20.3.2017

Get a Handle on Data Protection Risks and Seize New Business Opportunities

One of the main goals of the new Data Protection Regulation is to make the enforcement of data protection legislation more efficient. This can be seen in the fact that national supervisory authorities have been granted the power to impose very large fines for unlawful data processing.

Almost all companies process personal data, which makes them data controllers obligated to comply with data protection legislation. In this respect, the new regulation makes data protection a part of corporate risk management on an entirely new scale. In order to ensure that they identify, manage and minimise these risks properly and efficiently, companies must look beyond their own business risks and keep in mind whose risks they are really dealing with.

Data Protection Risks Are Individual Risks

The purpose of personal data legislation is to protect the rights of individuals—you, me, everyone—to data privacy. The risk that personal data will be abused also primarily affects individuals. If you look at the numbers, the legislator has really spelled this out in the new regulation: the word ‘risk’ appears in the new regulation about 70 times—a ten-fold increase over the current Data Protection Directive.

The Data Protection Regulation emphasises the data controller’s duty to plan its data processing procedures in such a way that the risks on the level of individuals are taken into account proactively. This requires more of companies than just incorporating data protection risks into their existing risk management processes—risk awareness needs to be present in data protection work that data controllers engage in on every level.

Without making an assessment of the potential effects on individuals, the effective implementation of data protection legislation is impossible. How can companies choose the correct legal grounds (such as determining whether the data controller’s legitimate interests are in balance with the rights of individuals) or determine the proper level of data security without knowing what the risks to the individual are?

Be Systematic

According to the principle of privacy by default, companies need to identify and account for risks to individuals well before starting to process data. Companies should adopt some kind of privacy impact assessment to systematically assess and document the risks relating to data processing.

One of the major changes being brought by the new Data Protection Regulation is accountability. It is no longer enough that a company’s actions are compliant, they have to be able to demonstrate it. The risk management methods mentioned above are a key part of fulfilling this obligation.

Systematic data protection procedures that take the risks to individuals into account will not only shield companies from fines and other penalties, but maintain the public’s trust in the company. This trust then forms the foundation for the next step, in which data protection ceases to be a risk and becomes a business opportunity. This should be the long-term goal of every company.

Latest references

We advised Efima Oyj on the sale of its AI business to Better Care Technologies Oy. The transaction included Efima’s Moiva AI platform developed for the care sector, the related technology and brand, customer contracts, and the experts working in the business. Efima is a Finnish digital company that supports the sustainable growth of large and mid-sized companies by streamlining their business processes and by creating competitive advantage through the innovative use of artificial intelligence and data. The company has nearly 200 experts based in Helsinki and Tampere. 
Case published 21.9.2026
We advised Neoen Renewables Finland Oy, part of the French Neoen Group, in its sale of a data centre project to a consortium consisting of international data centre developers and operators. This marked Neoen’s first data centre development project in Finland. Founded in 2008, Neoen is one of the world’s leading independent renewable energy producers. The company operates in 15 countries. It develops, finances, builds, owns, and operates solar power plants, wind farms, and battery storage systems. Neoen Group is owned by global alternative asset manager Brookfield Corporation.
Case published 17.9.2026
We advised Jolt Capital and Tesi in connection with their investment in VEV, a leading provider of commercial fleet electrification solutions. The investment, led by Jolt Capital with Tesi as co-investor, will support VEV’s next phase of growth and expansion across Europe. As part of the transaction, VEV became an independent company following the acquisition of Vitol’s stake in the business. Founded by Vitol, VEV provides integrated fleet electrification solutions combining fleet strategy, charging infrastructure, energy supply and operational services. Through its VEV IQ platform, the company supports more than 6,000 commercial electric vehicles across Europe and has been deployed across more than 600 sites spanning the transport, logistics and waste sectors. Jolt Capital is a private equity firm focused on growth investments in European deeptech companies. Tesi is a Finnish state-owned investment company that promotes Finnish business and economic growth through investments. We advised Jolt Capital and Tesi on the equity financing and structuring aspects of the transaction. International law firm Goodwin advised the investors on the acquisition of VEV.
Case published 10.9.2026
VR-Group Plc is a transport and logistics group owned by the Finnish State, operating passenger and freight rail transport in Finland with activities also in the Swedish market. VR Group provides passenger, logistics and maintenance services with over 160 years’ experience in developing responsible transport of the future. We advise VR Group in intellectual property matters as part of the company’s wider brand protection efforts. Our assignments have included advice on copyright, design rights and trademarks, focusing on the protection of the company’s visual identity – including its distinctive green colour – in connection with transport services as part of a comprehensive IP protection strategy. VR Group’s consistent brand building has also received recognition, including the Finland Chamber of Commerce’s Brand of the Year award in 2026. In the competition, brands were viewed comprehensively from various perspectives, including their story, strategic role, brand renewal ability and intellectual property protection. The jury found that VR had understood the importance of the protection of its brand as part of a comprehensive business strategy. 
Case published 9.9.2026