GDPR Article Crosswalk
Pension trustees are data controllers under EU Regulation 2016/679 (GDPR). They determine the purposes and means of processing member personal data — including sensitive financial data, benefit records, PPS numbers, and health information where relevant to ill-health retirement or death-in-service claims. PensionsPortal.ie acts as a data processor on behalf of each trustee client. We process personal data only on the documented instructions of the trustee-controller, as governed by the Data Processing Agreement (DPA) executed at onboarding. The Irish supervisory authority for GDPR is the Data Protection Commission (DPC), which has jurisdiction over schemes established in Ireland and over data processors with their EU establishment in Ireland.Controller vs. Processor distinction matters. GDPR obligations fall primarily on the controller (the trustee). PensionsPortal.ie, as processor, has specific obligations under GDPR Articles 28, 29, and 32 that are distinct from — and in addition to — the controller’s obligations. This crosswalk covers both.
Dual-Role Mapping Table
The table below maps each material GDPR Article to both the trustee’s obligation as controller and PensionsPortal.ie’s support as processor.Data Processing Agreement
The PensionsPortal.ie Data Processing Agreement (DPA) is executed as part of the standard Terms of Service. It covers all mandatory Article 28(3) requirements:Processing Instructions
PensionsPortal.ie processes personal data only on the documented instructions of the trustee-controller. Instructions are documented in the DPA and supplemented by platform configuration.
Confidentiality
All PensionsPortal.ie personnel with access to member data are subject to contractual confidentiality obligations. Background checks conducted for roles with production data access.
Sub-Processors
Sub-processor list maintained. Trustees receive 30-day advance notice of any sub-processor changes. Current sub-processors include GCP (hosting), Sentry (error monitoring), and email delivery providers (communications module only).
International Transfers
All primary processing within the EU/EEA. Where sub-processors involve international transfers, Standard Contractual Clauses (SCCs — 2021 Commission Decision) are in place. Transfer Impact Assessments available on request.
Security Measures
Technical and organisational measures are documented in the DPA Annex, aligned with Article 32 requirements. Updated when material changes occur to platform security architecture.
Assistance
PensionsPortal.ie assists the controller in responding to data subject rights requests and in fulfilling Article 32-36 obligations (security, breach notification, DPIA) to the extent that the obligation relates to processing by PensionsPortal.ie.
Special Category Data: Pension Scheme Considerations
Pension schemes frequently process special category personal data under GDPR Article 9. Common categories in a pension context:- Health data: Ill-health early retirement applications; death-in-service claims; enhanced transfer values linked to health conditions
- Trade union membership: Where scheme membership is linked to employment with a union
- Biometric data: If used for member identity verification (not current platform functionality)
- Flagged at the data model level with enhanced access restrictions
- Subject to mandatory audit logging of all access
- Excluded from general data exports unless the requesting user has explicit authorised access
DPC Notifications and Record-Keeping
All interactions with the Irish DPC — including data breach notifications, Data Protection Officer (DPO) correspondence, and subject access request responses — should be logged and retained. PensionsPortal.ie’s compliance module includes:- Breach register: Records all assessed incidents, whether or not they crossed the notification threshold, with documented rationale
- DSR log: Records all data subject rights requests (SAR, erasure, rectification, restriction, portability, objection), the date received, response issued, and outcome
- DPO register: If the scheme has appointed a DPO, contact details and appointment record maintained in the governance module