<quote>According to NordVPN's official statement on the affair, the server was rented and based in a data center in Finland.</quote>
Haha, why am I not surprised? Speaking from personal experience, not just NordVPN...
You don't put the words "secure" and "Finland" in one sentence. Their (Finn's) attutide towards data security is years behind and in some cases non-existant. In some companies you'll find private data on Sharepoint (or any other collaboration platform) with no lock down. They have no idea what an IT security audit is. When you politely raise this with your manager they'll brush you off. It is assumed that data is accessed only by people who are meant to see it. They are basically heavily relying on "trust". While this may work perfectly fine inside Finland it's not how the rest of the world (or IT) works.
If someone tells you your data is stored/managed in Finland - run as far as you can.