Security Measures for Data Protection in the Swiss Pension Fund Industry
In an increasingly digital world, protecting sensitive data is essential. Pension funds, in particular, bear a tremendous responsibility to maintain the trust of their members—a challenge that becomes even more complex when the pension fund is integrated into the IT system landscape of large corporate groups.
The Swiss Federal Administrative Court has already made it clear in its ruling of April 10, 2012 (A 4467/2011): Pension schemes may only provide employers with personal data that is objectively necessary for fulfilling tasks defined in the employment contract and within the framework of occupational pension provision. Unauthorized access to the personal data of insured persons and retirees violates the principle of data security. Therefore, the separation between employer and pension fund must be ensured not only technically, but also contractually and organizationally. Shared IT systems must not allow employers unauthorized access to personal data of the insured. IT services must remain absolutely impermeable to unauthorized employer access to insured persons’ data.
If a pension fund is integrated into the IT infrastructure and organization of a corporate group, the following contractual measures can help with data protection and delineation:
-
Clear regulations for employers and independently acting IT service companies within the corporate group: Agreements should include obligations to treat personal data as strictly confidential and strictly purpose-bound. Access to such data must be permitted only for contractually well-defined and specific purposes.
-
Conclusion of data processing agreements with external service providers: These contracts should ensure that data processing is carried out only on the instructions of the pension fund. If service providers are part of the corporate group, it must be clearly defined that the pension fund is the only authority authorized to issue instructions to these service providers.
-
Approval for sub-processors : If a service provider wishes to involve additional sub-processors, this may only occur with the explicit prior consent of the pension fund. Personal data may only be transferred to an additional sub-processor once approval has been granted.
-
Restrictions on powers of attorney : Ensure clarity and control. If the IT service company within a corporate group is granted power of attorney to conclude contracts and agreements for data processing on behalf of group companies, clear limitations must be defined. These restrictions should ensure that systems managing the technical aspects of the pension fund are not inappropriately influenced or used.
-
Sanctions for violations : Contracts should include penalties in the event that data protection regulations are not complied with.