GDPR and your pension
Data Protection Law controls how your personal information is used by organisations, businesses or the government. References in this section of our website to the 'GDPR' are to the UK’s implementation of the General Data Protection Regulation (GDPR) under the UK European Union (Withdrawal) Act 2018. The ‘UK GDPR’ sits alongside an amended version of the Data Protection Act 2018 to regulate how data is used.
Everyone responsible for using personal data has to follow strict rules called ‘data protection principles’. They must make sure the information is:
Used fairly, lawfully and transparently
Used for specified, explicit purposes
Used in a way that is adequate, relevant and limited to only what is necessary
Accurate and, where necessary, kept up to date
Kept for no longer than is necessary
Handled in a way that ensures appropriate security, including protection against unlawful or unauthorised processing, access, loss, destruction or damage
AI statement
We strongly recommend that you do not use AI tools to help you understand any pension communications. Read our AI statement.