Back to Browse

Finnish Law MCP Server

Developer ToolsUse Caution4.2Local
Free

Query Finnish statutes from Finlex, EU cross-references, case law, and preparatory works

About

Query Finnish statutes from Finlex, EU cross-references, case law, and preparatory works

Security Report

4.2
Use Caution4.2High Risk

This Finnish law MCP server is a well-intentioned legal research tool with generally sound architecture and proper authentication. However, there are several moderate-severity concerns: unauthenticated local operation mode, reliance on external Finlex/EUR-Lex APIs without comprehensive error handling, shell command risks in ingestion scripts, and insufficient input validation on statute IDs. The server's stated purpose (legal research) aligns reasonably with its permissions (network, file I/O, env vars), but the combination of ingestion script complexity and potential path traversal vectors warrants user awareness. Supply chain analysis found 7 known vulnerabilities in dependencies (1 critical, 3 high severity). Package verification found 1 issue.

3 files analyzed · 17 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

File System Write

Writes or modifies files on your machine. Check that this is expected for the tool.

env_vars

Check that this permission is expected for this type of plugin.

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "eu-ansvar-finnish-law-mcp": {
      "args": [
        "-y",
        "@ansvar/finnish-law-mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

Finnish Law MCP Server

The Finnish law corpus is now served through the Ansvar Gateway. Connect your AI assistant (Claude, Copilot, Cursor, custom MCP client) to https://gateway.ansvar.eu/mcp — one OAuth connection, free tier available, covering this corpus plus EU regulations, national law across dozens of audited jurisdictions (Europe + the US), and CVE/security intelligence, every result with a verbatim source citation. Start at https://ansvar.eu/docs/quickstart

Connect

Claude Code (one line):

claude mcp add ansvar --transport http https://gateway.ansvar.eu/mcp

Claude Desktop / Cursor — add to claude_desktop_config.json (or mcp.json):

{
  "mcpServers": {
    "ansvar": {
      "type": "url",
      "url": "https://gateway.ansvar.eu/mcp"
    }
  }
}

Claude.ai — Settings → Connectors → Add custom connector → paste https://gateway.ansvar.eu/mcp

First request opens an OAuth signup flow (setup details: ansvar.eu/docs/quickstart). After signup, your client is bound to your account; tier (free / premium / team / company) determines fan-out, quota, and which downstream MCPs are reachable.


Self-host this MCP

You can also clone this repo and build the corpus yourself. The schema, fetcher, and tool implementations all live here. What is not in the repo is the pre-built database — TDM and standards-licensing constraints on the upstream sources mean we host the corpus on Ansvar infrastructure rather than redistribute it as a public artifact.

Build your own: run this repo's ingestion script (entry-point varies per repo — typically scripts/ingest.sh, npm run ingest, or make ingest; check the repo root).

The Finlex alternative for the AI age.

MCP Registry License GitHub stars CI Daily Data Check Database Provisions

Query Finnish statutes -- from Tietosuojalaki and Rikoslaki to Osakeyhtiölaki, Ympäristönsuojelulaki, and more -- directly from Claude, Cursor, or any MCP-compatible client.

If you're building legal tech, compliance tools, or doing Finnish legal research, this is your verified reference database.

Built by Ansvar Systems -- Helsinki, Finland


Why This Exists

Swedish legal research is scattered across Riksdagen, SFS publications, lagen.nu, and EUR-Lex. Whether you're:

  • A lawyer validating citations in a brief or contract
  • A compliance officer checking if a statute is still in force
  • A legal tech developer building tools on Swedish law
  • A researcher tracing legislative history from proposition to statute

...you shouldn't need 47 browser tabs and manual PDF cross-referencing. Ask Claude. Get the exact provision. With context.

This MCP server makes Swedish law searchable, cross-referenceable, and AI-readable.


Example Queries

Once connected, just ask naturally:

  • "What does Dataskyddslagen 3 kap. 5 § say about consent?"
  • "Is PUL (1998:204) still in force?"
  • "Find provisions about personuppgifter in Swedish law"
  • "What EU directives does DSL implement?"
  • "Which Swedish laws implement the GDPR?"
  • "Get the preparatory works for Dataskyddslagen"
  • "Compare incident reporting requirements across NIS2 Swedish implementations"
  • "Validate the citation NJA 2020 s. 45"
  • "Find Labour Court cases about discrimination from 2020-2023"

What's Included

CategoryCountDetails
Statutes717 lawsComprehensive Swedish legislation
Provisions31,198 sectionsFull-text searchable with FTS5
Preparatory Works3,625 documentsPropositions (Prop.) and SOUs
EU Cross-References668 references228 EU directives and regulations
Legal Definitions615 termsExtracted from statute text
Database Size~70 MBOptimized SQLite, portable
Daily UpdatesAutomatedFreshness checks against Riksdagen

Verified data only -- every citation is validated against official sources (Riksdagen, lagen.nu, EUR-Lex). Zero LLM-generated content.


See It In Action

Why This Works

Verbatim Source Text (No LLM Processing):

  • All statute text is ingested from Riksdagen/SFS official sources
  • Provisions are returned unchanged from SQLite FTS5 database rows
  • Zero LLM summarization or paraphrasing -- the database contains regulation text, not AI interpretations

Smart Context Management:

  • Search returns ranked provisions with BM25 scoring (safe for context)
  • Provision retrieval gives exact text by SFS number + chapter/section
  • Cross-references help navigate without loading everything at once

Technical Architecture:

Riksdagen API → Parse → SQLite → FTS5 snippet() → MCP response
                  ↑                      ↑
           Provision parser       Verbatim database query

Traditional Research vs. This MCP

Traditional ApproachThis MCP Server
Search Riksdagen by SFS numberSearch by plain Swedish: "personuppgifter samtycke"
Navigate multi-chapter statutes manuallyGet the exact provision with context
Manual cross-referencing between lawsbuild_legal_stance aggregates across sources
"Is this statute still in force?" → check manuallycheck_currency tool → answer in seconds
Find EU basis → dig through EUR-Lexget_eu_basis → linked EU directives instantly
Check 5+ sites for updatesDaily automated freshness checks
No API, no integrationMCP protocol → AI-native

Traditional: Search Riksdagen → Download SFS PDF → Ctrl+F → Cross-reference with proposition → Check EUR-Lex for EU basis → Repeat

This MCP: "What EU law is the basis for DSL 3 kap. 5 § about consent?" → Done.


Available Tools (13)

Core Legal Research Tools (8)

ToolDescription
search_legislationFTS5 search on 31,198 provisions with BM25 ranking
get_provisionRetrieve specific provision by SFS + chapter/section
search_case_lawFTS5 search on case law with court/date filters
get_preparatory_worksGet linked propositions and SOUs for a statute
validate_citationValidate citation against database (zero-hallucination check)
build_legal_stanceAggregate citations from statutes, case law, prep works
format_citationFormat citations per Swedish conventions (full/short/pinpoint)
check_currencyCheck if statute is in force, amended, or repealed

EU Law Integration Tools (5)

ToolDescription
get_eu_basisGet EU directives/regulations for Swedish statute
get_swedish_implementationsFind Swedish laws implementing EU act
search_eu_implementationsSearch EU documents with Swedish implementation counts
get_provision_eu_basisGet EU law references for specific provision
validate_eu_complianceCheck implementation status (future, requires EU MCP)

EU Law Integration

668 cross-references linking 49 Swedish statutes to EU law, with bi-directional lookup.

MetricValue
EU References668 cross-references
EU Documents228 unique directives and regulations
Swedish Statutes with EU Refs49 (68% of database)
Directives89
Regulations139
EUR-Lex IntegrationAutomated metadata fetching

Most Referenced EU Acts

  1. eIDAS Regulation (910/2014) - 20 references
  2. E-Signatures Directive (1999/93) - 15 references
  3. GDPR (2016/679) - 15 references
  4. Data Protection Directive (1995/46) - 14 references
  5. Market Surveillance Regulation (2019/1020) - 14 references

See EU_INTEGRATION_GUIDE.md for detailed documentation and EU_USAGE_EXAMPLES.md for practical examples.


Data Sources & Freshness

All content is sourced from authoritative Swedish legal databases:

Automated Freshness Checks (Daily)

A daily GitHub Actions workflow monitors all data sources:

SourceCheckMethod
Statute amendmentsRiksdagen API date comparisonAll 717 statutes checked
New statutesRiksdagen SFS publications (90-day window)Diffed against database
Case lawlagen.nu feed entry countCompared to database
Preparatory worksRiksdagen proposition API (30-day window)New props detected
EU reference stalenessGit commit timestampsFlagged if >90 days old

The workflow supports auto_update: true dispatch for automated sync, rebuild, version bump, and npm publishing.


Security

This project uses multiple layers of automated security scanning:

ScannerWhat It DoesSchedule
CodeQLStatic analysis for security vulnerabilitiesWeekly + PRs
SemgrepSAST scanning (OWASP top 10, secrets, TypeScript)Every push
GitleaksSecret detection across git historyEvery push
TrivyCVE scanning on filesystem and npm dependenciesDaily
Docker SecurityContainer image scanning + SBOM generationDaily
Socket.devSupply chain attack detectionPRs
OSSF ScorecardOpenSSF best practices scoringWeekly
DependabotAutomated dependency updatesWeekly

See SECURITY.md for the full policy and vulnerability reporting.


Important Disclaimers

Legal Advice

THIS TOOL IS NOT LEGAL ADVICE

Statute text is sourced from official Riksdagen/SFS publications. However:

  • This is a research tool, not a substitute for professional legal counsel
  • Court case coverage is limited -- do not rely solely on this for case law research
  • Verify critical citations against primary sources for court filings
  • EU cross-references are extracted from Swedish statute text, not EUR-Lex full text

Before using professionally, read: DISCLAIMER.md | PRIVACY.md

Client Confidentiality

Queries go through the Claude API. For privileged or confidential matters, use on-premise deployment. See PRIVACY.md for Advokatsamfundet compliance guidance.


Documentation


Development

Setup

git clone https://github.com/Ansvar-Systems/swedish-law-mcp
cd swedish-law-mcp
npm install
npm run build
npm test

Running Locally

npm run dev                                       # Start MCP server
npx @anthropic/mcp-inspector node dist/index.js   # Test with MCP Inspector

Data Management

npm run ingest -- <sfs-number> <output.json>   # Ingest statute from Riksdagen
npm run ingest:cases:full-archive              # Ingest case law (full archive)
npm run sync:cases                             # Ingest case law (incremental)
npm run sync:prep-works                        # Sync preparatory works
npm run extract:definitions                    # Extract legal definitions
npm run build:db                               # Rebuild SQLite database
npm run check-updates                          # Check for amendments

Performance

  • Search Speed: <100ms for most FTS5 queries
  • Database Size: ~70 MB (efficient, portable)
  • Reliability: 100% ingestion success rate

More Ansvar MCPs

Full fleet coverage at ansvar.eu/coverage.

Contributing

Contributions welcome! See CONTRIBUTING.md for guidelines.

Priority areas:

  • Court case law expansion (currently limited coverage)
  • EU Regulations MCP integration (full EU law text, CJEU case law)
  • Historical statute versions and amendment tracking
  • Lower court decisions (Tingsrätt, Hovrätt)

Roadmap

  • Statute expansion -- 785% growth from 81 to 717 statutes (v1.1.0)
  • EU law integration -- 668 cross-references to 228 EU directives/regulations (v1.1.0)
  • Court case law expansion (scraper updated, re-ingestion needed for 12K-18K cases)
  • Lower court coverage (Tingsrätt, Hovrätt archives)
  • Historical statute versions (amendment tracking)
  • English translations for key statutes
  • Web API for programmatic access

Citation

If you use this MCP server in academic research:

@software{swedish_law_mcp_2025,
  author = {Ansvar Systems AB},
  title = {Swedish Law MCP Server: Production-Grade Legal Research Tool},
  year = {2025},
  url = {https://github.com/Ansvar-Systems/swedish-law-mcp},
  note = {Comprehensive Swedish legal database with 717 statutes and EU law cross-references}
}

License

Apache License 2.0. See LICENSE for details.

Data Licenses

  • Statutes & Decrees: FI-Statutory-PD — Finnish statutory public domain. Tekijänoikeuslaki 9 § (404/1961 as amended by 608/2015) excludes laws and decrees, decisions and statements of public authorities, and authority-produced translations of these works from copyright protection. Verified verbatim 2026-05-17 — see docs/audits/2026-05-17-eu-copyright-statutory-works-batch-1a-AT-BE-DK-FI-FR.md. Catalog entry: FI-Statutory-PD in infrastructure/attribution-licenses.json.
  • Case Law: Finnish court decisions — same statutory basis (Tekijänoikeuslaki 9 § public-authority-decisions clause)
  • EU Metadata: EUR-Lex (EU public domain, Decision 2011/833/EU)

About Ansvar Systems

We build AI-accelerated compliance and legal research tools for the European market. This MCP server started as our internal reference tool for Swedish law -- turns out everyone building for the Swedish market has the same research frustrations.

So we're open-sourcing it. Navigating 717 statutes shouldn't require a law degree.

ansvar.eu -- Stockholm, Sweden


Reviews

No reviews yet

Be the first to review this server!