Technical and Organizational Measures in the Paituli Service
Last updated: 25.6.2026
1 Purpose
The technical and organizational measures (TOMs) describe the agreement between the data controller and the data processor on how to process personal data as stated in article 28 of the General Data Protection Regulation (EU) 2016/679. The Data Protection Act (1050/2019) stipulates the obligations on how to protect special categories of personal data. On behalf of the partner organization, CSC – IT Center for Science Ltd. (“CSC“) processes personal data, where the partner organization acts as a data controller, to produce the services agreed in the service contract. The measures taken to protect this data by CSC when producing the Paituli service.
The data processor can unilaterally change the protective measures without notification when the changes retain or improve the general level of protection. Single protective actions can be replaced as long as it doesn’t affect the level of protection regarding personal data. CSC can make changes to this document when the protective measures are changed. Pertinent changes are reported to the data controller.
2 Protective Measures in the Paituli service
General Principles
- Segregation of Duties:
Administrative responsibilities are divided among network, data center, and system administrators to minimize risk. - User Terms of Use:
Users must NOT agree to CSC’s Terms of Use before accessing the service environment. Paituli is a service for downloading open data. Users must agree to the dataset license before downloading. - Shared Secret Management:
Administration-level credentials are stored securely and managed through dedicated system management servers. - Layered Security Architecture:
User access and system administration interfaces are segregated within secure network zones and protected by firewalls. - Contractual Basis:
All data processing operations are based on written agreements with the data controller. - Role-based Access Control:
Access rights are allocated according to roles and follow the principle of least privilege. CSC maintains its staff’s access rights, ensuring they are limited to tasks that require access. - Access Management:
Access rights are only for system admins at CSC. - Training and Awareness:
CSC personnel receive continuous data protection and security training. Training records are maintained internally. - Confidentiality Obligations:
All personnel handling personal data are bound by confidentiality agreements and comply with applicable data protection laws (such as the Finnish Act 1050/2018). Nevertheless, no personal data is handled in Paituli service. - Data Protection Officer:
CSC has appointed a dedicated Data Protection Officer (DPO) to oversee data protection compliance. - Data Storage Location:
All data is stored within the EU (Finland).
Measures to Ensure Confidentiality
- Network Protection:
Firewalling blocks access from the public Internet to Paituli server by default, allowing access with only specific secure protocols (SSH and HTTPS). - Data Encryption:
The data transfer over a public data network is done using encrypted or otherwise protected data transfer connections or methods - Filesystem Access Control & Data Ownership:
Standard UNIX-based access management (user-group-other) is applied to all data stored in the Paituli filesystem. Data stored in Paituli server is accessible to sysadmins only. - Multi-Factor Authentication (MFA):
Paituli is a download service for open data and does not require login nor MFA. - SSH Key Management:
Users can’t access Paituli servers and no SSH handling is needed. Sysadmins SSH is handled within LDAP (Lightweight Directory Access Protocol) authentication. - Session Access Control:
There are no sessions in Paituli. - Updates, Testing and Communication about Suspected Breach of Confidentiality:
- Vulnerability scans are regularly performed for services
- System vulnerabilities are monitored, and critical patches are installed immediately upon availability.
- There is a dedicated process for handling information security incidents
- The integrity and availability of services are monitored through controls implemented in a separate monitoring system.
Measures to Ensure Integrity
- Vulnerability Management:
The Services are being regularly scanned for vulnerabilities and other weaknesses. Security patches are being applied regularly. This means that the software is kept up to date with regular updates on all systems needed for the Services. Critical security patches are applied as soon as possible. - Change Management:
A formal change management process ensures all updates and changes are reviewed and implemented securely.
Measures to Ensure Availability and Resilience
- Checksums:
Paituli datasets are downloaded once from the data controller and saved in the system, where users don’t have access to. There is no need to calculate checksum for stored files in Paituli. - Automatic Monitoring:
CSC uses automated monitoring systems to detect and report service disruptions or anomalies to administrators. The integrity and availability of Paituli is monitored through controls implemented in a separate monitoring system. - Disaster Recovery & Backup:
- 1 Scenario A Paituli download service in the web-application not working
- 2 Scenario B Paituli APIs are unavailable
- 3 Scenario C Security Breach / API misuse
- 4 Scenario D Loss of data or data corruption
- 5 Scenario E Credentials or passwords are leaked/compromised.
Recovery from all of these incidents are described in Paituli Disaster Recovery Plan
- User Data Backup Policy:
Master copy of users’ data should always remain at the user.
In case NFS or database data is lost or corrupted, return from backup copy and in case of NFS return to latest stable state using snapshots. - Content Backup Policy:
The configurations and databases of the Paituli service are regularly backed up. Paituli has following data:- NFS, 17 TB, gisgeodata
- Daily/weekly NetApp snapshot NFS, only changes included
- Copy in Roihu
- All Paituli data backups are planned to be saved in 3-month-interval as NetApp snapshots through CommVault to tape later in 2026, when there will be more capacity for handling the geospatial data.
- NFS, 17 TB, gisgeodata
- Software Package Management:
Operating system software repositories are locally mirrored to ensure the availability of necessary updates even if external sources are unavailable. - User Account Synchronization:
There are no user accounts in Paituli. - Up-to-date User Account Information:
There are no user accounts in Paituli. - Application Logs:
User IPs are stored in service logs and used only for statistics (ROPA)
Measures for Testing, Evaluation, and Assessment
- Audits & Compliance:
CSC conducts regular internal and external audits, including ISO 27001 audits, to evaluate the effectiveness of security measures. - Incident Management:
Security incidents are managed according to defined operational processes, including analysis, response, and post-incident reviews.