Awareness and Training of Employees – A Data Protection Factor for Pension Funds
Pension funds store and process large amounts of personal data of insured persons — including particularly sensitive data, such as health information. The protection of this data is crucial. However, this protection can only be effective if the employees of the pension fund are properly trained and made aware of data protection requirements. After all, they are the ones who access and process personal data. Their mistakes pose real risks to data security. This is why employee training and awareness-raising are essential components of every security strategy.
- Why Awareness Matters – The Risks of Human Error
A large share of data protection violations doesn’t stem from malicious intent, but rather from ignorance, mistakes, or carelessness. Common examples include:
- Emails with sensitive data being sent to the wrong recipients
- Passwords being stored insecurely or shared
- Phishing emails being opened
- Paper files being improperly disposed of
Such incidents jeopardize not only the trust of insured persons, but also the legal security of the pension fund. A single mistake may trigger an obligation to report the breach to the Swiss Federal Data Protection and Information Commissioner (FDPIC) — with potential financial and reputational consequences.
- Training as an Element of Organizational Security
According to the Swiss Data Protection Act, pension funds, as data controllers, are required to implement appropriate technical and organizational measures. Training employees in data protection is a critical organizational measure. Anyone who processes personal data must understand:
- The principles of data processing and which personal data is considered particularly sensitive;
- Which personal data is required for their tasks and which data they are authorized to access;
- What internal rules and policies the pension fund has implemented for data protection — and how to comply with them;
- What risks exist when processing personal data and how to minimize them;
- What rights data subjects have, and how requests from data subjects should be handled internally;
- What to do in case of a suspected data breach;
- Who the internal points of contact are for data protection-related questions.
- Best Practices for Effective Awareness and Training:
To ensure your training measures are effective and not just seen as a tedious obligation, the following points should be considered:
- All new employees should be informed about the pension fund’s internal data protection policies and behavioral guidelines before they start processing any data.
- Not all employees require the same information. Training content should be tailored to specific roles and responsibilities. For example, IT personnel should be trained on technical security, telecom confidentiality, and interaction with data processors. Technical service staff should be trained on handling insured persons’ data in a data protection-compliant manner. HR staff should receive training on processing employee data lawfully and securely.
- One-off seminars are not enough. New legal requirements, changes in business processes, and emerging threats make regular refreshers necessary. Therefore, data protection training should be repeated at least annually.
- Training content should be practical and relevant to the daily work of the pension fund, using realistic examples from the work environment.
Practical experience shows that interactive workshops and in-person training sessions are the most effective and sustainable methods of raising awareness. These allow for experience sharing, in-depth discussion, and individual questions.