Data protection
‘Data protection’ refers to measures taken to protect an individual’s privacy during the processing of personal data. The City of Espoo has the responsibility to protect the personal data of its clients, personnel and stakeholders.
As the data controller, the City of Espoo collects and processes the data subjects’ personal data only to the extent necessary for the provision of its services. The legal basis for processing personal data may vary between different services. The details of personal data processing are described in the relevant privacy notices.
The General Data Protection Regulation of the European Union (GDPR) grants data subjects various rights related to the processing of their personal data. However, not all rights can be exercised in every situation. The applicability of each right depends, for example, on the legal basis for the data processing. Below is a description of the rights granted to data subjects, when they apply, and how they can be exercised.
If the collection of data is based on the data subject’s consent, the data subject may withdraw their consent at any time and ask for their data to be erased. However, most of the city’s services are based on complying with legal obligations or exercising public authority. In such cases, data subjects cannot request the erasure of their personal data.
Right of access
The data subject has the right to obtain from the controller confirmation as to whether or not personal data concerning them is being processed. If data concerning the data subject is being processed, the data subject has the right to receive a copy of the personal data being processed without undue delay, and at the latest, within one month. In cases of exceptionally large or complex data requests, the deadline may be extended to a maximum of three months, provided there are justified reasons for the extension.
The data subject can submit a request for access to personal data(external link, opens in a new window) by post to the contact person mentioned in the privacy notice, by email to tietosuoja@espoo.fi, or in person by visiting a Service Point, Espoo Info, or the Registry Office. Once the request has been processed, the data will be provided to the data subject in the agreed-upon manner.
Requests from the data subject and any resulting actions are free of charge. Where requests from a data subject are manifestly unfounded or excessive, in particular because of their repetitive character, the City of Espoo, as the data controller, may either charge a reasonable fee taking into account the administrative costs of providing the information or communication or taking the action requested, or refuse to act on the request.
Right to rectification
A data subject always has the right to have any data collected and stored about them rectified or completed.
If a data subject wishes to have their data rectified, they must contact the contact person mentioned in the privacy notice.
Right to erasure
If the processing of personal data is based on a legal basis other than compliance with a legal obligation, the data subject has the right to request the erasure of their personal data. The requested data will be erased unless the City of Espoo has a legal reason to refuse to erase the data. Such a reason may include, for example, a legal obligation to retain the data.
If a data subject wishes to have their data erased, they must contact the contact person mentioned in the privacy notice.
Right to restriction of processing
A data subject has the right to request the City of Espoo, as the data controller, to restrict the processing of their personal data if:
- the data subject considers their personal data to be inaccurate;
- the processing of personal data is unlawful and the data subject opposes the erasure of the personal data and instead requests the restriction of its use;
- the City of Espoo no longer needs the personal data for the purposes of the processing, but it is required by the data subject for the establishment, exercise or defence of legal claims;
- the data subject objects to the processing of their personal data while it is being verified whether the City of Espoo has the right to process the data.
If a data subject wishes to restrict the processing of their data, they must contact the contact person mentioned in the privacy notice.
Right to data portability
A data subject has the right to transfer their personal data to another data controller if they originally provided the data to the City of Espoo, the processing is based on consent or a contract, and the processing is carried out by automated means. This right does not apply to processing necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the city.
Right to object
A data subject has the right to object if the City of Espoo processes the data subject’s personal data based on public interest, the exercise of public authority, or legitimate interests.
A data subject may object to the processing of their personal data for reasons related to their specific personal situation. In such cases, the City of Espoo, as the data controller, must stop using the data unless there are compelling legitimate grounds for the processing that override the interests of the data subject. The city may also have a reason to continue processing personal data if it is necessary for the establishment, exercise, or defence of legal claims.
Under Article 21 of the GDPR, the data subject has the right to object to the use of their data for direct marketing purposes.
If a data subject wishes to object to the processing of their data, they must contact the contact person mentioned in the privacy notice.
Right to lodge a complaint
The data subject has the right to lodge a complaint with a supervisory authority if they feel that the processing of their personal data is in infringement of data protection legislation. The complaint can be submitted to the Office of the Data Protection Ombudsman: www.tietosuoja.fi.
Contact details of the Data Protection Officer
Data Protection Officer of the City of Espoo
Address: P.O. Box 12, 02070 City of Espoo
Tel. +358 9 81621 (Espoo Info)
Email: tietosuoja@espoo.fi