HPW

Member Portal (HPW Live) Privacy Notice

  1. 1. Purpose of this Notice

    Hughes Price Walker Limited (“HPW”, “we”, “us”, “our”) is committed to protecting your privacy and the information that is entrusted to us.

    This Privacy Notice (‘Notice’) provides information regarding your rights under data protection legislation and sets out how we collect and process personal data using HPW Live. You can access HPW’s general privacy notice here: https://www.hughespricewalker.co.uk/s/HPW-Privacy-Policy-external.pdf

    HPW processes personal data on behalf of our clients (Trustees of pension schemes) and in accordance with our clients’ instructions, we will generally act as the Data Processor and our clients will be the Data Controller.

    Where a Scheme Actuary employed by HPW has been appointed by a Trustee or Trustees, the Scheme Actuary will generally act as a joint Data Controller with the Trustee(s); except where they are legally required to act independently, they will act as Data Controller in common with our clients. Whilst the Scheme Actuary is in HPW’s employment, they will carry out their respective responsibilities for compliance with data protection legislation in accordance with this Notice. All HPW Scheme Actuaries are registered as Data Controllers with the Information Commissioner’s Office (ICO).

    The categories of data subjects for whom this Notice applies to include, but may not be limited to, members and potential beneficiaries of those pension schemes that have adopted the Member Portal. If you are a member of a pension scheme that we administer, you can obtain that scheme’s specific privacy notice by contacting the trustees of your pension scheme.

    We process personal data in respect of these individuals for the following purposes:

    • To provide our clients with the services detailed in our terms of agreement with them
    • To manage relationships and complete our contractual obligations to our clients
    • To comply with any laws and professional obligations that apply to us and our individual members of staff
    • To undertake necessary checks to prevent illegal activity or protect our interests
    • To respond to any query you have sent us
    • To send you any relevant information regarding our services and the latest news in pensions and investments
    • To provide you with information relating to the pension scheme you are a member of and other general information
    • The Member Portal does not use tracking cookies to obtain data or monitor the use of the site. We will keep our Notice under review and update it with any changes should they occur.

  2. 2. The data we process

    We process personal data that is provided to, or obtained by, HPW via the HPW Live. This personal data may include, but may not be limited to:

    • Personal – Name (including former surnames), gender, date of birth, home address (including address history), national insurance number, email address, phone number and marital status. Note that photographic information, proof of address documents, signatures, nationality, bank account details are not processed through the member portal but are recorded separately within HPW’s systems.
    • Special and other categories – Relevant health and medical information and any relevant background information relating to criminal offences and convictions are not processed via HPW Live unless you provide this through the Contact Us functionality. Where we collect these special categories of data from you, we will set out our specific purpose(s) for doing so. We will then only process this data if we have received your explicit consent, unless we are lawfully permitted to process the data due to legal and regulatory obligations. Note that these are typically not processed through the member portal but are recorded separately within HPW’s systems.

  3. 3. What we do with the data

    HPW will process your personal data in accordance with this Notice unless such processing would conflict with any applicable regulation or legislation when these would prevail.

    Our lawful bases for holding and processing personal data are for the following business purposes:

    • Administering your pension benefits
    • Providing you with access to your pension information
    • Processing benefit quotations, retirement and death benefits
    • Making pension and lump sum payments
    • Maintaining accurate records of scheme membership
    • Complying with legal and regulatory obligations applicable to pension scheme administration
    • Processing is necessary for the performance of a contract and / or letter of appointment to which our clients are party to, or in order to take steps at the request of prospective clients prior to entering into a contract
    • Processing is necessary for our Scheme Actuaries to act in accordance with their legal and professional obligations, as well as their ethical code; and
    • Processing is necessary for the purposes of our legitimate interests in carrying out specified services to our clients. These include but may not be limited to those purposes listed in section 1(i).

    In the unlikely event that we intend to further process your personal data for a purpose other than that for which your personal data has been collected, we will keep our Notice under review and update it with any changes should they occur.

  4. 4. Sharing your data

    In certain circumstances we will share your personal data with the following recipients:

    • Third parties contracted or obliged to provide services to our clients, for example: other pension providers, auditors, investment managers, legal advisers and any other party our clients may reasonably instruct us to share data with for the purposes of carrying out our services
    • Third parties instructed by us to carry out sub-contracted services as part of the services we provide our clients, for example: banking providers, pensioner payroll providers, professional tracing companies, IT consultants, companies supplying website services, the Pensions Dashboards Programme.
    • Those parties to whom we must report to for legal and professional reasons, for example: auditors, insurers, external accreditation bodies and HMRC
    • The recipients for whom we share personal data in respect of our clients’ data subjects (e.g. members of the pension schemes we administer) are different to those listed out above and can be obtained from HPW on a scheme specific basis.
    • HPW Live may contain links to other websites. Once you use these links to leave HPW Live, HPW does not have any control over these websites. Therefore, we cannot be responsible for the protection and privacy of any information you provide to these sites.

    Transferring data outside of the EEA

    In certain circumstances, your personal data may be transferred outside of the EEA. HPW shall only be entitled to transfer personal data outside the EEA where:

    • the recipient of your personal data has entered a European Commission approved standard contract with yourselves, obliging them to take all reasonable steps to safeguard your personal data;
    • the recipient is approved by the European Commission as offering a sufficient level of protection; or
    • it is a certified member of the EU-US Privacy Shield Framework (only relevant for US recipients).

  5. 5. How we store your data

    Keeping it safe

    Personal data processed from the Member Portal is stored electronically. We apply appropriate technical and organisational measures to protect your data against unauthorised access, alteration, disclosure or destruction. This includes access controls and regular monitoring of our systems.

    When transmitting personal data by email we take all reasonable steps to keep it secure by applying password protection, sending by secure email or using a secure portal. However, please be aware that transmitting data by email is not completely secure and if you transmit personal data by email, you do so at your own risk.

    We also expect third parties who provide services on our behalf to safeguard personal data in a similar manner and we take reasonable steps to monitor their compliance.

    We take every reasonable measure and precaution to protect and secure personal data against unauthorised access, improper use, alteration, destruction or accidental loss or disclosure. Full details of our data security policy are available on request.

    HPW is a Cyber Essentials accredited organisation.

    Retaining your information

    We will retain your personal information for as long as is necessary for the purposes specified in this Notice, unless a longer retention period is required by law or by regulations that apply to us. We have strict data retention policies in place to meet this requirement.

    If we no longer require your personal data and deem it appropriate to remove it from our properties, we will do so in a controlled manner, ensuring it is destroyed securely. All paperwork containing personal information is securely disposed of by a company that holds a BS EN 15713 Secure Destruction of Confidential Material Certification and whose members of staff are security vetted to BS7858 standards.

  6. 6. Your rights under data protection law

    Data protection law gives you the right to: obtain access, or copies of, your personal data; request that we rectify any errors in the data that we hold; request that we erase your personal data; request that we restrict the way we process your personal data; or object to its processing. In some circumstances you may also have a right to request a copy of your personal data for the purposes of transmitting elsewhere.

    Some of these rights may not constitute an absolute right and we may refuse your request if in doing so obstructs our legal obligation.

    If you would like to exercise any of these rights, or modify or withdraw your consent, you can do so by emailing us at info@hughespricewalker.co.uk. Note that HPW is the Data Processor and not the Data Controller. The Data Controller will be the Trustee or Trustees of your relevant pension scheme. The Data Controller is responsible for ensuring your rights are adhered to.

  7. 7. Relevant contact details

    If you are not satisfied with how we have handled your personal data, you can write to us using the contact details provided at the end of the Notice. If you are not satisfied with our response to your complaint or believe our processing of your information does not comply with data protection law, you can make a complaint to the ICO using the following details. The ICO is the UK’s independent body set up to uphold information rights.

    ICO helpline: 0303 123 1113 (or 01625 545 700 if calling outside of the UK)

    Email: By visiting the ICO website at https://ico.org.uk/global/contact-us/

    Head office:

    Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

    If you have any queries or require any further information about our privacy policies, or wish to enact any of your rights stated above, please contact us using the following details:

    Office line: 0117 427 8900

    Email: info@hughespricewalker.co.uk

    Website: www.hughespricewalker.co.uk

    Head office: Data Compliance Officer, Hughes Price Walker Ltd, Pembroke House, 15 Pembroke Road, Clifton, Bristol, BS8 3BA