# Data Protection Obligations for Pension Funds in Switzerland

> Data protection for Swiss pension funds: DSG, BVG and OAK BV in interplay. Duties on special-category data, TOMs and breach reporting.

- Source: https://www.sidd.swiss/en/insights/data-protection-obligations-for-pension-funds-in-switzerland/
- Language: en
- Published: 2026-02-12
- Last updated: 2026-05-24
- Author: Philipp Staiger
- Publisher: SIDD Institute for Data Protection and Data Security, a brand of Priverion GmbH, Zugerstrasse 32, 6340 Baar (ZG), Switzerland

## The dual regulatory structure: BVG and DSG

Swiss occupational pension funds (Pensionskassen) operate within a dual supervisory architecture. Substantively they are subject to the BVG (Swiss Occupational Pensions Act, formally the Federal Act on Occupational Old Age, Survivors and Invalidity Pension Provision) and the accompanying ordinances BVV 1 and BVV 2. Operational supervision lies with the cantonal or regional supervisory authorities, such as the BVS in Berne or the BVG and Foundation Supervision of the Canton of Zurich. At federal level, OAK BV (Swiss occupational-pensions supervisory commission) coordinates and issues directives that are binding on all pension institutions.

In parallel, the Swiss DSG (Federal Act on Data Protection / FADP), in force since 1 September 2023, applies in full. For pension institutions with insured persons or beneficiaries in the EU, the GDPR may apply in addition. This dual structure gives rise to conflicts of duty, for instance between actuarial retention periods and data protection deletion duties. A clean separation of responsibilities and a binding data classification model are therefore indispensable. The [DSG/FADP guide (German-language pillar)](https://www.sidd.swiss/einblicke/dsg-fadp-leitfaden) provides the legal foundation.

## Special-category personal data in the second pillar

The data processed in the pension relationship is almost entirely special-category personal data within the meaning of Art. 5(c) DSG. This includes in particular health data from disability-insurance applications, from risk assessments before admission to the supplementary occupational pension scheme, and from hospital invoices that arise in the course of benefit assessments. The AHV social-security number and detailed contribution histories also have a sensitive character because they allow a complete financial life history to be reconstructed.

Processing special-category personal data is subject to heightened requirements. Under Art. 8(3) DSG, the technical and organisational measures must be raised in line with the increased risk. Under Art. 30(2) lit. c DSG, disclosure to third parties regularly requires an explicit legal basis or explicit consent. In the relationship between pension institution and employer this means specifically: the employer in principle only receives the data it needs for payroll and BVG contribution reporting. Diagnoses, disability-insurance decisions and benefit details remain within the pension fund.

## Data flows: employer, pension fund, reinsurer

The typical data architecture of a pension fund involves at least four axes: the employer as contribution payer, the insured person, external bodies such as disability-insurance offices or doctors, and the reinsurer for death and disability risks. Each axis requires its own legal basis and its own contractual foundation.

In practical terms: with the employer there is an affiliation contract under Art. 11 BVG; the data flows regulated therein should be specified in a data protection compliant manner. External doctors and medical advisors generally act as Processors within the meaning of Art. 9 DSG, which requires written agreements with instruction rights, confidentiality and deletion duties. Reinsurers in Liechtenstein, Germany or the United States trigger cross-border disclosures under Art. 16 and 17 DSG and, absent adequacy, require Standard Contractual Clauses (SCCs) together with a Transfer Impact Assessment. SIDD recommends a consolidated data flow map as the central steering instrument; it is also regularly a prerequisite for the Records of Processing Activities (ROPA) under Art. 12 DSG.

## Technical and organisational measures under Art. 8 DSG

Art. 8 DSG requires data security appropriate to the risk; the Data Protection Ordinance (DSV) concretises this in Art. 1 to 6. For pension funds, which predominantly process special-category personal data, an elevated level of protection must be established. Alignment with ISO/IEC 27001:2022 and its 93 Annex A controls has proven its worth.

Several control families take priority. Annex A.5.34 requires defined processes for the protection of personal data as part of the ISMS. Annex A.8.11 (data masking) is relevant for test and training environments, where productive insured-person data has no place. Annex A.8.24 (cryptography) requires at minimum TLS 1.3 for transport and strong encryption of data at rest. Annex A.5.7 (threat intelligence) and A.8.16 (monitoring) form the basis for the timely detection of incidents. Certification is not mandatory but simplifies evidence towards supervisors and the foundation board. Further reading in the [ISO 27001 guide](https://www.sidd.swiss/en/insights/iso-27001-guide-2026/).

## ROPA, DPIA and deletion concept

Under Art. 12 DSG, Records of Processing Activities (ROPA) must be maintained. For pension funds, the exemption for small enterprises with fewer than 250 employees effectively does not apply, because special-category personal data is regularly processed on a large scale. The records should contain at minimum purpose, recipient categories, retention periods, data exports and a reference to the TOMs.

A DPIA (Data Protection Impact Assessment) under Art. 22 DSG is required in particular when introducing new policy administration systems, automated risk classifications, the use of cloud services or AI-supported claims assessment. The deletion concept must resolve the tension between BVG retention duties and deletion rights. Pension relationships must be retained under Art. 41 BVG for up to ten years after benefit entitlements expire; in practice this results in long-term retention covering the entire lifetime of the insured person. These retention periods supersede the deletion right under Art. 32 DSG; however, they must be documented cleanly and limited to what is required to evidence entitlement. Ancillary data without entitlement relevance must be deleted earlier.

## Data protection advisor, breach reporting and supervision

Appointing a data protection advisor under Art. 10 DSG is voluntary for pension funds but strongly recommended. The advisor serves as a point of contact towards the FDPIC, coordinates submissions and relieves the executive management and the foundation board. The function may be filled internally or mandated externally; the decisive factors are technical competence and freedom from instructions vis-a-vis the controller.

Breaches of data security must be reported under Art. 24 DSG to the FDPIC as soon as possible, where there is a high risk for the persons concerned. In particularly serious cases, the data subject must also be informed. In parallel, there is a reporting duty towards the supervisory authority within the annual reporting cycle, insofar as the incident affects proper governance. The OAK BV (Swiss occupational-pensions supervisory commission) has emphasised the growing importance of cyber resilience for pension institutions in several communications. Criminal offences under Art. 60 DSG include in particular the wilful violation of information, disclosure and due-diligence duties; the maximum fine is CHF 250,000 against the responsible natural person.

## GDPR relevance and cross-border insured persons

Pension institutions with cross-border commuters, with insured persons from EU establishments of Swiss groups, or with foreign reinsurers are regularly within scope of the GDPR. Art. 3(2) GDPR applies as soon as persons in the EU are specifically targeted or their behaviour is monitored. This triggers additional duties: representation in the EU under Art. 27 GDPR, a DPIA under Art. 35 GDPR, and information under Art. 13 and 14 GDPR with GDPR-compliant legal bases.

The reciprocal recognition of an adequate level of protection between the EU and Switzerland since 15 January 2024 significantly facilitates data flows within the EEA-Switzerland network. It does not, however, replace the other information and documentation duties of the GDPR. In case of breach, fines of up to EUR 20 million or 4 per cent of worldwide annual turnover of the economic unit apply under Art. 83 GDPR. In practice this means for Swiss pension funds: keep information sheets and insured-person notices DSG- and GDPR-compliant, and record cross-border cases separately in the ROPA. More in the [GDPR guide](https://www.sidd.swiss/en/insights/gdpr-guide-2026/).

## How SIDD supports pension funds

Pension institutions rarely need data protection as an isolated project. It only becomes effective when it is integrated with the internal control system, the regulatory framework and IT governance. SIDD and Priverion accompany Swiss pension funds with a three-stage approach. First, a focused baseline assessment with ROPA, data flow map, contract review against processors and a gap analysis against the DSG, DSV and, where applicable, the GDPR. Second, prioritised implementation with DPIA for critical procedures, updating insured-person information, contract adjustments and introducing a robust set of TOMs. Third, ongoing operations with training, incident management and regular reporting to the executive management and the foundation board.

We take on concrete mandates through the services [Swiss data protection advisor](https://www.sidd.swiss/en/services/data-protection-advisor-switzerland), [EU representative and Data Protection Officer](https://www.sidd.swiss/en/services/data-protection-officer-eu), and the build-up of an [ISMS to ISO/IEC 27001](https://www.sidd.swiss/en/services/iso-27001-isms). Pension funds benefit particularly from an external data protection advisor because this preserves independence vis-a-vis the executive management and the investment foundation, and addresses the recurring audit questions of the supervisor efficiently.

---

This document is the Markdown rendition of the page linked above. Please cite the HTML URL.
