Data protection and information security policy of Pihlajalinna Group
Updated 22 March 2023
This document specifies the goals, organisation, liabilities and implementation of Pihlajalinna Group’s data protection and information security policy. The policy is complemented by other approved plans and guidelines.
Pihlajalinna values and protects the privacy of all its stakeholders, as patient data related to health services and client data related to social services are subject to specific legislation. As a provider of social or health services, Pihlajalinna operates according to high-level security practices, including comprehensive log monitoring, 24/7 supervision of the IT environment, and constant improvement of information security.
Pihlajalinna complies with the EU General Data Protection Regulation, the Data Protection Act and the guidelines of the data protection authorities in all processing of personal data.
Each employee and information system user at Pihlajalinna must be familiar with this policy and comply with the instructions and regulations issued based on the policy.
The objectives of work related to data protection and information security include
Data protection and information security is managed and monitored by the CEO of Pihlajalinna. The CEO decides the development objectives, organisation, resources and operating authorisations of the various sections of overall safety and security.
The Medical Director of Pihlajalinna acts as the supervisor of data protection and appoints the data protection officers. The Head of ICT is responsible for information security and appoints the supervisor of information security and the information security officer.
The views of Pihlajalinna’s key operations are represented by a data protection and information security team appointed by the supervisors of data protection and information security. The data protection and information security team processes any policies and instructions before they are presented to the management for approval. The data protection and information security team includes at least the supervisors of data protection and information security, data protection officers, and an information security officer.
Data protection and information security complying with the approved data protection and information security policy must be integrated into all operations. The development and maintenance of data protection and information security are a part of Pihlajalinna Group’s and the group company’s security-related operations, risk management and internal monitoring.