Data Protection Impact Assessment (DPIA): When Is It Required for Pension Funds in Switzerland
With the revised Swiss Federal Act on Data Protection (FADP), the requirements for handling personal data have been significantly tightened. A key new obligation is the requirement to conduct a Data Protection Impact Assessment (DPIA) when planned data processing is likely to result in a high risk to the personality or fundamental rights of the individuals concerned. For pension funds, which regularly process particularly sensitive personal data—such as health information, benefits-related data, or insurance-related details—this topic is becoming increasingly relevant. The DPIA is intended to give the data controller the opportunity to proactively assess the risks associated with the data processing and to identify measures to mitigate those risks, as well as to adapt technical and organizational measures to the level of expected risk.
Criteria for a DPIA under the Swiss FADP
According to Art. 22 FADP, a DPIA must be carried out if the data processing may involve a high risk to the personality or fundamental rights of the affected individuals. This is generally the case when there is processing of particularly sensitive personal data , including health data and information related to social welfare measures. A high risk may also arise when new technologies are used. According to the Federal Data Protection and Information Commissioner (FDPIC), “high-risk profiling” as defined in Art. 5 letter g FADP also qualifies. Federal bodies must always assess whether the nature, scope, or context of the processing creates high risk to the fundamental rights of individuals. This includes restrictions of informational self-determination or the right to privacy. Indicators of high-risk processing in terms of scope include: a large volume of personal data, a large number of affected individuals, long-term processing, processing over a wide geographical area. A helpful tool for assessing risk is the Risk Pre-Assessment Tool developed by the Federal Office of Justice, available here: https://www.bj.admin.ch/dam/bj/de/data/staat/datenschutz/instrument-risikovorpruefung.xlsx.download.xlsx/instrument-risikovorpruefung-d.xlsx
A DPIA may be necessary if the pension fund uses a cloud solution for data processing and storage. A DPIA may also be necessary if there is a change of outsourcing partner(s), for example if technical administration has been outsourced to a third party and this service provider is to be changed
Approach and Methodology
The responsible entity is required to assess whether a DPIA is necessary. According to Art. 26 of the Data Protection Ordinance (DPO), the Data Protection Advisor must assist and review the DPIA for federal bodies. While the FADP provides the legal framework, it largely leaves the implementation to the data controller. According to Art. 22 para. 3 FADP, the DPIA must include a description of the planned processing, an evaluation of risks to the personality or fundamental rights of data subjects, measures to protect personality and fundamental rights. The following steps have been proven effective in practice:
- Conduct a threshold analysis to determine whether a DSFA is required. At a minimum, this should involve checking whether extensive processing of sensitive personal data is taking place, or whether public areas are being systematically and extensively monitored.
- Conduct the DPIA
- Describe the planned data processing. This should cover the nature, purpose, scope and duration of the processing, as well as the parties involved (e.g. IT service providers). Additionally, any circumstances that contribute to a high risk should be documented.
- Identify the risks: These risks can be categorised as either information security risks, such as system failure, data loss or manipulation, and lack of availability, or data protection risks, such as misuse, unauthorised access, incorrect data processing and lack of data subject rights).
- Evaluate the risks in terms of personality and fundamental rights, providing an assessment of the probability of occurrence and potential impact, such as discrimination, financial disadvantages, or limitations to the right to informational self-determination or privacy.
- Define the protective measures that will mitigate the risks (e.g. data minimisation, access restrictions, encryption, regular audits and raising employee awareness) and allocate these measures to the relevant risks.
- Evaluate residual risk. If the DPIA reveals that the risk remains high, the FDPIC must be consulted before data processing begins. The FDPIC will issue a statement within two months, which must be documented in the DPIA results.
The DSFA must be recorded in writing. It serves as evidence for supervisory authorities and, according to Art. 14 DPO, must be kept for at least two years after the end of the data processing.