Skip to content

Regulation Tracker / Other

B 05.1 Data Security Guideline [Tietoturvaohje]

Finnish Bar Association [Suomen Asianajajaliitto / Suomen Asianajajat]

last revised 2024-01-01last verified 2026-09-043 versionscountry page →

RegulationIn forceConfidentialityCompetenceClient consentSupervisionRecord-keeping

map categories:Client data in AI toolsTechnological competenceClient consent and transparencyVendor due diligenceMandatory AI training

The Finnish Bar's binding information-security guideline, adopted by its delegation and in force in its current form since 1 January 2024. Eighteen numbered duties on advocates covering competence and documented training, security policy, external audits, business-grade software, device and access management, encryption, backups, supplier contracts and secure disposal.

Applies to
lawyers, firms
Effective
See version history
Current version
9.6.2023 amendment · 01 Jan 2024
Last verified
04 Sept 2026

What the document requires

  • Point 6: software and services used in legal practice must be intended for business use; other services may be used only with the client's consent — the hook the Bar applies to AI applications.
  • Point 1: the advocate must ensure their own and staff information-security competence is sufficiently high, assured by planned training, with evidence produced on request as for continuing education (B 9).
  • Point 14: contracts with all external service providers must meet security requirements, in particular confidentiality terms, scoped access rights with periodic review, and agreed data destruction and portability.
  • Points 2 and 3: firms of 10 or more employees must have a board-approved security policy and commission periodic external security audits, logged, and after significant system changes.
  • Point 8: devices, tables, databases and cloud services holding client data must be encrypted; devices no longer receiving updates must be retired.

Version history

VersionDateWhat changedSource
9.6.2023 amendmentcurrent2024-01-01Delegation amendments of 9 June 2023 in force 1 Jan 2024: added competence and documented-training duty, security policy and external audit for firms of 10+ staff, business-grade software requirement, device management and access control, encryption, backup and supplier-contract terms.official
16.1.2020 amendment2020-02-01Added point 4 barring audits or information requests that would collect or disclose data on client relationships or engagements to outside parties.official
Original2019-06-01Guideline adopted by the Bar's delegation on 24 January 2019, in force 1 June 2019.official

Sources

Cite this record

SafeLegalAI Legal AI Regulation Tracker, "B 05.1 Data Security Guideline [Tietoturvaohje]" (Finnish Bar Association [Suomen Asianajajaliitto / Suomen Asianajajat], 9.6.2023 amendment, 2024-01-01), safelegalai.com/regulation/other/fi-bar-tietoturvaohje-b051 (accessed 2026-09-04). Data: CC BY 4.0.

More official documents in Other