Tietosuojavaltuutetun toimisto (Finland) - TSV/3375/2023
| Tietosuojavaltuutetun toimisto - TSV/3375/2023 | |
|---|---|
| Authority: | Tietosuojavaltuutetun toimisto (Finland) |
| Jurisdiction: | Finland |
| Relevant Law: | Article 12(1) GDPR Article 12(2) GDPR Article 12(3) GDPR Article 12(4) GDPR Article 12(5) GDPR Article 12(6) GDPR Article 15(1) GDPR Article 15(3) GDPR Article 15(4) GDPR Article 58(2)(b) GDPR Article 58(2)(d) GDPR Luottotietolaki (527/2007) 5 §, 10 § ja 19 § |
| Type: | Investigation |
| Outcome: | Violation Found |
| Started: | |
| Decided: | 10.03.2026 |
| Published: | |
| Fine: | n/a |
| Parties: | Dun & Bradstreet Finland Oy |
| National Case Number/Name: | TSV/3375/2023 |
| European Case Law Identifier: | n/a |
| Appeal: | Unknown |
| Original Language(s): | Finnish |
| Original Source: | FINLEX-Data Protection Ombudsman (in FI) |
| Initial Contributor: | Panpan |
The DPA reprimanded a credit information agency for improperly handling access requests. The controller referred data subjects to its data access portal without further action, and stated a fee would be charged for requests made more than once within 12 months.
English Summary
Facts
Dun & Bradstreet Finland Oy (the controller) is a credit information agency. It maintained a credit information register containing data on natural persons and businesses, as well as a contact information and personal marketing register.
Data subjects emailed the controller requesting access to their personal data and information on the processing of their data. The controller replied with a standard email. It told them to use OmaData, its personal data access portal. It did not respond to the requests otherwise or take any further measures to implement them.
The controller’s website stated that access was free once within a 12-month period. If a data subject requested access more than once within that period, the controller would charge EUR 9.90. This applied to requests concerning credit data.
The DPA received several complaints between May 2018 and June 2021. It then opened an ex-officio investigation into the controller’s handling of access requests and its fee practice.
Holding
The DPA held that the controller failed to respond properly to the data subjects’ requests and charged an unlawful fee for access requests. It breached Articles 12(2), (3), (4), (5), and 15(4) GDPR.
The DPA issued the controller a reprimand and an order to bring its procedures into compliance when implementing the data subjects’ right of access.
1. The controller failed to properly respond to access requests
In response to requests for access, the DPA found that the controller merely directed data subjects by email to the OmaData service.
The controller did not inform data subjects, as required by Article 12(3) GDPR, what measures it would take in response to the request; nor did it inform the data subjects that it would not take action on the request.
The DPA reasoned that this could reasonably lead data subjects to believe that access to their data was available only through OmaData. If data subjects did not wish to use that service, they had to contact the controller again. The controller therefore failed to facilitate the exercise of data subject rights, contrary to Article 12(2) GDPR.
2. Unlawful fee for further access requests within 12 months without an individual assessment
The DPA found that the controller systematically charged a fee when a data subject requested access more than once within a 12-month period.
The controller argued that repeated requests could be charged under the Credit Information Act as requests for a credit information extract. The DPA rejected this because the GDPR right of access and the right under national law to obtain a credit information extract have different purposes. A controller cannot avoid the GDPR rules on free access to personal data by treating an Article 15 request as a paid request for an extract.
In addition, the controller did not assess, on a case-by-case basis, whether the request was repetitive, manifestly unfounded or excessive. The DPA noted that, in credit information activities, data may change more than once a year, so a further request within 12 months may be justified unless the controller can demonstrate otherwise. The controller also did not consider whether the later request was a new request or merely a request for an additional copy.
The DPA found that by applying the fee automatically, without examining the content and scope of the request, the controller made it more difficult for data subjects to exercise their rights as data subjects, which breached Article 12(5) and 15(4) GDPR.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the Finnish original. Please refer to the Finnish original for more details.
Collection of fees and appropriate measures for a request to check information in credit information operations Keywords: Credit information, Right to check Year of case: 2026 Date of issue: 10.3.2026 Diary number: TSV/3375/2023 Legal basis: Decision pursuant to the EU General Data Protection Regulation Decision of the Deputy Data Protection Commissioner Parts of the decision have been encrypted. The encryption is based on Section 24, Subsection 1, Paragraph 7 of the Freedom of Information Act. Case Obligation of the controller to take appropriate measures in response to a request for access to personal data by a data subject Right of the controller to charge a fee for repeated requests for access to personal data by a data subject Controller Dun & Bradstreet Finland Oy Background of the case The controller carries out credit information activities referred to in the Credit Information Act (527/2007) and maintains a credit information register in which it collects, stores and produces credit information concerning natural persons, i.e. personal credit information and business credit information. In addition, the controller maintains, on the basis of its websites, in addition to its other databases, a contact information and personal marketing register, which is used as an address source for marketing and updating customer registers. 1 The Office of the Data Protection Ombudsman has received several contacts between 25 May 2018 and 9 June 2021 regarding the controller’s responses to data subjects who have wished to exercise their rights under Article 15 of the General Data Protection Regulation (EU) 2016/679 (the General Data Protection Regulation). Based on the contacts, the data subjects have sent an email to the controller’s customer service, in which they have wished to exercise their right to access their own data in the contact and personal marketing register maintained by the controller and to receive information about the processing of their personal data. The controller has responded to the requests with an email, in which it has directed the data subjects to access their own data by logging into the OmaData service (formerly the MyBisnode service) via strong electronic identification. According to the data subjects, the controller has not responded to these requests or taken any other measures to implement the requests. The data subjects have also informed the Office of the Data Protection Ombudsman that if the data subject wishes to access their data more than once in a twelve-month period in the data subject’s databases, the data subject will be charged a fee for this. According to the data subject’s website, the data subject can check what data about the data subject is stored in the databases managed by the data subject in the OmaData service. The website states that access to their own data processed by the data subject is free of charge once in a twelve-month period. If the data subject makes a request more often, the data subject will be charged a fee of EUR 9.90 for access to their own data. The controller charges a fee for accessing personal data more than once in a twelve-month period, also in cases where the data subject wishes to access their own data in the credit information register maintained by the controller. Due to the above-mentioned observations and contacts from data subjects, the Deputy Data Protection Commissioner has begun to investigate, as a matter of own initiative, how the controller acts when it processes data subjects' requests for access to their own data. Implementation of data subjects' right to access their own data Clarification received from the controller On 15 August 2022, the controller was asked to provide an explanation of how the controller acts if a data subject makes a request by email to access their own data in the contact information and personal marketing register. The controller has also been asked to state whether it is necessary for the data subject to be able to make a request for access to their own data only by logging in to the OmaData service. If the data subject makes a request in another way, whether the data subject will process this request. The data subject has responded to the request for clarification on 15 September 2022 and stated that it primarily recommends that data subjects use the OmaData service, which the data subject has created to exercise the rights of data subjects. In the OmaData service, the person requesting the data verifies their right to receive the data themselves by means of strong electronic identification. According to the data subject, with the OmaData service, the data subject can securely check what information about them is stored in the data subject's databases. Through the service, data subjects can also ask the data subject to exercise their other rights under the General Data Protection Regulation, and through the service, the data subject also has the opportunity to access, for example, their credit information. According to the controller, however, it does not require the use of the OmaData service and it will process the data subject's request for access to their own data, even if the data subject does not make the request through the service. According to the controller, the data subject also has the option of submitting requests for access to their data either by post, email or by visiting the controller in person. The controller states that it initially verifies the identity of the data subject requesting [confidential part deleted] information when the data subject makes a request regarding their rights by email. The controller then checks the scope of the request with the data subject and, if necessary, asks the data subject to clarify the request. Once the data subject's identity has been verified and the subject and scope of the request have been clarified with the data subject, the controller will send an inspection report on the data subject's own data in response to the request for access to their own data by letter or via an electronic data transfer link. Once the inspection report has been sent to the data subject, the controller's customer service or data protection officer will respond to the data subject's email. The controller has stated that sometimes data subject requests are unspecific or otherwise incomplete. In such situations, customers have been given the first instruction to use the OmaData service, where the data subject can specify the information that the data subject wishes to view at any given time. Applicable legislation The General Data Protection Regulation applies. According to Article 12(1) of the General Data Protection Regulation, the controller shall take appropriate measures to provide the data subject with (---) the information referred to in Article 15 (---) in a concise, transparent, easily understandable and accessible form, using clear and plain language (---). The information shall be provided in writing or by other means and, where appropriate, in electronic form. If the data subject so requests, the information may be provided orally, provided that the data subject's identity is otherwise confirmed. Pursuant to Article 12(2) of the GDPR, the controller shall facilitate the exercise of the data subject's rights under Article 15 (---). (---). Pursuant to Article 12(3) of the GDPR, the controller shall provide the data subject with information on the action taken on a request pursuant to Article 15 (---) without undue delay (---). (---). (---). Pursuant to Article 12(4) of the GDPR, where the controller does not act on a request from the data subject, the controller shall, without undue delay and at the latest within one month of receipt of the request, inform the data subject of the reasons for not acting on the request and of the possibility of lodging a complaint with a supervisory authority and of exercising other legal remedies. According to Article 12(6) of the GDPR, where the controller has reasonable grounds to doubt the identity of the natural person who has made a request pursuant to Article 15 (---), the controller may request further information necessary to verify the identity of the data subject (---). Pursuant to Article 15(1) of the GDPR, the data subject has the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where such personal data are being processed, access to the personal data and the information specified in that provision concerning the processing of the personal data. Legal question The case concerns whether the controller has acted in breach of Article 12(2), (3) and (4) of the GDPR when the controller has responded to requests for access to personal data in the contact and personal marketing register of data subjects pursuant to Article 15 of the GDPR. If the controller's conduct has been contrary to the provisions of the General Data Protection Regulation, the matter is to be decided whether the controller should be subject to any sanction pursuant to Article 58(2) of the General Data Protection Regulation. Decision and reasoning of the Deputy Data Protection Supervisor Decision The controller has acted contrary to Article 12(2), (3) and (4) of the General Data Protection Regulation when responding to the data subjects' requests for access to their own data pursuant to Article 15 of the General Data Protection Regulation in the contact information and personal marketing register. In response to the data subjects' requests for access to their own data, the controller has directed the data subjects by e-mail only to log in to the controller's OmaData service. The controller has not provided the data subjects with a response as required by Article 12(3) of the General Data Protection Regulation on the action the controller will take in response to the data subject's request, or informed the data subjects as required by Article 12(4) of the General Data Protection Regulation that the controller will not take action on the data subject's request. The controller's conduct could reasonably have given the data subject the impression that access to their own data in the controller's contact information and personal marketing register is only possible by logging in to the OmaData service, and that there are no other means of accessing their own data. In doing so, the controller has also not facilitated the exercise of the data subjects' rights as required by Article 12(2) of the General Data Protection Regulation. Remark The Deputy Data Protection Supervisor issues a notice to the controller pursuant to Article 58(2)(b) of the General Data Protection Regulation for the infringement of Article 12(2), (3) and (4) of the General Data Protection Regulation. Order The Deputy Data Protection Supervisor orders the controller pursuant to Article 58(2)(d) of the General Data Protection Regulation to bring its procedures for implementing data subjects' requests for access to their own data into line with Article 12(2), (3) and (4) of the General Data Protection Regulation. Justification The controller has stated that it primarily encourages data subjects to make a request for access to their own data in the OmaData service. Despite its priority, logging into the service is only one means in the controller's range of measures regarding how the controller implements requests for access to data from the contact information and personal marketing register of data subjects and how the controller identifies data subjects in order to implement the requests. According to the controller, logging into the OmaData service is not a prerequisite for processing the request. The controller has stated that if the data subject does not want to log into the OmaData service in the manner directed by the controller and the data subject contacts the controller, the data subject can use other channels, such as email, to access their own data. The controller's statement partly contradicts the contacts made to the Office of the Data Protection Ombudsman. These contacts and the responses provided to the Data Protection Ombudsman by the controller to the data subjects indicate that the controller has responded to requests for access to personal data only by instructing the data subject to use the OmaData service in its email reply, and has not provided any other response regarding what actions the controller will or will not take in response to the data subject's request. For example, the controller has not requested additional information to identify the data subject and has not stated what information the controller can process the request further after receiving it. In its report, the controller has indicated that the data subjects' requests are sometimes unidentifiable or otherwise incomplete. In such situations, the controller first instructs the data subject to use the OmaData service. The Deputy Data Protection Commissioner understands that by incomplete and non-identified requests, the controller means situations in which the controller has identified the data subject's request as a request for access to personal data in accordance with Article 15 of the General Data Protection Regulation, but the request is, in the controller's opinion, incomplete in some respects or the data subject's request lacks, for example, identification of the data to which the request relates. Based on the explanation provided by the controller and the data subjects' statements in their contacts, it can therefore be stated that at least in such situations the controller responds to the data subject's request by sending the data subject only a standard message in which the controller directs the data subject to use the OmaData service. Thus, the Deputy Data Protection Ombudsman can state in this regard, based on the information provided by the controller itself and the information provided to the Office of the Data Protection Ombudsman by data subjects, that in some situations the controller does not respond to the data subject's request in any other way than by sending the data subject instructions on how to use the OmaData service, even if the controller itself has identified the data subject's request as a request for access to their own data. It can therefore be stated that in regularly recurring situations the controller fails to take the measures required by Article 12 of the General Data Protection Regulation in response to a request made by the data subject, unless the data subject logs into the OmaData service or contacts the controller again on their own initiative and asks the controller to process the request through another channel. Article 12(3) and (4) of the GDPR are clear on how a controller should act upon receiving a request from a data subject for access to their personal data. The controller must either provide the data subject with information without delay on the action taken by the controller in response to the data subject’s request for access to their personal data, or the controller must inform the data subject without delay of the reasons why the controller is not taking action on the data subject’s request. If the controller is not taking action on the request, the data subject should also be informed of the possibility of lodging a complaint with a supervisory authority and of exercising other legal remedies. Where the controller has reasonable grounds to doubt the identity of the natural person who has made a request for access to his or her personal data, the controller may request additional information necessary to verify the identity of the data subject in accordance with Article 12(6) of the GDPR. It follows from Article 12(3) and (4) of the GDPR that this additional information must be requested without undue delay. The controller must inform the data subject of the action taken on the request within one month of receipt of the request. Taking into account the complexity and number of requests, this period may be extended by a maximum of two months, if necessary. Furthermore, if the controller does not act on the data subject's request, the controller should inform the data subject of the reasons for not doing so without delay and at the latest within one month of receipt of the request. The European Data Protection Council Guidelines 2 state that there are no specific requirements for the form of a data subject’s request for access to his or her own data. The controller should provide appropriate and user-friendly communication channels that the data subject can easily use. However, the data subject does not have to use these specific channels, but can send the request to the controller’s official contact point. The controller is not obliged to take action on requests sent to completely random or manifestly incorrect addresses. The same Guidelines address the appropriate steps that the controller should take when a data subject requests access to his or her own data. According to the Guidelines, it is necessary to avoid directing the data subject to different sources in response to the request for information. 3 If the controller is able to identify the data subject's request as a request for access to personal data, but the request is, in the controller's opinion, to some extent incomplete or non-specific, it is not sufficient for the controller to simply respond to the data subject's request in a standard manner by directing the data subject to use the OmaData service. Depending on the case, the controller must, for example, inform the data subject that it cannot process the data subject's request as such by email, but needs additional information to identify the data subject. The controller may, for example, ask the data subject to clarify what the data subject's request concerns 4 and mention the possibility of using the OmaData service as a means of implementing the data subject's request. 5 However, the controller must ensure that the discussion with the data subject about the different options does not lead to the controller failing to take the measures required by Article 12 of the General Data Protection Regulation to respond to requests concerning the rights of data subjects or to request necessary additional information. In the case under assessment, the data subjects did not contact the controller’s random addresses, but rather the customer service address used by the controller. The controller responded to the data subjects’ requests only by sending the data subject a standardised instruction to log in to the OmaData service. The controller failed to provide the data subjects with information about the measures taken by the controller in response to the data subject’s request. If the controller had grounds to refuse the requests, the controller also failed to inform the data subjects of the reasons why the controller did not take action on the data subject’s requests. By doing so, the controller has acted in violation of Article 12(3) and (4) of the General Data Protection Regulation. The Deputy Data Protection Ombudsman considers that the controller's response to the data subjects could have reasonably given the data subjects who exercised their rights the impression that access to their own data in the controller's contact information and personal marketing register is only possible by logging into the OmaData service, and that there are no other means of accessing their own data. If the data subject has not wanted to log into the OmaData service, the data subject should have contacted the controller again. The controller's approach has also not been conducive to facilitating the exercise of the data subject's rights in the manner required by the Data Protection Regulation. Fees for accessing personal data Clarification received from the controller On 15 August 2022, the controller was asked to provide an explanation as to whether the controller charges a fee to the data subject if the data subject wishes to access their own data in the controller's contact information and personal marketing register more than once every twelve months pursuant to Article 15 of the General Data Protection Regulation. The controller responded to the request for clarification on 15 September 2022 and stated that it charges a fee. According to the controller, the fee is based on allocated costs, which include the costs incurred in the process of accessing the data subject's data and the manual development of the register extract. The controller considers that in situations pursuant to Article 15(3) of the General Data Protection Regulation, it has the right to charge the costs incurred at the data subject's request. The controller has stated that the more often a data subject makes requests for information, the more the controller incurs, among other things, [confidential part deleted] costs, which the controller is obliged to pay in order for the controller to be able to fulfil its statutory obligations to provide information in a secure manner. [Confidential part deleted], the controller incurs costs from the use of these systems when it carries out requests for access to data subjects' own data. The controller considers that it has the possibility, in accordance with the General Data Protection Regulation, to recover the [confidential part deleted] or other reasonable administrative costs incurred by the controller. The controller states that it regularly assesses reasonable costs in accordance with its impact assessment process and aims to reduce the amount of manual work in situations where data concerning the data subject changes frequently or in situations where the data subject makes multiple requests for access to data. The controller states that it is currently conducting a study of the costs affecting the fee in order to be able to further reduce the costs incurred by it for implementing requests, if necessary. The controller states that it has begun to re-examine how often a data subject would be able to access their own data free of charge, especially in situations where the data subject’s data has been renewed or changed in a way that could be of significance to the data subject. A request for clarification was sent to the controller on 3 March 2025, referring to the fact that the controller’s website states that access to one’s own credit information is possible free of charge once every twelve months. Clarification has also been requested as to whether the controller intends to change its practices regarding the charging of a fee for accessing the data subject's own credit information. If the controller does not intend to change its practices in this regard, the controller has been asked to justify why it considers that requests made more than once within a twelve-month period would each time be a situation under Article 12(5) of the General Data Protection Regulation, where the data subject's requests are manifestly unfounded or unreasonable. The controller has responded to the request for clarification on 3 April 2025 and stated that it does not intend to change its practices regarding the charging of a fee for accessing the data subject's own credit information. The controller has stated that it only requires a fee for accessing the data subject's own credit information if it is made more than once within a twelve-month period. The controller has stated in its response that the relationship between the Credit Information Act and data protection legislation is that the Credit Information Act exhaustively lists the conditions for keeping and using personal credit information. For this reason, according to the controller, checking one's own credit information must be considered to be special requests for checking one's own information. According to the controller, in these cases, it is not a question of the data subject's right to access their own information, but of a written document comparable to a certificate. The controller has stated that, in accordance with the Credit Information Act, a natural person has the right to receive reasonable compensation for the personal credit information stored about them in the credit information register. The controller has assessed that a charge of EUR 9.90 is reasonable compensation in situations where the data subject wants to check their information more than once every twelve months. Applicable legislation The General Data Protection Regulation and the Credit Information Act apply in this case. Article 12 of the GDPR lays down detailed rules for the exercise of the data subject's rights. According to Article 12(1) of the GDPR, the controller shall take appropriate steps to provide the data subject (---) with all information concerning the processing pursuant to Article 15 (---). According to Article 12(2) of the GDPR, the controller shall facilitate the exercise of the data subject's rights pursuant to Article 15 (---). In the cases referred to in Article 11(2), the controller shall not refuse to act on a request from the data subject to exercise the rights pursuant to Article 15 (---) unless the controller demonstrates that it is unable to identify the data subject. According to Article 12(5) of the GDPR, (---) all information and measures based on Article 15 (---) shall be free of charge. If the data subject's requests are manifestly unfounded or unreasonable, in particular if they are repeated, the controller may either (a) charge a reasonable fee, taking into account the administrative costs of providing the information or communication or of taking the requested action; or (b) refuse to take the requested action. In such cases, the controller must demonstrate that the request is manifestly unfounded or unreasonable. Pursuant to Article 15(1) of the GDPR, the data subject has the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where such personal data are being processed, the right to access the personal data and to obtain the information referred to in points (a) to (h) concerning the processing of the personal data. Pursuant to Article 15(3) of the GDPR, the controller must provide a copy of the personal data being processed. If the data subject requests more than one copy, the controller may charge a reasonable fee based on the administrative costs. If the data subject submits the request electronically, the information must be provided in a commonly used electronic format, unless the data subject requests otherwise. Section 5 of the Credit Information Act provides for good credit information practice. According to Section 5(1) of the Credit Information Act, credit information providers, credit information users and other persons who otherwise process credit information must exercise due care in their operations. Credit information providers and other business operators who use or otherwise process credit information must in particular ensure that: 1. the quality of credit information, the implementation of the rights of natural persons and companies to access information, and the information security of information systems and the control of processing are properly ensured; 2. the protection of the private life of natural persons is not restricted without a basis provided for by law; 3. the right of natural persons and companies to be assessed on the basis of correct and appropriate information is not jeopardised. Section 10 of the Credit Information Act lays down the obligations of credit information providers regarding their services. According to Section 10(1) of the Credit Information Act, a credit information provider may not refuse to provide credit information from a credit information register established for public use to a person who is required by law to use the credit information when making a decision concerning a natural person or company. According to Section 10(2) of the Credit Information Act, a credit information provider shall, in individual cases, provide credit information to a person requesting it for a reasonable fee. The person requesting personal credit information must submit the necessary evidence to establish the lawfulness of the disclosure. According to Section 10(3) of the Credit Information Act, a natural person has the right to receive, for a reasonable fee, an extract from the personal credit information stored about him or her in the credit information register for the purposes laid down in Section 19. Section 19 of the Credit Information Act lays down general conditions for the disclosure and use of personal credit information, including the use of the information for the granting of credit and credit monitoring or, for example, for the conclusion of a room rental agreement. Legal issue The matter must be decided whether the controller has acted in breach of Article 12(2) and (5) or Article 15(4) of the General Data Protection Regulation when the controller has charged the data subject a fee of EUR 9.90 if the data subject has requested access to his or her own data in the contact and personal marketing register or credit information register maintained by the controller more than once in twelve months. If the controller's conduct has been in breach of the provisions of the General Data Protection Regulation, the matter must be decided whether the controller should be subject to any sanction pursuant to Article 58(2) of the General Data Protection Regulation. Decision and reasons of the Deputy Data Protection Supervisor Decision The controller has acted in breach of Article 12(2) and (5) and Article 15(4) of the General Data Protection Regulation by lawfully charging the data subject a fee of EUR 9.90 if the data subject has requested access to his or her own data in the contact and personal marketing register or credit register maintained by the controller more than once in a twelve-month period. Notice The Deputy Data Protection Supervisor issues a warning to the controller pursuant to Article 58(2)(b) of the General Data Protection Regulation for the infringement of the provisions of Article 12(2) and (5) and Article 15(4) of the General Data Protection Regulation. Order The Deputy Data Protection Supervisor orders the controller to bring its practices into line with Article 58(2)(d) of the GDPR when the controller exercises the data subject's right of access to his or her own data pursuant to Article 15 of the GDPR and when the controller provides the data subject with a copy of the data concerning him or her. Justification A credit report on the data subject and a copy of the data subject's own data The controller has stated that it only charges a fee for access to one's own credit report if the request is made more than once in twelve months. According to the data controller, this would not be a question of the data subject's right to access their own data on the basis of the General Data Protection Regulation, but of a written document that is comparable to a certificate for which it is permissible to demand a fee under the Credit Information Act. The General Data Protection Regulation applies in principle to all processing of personal data. In addition, in requests for access to personal data directed at the credit information register, the Credit Information Act applies as national special legislation alongside the General Data Protection Regulation and the national data protection act specifying it. According to Section 10(3) of the Credit Information Act, a natural person has the right to receive, in return for reasonable compensation, an extract of the personal credit information stored about them in the credit information register for the purposes laid down in Section 19. The provision-specific justifications for Section 10 of the original government proposal 6 for the Credit Information Act state that Section 10(3) would include a provision on the data subject's right to receive an extract. According to the government proposal, the data subject would have the right to receive an extract from the register of personal credit information stored in the register for a reasonable fee. According to the government proposal’s justifications, the provision of an extract is not a question of accessing the data subject’s own information, but of a document comparable to a certificate. According to the government proposal’s justifications, the provision would enable, for example, a person who intends to rent an apartment from another private person to present a certificate of their credit information to a potential landlord. The provision-specific justifications 7 also state that the right of a natural person to receive an extract concerning themselves does not mean expanding the use of credit information beyond what it would otherwise be under the law. According to the government proposal, the provisions of Section 19 of the Act will also apply when the data subject himself presents credit information concerning himself in an extract. The government proposal refers to the fact that this is due to the relationship between the Credit Information Act and the Personal Data Act. The Credit Information Act would be a special law compared to the Personal Data Act, which exhaustively regulates the conditions for storing and using personal credit information. The Personal Data Act (523/1999) has since been repealed by the Data Protection Act (1050/2018), which entered into force on 1 January 2019. Therefore, the matter under consideration must be assessed on the basis of the legislation of the General Data Protection Regulation, the Data Protection Act and the Credit Information Act. Section 10 of the Credit Information Act has been amended in terms of terminology by Act 331/2022. The preparatory work for the amending act has stated8 that, with regard to the processing of personal data, Section 10(3) of the Credit Information Act partially overlaps with Article 15(3) of the General Data Protection Regulation, which states that the data subject has the right to obtain a copy of the personal data processed. The Government's proposal states that the purpose of the data subject's right provided for in Article 15(3) of the General Data Protection Regulation is different from the purpose of a credit information statement. According to the government proposal, the data subject may use an extract with a less extensive content, for example to conclude a lease agreement, and the credit information provider may charge a reasonable fee for the extract. However, the government proposal states in this regard that the charging of a fee applies only to the credit information extract in accordance with the provision. The government proposal states that when the data subject exercises his or her right under Article 15 of the General Data Protection Regulation, the controller is not entitled to charge a fee for an individual copy. In general, Union law takes precedence over national law, i.e. if national standards conflict with EU law, the matter must be resolved on the basis of EU law, according to established case law. 9 The Deputy Data Protection Ombudsman considers that in the present case, however, it is not a question of EU law being in conflict with the provision of the national Credit Information Act, even though the data subject’s right to access his or her own information partly overlaps with the right of a natural person under Section 10(3) of the Credit Information Act to receive an extract of the personal credit information stored about him or her in the credit information register in return for reasonable compensation. The Deputy Data Protection Ombudsman considers that the data subject’s right under data protection legislation to receive a copy of personal data concerning him or her is a different right than the right of a natural person under the Credit Information Act to receive a corresponding credit information extract concerning him or her, which a credit information provider would prepare about the natural person, for example, for the purpose of granting credit to a bank, if the bank were to order this extract for a fee. An extract from a natural person's personal credit information pursuant to Section 10(3) of the Credit Information Act applies to situations where the natural person intends to use this extract in situations pursuant to Section 19 of the Credit Information Act. In such a case, the natural person could lawfully obtain a similar extract concerning himself, which, for example, a creditor would request when assessing the credit applicant's ability or willingness to pay. The person could provide such an extract to another party, for example a landlord or creditor. The possibility of charging a fee pursuant to Section 10(3) of the Credit Information Act applies only to such a credit information extract. The purpose of the right to access one's own information is for the data subject to know whether or not their personal data is being processed, and what personal data about them is being processed. This right enables the data subject to retain control over their own personal data and to have the opportunity to control how, for example, their credit information or other personal data is being processed. The right of access under Article 15 of the GDPR is determined by the scope of the concept of personal data as defined in Article 4(1) of the GDPR. 10 The European Data Protection Board has advised that the scope of the data subject’s right of access may include, for example, creditworthiness indicators. 11 When a data subject requests access to his or her own data, the data subject shall be provided with a copy of the personal data concerning him or her, if the controller is processing them at the time of the request, in order to enable the data subject to be informed of the content and extent to which the controller is processing his or her personal data. When a data subject requests a copy of his or her own data or requests access to his or her own data on the basis of Article 15 of the GDPR, the controller shall be entitled to charge a fee for the copy only in accordance with the rules of the GDPR. The regulation of Article 15 of the General Data Protection Regulation does not require that the controller, when implementing a request for access to data, should create a credit information extract of the data subject in a different form than the form in which the controller already processes the credit information concerning the data subject in its organisation at the time of receipt of the data subject's request. The controller must therefore, when providing the data subject with a copy in accordance with Article 15, provide the credit information concerning the data subject that it processes as such and in the form in which the controller processes it at the time of the request. If the controller is unclear as to whether the data subject is requesting access to his or her own data or a copy of his or her own data pursuant to Article 15 of the General Data Protection Regulation or a credit information extract prepared for the purposes of use pursuant to Section 19 of the Credit Information Act pursuant to Section 10(3) of the Credit Information Act, the controller may ask the data subject to specify his or her request. The Assistant Data Protection Supervisor stresses, however, that the controller must facilitate the exercise of the data subject’s rights under the GDPR. 12 In the present case, this means that, for example, the controller cannot only inform the data subject in its request for clarification about the right to request a certified credit report for a fee, but must also inform the data subject about the right to obtain a copy under Article 15 of the GDPR. The controller’s right to charge a fee for a copy provided under data protection legislation The controller considers that it has the right to charge the costs incurred at the data subject’s request under Article 15(3) of the GDPR if the controller provides the data subject with a copy of his or her data more than once every twelve months. The controller has stated that the more frequently a data subject makes requests for information, the more costs the controller incurs from external service providers, which the controller is obliged to pay in order to provide the data to the data subject in a secure manner. The starting point of Article 12 of the GDPR is that the controller must take reasonable steps to provide the data subject with the information referred to in Article 15. However, in accordance with Article 12(5) of the GDPR, controllers may refuse requests that are manifestly unfounded or unreasonable or charge a reasonable fee for such requests, in particular where the requests are made repeatedly. In such cases, the controller must demonstrate that the request is manifestly unfounded or unreasonable. The European Data Protection Board advises that the provision on manifestly unfounded and unreasonable requests should be interpreted strictly. What constitutes unreasonableness depends on the specificities of the sector in which the controller operates. The more frequently changes occur in the controller's database, the more frequently the data subject can request access to the data without it being unreasonable. Instead of refusing access, the controller may decide to charge the data subject a fee. This would only be appropriate in the case of unreasonable requests, in order to cover the administrative costs that such requests may entail. 13 In contrast, Article 15(3) of the GDPR provides that where the data subject requests more than one copy from the controller, the controller may charge a reasonable fee based on the administrative costs. According to the EDPB's guidance, this could arise, for example, if the first copy has been lost or damaged or if the data subject wishes to transmit the copy to another person or to a supervisory authority. The Guidelines emphasise that, since the controller must provide more copies at the request of the data subject, Article 15(3) provides that the controller may charge a reasonable fee for any additional copies requested, based on the administrative costs. The EDPB Guidelines also draw attention to the fact that if the data subject requests an additional copy after the initial request, it may be unclear whether this is to be considered a new request or whether the data subject wishes to obtain an additional copy of the data referred to in the second sentence of Article 15(3), in which case a fee may be charged for the additional copy. According to the Guidelines, the answer to these questions depends solely on the content of the request. It should be interpreted as requesting an additional copy if the request concerns the same processing of personal data in time and to the same extent as the previous request. However, if the data subject seeks access to data processed at a different time or to data other than those originally requested, the right to a copy free of charge under Article 15(3) applies. According to the Guidelines, this also applies in cases where the data subject has made the first request somewhat earlier. 14 The Deputy Data Protection Supervisor therefore notes that the law allows the controller to charge a fee for exercising the data subject’s right of access only on a case-by-case basis if the data subject’s requests are manifestly unfounded or excessive, in particular if the requests are made repeatedly. Secondly, a fee may be charged if the data subject requests several copies in connection with the same request. In the case at hand, it can be stated, according to the information provided by the controller and on the basis of the information available on the controller's website, that the controller's basic and regular operating method for all data subjects is that the controller charges the data subject a fee of EUR 9.90 in all cases if the data subject wishes to access his or her own data more than once every twelve months. The controller is obliged to comply with good credit information practice in accordance with Section 5 of the Credit Information Act, according to which the controller must ensure, among other things, the quality of credit information and the implementation of the right to access information. In addition, the credit information provider must ensure that the protection of the private life of natural persons is not restricted without a basis provided for by law and that the right of natural persons and companies to be assessed on the basis of correct and appropriate information is not jeopardised. The Government's proposal for the Credit Information Act states that good credit information practice would include exercising due diligence and taking care of the factors that are central to the legal protection of the subject of the credit information. 15 For example, according to Section 18 of the Credit Information Act, payment default information must be deleted within one month of the credit information company receiving information about the payment default. Also, among other things, enforcement information must be deleted from the data subject's credit information as soon as the bailiff has made a cancellation notice of a long-term or unjustified enforcement. Thus, the Deputy Data Protection Commissioner states that in credit information activities, it is customary to update data subjects' data more than once a year. In such situations, a data subject can be considered to have a legitimate reason to request access to their own data more than once every twelve months without it being unreasonable or unjustified from the data controller's perspective. Access to information promotes the data subject's right to be assessed on the basis of correct and appropriate information, as the data subject can then identify the need for rectification of their own personal data. The timeliness of credit information has a significant impact on the data subject's position, for example as a credit applicant or as an applicant for a rental apartment. The data controller should also be able to demonstrate the manifest unreasonableness or unfoundedness of the request if the data controller considers that it could charge the data subject a fee due to a repeated request. For example, marketing can be sent to a natural person based on the data controller's contact information and personal marketing register. Access to personal information is relevant for the data subject, especially when the data subject's information has been obtained from sources other than the data subject himself or herself. Assessment of the controller’s practices When the controller routinely charges a fee whenever a data subject requests access to their own data more than once every twelve months, the controller has completely failed to assess on a case-by-case basis whether the data subject’s requests are manifestly unfounded or excessive due to the frequency of the requests. The controller has failed to take into account in this initial charging of the fee that access to data more than once every twelve months may be justified due to possible changes in the data or because the data processed by the controller has a major impact on the data subject’s life. Thus, the controller has also failed to take into account in its practices that checking data can be very relevant for the data subject, especially with regard to credit information. Based on the information received, the controller has also not assessed when charging the fee whether it is a new request from the data subject or whether the data subject is requesting an additional copy of information that has already been provided to the data subject in connection with the same request. In this context, it should be noted that if even a little time has passed since the data subject's previous request for access to his or her own data, the controller must consider the data subject's request to be a new request and not a request for an additional copy, at a fairly low threshold. The controller has set the period for free copies at twelve months. This must be considered a relatively infrequent access to information, especially in cases where the information is of great importance to the data subject's life. It is not possible for the controller to determine in advance and on a regular basis that requests made more frequently than twelve months would be manifestly unreasonable or unfounded. The Deputy Data Protection Supervisor states that charging a fee for unfounded or unreasonable requests can only be based on a case-by-case assessment. In addition to other factors, such as possible changes in the data, the case-by-case assessment must also assess the content and scope of the data subject’s request. If the data subject requests a copy of data other than the data requested in the previous request, the right to a free copy under Article 15(3) applies. On the grounds set out above, the Deputy Data Protection Supervisor considers that the controller has not complied with the provisions of Article 12(5) and Article 15(4) of the General Data Protection Regulation when the controller has regularly charged a fee when the data subject requests access to his or her own data more than once in twelve months. The Deputy Data Protection Ombudsman estimates that by acting in this way, the controller has also made it more difficult for data subjects to exercise their rights, as data subjects may not have exercised their right to access their data due to the fee charged by the controller. Appeal According to Section 25 of the Data Protection Act (1050/2018), this decision may be appealed to the Administrative Court in accordance with the provisions of the Act on Judicial Proceedings in Administrative Matters (808/2019). The appeal shall be filed with the Helsinki Administrative Court. Notification The decision will be notified by post against a receipt in accordance with Section 60 of the Administrative Procedure Act (434/2003). Additional information The decision has been presented by Inspector General Niina Nieminen. The decision has been issued by Deputy Data Protection Ombudsman Heljä-Tuulia Pihamaa. The decision has not yet entered into force. Endnotes: 1 As the data protection notice for the controller's contact details and personal marketing register has been in force on the controller's website on 12.10.2025. 2 Data Protection Working Party established under the Personal Data Directive 95/46/EC, Guidelines on transparency under Regulation 2016/679, issued on 29.11.2017, revised and approved on 11.4.2018, p. 18. 3 European Data Protection Board; Guidelines 1/2022 on the rights of data subjects - right of access, 28.3.2023. 4 Recital 63 of the General Data Protection Regulation. 5 Among others, in the European Data Protection Board's Guidelines; Guidelines 1/2022 on the rights of data subjects – right of access to information, 28.3.2023, p. 45, it has been stated that in some situations it may nevertheless be appropriate for the controller to provide access to information in a manner other than by providing a copy. 6 HE 241/2006, p. 35. 7 HE 241/2006, p. 35. 8 HE 109/2021, p. 50. 9 For example, the decisions Costa v. Enel 6/64 or KHO 2002:85. 10 This has also been stated in the guidelines of the European Data Protection Board; Guidelines 1/2022 on data subjects' rights - right of access to data, 28.3.2023, p. 4. 11 European Data Protection Board, Guidelines 1/2022 on data subjects' rights - right of access to data, 28.3.2023, p. 4. 12 This is also the guidance of the European Data Protection Board; Guidelines 1/2022 on data subjects' rights - right of access to data, 28.3.2023, p. 18. 13 European Data Protection Board; Guidelines 1/2022 on data subjects' rights - right of access to data, 28.3.2023, p. 5. 14 European Data Protection Board; Guidelines 1/2022 on the rights of data subjects – right of access to information, 28.3.2023, p. 14. 15 HE 241/2006, p. 31.




