Skip to content
Tietosuoja haltuun harrastustoiminnassa -hankkeen logo, jossa on tietosuojalainsäädäntöön ja lapsiin liittyvä kirjainlyhenne GDPR4CHLDRN. Tietosuoja haltuun harrastustoiminnassa -hankkeen logo, jossa on tietosuojalainsäädäntöön ja lapsiin liittyvä kirjainlyhenne GDPR4CHLDRN.
Search
  • English
    • Suomi
    • Svenska
    • English
  • Front page
  • Guiding materials
    • Board of the association
    • Coaches and instructors
    • Parents
    • Children and young people
  • Material bank
    • Term bank
    • Quizzes
    • Downloadable materials
    • Data protection icons 
    • Articles
  • Information on the site
  • English
    • Suomi
    • Svenska
    • English
  • Front page
  • Guiding materials
    • Board of the association
    • Coaches and instructors
    • Parents
    • Children and young people
  • Material bank
    • Term bank
    • Quizzes
    • Downloadable materials
    • Data protection icons 
    • Articles
  • Information on the site
Search
  1. Front page
  2. Board of the association
  3. Why is the protection of personal data important?
  4. 2. Sensitive personal data requires particularly careful protection
Skip to page content

Board of the association

  • Starting page
  • Why is the protection of personal data important?
    • 1. Privacy is a fundamental right
    • 2. Sensitive personal data requires particularly careful protection
    • 3. Personal identity codes may only be processed if necessary
  • What roles are involved in processing?
    • 1. The controller is responsible for the processing of personal data
    • 2. A processor acts on behalf of the controller
  • What principles must be observed in the processing of personal data?
    • 1. Take data protection into account from the start and in all circumstances
    • 2. Processing requires a basis
      • 2.1 Legal bases for processing personal data
      • 2.2 Consent requires an indication of the participant's wishes
      • 2.3 Consent from minors
    • 3. Only use personal data for the planned purposes
    • 4. Inform data subjects transparently of the processing of personal data
    • 5. Only process necessary personal data
    • 6. Only process accurate personal data and rectify inaccurate data
    • 7. Ensure the security of processing
    • 8. Define storage periods for personal data and erase unnecessary data
      • 8.1. Storage period
      • 8.2. Storage location
      • 8.3 Erasure 
    • 9. Demonstrate compliance with data protection legislation
  • What obligations does a hobby organiser have in the processing of personal data?
    • 1. Fulfil the participants' data protection rights
    • 2. Describe the hobby organiser's processing of personal data with a record of processing activities
    • 3. Agree on processing
    • 4. Assess the risks and impact of processing
    • 5. Report personal data breaches
    • 6. Only transfer personal data out of the EU if the conditions are met
    • 7. Give people involved in the hobby instructions and training in data protection
    • 8. Manage the life cycle of personal data from planning to collection, storage and erasure
  • What should you take into account when publishing photos and videos?
  • What should you take into account when processing health data in hobby activities?
  • What should you take into account when disclosing personal data in hobby activities? 
  • Annex 1: Consent form - template
  • Annex 2: Comics to inform about data protection

2. Sensitive personal data requires particularly careful protection

The icon features a rectangle depicting information. There is an eye crossed over with a line on the bottom right corner of the rectangle. The icon is surrounded by a light green frame. The icon can be used to indicate the processing of special categories of personal data or instructions for such processing.
The icon features an open palm holding a rectangle, which represents personal data, with a symbol depicting a person in the centre. The icon is surrounded by a light green frame. This icon can be used to express that the situation involves the controller's obligations related to the processing of personal data.

‘Special categories of personal data’ include sensitive information indicating the person’s ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health status, sexual orientation or sex life, as well as genetic and biometric data. As a rule, the processing of such personal data is prohibited. Such data may only be processed on special grounds and with special care.

Hobby organisers may process data about a person’s

  • health,
  • religious or philosophical beliefs,
  • ethnic origin,
  • political opinions,
  • sex life and sexual orientation, and
  • trade union membership.ammattiliiton jäsenyydestä.

Sensitive data must be protected especially well. The processing of special categories of personal data is only allowed on specific grounds laid down in the GDPR or other legislation. Hobby organisers can process such data on the following grounds:

  1. The data can be processed with the person’s informed and unambiguous consent. Explicit consent can be given by means such as signing a written statement, or with an electronic signature or two-factor authentication. For example, the person can first reply to an email sent by the hobby organiser, after which an electronic confirmation link or code will be sent to them.
  2. A political, philosophical or religious association or other non-profit organisation can process special categories of personal data when all of the following requirements are met:
    • The data is being processed in connection with the organiser’s legal activities.
    • The data is appropriately protected (e.g. technical safeguards, access rights management and password protection).
    • The organisation is only processing the data of its members, former members or individuals with a close connection to the organisation.
    • Data is not disclosed to outside parties without the person’s consent.

What do hobby organisers need to take into account when processing sensitive personal data?

1. Identify the special categories of personal data being processed in your hobby activities and make sure that it is necessary to process them.

2. Make sure that the hobby organiser has special grounds for processing the data. For example, the processing of a participant’s allergy information during a scout camp in the woods could be based on the participant’s specific consent. If sensitive data is being processed on the basis of the person’s consent, you need to be able to demonstrate that the consent has been given.

3. Make sure that special categories of personal data are well protected, for example with technical safeguards, access rights management and password protection.

4. Specify the individuals whose duties include the processing of special categories of personal data in the hobby activity. Make sure that only the people whose duties include the processing of sensitive data have access to the data, and that those people are aware of the special requirements related to the processing of sensitive data.

5. Specify the storage period for the personal data. The storage period must reflect the purpose of the processing. For example, if information on the participants’ allergies has only been collected for a scout camp in the woods, the data must be erased at the end of the camp.

Remember

Take special care to protect sensitive data. Make sure that you have special grounds for processing special categories of personal data.

1. Privacy is a fundamental right
3. Personal identity codes may only be processed if necessary
The logo of the Office of the Data Protection Ombudsman.
The logo of TIEKE Finnish Information Society Development Centre.

The European Union flag, with the text "Funded by the European Union" on its right-hand side.

Funded by the European Union. Views and opinions expressed are however those of the author(s) only and do not necessarily reflect those of the European Union or European Commission. Neither the European Union nor the granting authority can be held responsible for them.

Information on the website

The site contains material that provide information on data protection legislation and the protection of personal data, especially for children and young people aged 13–17, their parents, and associations that organise hobby activities. The website has been developed in the GDPR4CHLDRN – Ensuring data protection in hobbies project (2022–2024) implemented by the Office of the Data Protection Ombudsman and TIEKE.

Feedback about the site can be given by e-mail to the address tietosuoja@om.fi. In the message field, you must mention tietosuojaharrastuksissa.fi, so that the feedback is directed to the correct address.

  • Data protection on the website
  • Accessibility statement
Guiding materials
  • Board of the association
  • Coaches and instructors
  • Parents
  • Children and young people

© 2024 Office of the Data Protection Ombudsman and TIEKE. The site uses free Font Awesome icons. The icons have not been changed. License: CC BY 4.0

Touched by Hutcode