Paul Ashcroft
- Partner
- Pensions & Employee Benefits
Data protection – vulnerability of pension schemes
Pension schemes are particularly exposed to data protection risks, as they hold high volumes of sensitive personal data, including not only basic identifiers but also salary information, national insurance numbers, health data and other personal information relating to members and beneficiaries.
Processing sensitive and special category data increases the risks of data breaches. Pension schemes are attractive targets for cyber-attacks, for example, the attack suffered by Capita in March 2023. Schemes are exposed to significant financial and reputational risk. Last year the Information Commissioner’s Office (“ICO”) fined Capita £14m. The subsequent mass data protection claim brought by nearly 4,000 scheme members presents a substantial ongoing financial risk.
Pension schemes often outsource administration of member data to third parties. These providers may, in turn, rely on other third-party processors, thereby increasing the risk of supply chain failures and information leaks leading to data protection breaches. However, pension scheme trustees remain responsible for compliance with data protection legislation. Trustees have a duty to ensure that member data is handled securely and in accordance with the legislation and the scheme’s governing documents. Failing to do so may expose trustees to regulatory intervention and complaints from members.
Key Points:
- Data protection complaints pose a significant risk for scheme trustees and administrators.
- Robust data governance and security arrangements should be reviewed and maintained to minimise exposure to complaints and regulatory intervention.
Trustees’ and administrators’ data protection duties: UK GDPR framework and fiduciary duties
Trustees’ and administrators’ data protection duties arise under the UK GDPR and the Data Protection Act 2018, other data protection legislation and the scheme’s governing documents.
In most cases, trustees will be controllers for the purposes of the UK GDPR, as they determine why and how the data is processed. Many of the third parties which help administer schemes are also likely controllers as regulated entities, required to process personal data to fulfil their statutory obligations. The precise allocation of roles and responsibilities will depend on the arrangements in place.
Controllers are responsible for compliance with the legislation. Their duties include identifying what personal data is processed and where it is held, implementing appropriate policies, procedures and security measures to protect that personal data and reviewing third parties appointed to process personal data on their behalf. To comply with the legislation, trustees must carry out appropriate due diligence before engaging third-party providers as processors. They must also implement written data processing agreements with those service providers.
The trustees’ obligations under data protection legislation also interact closely with trustees’ fiduciary duty to act in members’ best interests. This includes safeguarding members’ personal data and managing cyber and data protection risks. The Pensions Regulator expects trustees to put in place and operate adequate internal controls as a part of a governance framework proportionate to the size, nature, scale and complexity of the scheme. Trustees should:
- ensure cyber risks are on the risk register and regularly reviewed;
- regularly assess the vulnerability of the scheme’s key functions, systems and assets;
- implement appropriate policies, procedures and controls on data in line with data protection legislation;
- ensure regular system back-ups and secure storage of critical data;
- establish effective monitoring and controls over service providers; and
- maintain a data protection and cyber incident response plan.
Recent case law
Failing to adequately protect personal data can result in member complaints against the scheme trustees and administrators. The Data (Use and Access) Act 2025 requires organisations to put in place a procedure for dealing with individuals’ complaints about the handling of their personal data. For further details, see our data protection team’s article by clicking here. Recent cases demonstrate that trustees and administrators may be exposed to liability in a wide range of circumstances.
In Farley v Paymaster[1], letters containing members’ personal data (in this case, former police officers) were sent to incorrect addresses. Despite there being no evidence that the data was accessed by third parties, the Court of Appeal held that there is no “threshold of seriousness” in data protection law, and that a loss of control over personal data may result in a viable data protection claim, provided that a claimant’s fear of third-party misuse is objectively well-founded. However, the scheme administrator has been granted permission to appeal to the Supreme Court, with the hearing currently listed for October 2026.
Similarly, in Spurgeon v Capita Plc[2], an application was brought by around 4,000 individuals affected by the Capita 2023 cyber-attack. Capita argued that the claimants’ evidence had been irrevocably tainted by their lawyers on issue of loss and damage by relying on language such as “violation”, “tormented” and “betrayal of trust” which had not been used by the individual claimants themselves. The Court rejected that argument, holding that counsel has a wide latitude to determine how best to formulate pleadings, and it was legitimate to use repetitive or generic phrases in such circumstances. Trustees and administrators should note the increasing exposure to high value data protection claims.
Finally, in DSG Retail Limited v The Information Commissioner[3], the court confirmed that data controllers must safeguard personal data including where the individual unlawfully accessing that data may not be able to identify the data subjects and regardless of how it might be used or exploited by hackers. Although the case did not involve a pension scheme, the decision is a reminder for trustees and administrators that the obligation to implement appropriate security measures focuses on preventing unauthorised access to personal data itself, rather than on whether that access resulted in misuse or harm.
Overall, these cases demonstrate the low bar for bringing a data protection claim, as claimants do not need to prove that personal data was accessed or misused by a third party, or that they were harmed by the breach. Although individual awards of compensation are typically modest, there is an increasing number of high value collective-action claims. In addition, there remains a risk of intervention from the ICO. These decisions highlight the importance for pension scheme trustees and administrators to adopt a proactive approach to data protection and to put strong controls in place.
[1] [2025] EWCA Civ 1117.
[2] [2026] EWHC 241 (KB).
[3] [2026] EWCA Civ 140.
This article is for general information purposes only and does not constitute legal advice or a comprehensive statement of the law. Specific legal advice should always be sought in relation to individual circumstances.
Meet the team:

