20.3.2017

Get a Handle on Data Protection Risks and Seize New Business Opportunities

One of the main goals of the new Data Protection Regulation is to make the enforcement of data protection legislation more efficient. This can be seen in the fact that national supervisory authorities have been granted the power to impose very large fines for unlawful data processing.

Almost all companies process personal data, which makes them data controllers obligated to comply with data protection legislation. In this respect, the new regulation makes data protection a part of corporate risk management on an entirely new scale. In order to ensure that they identify, manage and minimise these risks properly and efficiently, companies must look beyond their own business risks and keep in mind whose risks they are really dealing with.

Data Protection Risks Are Individual Risks

The purpose of personal data legislation is to protect the rights of individuals—you, me, everyone—to data privacy. The risk that personal data will be abused also primarily affects individuals. If you look at the numbers, the legislator has really spelled this out in the new regulation: the word ‘risk’ appears in the new regulation about 70 times—a ten-fold increase over the current Data Protection Directive.

The Data Protection Regulation emphasises the data controller’s duty to plan its data processing procedures in such a way that the risks on the level of individuals are taken into account proactively. This requires more of companies than just incorporating data protection risks into their existing risk management processes—risk awareness needs to be present in data protection work that data controllers engage in on every level.

Without making an assessment of the potential effects on individuals, the effective implementation of data protection legislation is impossible. How can companies choose the correct legal grounds (such as determining whether the data controller’s legitimate interests are in balance with the rights of individuals) or determine the proper level of data security without knowing what the risks to the individual are?

Be Systematic

According to the principle of privacy by default, companies need to identify and account for risks to individuals well before starting to process data. Companies should adopt some kind of privacy impact assessment to systematically assess and document the risks relating to data processing.

One of the major changes being brought by the new Data Protection Regulation is accountability. It is no longer enough that a company’s actions are compliant, they have to be able to demonstrate it. The risk management methods mentioned above are a key part of fulfilling this obligation.

Systematic data protection procedures that take the risks to individuals into account will not only shield companies from fines and other penalties, but maintain the public’s trust in the company. This trust then forms the foundation for the next step, in which data protection ceases to be a risk and becomes a business opportunity. This should be the long-term goal of every company.

Latest references

Castrén & Snellman advised Nscale, a European AI infrastructure company, in connection with its planned data centre project in Harjavalta, Finland. The facility will be located in the Sievari industrial area. Castrén & Snellman’s advisory role encompassed the negotiation and execution of a site securing and development agreement (SSDA) with Fortum, as well as the preliminary land sale process for the Sievari site with the Town of Harjavalta. Under the SSDA, Fortum supports the advancement of Nscale’s project development, including grid connection design and permitting.
Case published 15.4.2026
We are acting as legal adviser to Taaleri Plc on its acquisition of a 51 per cent ownership stake in Nordic Science Investments Oy (NSI), marking Taaleri’s expansion into deeptech-driven venture capital. Through the transaction, Taaleri broadens its private equity offering into early-stage venture capital funds as well as the commercialisation and scaling of research-driven innovations. NSI is a Finnish venture capital fund manager operating across the Nordic and Baltic regions, focusing on early-stage investments in research- and science-based technologies. Its portfolio companies develop, among other things, health technologies, life sciences, advanced materials and AI-driven solutions. In addition to providing growth capital, NSI supports spin-out companies with strategic guidance, access to networks and assistance in building teams during the early phases of business development. NSI’s first fund, the EUR 45 million NSI Nordic Science I Ky, was established in 2024 and has to date invested in 22 early-stage companies in Finland, Sweden and the Baltic countries. Taaleri is a specialist in investments, private asset management and non-life insurance, with a strong position in renewable energy, bioindustry and housing investments as well as credit risk insurance. Taaleri has EUR 2.7 billion of assets under management in its private equity funds, co-investments and single-asset vehicles, employs approximately 130 people and is listed on Nasdaq Helsinki. The founders of NSI will continue in their operational roles following the transaction. The completion of the transaction is subject to approval by the FIN-FSA.
Case published 13.4.2026
We delivered two information design workshops for the legal department of the Finnish Centre for Pensions, with participants from both legal and other professional backgrounds. In the sessions, we applied the principles of legal design thinking to the Finnish Centre for Pensions’ field of operation and background materials, also utilising AI as a design tool. The participants found the tailored training highly useful and commended the trainers for their in-depth familiarisation with the Centre’s opinion drafting process and operating environment. As a result of the workshops, our experts proposed a new structural and linguistic model for the legal department of the Finnish Centre for Pensions for drafting opinions and guidelines. The proposal was well received as clear and applicable to the participants’ everyday work. In addition, we presented tailored AI use cases to support experts, allowing for a more efficient AI-assisted way of working. Our experts who delivered the workshops combined their legal expertise with their leading experience in legal design. The participants appreciated this versatile expertise, which enabled a knowledgeable, creative and applied approach to legal writing. ‘C&S created a well-structured training tailored to our needs, providing clear direction for our organisation and concrete takeaways for our experts in their day-to-day work,’ says Mari Kuunvalo, Head Of the Legal Department at the Finnish Centre for Pensions.
Case published 10.4.2026
We advised Aktia Bank Plc on the issuance of an EUR 80 million Additional Tier 1 (AT1) bond. The bond pays a fixed interest rate of 6.75 per cent semi-annually. The bond is perpetual, and Aktia has the right to redeem or repurchase it in accordance with the terms of the bond, subject to certain conditions. The bond was issued on 1 April 2026. In addition, we assisted Aktia in listing the bond on the Nasdaq Helsinki Ltd stock exchange. For the listing, we prepared Finland’s first EU Follow-on prospectus for a bond. The EU Follow-on prospectus was introduced on 5 March 2026 with an update to the Prospectus Regulation (EU) No. 2017/1129. The EU Follow-on prospectus is a new type of prospectus that can be used, among others, by issuers whose securities have been admitted to trading on a regulated market continuously for at least the 18 months preceding the offer to the public or the admission to trading on a regulated market of the new securities. A follow-on prospectus is simpler than a so-called traditional prospectus, and it is intended to avoid repeating information that the issuer has already disclosed. Nordea Bank Abp acts as the sole structuring advisor for the issue of the Notes. Nordea Bank Abp, Danske Bank A/S and ABN Amro Bank N.V. act as the lead managers for the issue of the Notes. 
Case published 7.4.2026