User Rights to Their Personal Data

Rights of the registered person regarding personal data processed and stored by Navigora

This document describes the rights of a person registered in Navigora online service and how the registered person can exercise these rights.

How does the registered person obtain information about the collection and processing of personal data?

The controller (Navigora Oy) is obliged to provide the registered person with information about the processing of personal data. We have compiled instructions in this document on the rights under the Data Protection Regulation and how the registered person can exercise these rights.

The registered person has the right to access their own data

A person has the right to obtain information from the controller, upon request, whether their personal data is being processed in the register. If personal data is processed, the data subject has the right to access their data in accordance with the General Data Protection Regulation/Credit Information Act:

  • The basis for the purpose and lawfulness of the data processing

  • Descriptions of the data content of the personal data groups, recipients and retention periods

The controller must provide a copy of the personal data processed

When exercising the right of inspection under the Finnish Credit Information Act or the General Data Protection Regulation, the data subject must prove their identity either in connection with a personal visit or by attaching a certified photocopy or scanned document of an official identity document to their written request. In this case, the person will be provided with the information provided for in Section 30 of the Credit Information Act and, after any additional information (e.g. employer information), information from other registers. Information from different registers must be requested separately.

Registers containing data that identifies a registered person:

  • Company responsible persons

  • Contact person information in Navigora customer register

  • Navigora’s own employee information (including personal identification number)


Registers requiring additional information:

  • User administration personal data (personal data of registered users of the business information service)

  • Decision-maker information in the business information service

  • Navigora’s marketing database

The right of the registered person to object to the processing of personal data

The registered person has the right, on grounds relating to his or her particular situation, to object to the processing of personal data concerning him or her (General Data Protection Regulation, Article 21) when the processing is based on the performance of a task carried out in the public interest or the pursuit of legitimate interests.

In Navigora online service, this may apply to the processing of data of the responsible persons of companies. Since the processing of this data is regulated by law (Finnish Credit Information Act and Data Protection Act), there cannot usually be a situation where there is a personal reason that would prevent the processing.

If personal data are processed for direct marketing purposes, the data subject shall have the right to object at any time to the processing of personal data concerning him or her for such marketing.

The data subject’s right to rectification of personal data, restriction of processing and right to be forgotten (erasure)

The data subject shall have the right to obtain from the controller without undue delay the rectification of inaccurate and incorrect personal data concerning him or her. Taking into account the purposes of the processing, the data subject shall have the right to have incomplete personal data completed, for example by means of additional information.

Rectification of personal data

The data subject shall have the right to obtain from the controller the rectification of inaccurate and incorrect personal data concerning him or her without undue delay.

Restriction of processing of personal data

The data subject has the right to obtain from the controller restriction of processing where one of the following four grounds applies:

  • The accuracy of the personal data is contested by the data subject. In such a case, the processing shall be restricted for a period of time during which the data subject may verify the accuracy of the personal data.

  • The processing is unlawful, but the data subject opposes the erasure of the personal data and requests the restriction of their use instead.

  • The data subject no longer needs the personal data for the purposes of the processing, but the data subject requires them for the establishment, exercise or defence of legal claims.

  • The data subject has objected to the processing of the personal data for purposes other than direct marketing, pending verification of whether the interests of the data subject override those of the data subject.


If processing is restricted, the data may be stored, but their processing is only permitted in specified cases. Such cases include, for example, the consent of the data subject, the establishment, exercise or defence of legal claims, and the protection of the rights of another natural or legal person.

According to Article 18(2) of the GDPR, data may be processed for reasons of public interest, despite the restriction requirement.

Right to erasure (‘right to be forgotten’)

The data subject has the right to obtain from the controller the erasure of personal data concerning him or her without undue delay where one of the following six grounds for erasure applies:

  • the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed

  • the data subject withdraws consent on which the processing is based and there is no other legitimate ground for the processing

  • the data subject objects to the processing of his or her personal data for direct marketing purposes or otherwise exercises his or her right to object and there are no other legitimate grounds for the processing

  • the personal data have been processed unlawfully

  • the personal data must be erased for compliance with a legal obligation to which the controller is subject under Union law or the law of a Member State

  • the personal data have been collected in the context of the provision of information society services.

However, the right to erasure does not apply if the processing is necessary, for example, for the performance of a task carried out in the public interest.

Notification of rectification, erasure and restriction of processing of personal data to recipients

The controller shall notify any rectification, erasure or restriction of processing of personal data to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort. The controller shall inform the data subject of these recipients if the data subject so requests.

Navigora is not obliged to keep a log file of all disclosures of personal data (disclosures of data of the responsible party, disclosures of decision-making information). Notification of rectification, erasure and restriction of processing of such data is therefore impossible.

How are data subjects informed of data breaches?

Where a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall notify the data breach as follows:

  • Individual Notification to data subjects without undue delay.

  • Notification to the supervisory authority without undue delay and, where possible, within 72 hours of becoming aware of it. The notification shall be made in accordance with Article 55, except in situations where the personal data breach is unlikely to result in a risk to the rights or freedoms. If the notification is not made within 72 hours, the controller shall provide the supervisory authority with a reasoned explanation.

  • The processor shall notify the personal data breach to the controller without undue delay after having become aware of it.


The notification shall include at least:

  • a description of the personal data breach. Where possible, it shall also include information on the categories and estimated numbers of data subjects concerned and the categories and estimated numbers of personal data types;

  • provide the name and contact details of the data protection officer or another point of contact from which further information can be obtained

  • describe the likely consequences of the personal data breach

  • describe the measures proposed or taken by the controller in response to the personal data breach and, where appropriate, the measures to mitigate any adverse effects.

The controller shall document all personal data breaches, including the circumstances surrounding the personal data breach, its effects and the corrective actions taken.

The supervisory authority shall be able to verify that this has been done by means of this documentation.

The data subject’s right to transfer the personal data he or she has provided to the controller.

The data subject shall have the right to receive the personal data concerning him or her which he or she has provided to the controller. This data shall be provided in a structured, commonly used and machine-readable format. The data subject shall have the right to transfer that data to another controller.

This right is available to individuals when the processing is based on consent or agreement and the processing is carried out automatically.

This right to transfer data from one system to another does not apply at all to, for example, data on company managers or decision-makers, because the processing of this data is not based on agreement or consent, but on other processing grounds.

In Navigora online service, such personal data includes customer information obtained from the customers of the business information service themselves and purchase transactions regarding services.

The right of the registered person to file a complaint with the supervisory authority, initiate legal action and receive compensation for the damage caused

Every registered person has the right to file a complaint with the supervisory authority (in Finland, the Data Protection Ombudsman) if the registered person considers that the processing of personal data concerning him or her violates the Regulation.

Furthermore, the data subject has the right to an effective remedy if he or she considers that his or her rights under the GDPR have been infringed because the processing of his or her personal data has not been in accordance with the GDPR.

If a person suffers material or non-material damage as a result of a breach of the GDPR, he or she has the right to receive compensation for the damage suffered from the controller or processor.