Finland is one of the strictest countries in Europe for pre-employment screening. A dedicated privacy in working life statute sets the rules, and its central principle catches most employers by surprise.
Collect from the candidate, not around them
The Act on the Protection of Privacy in Working Life requires an employer to collect personal data primarily from the employee themselves. Gathering information from any other source, including former employers or public registers, needs the candidate’s consent. There is also a necessity requirement: the data must be directly relevant to the employment relationship, and this cannot be waived even if the candidate agrees.
Criminal record checks
Extracts come from the Legal Register Centre and are requested by the individual. A specific statute covers work with children, requiring an extract for roles involving sustained contact with minors, and that extract discloses only a narrow set of offences. Outside that and other regulated contexts such as financial services or private security, requesting a criminal record extract is generally not permitted. Certain positions instead go through a formal security clearance handled by the security authorities.
What employers can check
Identity, right to work, employment history, and academic qualifications are all legitimate with consent. Credit checks are tightly restricted and permitted only for defined roles involving significant financial responsibility, and the candidate must be told.
Data protection
The GDPR applies alongside the working life statute, supervised by the Data Protection Ombudsman. Employers with staff representation obligations must also handle screening through the cooperation procedure rather than imposing it unilaterally.
Practical guidance
Work out what the law actually permits for the specific role before designing a process, ask the candidate directly, and document consent. An employer of record can manage this if you have no Finnish entity.

