Cybersecurity

Cybersecurity

Data is a valuable commodity in many organisations. We help you handle data in a compliant manner and protect it from misuse.

The legal requirements for cybersecurity are scattered across different regulations. The European Union is introducing a growing number of sector-specific regulations on information security requirements, such as DORA, NIS2, CRA and CER. We can help you identify the provisions that apply to your specific business and explain what they mean in practice. We speak the same language as ICT professionals. Several of our legal experts are also computer science graduates.

In addition to day-to-day advice, we can help you with a range of incidents. Data systems are vulnerable to disruptions and outside threats. In emergencies, the statutory and contractual obligations relating to data and personal data must be fulfilled in order to mitigate risks and safeguard your business’s ability to operate as effectively as possible. Our experts are experienced at resolving a wide range of disruptions, whether they originate from inside or outside the company.

Latest references

The Finnish Supreme Administrative Court has handed down decision KHO 2024:115 on balancing data protection and national security interests in cyber security incidents. We acted for the Finnish Ministry of Foreign Affairs in this precedent setting case, in which the Supreme Administrative Court agreed with our client’ core submissions and decided to overturn key parts of a data protection authority decision against our client. The court held that the Ministry had acted lawfully when taking a bit of time between discovering information about a cyber incident concerning certain diplomats and notifying all potentially affected people. The key point of principle for our client was the extent to which Article 34 of the GDPR requires such (essentially public) notifications when foreign policy and national security might require a more discrete initial approach. The court’s reasoning is important: since Finland has voluntarily, but not unreservedly, extended the scope of the GDPR to also cover foreign policy and national security, the primacy of EU law does not apply in that extended context. Thus, more specific local Finnish rules on freedom of information/confidentiality in these areas override the general Article 34 notification obligation (under the classic lex specialis derogat legi generali rule), even absent express statutory carve-outs to Article 34. Had Article 34 applied as a matter of EU law, the outcome could have been different, since the GDPR, under primacy, would override all local Finnish rules, irrespective of whether they are lex specialis or not. It’s important to understand why, and on what basis, an EU law applies to any given situation, since this could affect the principles of interpretation so much that the outcome changes significantly. The court did, however, hold that the Ministry will need to notify the DPA itself within the customary deadlines, since the DPA under Finnish law has the right to receive information confidentiality rules notwithstanding. We hope this outcome will contribute to authorities dealing with foreign policy and national security being able to balance all relevant interests going forward. Read the decision in Finnish or in Swedish .
Case published 15.11.2024
We acted as Finnish law legal adviser to the lenders and the export credit agencies in connection with the EUR 514.4 million green project financing for the development and construction of Easpring Finland New Materials Oy’s cathode active material (CAM) manufacturing plant in Kotka, Finland. The borrower, Easpring Finland New Materials Oy, is a joint venture owned by Beijing Easpring Material Technology, Finnish Minerals Group and LG Energy Solution. The financing was provided by six international commercial banks, with Société Générale acting as financial adviser and mandated lead arranger together with Natixis as co-mandated lead arranger, and DNB, ICBC, ING and Standard Chartered participating as lenders, with support from the export credit agencies Finnvera and Sinosure. The project represents a significant milestone for Finland and the European battery value chain by strengthening Europe’s domestic supply of cathode active materials, a key component in lithium-ion batteries for electric vehicles and energy storage applications. Once the first phase of the project is operational, the Kotka facility is expected to produce approximately 60,000 tonnes of cathode active material annually, making it one of the largest CAM production plants in Europe and supplying leading battery manufacturers across Europe. 
Case published 21.7.2026
We acted as Finnish legal advisor to Delta Capacity in connection with its acquisition of the ready-to-build Karppio battery energy storage system (BESS) project from Helios Nordic Energy. The acquisition was made and the project will be implemented together with Strioga Family Foundation. The Karppio BESS project is located in Teuva, Finland, and has a capacity of 125 MW / 300 MWh. Delta Capacity will lead the remaining development of the project through to commissioning, planned for 2027, and will serve as long-term asset manager. Delta Capacity is a Swiss-based developer of utility scale battery storage systems. The acquisition adds to Delta Capacity’s growing Nordic portfolio. 
Case published 20.7.2026
We advised Swedbank AB (publ) on the refinancing of a large Finnish retail real estate portfolio owned by Trophi’s Finnish subsidiaries. Trophi is the leading Nordic real estate company focusing on grocery anchored retail properties, with 278 properties across Sweden and Finland. Finland is a market that continues to develop and is also strategically important for Trophi, accounting for approximately 30% of Trophi’s letting and property value.
Case published 17.7.2026