1. General Information About the Environment
What is the VISU secure processing environment compliant with the Finnish Secondary Use Act?
- VISU is a secure virtual research and processing environment developed by the University of Oulu, audited in accordance with the Finnish Act on the Secondary Use of Health and Social Data and technically protected for the secure analysis of sensitive health and social care data.
- VISU is a University of Oulu computing server environment that provides researchers with a Linux-based high-performance computing platform.
- VISU has been audited in accordance with the Act on the Secondary Use of Health and Social Data (552/2019).
- VISU is registered in Astori, the processing environment register maintained by the licensing and supervisory authority.
- A separate user environment is created for each research project and is always assigned a unique name.
What is the environment designed for?
- VISU is designed to support secure research, statistical analyses, and government planning and investigation activities involving individual-level social and health care data, in accordance with permits issued by Findata.
- VISU can also be used for educational purposes.
- VISU can be used to process data not covered by the Secondary Use Act, but the same processing conditions apply to all datasets.
VISU Features
- VISU is accessed through a web browser using a remote desktop approach. No software is installed on the user’s local computer; all work is carried out within the protected virtual environment. Users log in using University of Oulu credentials and multi-factor authentication (MFA).
- Available only to users with University of Oulu-issued credentials.
- Users authenticate with strong two-factor authentication.
- Includes a standard software package.
- Allows installation of custom software.
- Scalable according to research requirements.
How much does VISU cost?
- VISU pricing is based on a monthly fee.
- Pricing is determined according to either research or educational use.
- Research pricing is based on the requested capacity and components.
- For educational use, VISU pricing is fixed and based on the number of users.
- The pricing list is available at: https://ict.oulu.fi/23976/.
What is the difference between a processing environment and a user environment?
- A project-specific user environment is created within the processing environment. The processing environment refers to the technical, organizational, and physical environment managed by the service provider that must comply with regulatory requirements.
- A user environment refers to a permit-specific, segregated data processing environment within the secure processing environment where a customer, researcher, or research group handles datasets containing personal data.
2. Access Rights and Environment Access
Who can use the environment?
- Only individuals who have been granted personal access rights and University of Oulu Univ or UFO user accounts for the specific environment may use it.
- User environments may also be used for educational purposes.
How are access rights requested?
- Access rights always require an order for a user environment.
- Access rights are granted when the user environment order is approved. However, access becomes available only when the environment is ready for use.
How is a VISU user environment ordered?
- A VISU user environment is ordered using the request form available on the ICT Services website: https://ict.oulu.fi/21383/.
- If the research is based on a data permit, only the permit holder named in the permit or their designated contact person may place the order.
- Required permits (such as data permit decisions) must be attached to the form. Administration reviews the request and begins deployment once all required information has been verified.
- Users receive confirmation when the environment is ready for use.
How are users identified?
- Users must have University of Oulu-issued user accounts, meaning identity has already been verified before ordering the user environment.
- Access to the environment always requires strong authentication.
How does login work?
- The user opens the designated URL using a web browser, which displays the login page. The user enters valid credentials and is then authenticated via MFA using a QR code or PIN.
What should I do if login fails?
- Verify that your account is active.
- Ensure MFA is functioning correctly (Authenticator updates, battery optimization settings, notifications).
- Confirm that you are using the correct login address: https://desktop.visu.oulu.fi/guacamole
- Switch networks (Wi-Fi ↔ mobile data) or disconnect VPN if it interferes with authentication.
- You can reset your MFA registration at https://account.oulu.fi/mfa using Suomi.fi authentication.
- If the problem persists, contact ICT Services at ict@oulu.fi or +358294 483 124.
Can the environment be accessed remotely?
- Yes. Users can access their user environment remotely, provided they are connected through the University of Oulu internal network or VPN.
How can access rights be modified or revoked?
- Changes to access rights must always be requested through the University of Oulu service management system using a dedicated change request form.
Can people who are not employees or students of the University of Oulu use the environment?
- Yes. Individuals without employment or student status at the University of Oulu or Oulu University of Applied Sciences may apply for access through their unit if they have valid reasons and rights to use university IT resources. Examples include parttime lecturers, visiting researchers, visiting teachers, grant-funded researchers, emeritus professors, and retired researchers continuing research activities.
Can users be granted rights to install and modify their own software?
- Generally yes. Users may install their own software and libraries in their user environment before data is imported. If software requires administrator or root privileges, installation must be performed by system administrators.
3. Data Management and Information Security
The processing environment may contain individual-level social and health care register data that cannot be released directly to researchers due to privacy requirements. These data may include:
- Pseudonymized data, where direct identifiers (such as names and personal identity codes) have been removed but individuals may still be indirectly distinguished and linked across datasets.
- Partially identifiable information (such as age at the time of research) when necessary and permitted by the permit.
- Special categories of personal data, such as health information, social service usage, or disease-related information.
- All processing of data covered by the Secondary Use Act must comply with permit conditions issued by Findata, the Secondary Use Act, and the GDPR. Data may only be used for the purposes specified in the permit.
How is information security ensured?
- Information security is implemented through multiple layers, combining strong user authentication, strict network segmentation, and a CIS Level 2 hardened Red Hat OpenShift platform. All user and administrative actions are logged centrally in Loki, while malware protection and quarantine-based inspection processes prevent malicious data from entering the environment.
What happens to the data and user environment when a project ends?
- The user environment is closed when the project ends, and the data is no longer available.
- If access to the environment or data is required after a permit expires, a new permit is required for the same datasets.
- User access rights are removed.
- Before results are exported, a re-identification risk assessment must be conducted and reported to Findata. In certain cases, results must be submitted to Findata for review.
- Risk assessment and export procedures must be completed before access rights expire.
- Users cannot export Secondary Use Act data themselves. Data exports are always performed by administrators through a quarantine process.
Will my actions be logged if I use a VPN?
- Yes. Using a VPN does not prevent logging. User activities are logged at the authentication level regardless of VPN usage.
4. Using the Environment and Working Practices
How do I import data into my environment?
- Data covered by the Secondary Use Act can only be imported via Findata or another authorized permit provider. Customers cannot transfer such datasets themselves. All datasets pass through a monitored quarantine environment for inspection before being approved for use.
- Research data not covered by the Secondary Use Act may also be transferred by the user. Data can be transferred securely using SFTP. Files are received into a monitored directory and automatically inspected before being moved into the user’s data directory.
- Separate instructions for SFTP are available at: https://ict.oulu.fi/21383/.
Can I import my own research data?
- Yes. However, if the data are subject to the Secondary Use Act, they must be permitted under the applicable data permit. Personal datasets must be transferred through the quarantine process by administration and must comply with permit conditions.
- Sensitive data can also be imported directly by users into sensitive data environments, but all imported data undergo mandatory virus scanning before delivery to the user environment.
Can I export data from my environment?
- Users cannot export data themselves from environments subject to the Secondary Use Act. Result exports are always performed by VISU administrators.
- Result export requests must be submitted through the service management system using a dedicated transfer request form.
- Sensitive research results may be exported by users directly.
Can I take screenshots or use the clipboard in VISU?
- Taking screenshots from a Secondary Use Act user environment on a personal computer is prohibited because it constitutes exporting data from a closed environment.
- Clipboard usage is subject to the same restrictions and cannot be used to copy data outside the environment without an approved export process.
What software is available?
- The University of Oulu provides a preinstalled software package containing commonly used applications. Additional software requirements should be specified in the order form.
How much storage space is available and can it be increased?
- Storage allocation is determined according to the order.
- Additional storage can be requested through the service management system using a change request form: https://ict.oulu.fi/21383/.
- Additional capacity becomes available after the requested changes have been implemented by administration.
Can I run long-running computations?
- Yes, provided they fit within the allocated resources.
- Long-running analyses may continue even if the browser connection is lost.
- Additional resources can be requested if workloads exceed available capacity.
- Maintenance periods may affect running jobs but are generally scheduled during
monthly maintenance windows.
Can I run my own scripts or software?
- Running custom scripts is permitted. Users may install software and libraries before research data are imported.
- Software requiring root or administrator privileges must be installed by administrators.
- Users are responsible for providing installation packages, licenses, and license fees.
- Administration evaluates software security and compatibility before installation but cannot guarantee functionality within the environment.
How quickly can additional software be installed?
- Installation typically takes 1 to 5 business days, depending on complexity and licensing requirements.
- Software requiring administrative privileges is installed by administration.
- Users must provide installation packages and valid licenses.
- Administration reserves the right to reject software that is deemed unsuitable for VISU.
5. How Do I Log In to VISU and My User Environment?
Multi-Factor Authentication (MFA)
Install an MFA application on your mobile phone and configure it according to the University of Oulu instructions, if it is not yet in use.
- Instructions are available at: https://ict.oulu.fi/21383/.
- Log in to VISU (desktop.visu.oulu.fi/guacamole/) using your web browser.
What should I do if I cannot log in to VISU?
- Ensure that your user account is active and that you have received a confirmation message indicating that your requested user environment has been created. If you are unsure whether your account is ready for use, contact customer support at ict@oulu.fi or call +358 294 483 124.
- Check your email for notifications regarding service disruptions or exceptional situations.
- Verify that you are using the correct login address.
- Verify that MFA authentication is functioning properly.
- Ensure that the Microsoft Authenticator application is updated to the latest version.
- Disable battery optimization for the application so that it can receive notifications in the background.
- Ensure that notifications are permitted for the application.
- Check that your phone is not in Do Not Disturb mode or Airplane Mode.
- Ensure that the device’s date and time are synchronized automatically, as manually configured time settings may prevent authentication.
- Switch between Wi-Fi and mobile data if notifications are not received.
- Disconnect any VPN connection that may interfere with authentication.
- If authentication does not work at all, you can reset your MFA registration.
- Go to https://account.oulu.fi/mfa.
- Sign in using Suomi.fi authentication with online banking credentials or a mobile certificate.
- You can then:
- Remove the old MFA method.
- Register a new phone or authentication method.
- If Suomi.fi authentication is unavailable or you no longer have access to your previous phone:
- Contact ict@oulu.fi or call +358 294 483 124.
- Alternatively, visit the Campus ICT Service Desk on the Linnanmaa campus (https://ict.oulu.fi/en/contact-information/).
The login page does not open. What should I do?
- Ensure that you are connected to the University VPN.
- Try another browser. When accessing VISU, it is recommended to use browsers supported by ICT Services:
- macOS: Edge, Safari, Chrome
- Windows: Edge, Chrome
- Linux: Edge, Chrome, Firefox
- If none of the above actions resolve the issue, record the error message and contact customer support. Describe the steps you have already taken to resolve the problem and include a screenshot of the error if possible.
I receive a notification that my account has been locked
- If your account has been locked, you will receive the following error message: ”Your account has been locked out due to excessive authentication failures. Please contact your administrator.”
- Account lockout is typically caused by too many failed authentication attempts. A locked account is usually unlocked automatically after approximately 20 minutes.
- If your account remains locked, contact customer support at ict@oulu.fi or call +358 294 483 124.
- Check your email. If the account lockout was initiated by administration, you should have received a notification from the administrators.
The software I installed indicates that the license needs updating
- If updating the license is required for your work to continue, contact administration by submitting a change request form.
- Include the identifier of your user environment and the name of the software requiring the license update.
- If the software is not provided by the University of Oulu, you must also supply a valid license.
A program freezes or I suspect that memory has run out. What should I do?
- Log out properly from the virtual desktop using “Log out” → “Sign out”, then log in again to start a clean session.
- If possible, research group members should schedule resource-intensive analyses at different times. This helps distribute resource usage evenly and prevents excessive simultaneous load.
- If you suspect memory exhaustion or applications become unresponsive, try the following:
- When you finish using the environment, always use the Log out button located in the upper-right corner of the virtual desktop under the power icon. This releases resources and helps prevent memory-related issues.
- Sign out: Releases the allocated resources and remote workstation. Use this option when you no longer need the session.
- If VISU becomes unresponsive or memory-related issues occur, sign out completely and then sign in again. This terminates the session and may resolve issues caused by temporary files.
Insufficient resources
- The resources originally ordered may be insufficient for your workload.
- Contact administration to review the resources allocated to your user environment and identify any limiting factors.
- If additional resources are required, submit a change request form to increase the capacity of the user environment.
How can a user obtain technical support?
- Support requests specifically related to VISU can be sent to visu-support@oulu.fi through the service management system. Administration will handle the request and communicate directly with the customer.
How quickly are support requests answered and when is support available?
- Support requests are handled as soon as possible during business days.
- Urgent issues and service interruptions are always prioritized.
- Support is not available during evenings, weekends, or public holidays.
- Support requests can be submitted to: visu-support@oulu.fi.
6. Legislation and Responsibilities
What should users know about the Secondary Use Act?
- Social and health care data may be used under the Finnish Act on the Secondary Use of Health and Social Data (552/2019) only when the data controller and Findata have granted the necessary permission.
- Users must comply with the following principles:
- Processing only as permitted: Data may only be used for the purpose specified in the permit.
- Use within a secure environment: Data may only be processed within an audited and registered secure processing environment. Users are prohibited from exporting data subject to the Secondary Use Act.
- No identification attempts: Users must not attempt to identify individual persons from the data.
- Activity logging: Use of the environment is logged and monitored at the authentication level.
- Consequences of misuse: Misuse of data may result in loss of access rights and legal consequences.
What are the user’s responsibilities?
- Users are responsible for complying with information security requirements, usage policies, and proper data handling.
- Users are responsible for ensuring that data are processed only in accordance with the terms of the data permit and only within the secure processing environment.
- Users must:
- Use data only for the purposes specified in the permit.
- Process data only within the approved processing environment.
- Refrain from attempting to identify individual data subjects.
- Accept and follow all user instructions and environment policies.
- Comply with information security and data protection regulations and accept the applicable security policies.
- Understand that all usage is logged and monitored.
- Misuse may result in the loss of access rights, notification of authorities, and potential legal consequences.
What happens if the rules are violated?
Each user is personally responsible for their own actions within the user environment. Violations of the rules may result in one or more of the following consequences:
- Revocation of access rights to the processing environment.
- Cancellation of the data permit for the entire organization.
- Notification of supervisory authorities such as Findata or the Office of the Data Protection Ombudsman.
- Disciplinary or employment-related actions (for example, a warning or termination of employment).
- Criminal penalties, for example in cases involving breaches of confidentiality or data protection legislation.
- Liability for damages if harm is caused to data subjects or the organization through the misuse of data.
Use this link to go to VISU website.