# KHO upholds cookie consent violation ruling; no CJEU referral needed for web requests

- Type: Case Law
- Source: Supreme Administrative Court
- Date: 2026-08-27
- Original: https://gdprhub.eu/index.php?title=KHO_-_KHO:2026:64
- Canonical: https://overview.legal/posts/353646

## Summary

Facts — A media company that provides news services did not request user context for the placement and use of cookies or certain web requests on several websites it managed. In June 2023, the Finnish Transport and Communications Agency issued a decision where it found that the company had violated Section 205(1) of the Finnish Act on Electronic Communications Services (917/2014), a provision implementing Article 5(3) of the ePrivacy Directive 2002/58/EC. The agency held that consent was required for both the cookies and the web requests, as these were not necessary within the meaning of the infringed provision. The company appealed the decision of the agency to an administrative court, which dismissed the appeal. Following this, the company appealed the decision of the administrative court to the Supreme Administrative Court. In addition, the company requested the Supreme Administrative Court to refer the case to the CJEU for a preliminary ruling on the interpretation of Article 5(3) ePrivacy Directive to clarify whether the provision also applies to web requests. Holding — The court dismissed the controller's appeal and stated that there were no grounds to amend the decision of the administrative court. First, the court held that there was no need to refer the case to the CJEU for a preliminary ruling – it considered the interpretation of the ePrivacy Directive to be sufficiently clear. Second, the court came to the same conclusion as the previous instances regarding the placement and use of cookies on the company's websites. The court held that the company had violated Section 205(1) of the Act on Electronic Communications Services, as the use of cookies was not necessary for the company within the meaning of Section 205(2). Moreover, the court interpreted the exception in Section 205(2) narrowly and pointed out that the wording of Article 5(3) ePrivacy Directive indicates that the threshold for applying the exception is intended to be quite high. A different assessment could not be supported by considerations related to freedom of speech or the role of pluralistic and independent media either. Finally, the court held that the company should also have obtained users’ consent for the web requests. A web request of this kind allows the recipient to create a user identifier as well as to gain access to e.g. the user’s IP address, browser information, and cookie data. According to the court, these web requests therefore constitute the gaining of access to information stored in the terminal equipment of a user within the meaning of Article 5(3) ePrivacy Directive. The court argued web requests could not be considered to fall outside the scope of the provision simply because their technical operating principles differ from those of cookies.

## Full text

The Supreme Administrative Court had to decide whether a media company that provided news services could be required to make cookies related to the personalized delivery of news content on its websites subject to consent. As a general rule, the storage of cookies or other data describing the use of the service on a user’s device, and the use of such data, required the user’s consent and appropriate notification. The threshold for deviating from the general rule was intended to be high, and no grounds for such a deviation were found in this case. The matter did not warrant a different assessment based on considerations related to freedom of speech or the role of the media. Freedom of speech did not, in and of itself, imply that a news service provider should be permitted to collect and use information pertaining to the private lives of users of its websites. Nor did the imposed obligation interfere with the pluralistic and independent media services guaranteed by law, nor with the free flow of reliable information, nor did the obligation restrict the company’s right to decide what content it publishes and when. Nor did the obligation prevent the provision of journalistic content in a personalized manner based on the user’s consent and the provision of information. The case also raised the question of whether the provision regarding user consent applied not only to cookies but also to certain online invitations. Section 205(1) and (2) and Section 330 of the Act on Electronic Communications Services Directive 2002/58/EC of the European Parliament and of the Council concerning the processing of personal data and the protection of privacy in the electronic communications sector, as amended by Directive 2009/136/EC (Electronic Communications Data Protection Directive), Article 1(1) and Article 5(3) Decision Subject to Appeal Helsinki Administrative Court, October 9, 2024, No. 5845/2024 Decision of the Supreme Administrative Court 1. The Supreme Administrative Court grants Sanoma Media Finland Oy leave to appeal insofar as the matter concerns making personalization and delivery cookies, as well as web beacons, subject to consent, and will examine the case in these respects. The requests for an oral hearing and for a preliminary ruling from the Court of Justice of the European Union are denied. The appeal is dismissed. The final outcome of the Administrative Court’s decision remains unchanged. 2. The application for leave to appeal is dismissed in all other respects. The Supreme Administrative Court therefore does not rule on the appeal in these respects. 3. Sanoma Media Finland Oy’s claim for reimbursement of legal costs is dismissed. Background of the Case In its decision of June 8, 2023, the Finnish Transport and Communications Agency found that Sanoma Media Finland Oy (hereinafter also “Sanoma”) had violated Section 205(1) of the Act on Electronic Communications Services (the Communications Services Act). The decision was based, among other things, on the fact that that several websites managed by the company do not request user consent regarding the placement and use of cookies related to the personalized delivery of digital news service content and delivery analytics cookies, nor do they request user consent as referred to in Section 205 of the Communications Services Actas defined in Section 205 of the Communications Services Act, even though they are not necessary in the manner intended by the provision. Pursuant to Section 330(1) of the Communications Services Act, the Finnish Transport and Communications Agency has required Sanoma to make the non-essential cookies referred to in the decision—which are used on its websites— as well as technologies that utilize the browser’s local storage and web beacons, to require user consent. The Administrative Court has dismissed Sanoma’s appeal. According to the Administrative Court, the personalization and delivery cookies used by Sanoma may improve the user experience on news websites. However, this is not a service that the user has specifically requested. It is not a necessary condition for the operation of websites and the provision of services that the websites be personalized based on users’ previous interests or that information about users’ activities be collected for this or any other purpose. Simply visiting a particular website does not imply acceptance of such cookies and, therefore, does not mean that the user has explicitly requested a personalized service that tracks the user’s activity. Nor should these cookies be considered necessary on the grounds that, for example, the digital services of Helsingin Sanomat or Ilta-Sanomat would not function in accordance with the objectives set by the editorial staff without them, according to Sanoma. The use of cookies would therefore have required the user’s consent. The Administrative Court has noted that the wording of Section 205 of the Communications Services Act leaves the applicability of the provision to web beacons somewhat unclear, as they are not stored on the user’s terminal device. However, referring to EU law and the purpose of the provision, the Administrative Court has held that the application of the provision does not require that data be explicitly stored on the terminal device. Any other interpretation could allow for the collection of user data without the user’s consent by using web beacons instead of cookies. The web beacons in question here cannot be considered necessary. Therefore, the user’s consent should have been sought for them. The case was decided by Administrative Court Justices Jukka Reinikainen, Esa Hakkola, and Joonas Ahtonen, who also presented the case. Appeal to the Supreme Administrative Court Sanoma Media Finland Oy has requested leave to appeal and demanded that the decisions of the Administrative Court and the Finnish Transportand Communications Agency be overturned, among other things, with regard to the obligation concerning personalization and delivery cookies as well as web beacons. Sanoma has further requested that the Supreme Administrative Court seek a preliminary ruling from the Court of Justice of the European Union and hold an oral hearing on the matter. The Finnish Transport and Communications Agency must also be ordered to reimburse the company’s legal costs, including interest for delay. The Finnish Transport and Communications Agency has demanded that the company’s appeal, as well as its requests for a preliminary ruling, for an oral hearing, and for reimbursement of legal costs, be dismissed. Reasons for the Supreme Administrative Court’s Decision Request for an oral hearing Sanoma has demanded that the Supreme Administrative Court hold an oral hearing, as the written report does not provide a sufficient overall picture of the detailed and complex technical issues involved in the case or of the principles of journalism. Pursuant to Section 57(3) of the Act on Proceedings in Administrative Matters, the Supreme Administrativemay, despite a party’s request, decline to hold an oral hearing if the case involves an appeal against a decision by an administrative court and holding an oral hearing is not necessary to resolve the matter. Taking into account the grounds on which Sanoma has requested an oral hearing, the evidence it has indicated it will present, and the evidence available from the documents, it is not necessary to hold an oral hearing to resolve the matter. The Request for a Preliminary Ruling The Parties’ Main Arguments Sanoma has argued that the Supreme Administrative Court should request a preliminary ruling from the Court of Justice of the European Union on the interpretation of Article 5(3) of the ePrivacy Directive. A preliminary ruling should be sought, among other things, on whether that provision applies to online calls. The Court of Justice’s interpretation is also required to determine whether the concept of “service” as defined in the provision includes essential and inseparable features and functions of the service, as well as whether whether the user must expressly request each such feature and function. Furthermore, a request for a preliminary ruling is necessary to determine whether the user’s explicit requests define which features or functions are essential to the service. According to the submission, a preliminary ruling must also be sought regarding the significance of the European Media Freedom Regulation. In particular, the question is whether the ePrivacy Directive should be interpreted, in light of Articles 3 and 4(2) of the Media Freedom Regulation, such that a cookie intended to implement editorial decisions and policies is necessary for the provision of the media service specifically requested by the subscriber or user. According to the Finnish Transport and Communications Agency, Article 5(3) of the ePrivacy Directive is technology-neutral. A request for a preliminary ruling on the applicability of that provision to online invitations is unnecessary. In other respects, the questions submitted for a preliminary ruling are hypothetical or unclear. User profiling and the analysis of user activity are a distinct part of the company’s service. Nor is the issue about cookies that are necessary for the implementation of editorial decisions and policies. Legal Assessment and Conclusion Under Article 267 of the Treaty on the Functioning of the European Union, the Court of Justice of the European Union has jurisdiction to give preliminary rulings, among other things, on the interpretation of the Treaty and of acts of the institutions of the Union. If such a question arises in a case pending before a national court whose decisions are not subject to further appeal under national law, that court must refer the question to the Court of Justice of the European Union for a preliminary ruling. In Finland, the Supreme Administrative Court exercises the highest judicial authority in administrative law matters. It follows from the case law of the Court of Justice that there is no obligation to make a request for a preliminary ruling under Article 267 of the Treaty on the Functioning of the European Union, however, if the national court has no genuine doubt as to the applicability of the existing case law of the Court of Justice to the case, or if it is entirely clear how Union law is to be properly applied in the situation at hand. Taking into account the case law of the Court of Justice referred to below in this decision, as well as the grounds on which the Supreme Administrative Court has decided the case, there is no reasonable doubt as to the interpretation of Union law relevant to the resolution of the case. Consequently, no question of Union law has been raised in this case that would necessitate a request for a preliminary ruling under Article 267 of the Treaty on the Functioning of the European Union. The Main Issue The Supreme Administrative Court must first determine whether Sanoma could have been required to make the personalization and delivery cookies used in the distribution of news content on its websites subject to consent. In this regard, the case specifically concerns whether, with respect to personalization and delivery cookies, the storage or use of data constitutes the type of activity referred to in Section 205(2) of the Communications Services Act, which is necessary within the meaning of the provision and for which the user’s consent is not required. Furthermore, the question specifically concerns the weight that should be given in this case to the considerations related to the role of the media, freedom of speech, and other fundamental rights, as referred to by Sanoma. Second, the Supreme Administrative Court must determine whether Section 205 of the Communications Services Act applies to the online invitations at issue in this case. If so, the question is specifically whether the online invitations constitute the storage or use of data referred to in subsection 2 of that section, for which the user’s consent is not required. Applicable and Other Relevant Legal Provisions According to Section 205(1) of the Act on Electronic Communications Services (the Electronic Communications Services Act), Section 205(1), the storage of cookies or other data describing the use of the service on the user’s terminal device and the use of such data are permitted for the service provider, provided that the user has given their consent and the service provider provides the user with clear and comprehensive information regarding the purpose of such storage or use. According to paragraph 2 of the same section, the provisions of paragraph 1 do not apply to the storage or use of data whose sole purpose is to facilitate the transmission of a message over communications networks or which is necessary for the service provider to provide a service that the subscriber or service user has expressly requested. According to paragraph 3 of the section, the storage and use referred to in the section are permitted only to the extent required by the service and must not restrict the protection of privacy more than is necessary. Pursuant to Section 330(1) of the Communications Services Act, among other things, the Finnish Transport and Communications Agency may, in carrying out its duties under that Act, issue a warning to any party anyone who violates the aforementioned Act or the regulations, orders, decisions, and license conditions issued pursuant to it, and require that person to correct their error or omission within a reasonable time. Directive 2002/58/EC of the European Parliament and of the Council concerning the processing of personal data and the protection of privacy in the electronic communications sector (the ePrivacy Directive), as amended by Directive 2009/136/EC, Article 1(1) provides that the Directive aims to harmonize the national provisions necessary to ensure an equivalent level of protection of fundamental rights and freedoms, in particular the right to privacy and confidentiality, in the processing of personal data in the electronic communications sector, as well as to ensure the free movement of such data and of electronic communications equipment and services within the Community. Pursuant to Article 5(3) of the amended Directive, Member States shall ensure that the retention of data or the use of data stored on a subscriber’s or user’s terminal equipment is permitted only on the condition the subscriber or user in question has given his or her consent after having been provided with clear and comprehensive information, including on the purpose of the processing, in accordance with Directive 95/46/EC. This does not preclude technical storage or access whose sole purpose is the transmission of communications over electronic communications networks or which is strictly necessary for the provider of an information society service to provide a service which the subscriber or user has specifically requested. The fourth recital of the preamble to the Directive states, among other things, that Directive 97/66/EC must be adapted to developments in the market for electronic communications services and in technology, in order to ensure a consistent level of protection of personal data and privacy for users of publicly available electronic communications services, regardless of the technology used. That Directive should therefore be repealed and replaced by the Directive on Privacy and Electronic Communications. According to Recital 24, the terminal equipment of users of electronic communications networks and the data stored on such equipment fall within the sphere of users’ private lives, which requires protection in accordance with the European Convention for the Protection of Human Rights and Fundamental Freedoms. So-called “snooping” techniques, tracking devices, hidden identifiers, and other similar methods allow access to a user’s terminal equipment without the user’s knowledge for the purpose of obtaining information, storing encrypted data, or tracking the user’s activities, and may seriously infringe upon the privacy of these users. The use of such methods should be permitted only for lawful purposes and in a manner that ensures the users in question are aware of it. Recital 25 states, among other things, that, for example, the use of cookies may nevertheless be legitimate and useful, for instance, when analyzing the effectiveness of a website’s design and advertising, and when verifying the identity of users participating in online transactions. Users should have the option to accept or refuse the storage of a cookie or a similar technique on their terminal equipment. Recital 66 of the preamble to Directive 2009/136/EC, Recital 66 states, among other things, that third parties may wish to store information on a user’s device or access information already stored there for various purposes, ranging from legitimate purposes (such as various types of cookies) to purposes involving unauthorized intrusion into privacy (such as spyware and viruses). It is therefore of the utmost importance that users be provided with clear and comprehensive information when they take actions that may lead to such storage or authorization of use. The methods used to provide information and offer the option to opt out should be as user-friendly as possible. Exceptions to the requirement to provide information and offer the option to opt out should be limited to situations where technical storage or the enabling of access is strictly necessary in order to lawfully enable the use of a specific service that the subscriber or user has explicitly requested. According to Article 1(1) of Regulation (EU) 2024/1083 of the European Parliament and of the Council on a common framework for media services in the internal market and amending Directive 2010/13/EU (the Media Freedom Regulation), Article 1(1) states that the Regulation establishes common rules for the proper functioning of the internal market for media services and establishes a European Media Services Board, while safeguarding the independence and pluralism of media services. Article 1(2) of the Media Freedom Regulation lists seven Union legal acts whose rules are not affected by the Regulation. The list includes, among others, the General Data Protection Regulation, but not the ePrivacy Directive. Article 3 of the Media Freedom Regulation sets forth the rights of media service recipients. Article 4, in turn, sets forth the rights of media service providers, and Article 6 sets forth the obligations of media service providers. Recital 16 of the Regulation states, among other things, that the free flow of reliable information is essential for a functioning internal market for media services. Therefore, no restrictions should be imposed on the provision of media services that are inconsistent with this Regulation or other provisions of Union law, such as Directive 2010/13/EU. Restrictions may also result from measures taken by national authorities in accordance with Union law. According to Recital— According to Recital 77, this Regulation respects fundamental rights and observes the principles recognized in the Charter of Fundamental Rights, in particular Articles 7, 8, 11, 16, 47, 50, and 52 thereof. Consequently, the Regulation should be interpreted and applied with due respect for those rights and principles. Article 7 of the Charter of Fundamental Rights of the European Union guarantees the right to respect for private and family life, Article 8 guarantees the protection of personal data, Article 11 guarantees freedom of expression and information, and Article 16 guarantees the freedom to conduct a business. The Obligation Regarding Personalization and Delivery Cookies Key Positions of the Parties According to Sanoma, personalization and delivery cookies for the digital news service are essential for the company to provide the service that subscribers and users have specifically requested. This constitutes a service as defined in Section 205(2) of the Communications Services Act, and the company is therefore not required to obtain the user’s consent. According to Sanoma, personalization is essential in a digital news service. Personalization cookies are used to personalize content distribution in accordance with editorial decisions and guidelines, taking into account the user’s usage habits and interests. Editorial cookies are also closely tied to the implementation of editorial decisions and accountability in a digital news service. They help us understand how different user groups engage with content and what interests them. These are first-party cookies, which do not pose a problem in terms of user privacy. These cookies are not used for targeted advertising. Sanoma has noted that, according to a survey commissioned by the company, more than half of Helsingin Sanomat’s readers want recommendations, filters, or personalization for media content that interests them. According to a reader survey conducted in 2023, nearly all Helsingin Sanomat readers assumed that the news service’s digital front page is different from—and functions differently than—the front page of the print newspaper. In addition, the majority of readers assumed that the digital front page of the news service shows readers both the most important news stories selected by the editorial staff and topics of broad interest, as well as content recommendations. According to Sanoma, a non-personalized digital news service does not meet users’ expectations or needs and is not competitive. Print newspapers, online editions, and other non-personalized services are entirely different products. When choosing a digital news service, the user is explicitly requesting a service with personalized content. The distribution of personalized content is an essential and inseparable part of the service, and this distribution logic is not a feature that can be requested separately. The necessity of cookies must be examined from the perspective of the nature of the service. The reader cannot explicitly request any service other than the one offered by the media company. According to Sanoma, the obligation imposed on the company prevents the exercise of editorial freedom and responsibility and constitutes a restriction prohibited by the Media Freedom Regulation. Content personalization and the order in which articles are presented fall within the scope of editorial discretion. Article 1(2) of the Media Freedom Regulation makes no reference to the ePrivacy Directive. Regulations concerning the use of cookies must not restrict the application of the Regulation, nor may Section 205 of the Communications Services Act be used to interfere with editorial freedom and independence. Furthermore, editorial freedom cannot be contingent on user consent. Personalization enables the transmission of information and the exercise of freedom of expression. The Finnish Transport and Communications Agency has referred to the reasoning presented in its decision. According to the Agency, the necessity of a cookie must be assessed primarily from the user’s perspective. The criterion of explicit consent requires that the user has requested a personalized service. In this case, the user cannot be considered to have explicitly requested the profiling and analysis of their behavior merely by visiting the news site. It is possible to present articles and other content in the order selected by the editorial staff and to determine the content without profiling the user or collecting data on the user’s activity for use by the editorial staff. Improving the quality of services through the use of cookies is not necessary within the meaning of the law. According to the Finnish Transport and Communications Agency, the obligation imposed on Sanoma does not prevent the implementation of editorial choices or decisions. Content personalization remains permitted provided it is done with the user’s consent or at the user’s request. Monitoring compliance with data protection regulations for electronic communications does not constitute prohibited interference with editorial practices or decisions as defined in the Media Freedom Act. Ensuring the financial viability of a media service provider’s operations does not justify deviating from the requirement for user consent. Legal Assessment and Conclusion Pursuant to the general rule set forth in Section 205,Based on the general rule in subsection 1, the storage of cookies or other data describing the use of the service on the user’s device, as well as the use of such data, requires the user’s consent and appropriate information. Paragraph 2 of the section provides for exceptions to this rule. Pursuant to subsection 2 of this section, the requirement for the user’s consent and notification does not apply, among other things, to the storage or use of data which is necessary for the service provider to provide a service that the subscriber or service user has explicitly requested. This section implements Article 5(3) of the Directive on Privacy and Electronic Communications. According to that provision, the exception in question applies to storage or use that is strictly necessary for an information society service provider to provide a service that the subscriber or user has specifically requested. The wording of the Communications Services Act and the Electronic Communications Data Protection Directive indicates that the threshold for applying the exception is intended to be quite high. This can also be considered justified in light of the fact that, when applicable, the exception allows for the storage and use of data without the user even being aware of it, even at the very moment they first arrive at a particular website. As an exception, Section 205(2) of the Communications Services Act must also, as a general rule, be interpreted narrowly. Furthermore, a general principle in the application of this provision is that the party invoking the exception bears the burden of providing sufficient evidence that the conditions for the exception’s applicability have been met. The primary purpose of the applicable regulations is to ensure the protection of privacy and confidentiality in the field of electronic communications. As stated in the preamble to the ePrivacy Directive, users’ terminal equipment and the data stored on such devices fall within the sphere of users’ private lives. The Court of Justice of the European Union has also held, in Case C-673/17, Planet49, that the provision in Article 5(3) of the Directive aims to protect users from infringements of their privacy, regardless of whether the infringement concerns personal data or other data (para. 69). With regard to the effects on the user’s privacy, the fact cited by Sanoma—that this case involves so-called first-party cookies—is relevant in and of itself. However, taking into account the aforementioned provisions and their purpose, this fact alone does not imply that the processing and use of data considered to fall within the scope of a user’s private life in the provision of Sanoma’s services in question would be permitted under the exception provided for in Section 205 of the Communications Services Act. When assessing whether the storage and use of data related to personalization and delivery cookies are necessary within the meaning of the exception provision of the Communications Services Act, the company’s choices regarding the implementation of the service cannot be given decisive weight. It is inconceivable that a service provider could offer a website based on the processing of data from the user’s device to the extent it desires, and then argue that a user visiting the site could not even request anything other than the service actually provided. Instead, what is of particular importance in assessing this matter is what service the website’s users must be deemed to have expressly requested. In making this assessment, factors such as an analysis of users’ reasonable expectations, as well as the nature of the service in question and how it can be implemented, may be relevant. Sanoma’s websites continuously publish updated news and other journalistic content. The primary purpose of a user of a website offering a digital news service can be considered to be obtaining information on current topics. It is evident that a digital news service differs from, among other things, the print newspaper referred to by the company in terms of the diversity, timeliness, and availability of its content. This is undoubtedly what users expect as well. However, it cannot be concluded from the above that users reasonably expect—let alone explicitly request— that, simply by visiting the website, they will be offered personalized content based on the tracking and analysis of their activity. Nor can such a conclusion be reliably drawn on the basis of Sanoma’s user surveys or any other study. The storage and use of data enabling personalization solely based on a visit to the website can, in light of the general rule set forth in Section 205 of the Communications Services Act, be considered rather surprising. It has been credibly argued in this case that personalizing the content offered in a digital news service is a viable means for the service provider to make the service more commercially attractive. However, based on the evidence presented, it cannot be concluded that the service would be economically or otherwise feasible only in a manner where users’ activities are monitored and analyzed without their consent, as is currently the case. Nor can it be established on any other grounds that the storage and use of data related to the personalizationand delivery cookies is necessary in the sense intended by Section 205(2) of the Communications Services Act. No other grounds for deviating from the general rule set forth in paragraph 1 of that section have emerged. However, it remains to be determined in this case what weight should be given to the considerations related to the role of the media, freedom of speech, and other fundamental rights cited by Sanoma when assessingand Communications Agency. Freedom of speech or freedom of the press is not independent of other fundamental rights or freedoms, such as the protection of privacy and personal data. Freedom of speech does not, in and of itself, imply that a provider of a digital news service should be permitted to store and use information pertaining to the private lives of its website users. Nor is freedom of speech a right that unilaterally protects the dissemination of information. Freedom of speech also includes the right to receive information, in light of which it is not insignificant that the obligation imposed on Sanoma allows users to influence the use of methods that limit or target the news content offered to them. Nor does the Media Freedom Regulation indicate that it is intended to provide for substantial exceptions to the rules on cookies or otherwise to curtail users’ rights in the field of electronic communications. On the contrary, the preamble to the Regulation emphasizes respect for privacy and the protection of personal data in the application of the Regulation. This principle is not called into question by the fact that Article 1(2) of the Regulation does not specifically mention the ePrivacy Directive. The decision by the Finnish Transport and Communications Agency was based on regulations binding on the company, the purpose of which is, among other things, to ensure the protection of users’ privacy in the field of electronic communications. The obligation imposed on Sanoma has not interfered with the pluralistic and independent media services safeguarded by the Media Freedom Regulation, nor with the free flow of reliable information. The obligation has not restricted the company’s right to decide what content it publishes and when it does so. Nor has it prevented the provision of journalistic content in a personalized manner based on the user’s consent and information. The obligation has restricted the implementation of personalization in a manner based on monitoring and analyzing the activities of website users without their consent. Based on the foregoing, the Media Freedom Act cannot be considered an obstacle to the obligation imposed by the decision of the Finnish Transport and Communications Agency. Nor does the decision constitute an unjustified interference with freedom of speech or freedom of the press, nor with the company’s freedom of enterprise or other rights. Based on the foregoing, the Transport and Communications Agency was entitled, pursuant to Section 330 of the Communications Services Act, to require Sanoma to make the personalization and delivery cookies at issue subject to consent. For this reason, and taking into account the arguments presented before the Supreme Administrative Court and the evidence obtained in the case, there are no grounds in this regard to alter the outcome of the Administrative Court’s decision. Obligation Regarding Web Requests Key Arguments of the Parties According to Sanoma, web requests are part of the normal operation of the HTTP protocol, which enables communication between the server and the terminal device. Certain information is always transmitted from the terminal device in connection with web requests. Web requests are not a tracking technology comparable to or an alternative to cookies. According to Sanoma, the wording of Section 205 of the Communications Services Act is unambiguous and clear, and web requests do not fall within its scope of application. The provision applies only to the storage of cookies or other data describing the use of the service on the user’s terminal device and the use of such data. Web beacons are not stored on the user’s device, nor do they store data on the user’s device or contain data stored by the user on their device. The interpretive effect of Union law cannot lead to an interpretation that contradicts the wording of national law. The Directive cannot, as such, create obligations for private individuals, nor can it be invoked against a private individual to their detriment. Nor is it clear whether web calls fall within the scope of the ePrivacy Directive. An interpretation that deviates from the wording of the provisions cannot be justified by interpretive guidelines. Sanoma has argued that web calls are, in any case, essential technologies for providing the service requested by the user or subscriber. They are related to the basic functioning of the Internet and the technology that enables the use of website content via the user’s terminal device. Their use involves the transmission of messages over communications networks. Furthermore, it is not possible to display a digital news service’s website without web beacons; thus, they are also essential for providing the service. Under the Digital Services Act, Sanoma is required to measure the number of users on its websites, which is not technically possible without anonymized web requests. The Finnish Transport and Communications Agency has referred to the grounds presented in its decision. According to the Agency, when interpreting Section 205 of the Communications Services Act, one must take into account the interpretive impact of the ePrivacy Directive. The provision applies to the use of data from the user’s terminal equipment even in cases where the data in question was not stored on the user’s terminal equipment by the service provider. Any other interpretation would lead to a result that is untenable from the perspective of the Directive and the protection of privacy. According to the Finnish Transport and Communications Agency, Sanoma has not, despite a request, provided the agency with information regarding the web beacons it uses and their intended purposes. The Digital Services Act does not limit the application of the ePrivacy Directive. The applicability of the Directive to the web calls at issue in this case is now clear based on the guidelines issued by the Data Protection Board regarding the technical scope of Article 5(3) of the Directive. Legal Assessment Section 205 of the Communications Services Act:(1) sets forth the conditions under which a service provider is permitted to store cookies or other data describing the use of the service on a user’s terminal device and to use such data. This section implements Article 5(3) of the ePrivacy Directive, as amended. Article 5(3) of the Directive concerns the storage of data or the use of data stored on a terminal device. Taking into account the wording of the provision and the purpose of the Directive as set forth in paragraph 46 of this decision, the provision must be deemed to also apply to the use of data stored on a terminal device that does not involve the storage of data or that concerns data other than that stored by the service provider itself. In this respect, the wording of Section 205(1) of the Communications Services Act differs to some extent from the wording of Article 5(3) of the Directive. However, the wording of the Act allows for an interpretation consistent with the Directive. Section 205(1) of the Act must therefore be considered, in the same way as the Directive, to also apply to the use of data stored on the terminal equipment referred to in the provision, which does not involve the storage of data or which relates to data other than that stored by the service provider itself. As stated in the preamble to the Directive, the purpose of the applicable regulation is to ensure a consistent level of protection for personal data and privacy, regardless of the technology used. Online calls cannot therefore be considered to fall outside the scope of the regulation merely because their technical operating principles differ from those of cookies. What is essential is to assess whether web beacons constitute the use of data as referred to in the provisions. Based on the decision by the Finnish Transport and Communications Agency, the recipient of a web beacon receives, for example, the user’s IP address, operating system information, browser information, browser version information, language settings, and any cookie data. The decision states that, based on Sanoma’s own investigation, it is also possible to create a unique identifier for the user from the data transmitted with the web request. Furthermore, as Sanoma has stated in this case, information is transmitted from the terminal device in connection with web calls; as an example, the company cited in the Administrative Court information regarding the characteristics of the user’s browser or device. Based on the presented analysis, web invitations thus constitute the use of data stored on a terminal device as referred to in Section 205(1) of the Communications Services Act. This provision must therefore be applied to the web calls in question. According to the general rule in Section 205(1) of the Communications Services Act, the use of the data referred to in the provision requires the user’s consent. Paragraph 2 of the section sets forth exceptions to this rule. Based on the decision of the Finnish Transport and Communications Agency, Sanoma has not provided the Agency with the information it requested regarding online calls. Nevertheless, the Agency has determined that the exception under Section 205(2) of the Communications Services Act can be applied to some of the online invitations and, in this regard, has not required the company to correct its practices. However, with regard to certain online invitations, the conditions for applying the exception were not deemed to have been met. The obligation imposed on the company concerns these online invitations. As noted above, Section 205(2) of the Communications Services Act, as an exception, must in principle be interpreted narrowly. Furthermore, a general principle in applying the provision is that the party invoking the exception bears the burden of providing sufficient evidence that the conditions prescribed for the application of the exception have been met. Given the incomplete information provided by Sanoma regarding its online invitations, the agency was justified in concluding that it remained unproven that the conditions for applying the exception were met. The matter should not be assessed differently on the basis of the evidence presented during the proceedings. To the extent that Sanoma also intended to invoke the status of the media, freedom of speech, or other fundamental rights or -freedoms, the Supreme Administrative Court refers to the statements made earlier in this decision. Based on the foregoing, the Finnish Transport and Communications Agency was entitled, pursuant to Section 330 of the Communications Services Act, to require Sanoma to make the online calls at issue subject to consent. For this reason, and taking into account the arguments presented before the Supreme Administrative Court and the evidence presented in the case, there are no grounds for altering the outcome of the Administrative Court’s decision in this regard either. Rejection of the Application for Leave to Appeal Pursuant to Section 111(1) of the Act on Proceedings in Administrative Matters, leave to appeal must be granted if: 1) it is important, for the purposes of applying the law in other similar cases or for the sake of consistency in judicial practice, to have the matter decided by the Supreme Administrative Court; 2) there are special grounds for referring the matter to the Supreme Administrative Court for a ruling due to a manifest error in the case; or 3) there is another compelling reason to grant leave to appeal. Based on the arguments presented in the case and what is otherwise evident from the documents, there are no grounds for granting leave to appeal to have the case decided by the Supreme Administrative Court other than those referred to above. Legal Costs As the case has thus been concluded, and taking into account Section 95 of the Act on Proceedings in Administrative Matters, Sanoma Media Finland Oy shall not be ordered to pay compensation for legal costs before the Supreme Administrative Court. The case was decided by Justices Outi Suviranta, Taina Pyysaari, Monica Gullans, Toni Kaarresalo, and Päivi Pietarinen. The case was presented by Elina Ranz.

## Cited law provisions (10)

### GDPR — gdpr-art-1-par-1-en

This Regulation lays down rules relating to the protection of natural persons with regard to the processing of personal data and rules relating to the free movement of personal data.

### GDPR — gdpr-art-1-par-2-en

This Regulation protects fundamental rights and freedoms of natural persons and in particular their right to the protection of personal data.

### GDPR — gdpr-art-3-en

Territorial scope

### GDPR — gdpr-art-4-en

For the purposes of this Regulation:

### GDPR — gdpr-art-5-en

Principles relating to processing of personal data

### GDPR — gdpr-art-6-en

Lawfulness of processing

### GDPR — gdpr-art-7-en

Conditions for consent

### GDPR — gdpr-art-8-en

Conditions applicable to child's consent in relation to information society services

### GDPR — gdpr-art-11-en

Processing which does not require identification

### GDPR — gdpr-art-16-en

The data subject shall have the right to obtain from the controller without undue delay the rectification of inaccurate personal data concerning him or her. Taking into account the purposes of the processing, the data subject shall have the right to have incomplete personal data completed, including by means of providing a supplementary statement.

---
Generated by overview.legal · https://overview.legal/posts/353646 · 2026-09-03
