Why this happens

Open source deepfake tools require only a single clear facial photograph to produce convincing synthetic intimate content. Any public photo on social media or LinkedIn can be the source.

Targeted deepfake attacks frequently begin in private Telegram or Discord communities and spread to public sites within days. Early detection through biometric scanning is the only reliable way to find every copy.

Legal framework in Finland

Rikoslaki 24 luku 8a § (dissemination of information violating personal privacy). Fine or imprisonment up to 2 years.

Finland's chapter 24 section 8a covers sexual and intimate content disseminated without consent. The 2023 reform clarified that synthetic intimate images are within scope when they depict an identifiable person.

Evidence to preserve

Do not: Do not amplify the content by responding publicly. Engagement increases visibility and may also be used by the perpetrator to claim consent or interaction.

Five step removal process

  1. 1

    Preserve all evidence first

    Full page screenshot of every URL where the content appears. The username and account handle that posted the content.

  2. 2

    File the Rikoslaki 24:8a (yksityiselämää loukkaava tiedon levittäminen) criminal complaint

    Report to local police or the national cybercrime unit. Nettivihje can assist.

  3. 3

    Submit an erasure request under GDPR Article 17 (right to erasure) plus Tietosuojalaki

    Each major platform has a designated data protection contact. The request must cite the legal basis and identify the URLs. The platform has 30 days to respond. Tietosuojavaltuutettu accepts complaints for non compliance.

  4. 4

    Run a biometric scan to find every additional copy

    Content posted to one platform is rarely confined to one platform. ScanErase identifies every current hosting location in a single scan, including mirror copies and AI generated variants.

  5. 5

    File TAKE IT DOWN Act notices for covered platforms

    Use your scan report to file the federal 48 hour notice yourself, in parallel with your domestic rights. The two regimes are cumulative, not exclusive.

Statutory citations to include in your complaint

Frequently asked questions

Is deepfake of me a crime in Finland?

Yes. Rikoslaki 24 luku 8a § (dissemination of information violating personal privacy) criminalises this conduct. Fine or imprisonment up to 2 years.

What evidence should a Finland victim of deepfake of me preserve?

Full page screenshot of every URL where the content appears. The username and account handle that posted the content. Any source images credited or visibly used, which proves the deepfake derivation. The video or image file itself, downloaded for evidence preservation.

Does GDPR Article 17 (right to erasure) apply to this scenario?

Yes. GDPR Article 17 (right to erasure) plus Tietosuojalaki gives the victim a direct erasure right against any platform processing the imagery. Tietosuojavaltuutettu enforces non compliance.

What support is available in Finland for deepfake of me?

Nettivihje provides direct support to victims and can assist with both the criminal complaint and the platform removal process. Contact at https://www.pelastakaalapset.fi/nettivihje.

Can a Finland victim also file a US TAKE IT DOWN Act notice?

Yes when the hosting platform is subject to US jurisdiction. The 48 hour federal removal obligation runs in parallel with rights under Rikoslaki 24:8a (yksityiselämää loukkaava tiedon levittäminen) and GDPR Article 17 (right to erasure) plus Tietosuojalaki.