Legal requirements for websites in Finland: accessibility, cookies, privacy
The four things every Finnish business site must have
Independent of size or industry, these four apply to any Finnish business with a website.
1. Business identity information. Finnish company name, business ID (Y-tunnus), postal address, email, and phone number must be findable — typically in the footer or on a dedicated contact page. This comes from the Finnish Trade Register Act and consumer protection law.
2. Privacy policy. Required under GDPR whenever the site collects any personal data — and it always does, because analytics and contact forms count. The privacy policy must be linked from every page (usually footer). It must explain: what data you collect, why, how long you keep it, who else sees it, and what rights the visitor has.
3. Cookie consent for non-essential cookies. If your site uses Google Analytics, Facebook Pixel, Hotjar, or any marketing tag, the visitor must actively consent before those load. A banner that says "by using this site you accept cookies" is not consent under EU law — the visitor must have a real choice, and "reject" must be as easy as "accept".
4. Accessibility statement (if applicable). Required for public sector sites, larger private services (banks, telecoms, transport), and any site over certain thresholds. The statement is a page describing how the site meets WCAG 2.2 AA, what does not, and how a user can report a barrier.
E-commerce adds four more
Online shops selling to Finnish consumers have extra obligations under the Consumer Protection Act:
5. Terms of service (käyttöehdot / toimitusehdot). Must state the seller's identity, price with taxes, delivery time, delivery cost, payment methods, and right of withdrawal.
6. Right of withdrawal information. Consumer has 14 days to withdraw from most online purchases. The site must state this and provide a withdrawal form or clear instructions.
7. Clear total price before payment. Including VAT, delivery, and any surcharges. Hidden fees revealed at the checkout step are illegal.
8. Confirmation of order in a durable medium. Email is fine. Must be sent within a reasonable time after the order.
Accessibility in practice — WCAG 2.2 AA
If you are legally required to meet WCAG 2.2 AA, the practical checklist is roughly:
- Text contrast at least 4.5:1 against its background.
- Every image has a meaningful alt attribute (or empty alt if purely decorative).
- The site can be fully operated with the keyboard alone.
- Focus indicators are visible when tabbing through interactive elements.
- Form fields have visible labels, not just placeholders.
- Videos have captions, audio has transcripts.
- Heading order is logical (H1 once, H2s under it, no skipping levels).
- Colour is not the only way information is conveyed.
Even if you are not legally required, meeting the basics is worth it: 10 to 20% of adults have some form of impairment, and accessible sites usually rank better on Google too.
What the fines actually look like
GDPR breaches: For SMEs in Finland, published cases from the Data Protection Ombudsman typically fall in the 2000 to 50 000 euro range. The maximum in law is 20 million euros or 4% of global revenue, but that is for the very worst violations by large companies. A small business is more likely to receive a warning + corrective order for a first offence.
Cookie violations: Enforcement is inconsistent in Finland today. Traficom (previously Ficom) handles complaints. Most action so far is warnings; monetary fines are rare but starting to appear.
Consumer protection breaches (e-commerce): The Consumer Ombudsman can issue orders and, since 2023, direct penalty fees up to 4% of turnover.
Accessibility breaches: For public sector, the Regional State Administrative Agency (aluehallintovirasto) can issue conditional fines. For private-sector obligated parties, enforcement is newer and less predictable.
Cheap and correct: what to do this month
- Confirm your business ID, address, and email are in the footer of every page.
- Publish a privacy policy. Templates are fine as a starting point; adapt to your actual data flows.
- Install a real cookie consent tool. Cookiebot and Osano are common; Iubenda works for smaller sites. Do not use a fake banner.
- If you sell online, publish terms of service and check that your checkout shows the full total.
- If you are in a WCAG-obligated sector, run a Lighthouse accessibility audit, fix the low-hanging items, and publish an accessibility statement.
None of this makes anyone money. All of it prevents specific, forecastable losses. Treat it like insurance and move on.
Frequently asked questions
Do I need a cookie banner even if I only use Google Analytics?
Yes. Google Analytics is not a technically essential cookie. Under EU law it requires explicit consent before loading. Alternatives without a banner exist (Plausible, Simple Analytics, Fathom) — many small sites switch to those to avoid the consent-management overhead.
Where should the privacy policy and terms live?
Both should be linked from the footer of every page. The privacy policy is also often linked from any form that collects data ('by submitting, you accept our privacy policy'). Do not hide them in obscure menus.
Can I use a template privacy policy?
Yes as a starting point. Iubenda, Termly, and Finnish-language templates from Yrittajat.fi are legitimate. You must customise it to reflect your actual data collection — a copy-pasted template that says you use tools you do not use is worse than no policy.
Does WCAG 2.2 AA apply to a small e-commerce shop?
It depends on your revenue and category. The European Accessibility Act (in force from June 2025) extends accessibility duties to more private-sector services, including many online shops above certain thresholds. If you sell online and turn over more than a few million euros, get legal advice.
What happens if a customer files a GDPR complaint against my small business?
The Data Protection Ombudsman contacts you, asks for your account, and gives you a chance to respond and fix things. First-time offences by cooperative small businesses usually end with a warning and required corrections. Ignoring the ombudsman is what leads to fines.
Is a Y-tunnus really required on the website?
Yes, for any registered Finnish business. It is part of the trade register requirements and helps consumers verify who they are dealing with. It costs nothing to display and there is no reason to omit it.
Published · Kaspar Eevald
Bluefour – Helsinki digital agency | hello@bluefour.fi | +358 45 850 4236