FI | EN

Confidentiality and information privacy


Confidentiality is a requirement and prerequisite for incident handling.

Funet CERT will only pass on information related to the incident if the reporting party has given its consent or it is required by the Finnish legislation.

In certain circumstances Funet CERT will pass on publicly undisclosed vulnerability information to predefined security personnel in customer organizations. In such cases, Funet CERT specifically requires that the information is not passed on before public disclosure of the vulnerability.


Encryption of confidential communications

In case you wish to send confidential information to Funet CERT via e-mail, you should always send it encrypted to prevent third parties from reading the mail in transit. Funet CERT uses PGP-encryption for confidential messaging.

To send Funet CERT an encrypted message, you need to encrypt it with Funet CERT's public PGP key. Teams public key has been signed by the Trusted Introducer Services  master signing key.

If you wish to send confidential information to Funet CERT and you do not have PGP available or you have other problems with email, then contact us by phone .

If Funet CERT provides you with information pertaining to an incident, please handle it with due caution, especially if the data contains identity information or information about an ongoing security breach. Confidential information should always be stored encrypted on a secure server.

If you are a victim of an information security breach or some other serious incident, you should and in certain cases you are required by the law to report it also to NCSC-FI.


Data protection

Data protection deals with the integrity and protection of an individual's privacy and identity. Data protection is a part of information security. Investigation of information security breaches poses a challenge, since even when investigating an incident, the involved parties have their rights to privacy.

Finnish legislation protects an individual with a strong right to privacy. Privacy is safeguarded in the constitution, in addition there are number of laws pertaining to data protection.

Implementation and follow-up of data protection in Finland is responsibility of the Data Protection Ombudsman.



CSC - IT Center for Science Ltd.

  • No labels