Skip to content
Tietosuoja haltuun harrastustoiminnassa -hankkeen logo, jossa on tietosuojalainsäädäntöön ja lapsiin liittyvä kirjainlyhenne GDPR4CHLDRN. Tietosuoja haltuun harrastustoiminnassa -hankkeen logo, jossa on tietosuojalainsäädäntöön ja lapsiin liittyvä kirjainlyhenne GDPR4CHLDRN.
Search
  • English
    • Suomi
    • Svenska
    • English
  • Front page
  • Guiding materials
    • Board of the association
    • Coaches and instructors
    • Parents
    • Children and young people
  • Material bank
    • Term bank
    • Quizzes
    • Downloadable materials
    • Data protection icons 
    • Articles
  • Information on the site
  • English
    • Suomi
    • Svenska
    • English
  • Front page
  • Guiding materials
    • Board of the association
    • Coaches and instructors
    • Parents
    • Children and young people
  • Material bank
    • Term bank
    • Quizzes
    • Downloadable materials
    • Data protection icons 
    • Articles
  • Information on the site
Search
  1. Front page
  2. Board of the association
  3. What principles must be observed in the processing of personal data?
  4. 7. Ensure the security of processing
Skip to page content

Board of the association

  • Starting page
  • Why is the protection of personal data important?
    • 1. Privacy is a fundamental right
    • 2. Sensitive personal data requires particularly careful protection
    • 3. Personal identity codes may only be processed if necessary
  • What roles are involved in processing?
    • 1. The controller is responsible for the processing of personal data
    • 2. A processor acts on behalf of the controller
  • What principles must be observed in the processing of personal data?
    • 1. Take data protection into account from the start and in all circumstances
    • 2. Processing requires a basis
      • 2.1 Legal bases for processing personal data
      • 2.2 Consent requires an indication of the participant's wishes
      • 2.3 Consent from minors
    • 3. Only use personal data for the planned purposes
    • 4. Inform data subjects transparently of the processing of personal data
    • 5. Only process necessary personal data
    • 6. Only process accurate personal data and rectify inaccurate data
    • 7. Ensure the security of processing
    • 8. Define storage periods for personal data and erase unnecessary data
      • 8.1. Storage period
      • 8.2. Storage location
      • 8.3 Erasure 
    • 9. Demonstrate compliance with data protection legislation
  • What obligations does a hobby organiser have in the processing of personal data?
    • 1. Fulfil the participants' data protection rights
    • 2. Describe the hobby organiser's processing of personal data with a record of processing activities
    • 3. Agree on processing
    • 4. Assess the risks and impact of processing
    • 5. Report personal data breaches
    • 6. Only transfer personal data out of the EU if the conditions are met
    • 7. Give people involved in the hobby instructions and training in data protection
    • 8. Manage the life cycle of personal data from planning to collection, storage and erasure
  • What should you take into account when publishing photos and videos?
  • What should you take into account when processing health data in hobby activities?
  • What should you take into account when disclosing personal data in hobby activities? 
  • Annex 1: Consent form - template
  • Annex 2: Comics to inform about data protection

7. Ensure the security of processing

The icon features a closed padlock with a symbol depicting a person in the middle. The shackle of the padlock is broken. The icon is surrounded by a light green frame. This icon can be used to express that the situation involves a personal data breach.

The hobby organiser must take care of the protection of data at all stages of processing from collection to erasure. Secure processing requires that the controller is able to guarantee the confidentiality, integrity, usability and resilience of the systems and services at all times and is able to restore the data quickly in the event of a fault. The processing of personal data must also be monitored and supervised to ensure security.

The adequate level of data security depends on the nature and volume of the data being processed. For example, sensitive data and special categories of personal data require more effective technical safeguards. Large volumes of data can attract interest from outside parties and thus require more effective safeguards. Personal data must be secured at all stages of processing, that is, from collection to erasure.

Data must be protected from access by third parties. ‘Third parties’ means everyone without a basis or right to process the personal data.

In electronic systems, third-party access to personal data can be prevented with access rights management. The controller must ensure that only persons whose duties give them the right to process personal data can gain access to the data. Remember that viewing the data also counts as processing. When a person changes roles within the club, you should also remember to immediately deactivate their access rights to systems they are no longer entitled to access.

Example

In a sports club, the coaches and team manager of a football team have the right to process the personal data of their team’s players but not the personal data of players from other teams in the club.

You should use individual usernames in your systems. The use of shared usernames is not recommended. With individual usernames, the controller can control and verify the processors of personal data, including retrospectively.

The controller must check the default settings of new systems and applications before starting to use them. With regard to data protection, you should check that all users cannot see personal data by default.

What does data security mean?

Data security is one way of implementing data protection. It is intended to protect data and information systems. Among other things, it refers to organisational and technical measures taken to ensure the confidentiality and integrity of data, usability of systems and the realisation of the rights of the data subject.

Who has the right to process personal data?

The controller must specify the persons who have appropriate grounds for processing personal data in any given situation. You should also document these grounds. Appropriate grounds can include both regular work duties and one-off circumstances.

Remember

Check the default settings of new systems and applications to ensure that they are not collecting unnecessary data or allowing too many users to see personal data.

6. Only process accurate personal data and rectify inaccurate data
8. Define storage periods for personal data and erase unnecessary data
The logo of the Office of the Data Protection Ombudsman.
The logo of TIEKE Finnish Information Society Development Centre.

The European Union flag, with the text "Funded by the European Union" on its right-hand side.

Funded by the European Union. Views and opinions expressed are however those of the author(s) only and do not necessarily reflect those of the European Union or European Commission. Neither the European Union nor the granting authority can be held responsible for them.

Information on the website

The site contains material that provide information on data protection legislation and the protection of personal data, especially for children and young people aged 13–17, their parents, and associations that organise hobby activities. The website has been developed in the GDPR4CHLDRN – Ensuring data protection in hobbies project (2022–2024) implemented by the Office of the Data Protection Ombudsman and TIEKE.

Feedback about the site can be given by e-mail to the address tietosuoja@om.fi. In the message field, you must mention tietosuojaharrastuksissa.fi, so that the feedback is directed to the correct address.

  • Data protection on the website
  • Accessibility statement
Guiding materials
  • Board of the association
  • Coaches and instructors
  • Parents
  • Children and young people

© 2024 Office of the Data Protection Ombudsman and TIEKE. The site uses free Font Awesome icons. The icons have not been changed. License: CC BY 4.0

Touched by Hutcode