name who handles it. You must determine in advance whose duties include processing personal data.
- Do not keep what you should not. Outdated, incorrect or unnecessary data about employees may not be retained, and outdated employee data may not be kept at the workplace.
Collect primarily from the person themselves. If you collect from elsewhere, you generally need their consent — with two narrow exceptions: an authority disclosing information to you in performance of a statutory duty, and credit or criminal record data obtained on lawful grounds to establish trustworthiness.
Next: look at your applicant tracking system and ask what it holds about rejected candidates from two years ago. If you cannot state the purpose, it should not be there.
When can you run a credit check?
Rarely, and never as a routine screen. Two conditions must both hold, and at least one job element from the list below must also be present:
| Requirement | What must be true |
|---|---|
| Baseline condition (both required) | Duties require particular trustworthiness |
| Baseline condition (both required) | Duties involve an opportunity to pursue unlawful financial gain |
| Job element (at least one required) | Decision-making or independent discretion over significant financial commitments |
| Job element (at least one required) | Granting and supervising economically significant credit |
| Job element (at least one required) | Access to protected trade or professional secrets of yours or your client’s |
| Job element (at least one required) | Right to use an information system through which your or your client’s funds can be handled |
| Job element (at least one required) | Handling significant money, securities or valuables as an essential part of the job, without direct supervision |
| Job element (at least one required) | Guarding your or your client’s property |
| Job element (at least one required) | Largely unsupervised work in a private home |
You may only request credit information for a candidate already selected for the role, or an existing employee changing duties — not for a shortlist. You must tell the person the role involves a credit check. And you pay for obtaining the information, even if the candidate supplies it themselves at your request. If you obtain it, you must tell them which register it came from.
Next: before you request a credit check, write down which of the seven job elements the role meets — if you cannot name one, you cannot run the check.
When can you require a drug test?
Under conditions, and never at application or interview stage. Your right to handle drug test information applies only to the candidate already selected for the role, so a certificate cannot be requested alongside an application or in an interview.
Two prerequisites have to exist first:
- a written substance abuse programme as referred to in the Occupational Health Care Act, and
- the duties justifying a drug test certificate must have been dealt with in the co-operation procedure
Use of drug testing has to be agreed in the substance abuse programme drawn up with occupational health care. You must inform a candidate before the employment contract is made — or an existing employee before changing their terms — that the duties require a certificate.
The role itself must require accuracy, reliability, independent judgement or good reactive capacity, with a further condition on top relating to the risk created by performing the work under the influence of, or dependent on, drugs.
Even then the limits are tight: you may handle and record only the information given in the certificate, and only with the person’s consent. You pay for the test.
Next: if you drug test, check that a written substance abuse programme actually exists and that the roles were run through the co-operation procedure. Without both, the testing has no basis.
What about health information?
Health data is a special category under the GDPR, and collecting or handling it must be directly necessary for the employment relationship. You may handle it where needed:
- to pay sick pay or comparable benefits related to health
- to establish whether there is a justified reason for absence from work
- at the employee’s own express request, when they want their work ability assessed on health grounds
Beyond those, only where another statute specifically provides. And not even the employee’s consent permits collecting or handling data unlawfully at the workplace.
You may not compile a register of illness data. Only a healthcare actor — occupational health care, for instance — may keep such a register.
Occupational health cannot hand you its records. It may not disclose an employee’s health data from its register unless the employee expressly consents, or a statute specifically provides for the situation.
A fitness-for-work statement carries no health information. If you require one at a pre-employment examination, occupational health may tell you only whether the person is suitable for the role, or whether there are limitations on that suitability. Not why.
Only named individuals may handle health data. How sick pay itself works is covered in Who pays for sick leave, and for how long?
Next: check who in your organisation can currently open a sickness absence record. If the answer is “anyone with HR access”, narrow it and write down the names.
What rights does the candidate have?
The GDPR gives data subjects several rights: to be informed about processing, to access the data, to rectify it, to erase it and be forgotten, to restrict processing, to port it, and to object. It also gives them the right not to be subject to automated decision-making.
One caveat matters in an employment setting. Not every right applies in every situation — what applies depends on the basis for processing, and employment processing is most often statutory. Where it is, rights such as erasure or objection generally cannot be applied. So “we deleted everything on request” is not automatically the compliant answer either.
You must nonetheless take appropriate measures to implement those rights and to make exercising them easier.
Next: check whether your candidate-facing privacy notice actually lists these rights and names who in your organisation handles a request to exercise one.
How does Taito.ai help with this?
Taito.ai is a people operations system. It sets up employee data with defined access and retention, and keeps it maintained automatically, so who can see a given record — and why it is still held — has an answer.
Sources
- Act on the Protection of Privacy in Working Life 759/2004
- Occupational Safety and Health Administration — protection of privacy
- Requesting credit information
- Drug testing
- Handling health information
- General Data Protection Regulation (EU) 2016/679
Finlex publishes this act in Finnish and Swedish only. There is no citable official English translation, so every rule here is paraphrased rather than quoted. Where the exact wording matters, follow the link and read the Finnish or Swedish text.
Disclaimer
Taito.ai does not provide legal, tax or accounting advice. This article is general information about the law as it stood on the date above, not advice on your situation, and it is not a substitute for it. Rates and thresholds change. Check with a qualified adviser before acting on anything here.

