20.3.2017

Get a Handle on Data Protection Risks and Seize New Business Opportunities

One of the main goals of the new Data Protection Regulation is to make the enforcement of data protection legislation more efficient. This can be seen in the fact that national supervisory authorities have been granted the power to impose very large fines for unlawful data processing.

Almost all companies process personal data, which makes them data controllers obligated to comply with data protection legislation. In this respect, the new regulation makes data protection a part of corporate risk management on an entirely new scale. In order to ensure that they identify, manage and minimise these risks properly and efficiently, companies must look beyond their own business risks and keep in mind whose risks they are really dealing with.

Data Protection Risks Are Individual Risks

The purpose of personal data legislation is to protect the rights of individuals—you, me, everyone—to data privacy. The risk that personal data will be abused also primarily affects individuals. If you look at the numbers, the legislator has really spelled this out in the new regulation: the word ‘risk’ appears in the new regulation about 70 times—a ten-fold increase over the current Data Protection Directive.

The Data Protection Regulation emphasises the data controller’s duty to plan its data processing procedures in such a way that the risks on the level of individuals are taken into account proactively. This requires more of companies than just incorporating data protection risks into their existing risk management processes—risk awareness needs to be present in data protection work that data controllers engage in on every level.

Without making an assessment of the potential effects on individuals, the effective implementation of data protection legislation is impossible. How can companies choose the correct legal grounds (such as determining whether the data controller’s legitimate interests are in balance with the rights of individuals) or determine the proper level of data security without knowing what the risks to the individual are?

Be Systematic

According to the principle of privacy by default, companies need to identify and account for risks to individuals well before starting to process data. Companies should adopt some kind of privacy impact assessment to systematically assess and document the risks relating to data processing.

One of the major changes being brought by the new Data Protection Regulation is accountability. It is no longer enough that a company’s actions are compliant, they have to be able to demonstrate it. The risk management methods mentioned above are a key part of fulfilling this obligation.

Systematic data protection procedures that take the risks to individuals into account will not only shield companies from fines and other penalties, but maintain the public’s trust in the company. This trust then forms the foundation for the next step, in which data protection ceases to be a risk and becomes a business opportunity. This should be the long-term goal of every company.

Latest references

We advised Yellow Film Studios, the largest independent film and television production company in the Nordics, in its strategic merger with Danish film industry sales and financing studio REinvent Studios. Together they form Reinvent Yellow, a unified hub for television and film production, sales, financing and innovation, combining over three decades of production experience and a vast catalogue of titles.
Case published 8.10.2025
We successfully represented a panel of reinsurance companies in an international ad hoc arbitration. The dispute arose out of a reinsurance treaty under the terms of which the reinsurers had reinsured a portfolio of risks underwritten by the cedent. The parties disagreed as to whether the reinsurance provided coverage for a certain loss that had occurred because of the market turmoil caused by the Covid-19 pandemic. The case involved highly complex legal and contractual questions requiring special expertise on reinsurance law and practice. The arbitral tribunal rejected the counterparty’s claims for reinsurance compensation against our clients in full. The amount in dispute was approximately EUR 34 million.
Case published 16.9.2025
We supported byFounders.vc as the Finnish counsel in their investment in DataCrunch Oy in a USD 64 million Series A funding round. DataCrunch provides scalable AI compute solutions from energy-efficient data centers in Iceland and Finland. byFounders.vc is the community-powered early-stage venture fund investing in globally ambitious teams connected to the Nordic and Baltic countries.
Case published 11.9.2025
We advised Springvest Oyj in organising a EUR 45 million Series A funding round for ReOrbit, a space technology company and a leading provider of software-first satellites. It’s the largest all-equity Series A round in Finland and one of the most significant deals overall in the European space and defence sector. The purpose of the funding round is to support ReOrbit’s growth. The round consisted of a private placement reserved for professional and institutional investors, which included, e.g. Icebreaker.vc, Expansion VC, 10xFounders, Inventure VC, Varma Mutual Pension Insurance Company, and Elo Mutual Pension Insurance Company, and an EUR 8 million public share offering, which was oversubscribed within 4.5 hours. Springvest is a Finland-based investment firm that connects unlisted growth companies with investors. ReOrbit builds sovereign satellites and connected systems for national security.
Case published 9.9.2025