EU Pensions and GDPR – 12 Month Countdown Begins! General Data Protection Regulation


The European Union General Data Protection Regulation (GDPR) comes into force on 25 May 2018.  Before that date, trustees of UK occupational pension plans will need to undertake some preparatory work, including:

There are some obvious and less obvious pitfalls to consider here.  For example, if a trustee is on holiday outside of the EEA and picks up emails containing personal data whilst away, that will constitute transferring data outside of the EEA.

The recent global cyber attack has thrown into sharp focus the need for trustees to ensure the robustness of cyber security measures put in place by their data processors. As Investment & Pensions Europe report, there has also been a recent instance of a Belgian pension fund being subject to a cyber attack – Ogeo hack.

Where trustees access emails and documents containing personal data through their own home computers and/or personal mobile devices, there are some key issues about how this is managed:


© Copyright 2025 Squire Patton Boggs (US) LLP
National Law Review, Volume VII, Number 144