B 05.1 Data Security Guideline [Tietoturvaohje]
Finnish Bar Association [Suomen Asianajajaliitto / Suomen Asianajajat]
last revised 2024-01-01last verified 2026-09-043 versionscountry page →
RegulationIn forceConfidentialityCompetenceClient consentSupervisionRecord-keeping
map categories:Client data in AI toolsTechnological competenceClient consent and transparencyVendor due diligenceMandatory AI training
The Finnish Bar's binding information-security guideline, adopted by its delegation and in force in its current form since 1 January 2024. Eighteen numbered duties on advocates covering competence and documented training, security policy, external audits, business-grade software, device and access management, encryption, backups, supplier contracts and secure disposal.
- Applies to
- lawyers, firms
- Effective
- See version history
- Current version
- 9.6.2023 amendment · 01 Jan 2024
- Last verified
- 04 Sept 2026
What the document requires
- Point 6: software and services used in legal practice must be intended for business use; other services may be used only with the client's consent — the hook the Bar applies to AI applications.
- Point 1: the advocate must ensure their own and staff information-security competence is sufficiently high, assured by planned training, with evidence produced on request as for continuing education (B 9).
- Point 14: contracts with all external service providers must meet security requirements, in particular confidentiality terms, scoped access rights with periodic review, and agreed data destruction and portability.
- Points 2 and 3: firms of 10 or more employees must have a board-approved security policy and commission periodic external security audits, logged, and after significant system changes.
- Point 8: devices, tables, databases and cloud services holding client data must be encrypted; devices no longer receiving updates must be retired.
Version history
| Version | Date | What changed | Source |
|---|---|---|---|
| 9.6.2023 amendmentcurrent | 2024-01-01 | Delegation amendments of 9 June 2023 in force 1 Jan 2024: added competence and documented-training duty, security policy and external audit for firms of 10+ staff, business-grade software requirement, device management and access control, encryption, backup and supplier-contract terms. | official |
| 16.1.2020 amendment | 2020-02-01 | Added point 4 barring audits or information requests that would collect or disclose data on client relationships or engagements to outside parties. | official |
| Original | 2019-06-01 | Guideline adopted by the Bar's delegation on 24 January 2019, in force 1 June 2019. | official |
Sources
Cite this record
SafeLegalAI Legal AI Regulation Tracker, "B 05.1 Data Security Guideline [Tietoturvaohje]" (Finnish Bar Association [Suomen Asianajajaliitto / Suomen Asianajajat], 9.6.2023 amendment, 2024-01-01), safelegalai.com/regulation/other/fi-bar-tietoturvaohje-b051 (accessed 2026-09-04). Data: CC BY 4.0.
More official documents in Other
- Letter No. 112/WKMA.Y/HK2.1/IX/2026: draft judgment-writing guidance and templates for the new Criminal Codes · Mahkamah Agung
- AI in the advocate's practice: opportunities, tools and safe use [DI advokato praktikoje: galimybės, įrankiai ir saugus naudojimas] · Lietuvos advokatūra
- Supreme Court of Japan generative-AI demonstration for civil trials (FY2027 budget request) · Supreme Court of Japan
- Recommendation Guide on the Use of Artificial Intelligence for Lawyers [Avukatlar İçin Yapay Zekâ Kullanımı Tavsiye Rehberi] · Türkiye Barolar Birliği (TBB)
- Decision No. 1671/QD-TTg approving the National Strategy on Artificial Intelligence to 2030, vision to 2045 · Prime Minister of Vietnam
- Guideline on the Use of Artificial Intelligence for Indonesian Advocates [Pedoman Penggunaan Kecerdasan Buatan] · PERADI