Client feedback


Good, helpful guidance.
Christine Morris,
Twyford Bathrooms
The trustee training course covered a wide variety of subjects which gives a good basis for future discussion and decision making during trustee meetings.
Jean-Paul Gobel,
Heerema
Kathy, may l take this opportunity to thank you for your assistance. There were many times l thought l was losing my mind during my efforts with Aviva. You were a pillar of support for me and you saw my case through to the very end. I cannot thank you enough but thank you again. It is through people like you who strive for professional fairness as well as thoroughness, HCA has such a good reputation.
Ethel Chimutwe,
HCA International Ltd Staff Retirement Benefits Scheme
Keen to assist and helpful.
Where PSGS are appointed to act in conjunction with an existing body of trustees, we have found that they are quickly able to fit in well and gain the trust and respect of their co-trustees.
Duncan Buchanan,
Partner at Hogan Lovells
Great communication and practical help.

GDPR: the nightmare revisited!

I’m sorry to bring back the agonies of this time last year, but as pension trustee secretary I’ve started the first review of my clients’ GDPR policies. These are due to be completed within the next few weeks and, so far, I’ve found a couple of changes that I have recommended to my clients.

Over the top actions aren’t needed

The first change is to tweak the wording around breaches so we could avoid a full-blown crisis meeting when in fact the breach was very minor and it was a no-brainer that no report to the Information Commissioner’s Office (ICO) was needed.

Fortunately, I haven’t experienced any major breaches during the year (touch wood that continues) but I have found administrators are rightly reporting every minor breach. When a breach is obviously minor and only involves one or two individuals, it is clearly disproportionate to lodge a report or indeed to involve the full pension trustee board in reaching this decision. One of my clients agreed to amend their policy so, in such cases:

  • only the Trustee Chair and a member nominated trustee (MNT) needs be notified to reach a decision
  • the breach is also reported to the governance committee and recorded on the data breach log

Talking of no-brainers…

The second change relates to the ICO’s recommendation for data controllers to complete a three part test when they rely on legitimate interests as their grounds for data processing (see: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/lawful-basis-for-processing/legitimate-interests/). This isn’t a GDPR requirement and so isn’t essential, but it is seen as best practice. Frankly, when dealing with pension schemes, the responses to the ICO’s list of questions show it is a no-brainer that processing data is in the members’ best interests.

I drew up a note to record the trustee’s responses to the test and its conclusion. A simple way to deal with something you could find pension administrators or lawyers over-complicate.

Although GDPR may still feel like a fresh wound, this is a good time to check everything remains fit for purpose.

 

 

Back to opinions

 

Hot topics


PSGS & 20-20 Trustees merge to form Vidett
Hot Topic

Punter Southall Governance Services (PSGS) & 20-20 Trustees (20-20) have today announced they...

Read more »


Don’t be surprised that your gilt funds are being treated like an emerging market
Image of Hot Topic author Sophia Harrison, Client Director

You may have seen or heard about the article in the Financial Times about how Insight...

Read more »


More opinions »


Call: 0118 207 2900

online enquiry