Finland's constitutional structure is younger than Sweden's but unusually well-drafted for the digital era. The current Suomen perustuslaki (Constitution of Finland, 731/1999) consolidated four older constitutional acts into a single document and entered into force on 1 March 2000. Section 12, "Freedom of expression and right of access to information," is the clause that reaches a hosting provider. It is short, precise and pairs two things that European constitutional drafting usually keeps apart: the negative right of expression (paragraph 1) and the positive right of access to public information (paragraph 2).
Paragraph 1 guarantees the right to express, disseminate and receive information, opinions and other communications "without prior prevention by anyone." The phrase is doctrinally important — it is read as a constitutional prohibition on prior restraint, including by private intermediaries acting under state pressure. Paragraph 2 reverses the default for public bodies: documents and recordings held by authorities are public unless restriction has been specifically and compellingly ordered by Act of Parliament. The two paragraphs together create a constitutional baseline that is consistently described as one of the most expression-friendly in Europe.
Sananvapauslaki (Act on the Exercise of Freedom of Expression in Mass Media, 460/2003) is the implementing statute. Section 16 is the headline clause for an infrastructure operator: a publisher, an editor, or any person who has participated in the preparation of a publication has the right to refuse to disclose the identity of a source, and the right to refuse to disclose any information that would reveal that identity. Finnish legal scholarship reads § 16 as creating a positive duty to refuse — not a privilege the witness can choose to waive — with narrower enumerated exceptions than the Swedish TF Chapter 3 equivalent. In comparative law it is routinely cited as the strongest source-protection statute in the European Union.
Around the constitutional and statutory core sits an unusually mature data-protection apparatus. Finland was an early adopter of the GDPR national legislation (Tietosuojalaki, 1050/2018) and the Tietosuojavaltuutettu — the Data Protection Ombudsman — sits alongside a five-member sanctions board (seuraamuslautakunta) that issues administrative fines. Recent enforcement targets include telecommunications retention, biometric overreach in retail, and consent dark-patterns. For a hosting customer this means Article 5 minimisation and Article 17 erasure are backed by a regulator with documented willingness to fine.
