1.2.2017

Procurements Units to Check Criminal Records

The reform of the Act on Public Contracts that entered into force at the beginning of the year tightened the suitability conditions for suppliers participating in competitive tender processes. Procurement units must now rule out tenderers who have committed a serious crime listed in the act, such as tax fraud, accepting or giving bribes or money laundering.

Background Checks for Winning Tenderers

Even before the reform, procurement units had to rule out suppliers that they knew, for example based on information in the media, to have committed a serious crime. What is new is that the procurement unit now has an express obligation to check that the winning tenderer has not committed a crime leading to mandatory exclusion before signing the agreement.

The procurement unit’s background check obligation applies to larger procurements for goods and service and construction contracts, i.e. those exceeding the EU thresholds. The act also provides the opportunity to carry out corporate backgrounds checks in competitive tender processes exceeding the national thresholds.

The procurement unit carries out the background check by asking the winning bidder to submit criminal record excerpts on the members of its administrative, management or supervisory bodies and on persons exercising representation, decision-making or supervisory powers in the company. The company requests the criminal record excerpts from on these persons itself from the Legal Register Centre. Prior to requesting the information, the company must obtain the consent of the persons in question.

No Copying or Storing of Criminal Record Data

Criminal records are sensitive personal data that companies must have legal grounds to process. It is clear that criminal record excerpts cannot include data on crimes other than those expressly stated in the Act on Public Contracts.

In accordance with the Act on Public Contracts, a company participating in a competitive tender process cannot copy or store criminal records for itself. In practice, this means that each person must keep their own criminal records excerpt and submit it separately for each tender process to the tendering company, which will then send the excerpt on to the procurement unit.

This can cause practical problems if the number of tendering processes and excerpts to be summited is high. Bidding companies would be well advised to create efficient internal process to handle these filings.

The procurement unit must dispose of the criminal records excerpt or return it directly to the person in question once the person’s background has been checked from the excerpt. Information provided in the criminal records cannot be disclosed to people in the procurement unit who do not need it.

The Newer the Criminal Record Excerpt, the More Reliable It Is

The Act on Public Contracts states that the criminal record excerpt cannot be more than twelve months old. This is understandable, as it makes it possible to use the same excerpt for more than one tendering process.

On the other hand, a year is a long time, and it is possible that a member of a company’s management could commit an offence during that time. So from the perspective of the accuracy of the information, older excerpts constitute a risk for the procurement unit. Of course, employees are obligated to inform their employers changes to their data.

Collected Data Forms a Register

From the perspective of employer obligations, collected criminal record data forms its own register or at least a new data category, and the matter must be discussed in cooperation negotiations prior to starting the collection of the data. Procurement units, for their part, have an obligation to record the fact that criminal record excerpts have been collected from the necessary parties. This forms its own register and the units incur the related data controller obligations, such as the obligation to draft a file description.

The data protection legislation set to change in a year  will tighten the requirements for maintaining registers even further. Many suppliers are currently reviewing their current data protection practices, and procurement units should also take a close look at the data protection issues relating to competitive tender processes.

Latest references

We are acting as the joint legal advisor to Oomi Oy and Lumme Energia Oy in a transaction whereby Lumme Energia will merge with Oomi. As from the completion of the merger, the combined entity will be the largest electricity retail and service company in the Finnish market. In 2024, Oomi reported a turnover of EUR 373.9 million and had approximately 110 employees. Lumme Energia’s turnover for the same year was approximately EUR 314.6 million and it had approximately 50 employees. The transaction is primarily driven by the recent developments in the electricity market and the strategic goal to develop competitive products and services. Another key objective is to further enhance the customer experience, which is a shared value between the two companies. As a result of the merger, Lumme Energia’s customers will transfer to Oomi, and Lumme Energia will become one of Oomi’s shareholders. The completion of the transaction is subject to an approval by the Finnish Competition and Consumer Authority.
Case published 29.8.2025
We assisted Oomi Oy in its expansion into the mobile telecommunications market with the launch of Oomi Mobiili, a new MVNO brand. Our work covered the preceding due diligence process as well as structuring and negotiating key partner agreements, laying a solid foundation for Oomi’s entry into the new market. Oomi Mobiili will operate as a virtual mobile network operator, offering customers the option to purchase a mobile subscription together with their electricity contract. The phased launch is set to begin in autumn 2025, with nationwide availability targeted for early 2026. 
Case published 15.8.2025
We are acting as the legal advisor to WithSecure Corporation in Diana BidCo Oy’s voluntary public cash tender offer for all the issued and outstanding shares in WithSecure. The tender offer values WithSecure’s total equity at approximately EUR 299 million. Diana BidCo is a private limited company incorporated and existing under the laws of Finland that will be indirectly owned by a consortium formed for purposes of the tender offer by certain affiliated funds of CVC Capital Partners Plc and Risto Siilasmaa. The consortium believes that the partnership strengthens and accelerates the road to WithSecure’s long-standing goal of becoming Europe’s most trusted cybersecurity partner by positioning the company to lead the next era of business cybersecurity. WithSecure’s shares are listed on the official list of Nasdaq Helsinki. WithSecure is a Europe-based cybersecurity company that helps protect businesses and is committed to strong partnerships with customers and collaborators. WithSecure’s customers trust WithSecure with outcome-based cybersecurity that protects and enables their operations. The completion of the tender offer is subject to the satisfaction or waiver by the offeror of certain customary conditions on or prior to the offeror’s announcement of the final results of the tender offer. The tender offer is currently expected to be completed during the fourth quarter of 2025. The Takeover Board of the Securities Markets Association issued on 4 August 2025 a new recommendation (1/2025) on good securities market practice that deals with the target company’s board of directors’ obligations in case of a consortium offer in which a major shareholder of the company participates in the consortium.
Case published 8.8.2025
We acted as Finnish legal advisor to HANZA AB in connection with its acquisition of the contract manufacturing division of Milectria, a group of companies specialising in electrical systems for the defence industry.  The transaction comprises 100% of the shares in Milectria Oy (Finland), Milectria OÜ (Estonia), and the real estate company Kiinteistö Oy Kanungin Karhu. The transaction is expected to close in September 2025, subject to customary closing conditions, including regulatory approvals.  Founded in 2008, HANZA is a Swedish mechanical engineering and electronics contract manufacturing company listed on the Nasdaq Stockholm main list. The company operating in seven countries currently has annual sales of approximately SEK 6 billion and approximately 3,100 employees. Milectria is a Finnish contract manufacturer of electrical systems for the defence industry.
Case published 21.7.2025