Obligations of Pension Funds in Granting Data Protection Rights to Insured Persons

Pension funds must implement appropriate measures to protect the personal data of insured persons. Insured individuals rely on their personal data being handled securely and responsibly. But what rights do the insured have with respect to their data, and how can pension funds ensure that these rights are upheld.

Under the Swiss Data Protection Act (DSG), insured individuals have certain rights that are legally protected. For pension funds, it is essential not only to understand and comply with these legal requirements, but also to implement them in their internal processes. Among other things, insured individuals have the following data protection rights:

  • Right to Information: According to Art. 25 DSG, individuals have the right to request information about whether personal data about them is being processed;
  • Correction, Deletion, or Restriction: Under Art. 41 DSG, individuals may request that personal data be corrected, deleted, or destroyed. Alternatively, instead of deletion, processing may be restricted if, the accuracy of the data is contested and neither its accuracy nor inaccuracy can be determined; the restriction is required due to overriding interests of third parties; there is an overriding public interest; deletion or destruction would jeopardize an investigation or legal proceeding;
  • Data Portability : If personal data is processed automatically and with the person’s consent or directly in connection with the conclusion or execution of a contract, Art. 28 DSG allows individuals to request their data in a commonly used electronic format or to have it transferred to another controller.

The right to information is the most comprehensive, operationally intensive, and potentially consequential right. Providing deliberately false or incomplete information may result in criminal prosecution under Art. 60 DSG, with fines of up to CHF 250,000. Additionally, mishandling such requests can severely damage the pension fund’s reputation. Therefore, it is crucial to establish robust internal procedures to ensure legal compliance. Pension funds should implement clear and transparent processes for identifying and responding to data subject requests.

Designing an Appropriate Process for Handling Information Requests (Art. 25 DSG):

  • Secure Identification of Requests:
    In general, requests should be made in writing. However, they are not required to follow a specific format or be addressed to a specific department. Therefore, requests may be submitted to various contact points within the pension fund. Employees must be well-trained to recognize such requests and direct them into the proper handling process. Training should be regularly repeated.

  • Identification of the Requester:
    Pension funds must take appropriate measures to verify the identity of the requesting individual, who is also required to cooperate. This is particularly important, as applicants may provide false names or email addresses. If a request is processed without verifying identity, personal data of uninvolved third parties could be disclosed, violating their privacy rights.

  • Costs:
    Requests for information are generally free of charge. However, if responding requires disproportionate effort, the pension fund may ask the individual to contribute to the cost, up to a maximum of CHF 300. This fee must be communicated in advance, and if the person does not confirm acceptance of the cost within ten days, the request is considered withdrawn without consequence.

  • Time Limits:
    The response must be provided within 30 days of receiving the request. If this is not possible, the pension fund must inform the individual and specify when the response will be delivered. If the request is denied or restricted, the person must be informed within the same time frame.

  • Completeness of the Response:
    The response must be complete and presented in an understandable form. It must include all data stored and processed by the pension fund, including data processed by data processors (e.g., external service providers managing systems). These processors are obligated to support the pension fund, e.g., by helping identify and compile relevant data. According to Art. 25 DSG, a complete response must at least include:

    • Confirmation that personal data is being processed;
    • Identity and contact details of the controller;
    • The personal data itself;
    • Purposes of processing;
    • Retention period or criteria for determining it;
    • Available information on the origin of the data, if not collected from the individual;
    • Any existence of automated individual decision-making, including the logic behind it;
    • Recipients or categories of recipients, as well as safeguards for protecting the individual during data transfers.
  • Form of the Response:
    The information may be provided electronically, in writing, or in the format in which the data exists. Under the Swiss Data Protection Ordinance, responses can also be given orally, with the person’s consent. The individual may also inspect the data on-site if agreed with the controller.

  • Refusal to Provide Information:
    According to Art. 26 DSG, there are legitimate grounds for refusing or delaying access. For example:

    • To protect the privacy and data protection interests of third parties, the pension fund may refuse to disclose information not solely related to the requesting individual (e.g., data about beneficiaries, employees, or other insured persons).
    • If the request is abusive, frivolous, or serves unlawful purposes, the pension fund may deny it or ask for clarification.

Conclusion

The responsibility of pension funds in protecting personal data goes far beyond merely complying with legal requirements. Complying with data protection obligations not only helps avoid substantial fines—it is also key to maintaining the trust of insured individuals. A thoroughly implemented data protection framework that meets all requirements of the Swiss Data Protection Act demonstrates both competence and accountability. Through transparent processes, regular employee training, and the consistent use of modern security measures, data protection becomes a strategic success factor. This is the only way to sustainably build trust among insured individuals and preserve the institution’s good reputation over the long term.