Technical and Organizational Measures in the Chipster Service
Last updated: 27.5.2026
1 Purpose
The technical and organizational measures (TOMs) describe the agreement between the data controller and the data processor on how to process personal data as stated in article 28 of the General Data Protection Regulation (EU) 2016/679. The Data Protection Act (1050/2019) stipulates the obligations on how to protect special categories of personal data. On behalf of the partner organization, CSC – IT Center for Science Ltd. (“CSC“) processes personal data, where the partner organization acts as a data controller, to produce the services agreed in the service contract. The measures taken to protect this data by CSC when producing the Chipster service are listed below.
The data processor can unilaterally change the protective measures without notification when the changes retain or improve the general level of protection. Single protective actions can be replaced as long as it doesn’t affect the level of protection regarding personal data. CSC can make changes to this document when the protective measures are changed. Pertinent changes are reported to the data controller.
2 Protective Measures in the Chipster service
General Principles
- User Terms of Use:
Users must agree to CSC’s Terms of Use before accessing the service environment. - Secret Management:
Administration-level credentials are stored securely for example in encrypted password management software. Machine-to-machine credentials are stored in plaintext only on the server where they are needed and access rights of those credentials are minimized. - Layered Security Architecture:
The public service API is carefully constructed to check required user authorisation of each request to private resources. More restricted credentials are automatically created for operations, where there is an increased risk of a leak of User’s full access credentials (for example file download addresses). - Access Management:
Data controller retains control over its own staff’s access rights. - Training and Awareness:
CSC personnel receive continuous data protection and security training. Training records are maintained internally. - Confidentiality Obligations:
All personnel handling personal data comply with applicable data protection laws (such as the Finnish Act 1050/2018). - Data Protection Officer:
CSC has appointed a dedicated Data Protection Officer (DPO) to oversee data protection compliance. - Data Storage Location:
All data is stored within the EU (Finland).
Measures to Ensure Confidentiality
- Network Protection:
Firewalling blocks access from the public Internet to APIs by default, allowing access with only specific secure protocols (HTTPS and WebSocket Secure). System administration interfaces are protected with an authentication and additionally protected by firewalls when technically sensible. - Data Encryption:
Data transfers in public internet between users and systems are encrypted with Transport Layer Security (TLS). When using external identity providers (CSC Login, Haka, Virtu), the users’ password is not processed or stored in the Chipster service. User’s data stored in Chipster is encrypted with a unique encryption keys. Data encryption cannot be guaranteed under certain circumstances. - Session Access Control:
By default, the user who creates an analysis Session, can access data in that Session, and manage the access rights for that Session to other user accounts. - Updates, Testing and Communication about Suspected Breach of Confidentiality:
Server hardware and software is regularly updated to fix vulnerabilities and errors. Automated and manual tests are used to ensure correctness of the changes. However, as the service is available in the public internet, new or unforeseen vulnerabilities and errors may allow unidentified attackers to affect the availability of the Service, confidentiality of the Content, or authenticity of the Content. Any identified traces of such activity are mitigated, investigated and communicated to relevant parties as soon as possible, considering the safe handling of the situation.
Measures to Ensure Availability and Resilience
- Checksums:
Checksums are calculated for the data and this checksum is saved in a database. When the data is read, the checksum is verified. User is notified if there is a mismatch with the checksums. - Automatic Monitoring:
CSC uses automated monitoring systems to detect and report service disruptions or anomalies to administrators. - Disaster Recovery & Backup:
Chipster takes backup copies of its internal databases and may store it up to 24 months. However, due to limitations outlined in the Content Backup Policy, users are responsible for maintaining their own backups of critical data stored in Chipster service. - Content Backup Policy:
Chipster has an automated system, which tries to maintain a second, independent copy of users’ data. This offers limited protection for example against sudden hardware or software errors that would remove or corrupt the primary copies. However, due to size of the data, we cannot store full version history of the data and thus this isn’t a proper backup system. Second copies are not always successful, they may be removed during maintenance operations and may not survive the loss of the primary copy. This second copy can store data for 60 days after User has deleted the data from Chipster’s primary copy. Users are responsible for maintaining their own backups of critical data stored in Chipster service. - Up-to-date User Account Information:
Chipster service will get the up-to-date user account information from the authentication service every time a User logs in. - Application Logs:
Chipster collects application log files that are used by CSC for example to monitor and investigate correct functioning of the Service. However, availability and coverage of these log files is not part of the Service. The Service does not collect Session access logs in a form that would allow User to review who has accessed User’s Content in the Service.