top of page

Electronic direct marketing is a key part of sales and customer communications for many companies. However, newsletters, promotional emails and marketing automation only work when there is also a valid legal basis for sending them. Recently, automated marketing calls have attracted particular attention in supervisory practice. In practice, a company should answer three questions before sending a message: who is the recipient, does the message constitute marketing or customer communication, and what is the legal basis for sending it? Electronic direct marketing includes emails, text messages, multimedia messages, voice messages and automated calls used to market products or services to the recipient. The format of the message is not decisive. What matters is its purpose and content. If the objective is to promote the sale of a product or service, the message will generally constitute direct marketing.


A newsletter will usually constitute direct marketing if it contains offers, presentations of services, invitations to events, campaigns or other content intended to promote sales. Even content that appears purely informative may constitute marketing if its main purpose is to encourage the recipient to make a purchase, book a demonstration, download sales materials or attend a commercial event.

However, not every message sent to customers constitutes direct marketing. Order confirmations, delivery notifications, service interruption notices and other messages relating to the performance of a contract or the provision of a service are generally considered customer communications. If sales-oriented content is added to the message, it may nevertheless become direct marketing. For example, adding an offer to “upgrade to the premium version” to a service interruption notice may change how the message is assessed.


Marketing to a personal address generally requires prior consent


As a general rule, electronic direct marketing may only be sent to a natural person if they have given their prior consent. This is the main rule for electronic direct marketing aimed at consumers. The same applies, for example, to automated calling systems. Marketing through automated calls requires the recipient’s prior consent.


Consent must be freely given, specific, informed and unambiguous. In practice, the recipient must take an active step themselves, such as ticking a box to subscribe to a newsletter. A pre-ticked box, silence or the fact that the individual has not specifically objected to marketing does not constitute valid consent.


The requirement that consent be freely given does not necessarily prevent direct marketing consent from being linked to participation in a voluntary prize draw. The Finnish Data Protection Ombudsman has considered that consent to direct marketing requested as a condition for participating in a prize draw may be valid if participation is genuinely voluntary, choosing not to participate causes no detriment and the prize draw is not connected to a service that is essential to the data subject. However, the assessment must always be made on a case-by-case basis.


Separate consent is not always required. If a customer has purchased a product or service from a company and provided their electronic contact details in connection with the purchase, the company may, subject to certain conditions, market its own similar products or services to that customer.

However, this exception cannot be treated as a general authorisation for all marketing. It requires that the contact details were obtained directly from the customer in connection with a sale, that the marketing concerns the same company’s own products or services, and that the products or services being marketed are similar to the customer’s previous purchase. For example, if a customer has purchased a particular software service, it may, depending on the circumstances, be permissible to market additional features within the same service package or other similar services to them. The same contact details do not, however, permit the marketing of services offered by an entirely different group company, products offered by a business partner or products belonging to a completely different category.


The customer must also be given an easy and free opportunity to object to marketing both when their contact details are collected and in every subsequent marketing message.


In B2B marketing, it is not enough that the recipient works for a company


In business-to-business marketing, the assessment depends on the type of address to which the message is sent and the recipient’s role. As a general rule, electronic direct marketing may be sent without prior consent to general company addresses, such as info@company.com or sales@company.com. However, the message must still provide an opportunity to object to further marketing.


If the message is sent to a named individual, such as firstname.lastname@company.com, the sender must assess whether the product or service being marketed is materially related to the recipient’s professional duties. For example, marketing financial administration services to a person responsible for financial decision-making may be justified. The same message cannot, however, be sent as a precaution to every individual whose contact details can be found at the company.


The essential point is that the recipient’s role and the content being marketed must correspond with one another. A mere assumption that the recipient might be interested is not enough. In B2B marketing, it is also important to remember that a personal work email address does not become a freely available marketing channel simply because the address is publicly available or can be found on LinkedIn, a website or an event participant list. The sender must still be able to explain why the message sent to that particular person relates to their professional duties and why the marketing has been appropriately targeted.


Companies must be able to demonstrate consent


A company must be able to demonstrate the basis on which it sends electronic direct marketing. If the marketing is based on consent, the documentation should indicate at least when the consent was given, through which channel it was given, the type of marketing to which it applies and the information provided to the recipient when consent was requested.


Every electronic direct marketing message must include an easy and free method of objecting to the marketing or withdrawing consent, such as a functioning unsubscribe link. Withdrawing consent must be as easy as giving it. In practice, recipients should not be required to contact customer service separately or log in to a complicated system merely to unsubscribe from a newsletter.


Electronic direct marketing usually involves the processing of personal data, which means that the requirements of the General Data Protection Regulation also apply. The recipient must therefore be clearly informed about how their personal data is processed.


In practice, a company should ensure that its privacy notice explains who processes the personal data, the purposes for which the data is used, the legal basis for the processing, the source of the data, how long the data is retained and how the recipient can exercise their rights.


The regulation of electronic direct marketing does not prevent effective marketing, but it does require companies to handle the fundamentals carefully. Before launching a campaign, a company should verify where the recipients’ contact details came from, the legal basis for sending the messages and how marketing objections and withdrawals are implemented in practice.


Hymyilevä nainen valkoisessa paidassa nojaa tiiliseinään, kädet ristissä.


Lila Kallio

Counsel

+358 41 465 1365








To receive our articles directly in your inbox, subscribe to the Folks newsletter here.

AI tools are developing at a remarkable pace. Not long ago, an AI-generated image was easy to recognise, but today, the best AI-generated images are so convincing that they can be indistinguishable from genuine photographs. AI can also be used to produce text, audio and video, offering creative industry professionals significant opportunities to accelerate content production and develop new forms of expression.


At the same time, the use of AI raises numerous legal questions. In this blog post, I discuss the legal considerations that companies operating in the creative industries should take into account before introducing AI tools and using them as part of their creative work.


Who owns AI-assisted content, and how can it be protected?


A key question is whether the creator obtains an exclusive right to use and license material produced with the assistance of AI, or whether the result remains freely available for anyone to use. There is no straightforward answer, as it depends on the extent of the human creator’s own creative contribution to the work.


Copyright belongs to the person who creates a work, provided that the work is sufficiently independent and original. Copyright protection always requires a creative contribution by a human, and the assessment is made on a case-by-case basis. Copyright never protects an idea as such, but only the specific form in which the idea is expressed.


When a creative professional uses AI as a tool in their work, the existence of copyright is assessed according to these same principles. Copyright does not arise where a person gives the AI only a general instruction and the AI produces the final content entirely without any creative contribution from the user.


The situation is different if AI is used as part of a broader creative process. If the creator uses AI, for example, to support brainstorming, then creates the content themselves and uses AI only for final refinements, the work is likely to contain enough of the creator’s own creative contribution to qualify for copyright protection.


The use of AI should also be documented in case of potential disputes. Retaining the creator’s own drafts and the prompts used can make it easier to demonstrate which parts of the final result are based on human creative work.


If content is created using generative AI and the result does not qualify for copyright protection, protection may in some cases also be sought through trademarks. For example, Moomin Characters has protected Moomin characters as trademarks. However, it is important to note that a trademark only provides protection in specified classes of goods and services and within a particular geographical area. It does not protect the creative content as such. Its scope and purpose therefore differ from those of copyright protection.


If a creative project involving extensive use of generative AI is being planned, trademark protection may nevertheless be worth considering alongside copyright as a complementary form of protection.


Can AI-generated material be used freely?


Material created with AI is not automatically free from third-party rights. The key questions are which AI service was used to produce the material and how liability has been allocated in the service’s terms of use.


Some AI services use only licensed training data or other material that is not protected by copyright and contractually assume responsibility for ensuring that the materials generated by the AI do not infringe third-party copyrights. In such cases, the service provider bears responsibility for the output to the extent agreed in the terms of use, and the user’s legal risk is substantially lower.

Many widely used services, however, have been trained on extensive datasets collected from the internet, which may also contain copyright-protected material. In most services, the service provider does not contractually assume responsibility for ensuring that the generated content does not infringe third-party rights. Instead, responsibility for using the content remains with the user. Material produced using such services therefore requires careful review before publication.


In summary, there is no universally applicable answer as to whether AI-generated materials may be used freely. The allocation of responsibility depends primarily on the service used and its terms of use, which should be reviewed before AI is introduced as part of content production.


Can confidential information be entered into an AI service?

As a general rule, confidential information should not be entered into an AI service unless the service is specifically intended for business use and its terms and information security have been carefully assessed.


For business purposes, companies should use business or enterprise versions of generative AI services unless they operate a local AI solution on their own servers. In consumer services, such as the free and Plus versions of ChatGPT, materials and prompts entered into the service may, in accordance with the terms of use, be used to train the AI model. In addition, the service provider may reserve broad rights to use and even share material uploaded by users for purposes other than AI model training.

This means that if a company’s employees use consumer licences in their work, they may compromise the confidentiality of information by entering confidential material into the service.


The practical risk may arise, for example, where a screenwriter or copywriter uses a free consumer AI service to refine a text and enters an unpublished script or campaign concept into the service. Under consumer licences, the content may be used to develop AI models, meaning that the material is no longer under the company’s exclusive control. Even if the content does not appear elsewhere in an identical form, there is a risk that recognisable features of the material may be used as part of outputs generated for other users.


It is also important to note that other risks do not disappear even if the use of content for training purposes can be prohibited separately in the service settings or terms of use. Under consumer licences, service providers often do not provide binding guarantees regarding the security of the service. Information entered into the service may therefore be exposed to data breaches or other information security incidents. Protecting confidential information requires selecting a licence suitable for business use and assessing the service’s terms and information security before introducing the AI service.


Can personal data be entered into an AI service?


If personal data, such as a person’s image, voice or name, is entered into an AI service, the General Data Protection Regulation, or GDPR, applies.


The company is responsible for ensuring that the licensing terms of the AI service have been carefully assessed. As part of its compliance with the GDPR, the company must ensure, among other things, that material uploaded to the service is not used to train the AI, that it is possible to enter into the data processing agreement required by the GDPR with the service provider, and that the AI service provides appropriate security for the protection of personal data. In practice, the use of an AI service will generally also require a data protection impact assessment.


The use of AI services under free consumer licences will generally not comply with the GDPR, as service providers often also use uploaded material for their own purposes.


Is it permissible to use AI to generate images or voices of real people?


Particular attention is also required where AI is used to produce images of real people or to create AI-generated copies of a real person’s voice. A person’s image, voice and other identifying features constitute personal data. AI-generated material may also be considered personal data if a specific individual can be identified from it. In such cases, all GDPR requirements apply, including the requirement to inform the individual about the processing of their personal data and the requirement to have a lawful basis for the processing.


In content production, it is also important to recognise that using a person’s image or voice for commercial purposes requires that person’s consent. In 2025, the Helsinki Court of Appeal ordered an underwear company to pay Jasper Pääkkönen EUR 300,000 in compensation for the unauthorised use of his name, image and voice in an extensive advertising campaign. The judgment is not yet final, and the Supreme Court has granted leave to appeal. The obligation to obtain consent also applies where the person’s image or voice has been generated using AI.


When must AI-generated content be labelled as a deepfake?


The EU’s new AI Act introduces transparency requirements concerning deepfakes. The Act will become applicable gradually, and the provisions concerning deepfakes will apply from 2 August 2026.

Deepfakes are AI-generated or AI-manipulated image, audio or video content that resembles existing people, objects, places, entities or events and may falsely appear to the recipient to be authentic or truthful. The transparency obligation is therefore not limited to deepfakes depicting people.

Under the AI Act, deepfakes must be clearly labelled as having been artificially generated or manipulated. However, the Act includes an exception for creative works. Where the content forms part of an evidently artistic, creative, satirical, fictional or similar work or programme, the disclosure may be made in a manner that does not interfere with the display or enjoyment of the work.


For example, a documentary-style television production may use highly realistic AI-generated images or videos to illustrate historical events. If the context does not otherwise indicate that the material is artificial, viewers may believe it to be genuine archival footage. In such a case, the transparency obligation under the AI Act must generally be considered. However, the exception for creative works allows the use of AI to be disclosed in a manner appropriate to the nature of the work, for example in the programme’s end credits, provided that the audience is not left with a false impression of the authenticity of the content.


A breach of the transparency obligation concerning deepfakes may result in an administrative fine under the AI Act.


Checklist for creative industry professionals

Rights: ensure that your own creative contribution is sufficient if you want the final result to qualify for copyright protection.


  • Documentation: document the use of AI and your own creative contribution.

  • Terms of use: review the service terms and determine what rights you receive to the generated content and who is responsible for potential infringements.

  • Business-level licences: only use business-level licences for professional purposes and enter into a data processing agreement where necessary.

  • GDPR and consent: using a person’s image or voice requires compliance with data protection rules and, for commercial use, the person’s consent.

  • Deepfakes: if content has been artificially generated or manipulated, ensure that the disclosure requirements of the AI Act are met.


Would you like to discuss the legal questions surrounding AI? We help companies assess the legal risks and opportunities associated with the use of AI in the creative industries and in other AI-enabled business operations.


Nainen valkoisessa paidassa hymyilee, seisoo tiiliseinää vasten. Taustalla punainen tiilikuviollinen seinä. Folksin Counsel Lila Kallio

Lila Kallio Counsel

+358 41 465 1365









Nainen valkoisessa paidassa hymyilee urbanistisen tiiliseinän edessä. Hänellä on pitkät ruskeat hiukset. Tausta on rosoinen. Folksin counsel Katri Aarnio

Katri Aarnio Counsel

+358 50 306 2031








To receive our articles directly in your inbox, subscribe to the Folks newsletter here.

The EU Data Act became applicable on 12 September 2025 and introduced new obligations aimed at making it easier for customers to switch service providers. The objective is to prevent so-called vendor lock-in and require cloud service providers to compete on service quality and pricing, rather than allowing customers to become tied to a service because of technical or contractual barriers.


The Data Act requires cloud service providers to enable customers to switch services with a notice period of no more than two months. The rules apply to services including IaaS, PaaS and SaaS.


However, the reform directly affects the core of many SaaS companies’ business models. Many SaaS services are sold under fixed-term agreements, often for one year or several years, and the business model is based on annual recurring revenue, or ARR. Service providers typically offer a lower monthly price to customers who commit to annual billing. The possibility of switching service providers during the contractual term under the Data Act therefore raises questions about the binding nature of fixed-term agreements.


Does the Data Act allow a fixed-term SaaS agreement to be terminated during the contractual term?


The Data Act does not create a general, entirely unrestricted and consequence-free right of termination in all circumstances. It does, however, give customers the right to switch service providers or move to their own solution with a notice period of no more than two months, and generally a transition period of one month, at limited cost. This applies even during the term of a fixed-term agreement where the cloud service falls within the scope of the Data Act. In practice, the outcome comes very close to a “free right of termination” in the situation that matters most to the customer, namely when the customer wishes to switch providers and take its data with it.


During the switching process, the previous service provider must continue providing the service and assist with the transfer of data. Once the switching process has been completed, the agreement and the customer’s payment obligation come to an end. The agreement will therefore generally end three months after the customer gives notice of its intention to switch, as the notice period is two months and the transition period is usually one month.


Can a SaaS provider charge for early termination or assistance with the switching process?


The Data Act permits two types of charges that a service provider may, to a limited extent, impose in connection with the switching process: switching charges and early termination penalties under fixed-term agreements.


During the transitional period ending on 12 January 2027, the Data Act allows service providers to charge fees for switching services where those fees are based on direct and demonstrable costs. After 12 January 2027, switching charges will be prohibited altogether. Customers may not be charged for transferring their data to another cloud service or to their own environment to the extent that the transfer falls within the minimum obligations imposed by the Data Act. Even after the transitional period, customers may purchase additional services that go beyond the minimum obligations, and the service provider may charge for those services where they are provided at the customer’s request and the customer has accepted the price in advance.


The Data Act also allows a SaaS provider to include a “proportionate” penalty in the agreement for terminating a fixed-term agreement before the end of its contractual term. The customer must be informed of such a penalty before the agreement is concluded.


The Data Act does not define what “proportionate” means. In practice, however, the penalty must be proportionate to the actual costs incurred by the service provider, such as investments made on the basis of the agreed contractual term or expenditure relating to the implementation of the service. The penalty may not be used as a concealed switching charge or as a means of preventing switching by making it financially difficult.


From the provider’s perspective, it is therefore necessary to consider which costs arise specifically because the agreement ends earlier than expected. The provider must also assess whether the penalty has been calculated on the basis of those costs or whether its actual purpose is to keep the customer tied to the service. If the latter is the case, the arrangement is likely to be risky under the Data Act.


What contractual obligations does the Data Act impose on SaaS providers?


The Data Act requires SaaS providers to include contractual terms concerning the switching of services in their service agreements. When updating their agreements, SaaS providers may choose to use the model contractual terms published by the European Commission on 19 November 2025. The use of the model terms is voluntary, and the Commission’s objective is to help parties comply with the Data Act in a consistent manner.


It should also be noted that on 19 November 2025, the Commission published its Digital Omnibus proposal, which would introduce lighter cloud switching obligations for small service providers and customised services. The proposed relief would apply to agreements concluded before 12 September 2025. At this stage, it is only a Commission proposal, and its final content may still change.


What should companies do now?


  • Service agreements should be updated to include the contractual terms concerning switching service providers required by the Data Act.


  • SaaS providers should consider whether their service agreements should include a penalty for the early termination of a fixed-term agreement.


  • In the longer term, providers should reconsider their business models in anticipation of customers being able to switch to competitors more easily and at a lower cost. From the SaaS provider’s perspective, the focus of revenue generation will increasingly shift towards the value of the service, customer experience and continuous customer satisfaction.


We have familiarised ourselves with the requirements of the Data Act and assisted SaaS providers in updating their contractual terms accordingly. Should you require advice or practical assistance in updating your own terms or exercising the right to switch services, our contracts team is ready to help.


Folksin Counsel Lila Kallio seisoo valkoisessa paidassa hymyilee ja seisoo ruskeaa tiiliseinää vasten. Aurinkoinen ja rento tunnelma.


Lila Kallio Counsel lila.kallio@legalfolks.fi

+358 41 465 1365









To receive our articles directly by email, subscribe to the Folks newsletter here.

bottom of page