TL;DR for the DPO
Customer data was kept until the customer themselves asked for deletion. And because buying online required creating an account, individual purchase data was kept longer than necessary too. Storage limitation is an obligation on the controller, not an option to be delegated to the data subject's initiative.
The two failings, and both are mundane
The first: retention periods for customer account data had not been defined. They were not wrong, they did not exist. Data stayed until someone asked for it to be deleted, that is, potentially forever. Art. 5(1)(e) requires the opposite: that the controller determine in advance how long the data is needed, and that it be erased or anonymised when that period expires.
The second: buying on the site required creating an account. That apparently commercial choice has a precise legal effect: it pulls individual purchase data inside the perimeter of the account, and makes it live as long as the account does. Had guest checkout been possible, retention of purchase data would have been governed by tax and warranty rules, which have an end date.
The path, and why the reduction is not a win
- March 2024: the Finnish DPA's sanctions board imposes EUR 856,000.
- The Administrative Court reduces the amount to EUR 792,639, not because the infringement was less serious but because the cap must be calculated on the most recent turnover. It is a recalculation, not a softening of the finding.
- 12 June 2026: the Supreme Administrative Court dismisses the appeal and does not amend the lower court's decision.
The contrast with last week's Dutch case
On 29 July the Dutch Council of State annulled an authority's fine because the investigation did not hold up. Here a Supreme Court upholds everything. The difference is not judicial severity: it is what the authority had to prove. In the Netherlands it had to establish that MAC addresses were personal data, and it stumbled there. In Finland it was enough to observe that a retention period had never been written down. Documentary findings survive litigation because there is nothing to interpret.
What to do now, across your clients
Four checks, half an hour of work
1) In the Art. 30 records, run down the retention column: every cell that says 'until withdrawal', 'as long as necessary' or is blank is precisely the Finnish finding. 2) Ask your e-commerce client whether one can buy without registering: if not, the account becomes the container that extends the life of everything else. 3) Check that deletion at expiry is automatic, not a manual procedure nobody performs. 4) Write down the criterion, not just the number: '10 years from the last purchase, under the Civil Code' is defensible, '10 years' on its own is not.
Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free