Skip to content

Although many pension funds have implemented initial measures, key obligations – such as records of processing activities broken down into procedures under the mandatory provisions of the BVG and private insurance, records of data processing, data protection impact assessments and clear lines of responsibility – are still incomplete in some cases. In light of new risks, the FDPIC is stepping up its monitoring. Read on to find out what you need to do and how to ensure your organisation is compliant with the law.

Introduction

With the revised Data Protection Act (DSG) coming into force on 1 September 2023, the regulatory environment regarding data protection for Swiss pension funds has become significantly more stringent. First of all, it must be clarified which data protection regime a pension fund and its service provider are subject to. Compliance measures must then be put in place to ensure the requirements are properly implemented.

Applicable provisions

For pension funds, the following statutory provisions are particularly relevant under data protection law:

  • Federal Act on Occupational Old-Age, Survivors’ and Disability Pension Provision (BVG; SR 831.40): Contains specific provisions on data processing by pension funds, in particular Article 85a BVG (‘Protection of personal rights in data processing’). This provision obliges pension funds to observe the principles of proportionality, purpose limitation and transparency. The provisions of the BVG take precedence over data protection regulations as lex specialis.
  • Ordinance on Occupational Old-Age, Survivors’ and Disability Pension Provision (BVV 2; SR 831.441.1): Specifies the processing of data in connection with actuarial tasks (see Article 96a BVV 2 on the processing of health data).
  • Federal Act on the General Part of Social Insurance Law (ATSG, SR 830.1): The General Part of Social Insurance Law also applies to pension funds. There are a number of topics, for example concerning electronic data exchange (Art. 76a ATSG) and access to files (Art. 47 ATSG), which are also relevant to data protection issues affecting pension funds.
  • Vested Benefits Act (FZG; SR 831.42): Regulates the entitlements and procedures upon leaving a pension fund, in particular the transfer of vested benefits to a new institution. In this context, master data, vested benefits, the technical interest rate, the duration of insurance and the date of birth may be processed.
  • Federal Act on Accident Insurance (UVG; SR 832.20): Applies when pension funds need to coordinate benefits with accident insurers, particularly in the case of supplementary insurance or parallel pension payments. Article 97 of the UVG permits the processing and exchange of health data, details of the circumstances of the accident and benefit decisions between the insurance providers involved.
  • Federal Act on Disability Insurance (IVG; SR 831.20): This is particularly relevant when assessing a degree of disability or coordinating pension entitlements. Under Article 66a et seq. of the IVG, pension funds may access IV decisions, medical reports and information on capacity for work in order to properly assess their own benefit obligations.
  • Data Protection Act (DSG; SR 235.1): The DSG applies in principle to all data processing carried out by private and public bodies in Switzerland. Among other things, it regulates the principles of lawful data processing (Art. 6 DSG), the duty to provide information (Art. 19 DSG), the right of access (Art. 25 DSG), as well as the data protection impact assessment (Art. 22 DSG) and reporting obligations in the event of data security breaches (Art. 24 DSG).
  • Data Protection Ordinance (DSV; SR 235.11): Supplements the DSG with detailed implementing provisions, for example on the structure of data processing registers, the form in which information is to be provided, or risk assessment.
  • Swiss Code of Obligations (CO; SR 220), Art. 328b CO: Employers – and thus also pension funds in their dealings with their employees – may only process data insofar as it relates to the employee’s suitability for the employment relationship or is necessary for the performance of the employment contract. This provision is often understood as a data protection requirement under employment law and may also apply to personnel-related processes within the pension fund.
  • Swiss Civil Code (ZGB; SR 210), Art. 28 et seq.: These provisions provide comprehensive protection for the personality rights of data subjects. The processing of personal data may fall under Art. 28 ZGB if it infringes the right to privacy or personal integrity. In the event of a dispute, claims for injunctive relief, rectification or damages may be asserted.
Legislation Relevant articles Typical situation in pension funds Permissible data
BVG Articles 85a–85e BVG Comprehensive administration of occupational pension schemes: enrolment, withdrawal, benefit claims, lump-sum withdrawals, coordination Master data, salary, contribution data, periods of insurance, health data, marital status, dependants
UVG Art. 97 Coordination of accident benefits, supplementary insurance and parallel pensions Health data, circumstances of the accident, benefit decisions
IVG Art. 66a–b Disability assessments, entitlement to a pension, integration measures Expert reports, IV decisions, capacity for work
KVG Art. 84–84a Co-ordination of daily allowances, illness-related disability Diagnoses, periods of sick leave, medical correspondence
AHVG Art. 50c–e Old-age pension adjustment, survivors’ benefits Pension amounts, insurance numbers, family circumstances
FZG Art. 8, 22c, 22d, 24d, 22f, 24fbis Withdrawal, transfer of vested benefits, change of pension fund Vested benefits, technical interest rate, date of birth, period of insurance

Federal body or private controller?

For mandatory pension schemes, Art. 2(1)(a) of the Data Protection Act (DSG) is decisive, according to which federal bodies (including institutions organised under public law or acting on the statutory mandate of the Confederation) are subject to specific data protection requirements.

By contrast, non-mandatory pension schemes are regarded as private data controllers within the meaning of Article 5(j) of the Data Protection Act (DSG), which is why the general provisions of the DSG and the Data Protection Ordinance (DSV) applicable to private individuals primarily apply to them (Article 40 DSG).

However, the pension fund does not carry out the management and day-to-day operations itself, but has delegated these tasks to a so-called service company, which undertakes the associated activities. The contract is concluded with the service company and not with individual employees. In this case, this service company – acting through its employees – generally also determines (solely) how personal data is processed. It thus becomes the so-called ‘controller’ under data protection law, i.e. it is directly responsible for compliance with most of the obligations under the DSG.

If a pension fund foundation has transferred its management and day-to-day operations to a so-called service company, which takes on all tasks relating to administration, it makes the key decisions regarding the purposes and means of processing personal data. In particular, it determines which data is processed and in what manner, and acts on its own responsibility in doing so. It thus becomes the data controller within the meaning of the DSG and is therefore responsible for compliance with data protection requirements. However, it may well be the case that, under the terms of the service contract, responsibility remains with the pension fund foundation and the service company therefore remains solely a data processor. A clear provision helps to clarify this between the parties.

Key data protection obligations

Depending on whether they operate in the mandatory or supplementary sector, pension funds are subject to either public-law or private-law data protection legislation. This has a direct impact on the scope and nature of their data protection obligations.

Obligations for all pension funds (in both the mandatory and supplementary sectors):

  • Compliance with the fundamental data protection principles (Art. 6 of the Data Protection Act): Compliance with the fundamental data protection principles set out in Art. 6 of the Data Protection Act is mandatory for both the pension fund (PF) and its contracted service provider. These principles – in particular lawfulness, proportionality, purpose limitation, transparency, accuracy of data and data security – must be upheld whenever personal data is processed. If data processing is carried out by a service provider, it must be ensured that the service provider also strictly complies with these requirements. Where the service provider acts as the data controller, it bears the direct responsibility for implementing the fundamental principles. This includes, in particular, ensuring that the processing serves a clear, legally permissible purpose, that only as much data as is necessary for this purpose is processed, and that appropriate technical and organisational measures are taken to protect the data. If, on the other hand, the service provider acts as a data processor, responsibility under data protection law remains with the pension fund, which must ensure that the service provider is contractually obliged to comply with the data protection principles and must monitor such compliance. In both cases, it is crucial that the fundamental principles are not merely complied with in a formal sense, but are effectively implemented in day-to-day processing practices.
  • Register of processing activities (Art. 12 FADP in conjunction with Art. 3 et seq. FADP):
    It is mandatory to maintain a detailed register of processing activities in accordance with Article 12 of the Data Protection Act. This must include all processing purposes, the categories of personal data and the categories of data subjects, the categories of recipients, the retention period for personal data or the criteria for determining this period, the measures to ensure data security in accordance with Article 8 of the FAD, as well as details of the country to which personal data is disclosed and the safeguards in place pursuant to Article 16(2). Even for seemingly small organisations, the exemption does not apply, as data requiring special protection, such as health or salary data, is regularly processed (Art. 24(a) of the Data Protection Ordinance). A template for a processing register from ASIP can be found here.
  • Privacy by Design and Default (Article 7 of the DSG):
    In line with the principles of Privacy by Design and Default, pension funds must also ensure that data protection is guaranteed as standard right from the planning and design stage of IT systems and business processes. This applies in particular to digitised benefit processes, internal administrative systems and external platforms. In practice, this is achieved whenever processing operations are also subject to a data protection impact assessment (see the following point), as this involves in-depth consideration of risks and mitigation measures.
  • Data Protection Impact Assessment (DPIA; Art. 22 DPA in conjunction with Art. 6 DPA Regulation):
    Where there is a high risk to fundamental rights – e.g. when processing health data, profiling data or new technologies – a structured risk analysis is required.
  • Notification of data breaches (Art. 24 DSG):
    Breaches posing a high risk to data subjects must be reported to the FDPIC without delay. It is advisable to document the incident and carry out a risk assessment before making a notification. The pension fund is required to define an appropriate process and to test it in advance. Notifications to the FDPIC that may reach the threshold of high risk can be made via the notification form
  • Information obligations (Art. 19 FADP and Art. 86b BVG):
    Data subjects must be informed transparently about the scope, purpose, recipients, retention periods and their rights – in writing, in a comprehensible manner and in a timely fashion. In doing so, the minimum content of the information required for each processing operation must be observed. In addition, there are specific statutory information obligations under Art. 86b of the BVG, some of which involve personal data.
  • Contracts with data processors (Art. 9 DSG in conjunction with Art. 7 DSV): Pension funds must establish data protection-compliant arrangements with their data processors. This includes, in particular, compliance with instructions, subcontracting clauses, security requirements and data return. You can obtain a template for data processing agreements from us for a fee.
  • Appointment of a data protection officer (Art. 10(1) DSG): For activities falling purely within the non-mandatory scope, the appointment of a data protection officer is not compulsory. However, this means that the EDÖB must be consulted in the event of data protection impact assessments (Art. 23 DSG). See, however, the section below regarding the mandatory scope.

Extended obligations for federal bodies (in the mandatory area):

  • Existence of a legal basis (Art. 34 FADP): Federal bodies may, in principle, only process personal data if there is a legal basis for doing so. Article 85a of the Federal Pension Act (BVG) governs the protection of personal rights in relation to data processing. According to this, personal data may only be processed by the pension fund if this is necessary to fulfil the statutory tasks of occupational pension provision. Personal data requiring special protection and personality profiles may only be processed if this is essential for the fulfilment of these tasks. This further emphasises the principles of purpose limitation, proportionality, transparency and necessity. A legal basis in the formal sense is always required where personal data requiring special protection is processed, where profiling takes place, or where the nature or purpose of the processing potentially constitutes a serious interference with the fundamental rights of the data subject. Exceptionally, in cases of profiling or the processing of data requiring special protection, a legal basis in the substantive sense is also sufficient – provided that the processing is indispensable for the fulfilment of a task defined in a formal law and the purpose of the processing does not entail any particular risks to the data subject’s fundamental rights. Irrespective of the above requirements, federal bodies may also process personal data where the data subject has given their explicit consent or where the data subject has made their data generally accessible without objecting to the processing. Furthermore, processing is permitted if it is necessary to protect the life or physical integrity of the data subject or a third party and timely consent cannot be obtained. Finally, the Federal Council may authorise the processing provided it concludes that this does not jeopardise the rights of the data subject. Consequently, a legal basis analysis must always be carried out before any processing can take place (see the FDPIC’s guidance note on ‘Planning and Justification of Online Access to Personal Data’). Depending on the circumstances, a data protection impact assessment may also be required.
  • Drawing up processing regulations (Art. 6 DVV): Where a pension fund or a data processor commissioned by it carries out automated data processing, processing regulations must be drawn up provided that one of the following conditions is met:
  • Personal data requiring special protection is processed,
  • profiling is carried out,
  • the processing is carried out on the basis of Section 34(2)(c) of the Data Protection Act (refusal of rights of access where there is an overriding public interest),
  • personal data is disclosed to cantons, foreign authorities, international organisations or private individuals,
  • datasets are linked, or
  • an information system is operated jointly with other federal bodies or a joint database is managed.

The data processing regulations must, in particular, contain details of the internal organisation, the procedures for data processing, the control mechanisms and the technical and organisational measures to ensure data security.

Furthermore, the regulations must be updated regularly and made available to the responsible data protection adviser. The FDPIC provides a framework for data processing regulations for federal bodies.

  • Appointment of a data protection adviser (Art. 10 FADP in conjunction with Art. 25 et seq. FADP): The federal body must appoint an independent, professionally qualified contact person for internal advice and coordination with the FDPIC (Art. 28 FADP). The data protection adviser is responsible for: 1) ensuring compliance with data protection regulations, in particular by reviewing the processing of personal data and recommending corrective measures where a breach of data protection regulations is identified, as well as advising the controller on the preparation of the data protection impact assessment and monitoring its implementation; 2) acting as a point of contact for data subjects; and 3) training and advising the staff of the federal body on data protection matters. Given the limited staff resources of many pension funds, they frequently rely on external advisers (we are available as external data protection advisers). Such outsourcing to external service providers is permitted, but must be safeguarded by contractual arrangements that comply with data protection regulations. The data protection adviser must be registered with the FDPIC via the registration portal. The pension fund also has a duty towards the data protection adviser to grant access to information, processing records and personal data, and to notify the adviser of any data security breaches (Art. 27 of the Data Protection Ordinance).
  • Consent for profiling (Art. 6(7)(c) of the Data Protection Act): Federal bodies require consent for the profiling of personal data. There is no legal basis for profiling within the framework of the BVG.
  • Notification obligations and consultations:

    • Notification of data processing to the FDPIC: The register of processing activities must be notified to the FDPIC (Art. 12(4) of the Data Protection Act). The FDPIC has a notification portal for this purpose, DataReg
    • Consultation in the case of high-risk processing operations (Art. 23 of the Data Protection Act): Notification to the FDPIC is mandatory prior to the commencement of any processing of personal data if, following a data protection impact assessment and the implementation of appropriate mitigation measures, a high risk remains.
    • Notification of projects involving the automated processing of personal data to the FDPIC (Art. 31 of the Data Protection Ordinance): Federal bodies must notify the FDPIC of planned automated processing activities at the time the decision to develop or approve the project is taken. The notification must contain the information specified in Article 12(2)(a)–(d) of the Data Protection Act, as well as the expected date on which the processing activities will commence. The FDPIC enters this notification in the register of processing activities. The responsible federal body updates the notification upon transition to live operation or upon termination of the project.
  • Obligation to label automated individual decisions (Art. 21(4) of the Data Protection Act): Where a federal body issues an individual decision automatically, it must label it accordingly (Art. 21(4) of the Data Protection Act). This applies, for example, to decisions generated by artificial intelligence.
  • Transfer of personal data abroad (Art. 16 FADP and Art. 8 et seq. FADP): A transfer abroad is, in principle, permissible provided that Art. 16 FADP and Art. 8 FADP are complied with. Federal bodies may also notify the FDPIC in advance of specific safeguards they have drawn up to ensure adequate data protection.
  • Disclosure to third parties and restrictions thereon (Art. 36 FADP in conjunction with Art. 86a BVG): Disclosure to third parties is only permitted if there is a legal basis for doing so, in particular via automated information and communication services (para. 5) or, in individual cases, where the conditions set out in para. 2 of the Federal Act on Pensions (BVG) are met. Disclosure in connection with the Freedom of Information Act or where there is an overriding public interest is likely to occur rather rarely in the context of pension funds. A data subject may object to the disclosure of data (Art. 37 BVG). Art. 86a BVG permits disclosure to third parties provided that no overriding private interests stand in the way.
  • Additional information requirements (Articles 29 and 30 of the Data Protection Ordinance): There is an additional obligation to provide information when disclosing data to third parties (Article 29 of the Data Protection Ordinance), namely regarding how up-to-date, reliable and complete the personal data being disclosed is. Where personal data is collected systematically, the data subject must be informed of this, unless they are not obliged to provide such information (Art. 30 of the Data Protection Ordinance).
  • Logging (Art. 4 of the Data Protection Act): In the case of the automated processing of personal data requiring special protection on a large scale, or in the case of high-risk profiling, where preventive measures cannot guarantee data protection, the responsible federal body and its data processor must, at the very least, keep a record of the storage, modification, reading, disclosure, deletion and destruction of the data (Art. 4(2) of the Data Protection Ordinance). The logging must provide information on the identity of the person who carried out the processing, the nature, date and time of the processing and, where applicable, the identity of the recipient of the data. The logs must be retained for at least one year, separately from the system in which the personal data is processed. They may only be accessible to the bodies and persons responsible for verifying compliance with data protection regulations or for safeguarding or restoring the confidentiality, integrity, availability and traceability of the data, and may only be used for this purpose.
  • Specific retention, archiving and deletion obligations (Art. 38 DSG and 15 DVV): Pursuant to Art. 41(8) of the BVG in conjunction with Art. 27j of BVV 2, data held by pension funds shall be retained, in the case of benefit payments, for up to 10 years after the end of the obligation to pay benefits; if no pension benefits are paid, the data shall be retained until the insured person reaches or would have reached the age of 100 or would have reached their 100th year of age; and, in the event of a transfer of vested benefits, for up to ten years after the transfer of the insured person’s vested benefits to the new occupational pension scheme or to an institution that maintains vested benefits accounts or policies. In the event of the liquidation of an occupational pension scheme, it is the responsibility of the liquidators to ensure that the documents are stored correctly (Art. 27k BVV 2). Accordingly, the general principle applies that personal data must be deleted or anonymised as soon as the purpose for which it was processed no longer applies. In accordance with the Archiving Act of 26 June 1998, pension funds operating under the compulsory pension scheme must submit to the Federal Archives all personal data which they no longer require on a permanent basis. Prior to this, personal data not suitable for archiving must be destroyed, unless it is anonymised or needs to be retained for evidential or security purposes, or to safeguard the legitimate interests of the data subject.
  • Data processing for research, planning and statistics (Art. 39 FADP): Federal bodies may also use personal data for research, planning and statistics, but must ensure that third parties do not disclose such data and that re-identification is ruled out.
  • Rights and procedures of data subjects vis-à-vis federal bodies: The rights granted under Article 41 of the Data Protection Act (DSG) correspond in substance to those set out in Articles 25 et seq. of the DSG. The only specific feature concerns the refusal of access under Article 42 of the FADP. However, the procedure differs in this respect, as administrative proceedings under the Administrative Procedure Act (VwVG) then apply.

Simplifications and Voluntary Measures

  • Duties to provide information (Article 21 of the DSG): There are also exemptions from the duty to provide information under Article 21(3)(d) of the DSG for federal bodies, insofar as Article BVG does not apply. For example, information need not be provided if doing so would jeopardise an investigation or administrative or judicial proceedings. This may apply, for instance, to pension funds when cases of misuse are being investigated.
  • Criminal provisions: Federal bodies are not subject to criminal sanctions under Article 60 et seq. of the DSG, but are subject to administrative oversight by the EDÖB, which has the power to issue instructions and carry out audits.
  • Codes of conduct (Art. 11 DSG): Federal bodies may submit codes of conduct to the EDÖB (Art. 11(1) DSG); this does not have to be done on their behalf by an association of pension funds.

Conclusion and recommended action

In practice, this means that establishing a data protection management system – i.e. data protection governance – is essential. In this context, it must be assessed for every instance of data processing whether it falls within the mandatory or non-mandatory scope. In particular, compliance with the additional obligations for federal bodies must be ensured. Limited resources can be addressed through external support.

 

Sources