Nordic Youth Council’s privacy policy 

 22.02.2026  

Ungdomens Nordiska Råd rf. 

General 

This data protection policy describes how and according to which rules the Nordic Youth Council (UNR) handles personal data. The policy contains several privacy statements for the various registers that the UNR maintains in order to carry out its activities. 

Since 1 January 2025, UNR has been a registered association in Finland. The UNR has a secretariat responsible for the administrative and organisational functions of the UNR, and is based in Helsinki. The secretariat has staff who are employed by the Pohjola-Norden Youth Union (PNU) through a cooperation agreement.  The UNR considers itself to be covered by the General Data Protection Regulation (EU 2016/679) and the Finnish Data Protection Act (1050/2018) because the association is based in Finland. 

The UNR processes personal data in accordance with applicable law and good practice. The processing is limited to what is necessary in relation to the specific purpose of the processing. Personal data is any information that can be directly or indirectly linked to a natural living person. Name, address details, nationality, social security number and digital traces may be personal data. The person whose personal data is processed is referred to in legislation as a data subject. 

Member register 

Data controller 

Nordic Youth Council r.f.  
Organisation number: 3494218–6 
Toinen linja 14 
00530 Helsinki 

Data controller and contact person 

Secretary General Helena Hyvönen 
helena.hyvonen@pnn.fi 
+358 447 335 781 

Name of the register 

Nordic Youth Council member register 

Purpose and legal basis for processing personal data   

The main basis for the processing of personal data is the statutory obligation to keep a register of members. The purpose of the register is to collect the personal data required by section 11 of the Associations Act (503/1989) and other information on member organisations that is necessary for the association’s operations. In addition to these grounds, personal data is processed for the realisation of the controller’s legitimate interests.  

The members of the Nordic Youth Council are organisations. However, membership may entail that the UNR indirectly processes personal data, if the contact persons or information of the member organisations are personal. Personal data is processed in order to maintain the Nordic Youth Council’s membership register, to manage the membership relationship, and to be able to organise the activities of the Nordic Youth Council. 

Categories of persons and data content of the register  

The register contains contact details of the UNR’s member organisations. As a rule, the register contains the following information: 

  • Name and contact details (including domicile) of the member organisation 
  • Name, email address and telephone number of the chairperson of the member organisation 
  • Name, email address and telephone number of the executive director or other senior officer of the member organisation, if applicable 

Regular sources of information 

As a rule, the data consist of publicly available data. Additionally, the information in the register may be collected from the member organisations and the data subjects themselves at the beginning of and during their membership. Data subjects can update their data by contacting the controller. 

Regular disclosure of data   

Register data is handled by the controller and is not disclosed to third parties. 

Transfer of data outside the EU or EEA  

The data is stored in the Microsoft SharePoint cloud service, which complies with the requirements of the General Data Protection Regulation (EU 2016/679). Data is not transferred outside the EU or EEA.   

Storage period for personal data  

Personal data is stored for as long as necessary. The data is deleted when it is no longer needed (for example, if the person in charge of the organisation changes) or when the member organisation’s membership ends. 

Principles for the protection of the register  

As the data controller, the Nordic Youth Council is obliged to ensure that the personal data processed by the organisation is adequately protected by means of the necessary technical and organisational security mechanisms. 

The Nordic Youth Council has instructed its staff involved in the processing of personal data on the correct processing of personal data and confidentiality. Personal data is protected from external use and access. 

The Nordic Youth Council and its subcontractors’ computer networks and equipment are protected by firewalls, passwords and other appropriate technical measures. 

Physical copies of materials are avoided. Any such material is stored in a locked space accessible only to authorised persons. 

Rights of the data subject 

The data subject has the right, among other things, to: 

  • receive information about the processing of their personal data 
  • access their data 
  • correct their information 
  • remove their data and be forgotten 
  • restrict the processing of their personal data 
  • object to the processing of their personal data; 
  • to the extent that the processing of personal data is based on the data subject’s consent, the right to withdraw consent at any time without affecting the lawfulness of the processing based on consent before its withdrawal. 

Nordic Council Youth Events and Communication Register 

Data controller 

Nordic Youth Council r.f.  
Organisation number: 3494218–6 
Toinen linja 14 
00530 Helsinki 

Data controller and contact person 

Secretary General Helena Hyvönen 
helena.hyvonen@pnn.fi 
+358 447 335 781 

Administrator of the register 

Creamailer Oy (2255533–0)
Valimotie 13 A
00380 Helsinki 

Name of the register 

Nordic Youth Council Events and Communication Register 

Purpose and legal basis for processing personal data   

Participation in Nordic Youth Council events requires registration. Personal data is processed based on the data subject’s consent in order to handle registrations and contacts in connection with the event. The personal data processed in the register may also be used for communication about events and marketing measures related to the event in question. 

If the data subject does not provide the requested information to complete the event registration, the controller cannot accept the data subject’s registration that would enable participation in the event. 

Categories of persons and data content of the register  

The persons whose data may be processed are participants in events organised by the controller. The register may process data provided by persons who have registered for an event and that is necessary for the implementation of the event. This register information provided by the data subject may include, among other things, the following information: 

  • first and last name 
  • contact information (email address, telephone number, postal address)  
  • member organization  
  • gender  
  • age  
  • allergies, the need for special arrangements (e.g. due to illness, etc.), which are needed for the organisation of the event and for possible first aid situations  
  • information about invoicing, or  
  • other information relevant to the implementation of the event. 

Regular sources of information  

Information that the registrants provide when they register for an event through the Creamailer form or via another similar service. 

Regular disclosure of data  

Register data may be shared within the controller’s organisation and between the event’s stakeholders and external service providers involved in the implementation of the event. Notifications and collection of personal data are done through the Finnish service Creamailer Oy. The company’s privacy policy can be found here. 

Transfer of data outside the EU or EEA  

In addition to Creamailer’s system, the data is also stored in the cloud service Microsoft SharePoint, which complies with the requirements of the General Data Protection Regulation (EU 2016/679).  The data is not transferred outside the EU or EEA.   

Storage period for personal data  

Personal data on events is stored for as long as it is necessary for the organisation of the event, the collection of feedback and invoicing. Personal data required for accounting purposes is stored for the time required by law. All data is deleted when the basis for the processing no longer exists and is no longer needed for the implementation of the event and/or activities. 

Principles for the protection of the register  

As the data controller, the Nordic Youth Council is obliged to ensure that the personal data processed by the organisation is adequately protected.  

The data is kept technically secure. Logging in to the register requires a personal username and password, which means that the personal data is protected from external use and access. Unauthorised access is also prevented, for example, with the help of firewalls and technical protection. Only the controller and specially appointed personnel have access to, the right to process and maintain the data in the register. Registry data is backed up securely and can be restored if necessary.  

If it is necessary to make manual copies of personal data, such as paper lists, they will be handled carefully in accordance with good data management practices. Copies are destroyed immediately when they are no longer needed. Physical access to data is blocked by access control and other security measures. 

Rights of the data subject 

The data subject has the right, among other things, to: 

  • receive information about the processing of their personal data 
  • access their data 
  • correct their information 
  • remove their data and be forgotten 
  • restrict the processing of their personal data 
  • object to the processing of their personal data; 
  • to the extent that the processing of personal data is based on the data subject’s consent, the right to withdraw consent at any time without affecting the lawfulness of the processing based on consent before its withdrawal. 

 

Contact information 

Nordic Youth Council r.f.  
Organisation number: 3494218–6 
Toinen linja 14 
00530 Helsinki 

Questions about the privacy statement should be directed to unr@unginorden.org. The UNR has the right to change its data protection policy by updating this page.