28.3.2023

The EU regulation on digital operational resilience for the financial sector poses new obligations for boards of financial entities

The Digital Operational Resilience Act DORA governing both digital operational resilience and the use of information and communication technology (ICT) in the financial sector entered into force in the European Union in January. The regulation is part a larger digital finance package and will apply to EU Member States from January 2025 onwards.

Regulated industries and operators

DORA applies to various financial entities, including banks, insurance companies and investment firms. The regulation also applies to service providers that provide financial entities with critical ICT services, such as cloud computing services and data analytics services.

New obligations for boards of financial entities

One of the aims of the regulation is to ensure that the boards of financial entities take on a pivotal and active role in steering and adapting the overall strategy concerning ICT risk management and operational resilience. Under DORA, the board is ultimately responsible for the entity’s ICT risk management.

First, the board must define, oversee and be responsible for the implementation of all arrangements related to the ICT risk management framework. DORA lays down the concrete minimum requirements for risk management frameworks in more detail, but they must include at least strategies, policies, procedures, protocols and tools that are necessary to protect all ICT assets (such as computer software, hardware and servers) and infrastructures (such as premises and data centres) against ICT risks including damage and unauthorised access or usage. In practice, this includes the following:

As part of their ICT risk management framework, financial entities must also define a strategy for the risks related to the use of third-party ICT services. This requires that the board members of financial entities regularly review the risks concerning contractual arrangements on the use of ICT services supporting critical or important functions.

Board members of financial entities are also required to keep up to date with sufficient knowledge and skills to understand and assess the entity’s ICT risk. Under the regulation, maintaining sufficient knowledge requires, among other things, regular participation in specific training on ICT risks and their effects.

Liability for non-compliance

Under DORA, Member States must ensure that the national authorities have the power to apply different administrative penalties and remedial measures in case the obligations are breached. It must be possible to direct these administrative penalties and remedial measures at board members of financial entities and other natural persons who are responsible for the breach of DORA under national law. However, the final form of these sanctions will not be known before the national law is amended as required by the regulation. Authority initiative on this matter has not yet begun in Finland.

Preparing for the future

All in all, DORA creates a comprehensive and detailed framework for the management of risks related to digitalisation in financial entities. DORA includes new requirements with respect to cyber security and operational resilience. The regulation also lays down new obligations for boards of financial entities. Failure to comply with these obligations could even result in administrative penalties to board members on an individual level. The sanctions for breach in Finnish legislation will likely be specified in the coming years. However, it is advisable that financial entities start to evaluate their ICT risks and practices in good time, also with respect to their ICT service providers.

 

Latest references

We advised Lantmännen ek för in its contemplated acquisition of Leipurin from Aspo Plc. Lantmännen is an agricultural cooperative and Northern Europe’s leader in agriculture, machinery, bioenergy and food products. Lantmännen is owned by 17,000 Swedish farmers and has 12,000 employees in over 20 countries. Leipurin is a leading Nordic supplier of bakery ingredients, equipment, and expert services to professional bakeries, confectioneries, and food manufacturers. The company operates across Finland, Sweden, and the Baltic countries with subsidiaries located in the aforementioned countries, providing comprehensive solutions to the baking industry. The closing of the transaction remains subject to regulatory approvals.
Case published 25.8.2025
We assisted Oomi Oy in its expansion into the mobile telecommunications market with the launch of Oomi Mobiili, a new MVNO brand. Our work covered the preceding due diligence process as well as structuring and negotiating key partner agreements, laying a solid foundation for Oomi’s entry into the new market. Oomi Mobiili will operate as a virtual mobile network operator, offering customers the option to purchase a mobile subscription together with their electricity contract. The phased launch is set to begin in autumn 2025, with nationwide availability targeted for early 2026. 
Case published 15.8.2025
We advised Nevel Oy in its acquisition of the business of Labio Oy. Lahti Aqua Oy and Salpakierto Oy sold their entire shareholdings in Labio to Nevel, expanding Nevel’s already significant biogas portfolio. The transaction will have no impact on Lahti Aqua’s water utility operations or Salpakierto’s municipal waste management responsibilities. Labio’s operations and customer relationships will continue as before. ‘This partnership is a natural next step for us as we continue investing in sustainable material efficiency and renewable energy solutions. By integrating Labio’s comprehensive offerings and expertise, we can provide customers with a strong platform for material circularity. We are also strengthening our market position as one of Finland’s leading material efficiency solution providers,’ says Ville Koikkalainen, Director of Industrial and Biogas Business at Nevel. Nevel is an energy infrastructure company offering advanced, climate-positive solutions for industry and real estate. It operates more than 130 energy production plants and manages over 40 district heating networks. Nevel’s annual turnover is EUR 150 million, and it employs 190 experts in Finland, Sweden and Estonia.
Case published 16.7.2025
The Supreme Administrative Court (SAC) issued a significant precedent (decision KHO:2025:23) in a case in which it found that the Finnish Motor Insurers’ Centre (Liikennevakuutuskeskus, LVK) processed patient data in accordance with the requirements concerning fairness, data minimisation, and privacy by design and by default when deciding on compensation claims. We represented LVK in this case in which the SAC upheld the Administrative Court’s decision to repeal the EUR 52,000 administrative fine imposed on LVK by the Sanctions Board of the Office of the Data Protection Ombudsman. The SAC also confirmed the Administrative Court’s decision, which, as far as we know, was the first of its kind in Finland, ordering the Office of the Data Protection Ombudsman to reimburse some of our client’s legal costs. The decision bears great significance for the insurance industry as a whole. The crux of the matter were LVK’s information requests under the Motor Liability Insurance Act for patient data that were essential in determining insurance or compensation claims. In certain cases, making a decision may require extensive patient data. The Office of the Data Protection Ombudsman had found that LVK had systematically made overly broad information requests infringing Articles 5 and 25 of the GDPR and that the information should have been provided in the form of separate medical opinions. The Administrative Court repealed the Data Protection Ombudsman’s decision and found that patient records from medical appointments are, as a general rule, essential in establishing causality in compensation matters. It also stated that the tasks related to the consideration of compensation matters are specifically the core tasks of the insurance company and not of the controller of patient data. Furthermore, the Administrative Court found no evidence indicating that LVK would have systematically made overly broad information requests. ‘Once again, our collaboration with C&S was seamless throughout this extensive process, and we could trust that our case was in expert hands’, says Visa Kronbäck, Chief Legal Officer of the Insurance Centre. The full decision is available on the SAC website (in Finnish):  KHO:2025:23.
Case published 18.6.2025