Skip to content
Pensions dashboards programme logo
  1. Home

Pension providers, schemes and ISPs privacy notice

Who we are

We are the Money and Pensions Service (MaPS) – an arm's-length body sponsored by the Department for Work and Pensions (DWP). Our contact details are:

  • email: [email protected]
  • post: Money and Pensions Service, Bedford Borough Hall, 138 Cauldwell Street, Bedford, MK42 9AP

More information about MaPS can be found on the MaPS website.

MaPS’ Data Protection Officer contact details are:

It will take you about 10 to 15 minutes to read this notice.  

Privacy notice

This notice covers our processing of your personal data as a contact for personal pension providers and occupational pension schemes (pension providers and schemes), or for third-party organisations connecting on behalf of pension providers and schemes, who are connecting to the pensions dashboards ecosystem. It explains why and how we collect and use your personal data as part of operating the central digital architecture and associated services which make pensions dashboards possible, and connecting pension providers and schemes and dashboards.

The central digital architecture comprises the central infrastructure, interfaces and services that connect pension providers and schemes to dashboards and facilitate individuals to search for their pensions and manage access to their pensions information via the dashboard.

Please note that where you use other services MaPS provides, you should ensure you review the privacy notices which relate to those services. This includes the privacy notice provided on the MoneyHelper website. 

This privacy notice solely relates to the central digital architecture and associated services. 

Not covered 

For primary business contacts (PBC) and primary technical contacts (PTC) in connecting organisations, you will need to verify your identity. To do this, GOV.UK One Login (the identity service for pensions dashboards) will process your personal data to verify your identity for us. See the GOV.UK One Login privacy notice.  

What personal data do we collect?

‘Personal data’ means information relating to an identified or identifiable living individual.

Personal data also includes personal identifiers. This could be an identification number, location data, an online identifier, or pseudonymous data.

To deliver the central digital architecture and related services, we/our suppliers collect and use these items of personal data:

1. For PBCs and PTCs only: Data we receive from GOV.UK One Login once you have verified your identity: 

  • name 
  • date of birth
  • email address 
  • mobile phone number (if you have used a mobile phone for two-factor authentication) 

2. For all key connecting party role holders on the connection portal (Salesforce) – see details on all roles:

  • name and contact information provided to register
  • cookies used to deliver the connection portal (Salesforce) - our supplier has a Salesforce cookies policy which details the cookies processed
  • IP addresses processed by Salesforce

3. For vouching schemes only – see details on vouching scheme checks: Data we receive from The Pensions Regulator (TPR) or Financial Conduct Authority (FCA):

  • name and email address for the trustees/managers/SMF-16 at the pension provider or scheme being used as the vouching scheme at the point of initial connection of a third-party connection provider connecting to the ecosystem on behalf of a pension provider/scheme.

4. For voluntary connection applications:

  • name, email, phone number and job title for the applicant
  • name of the trustee(s) that have authorised the application

5. For all industry support tickets raised via the Pensions Dashboards Service (PDP) support including PDP connection support portal (Jira) and technical service desk (Service Now):

  • name and contact information
  • cookies used by suppliers to provide PDP connection support and technical support desk. Our suppliers have cookies policies detailing the cookies processed in providing these services:
  • IP addresses processed by the connection support portal and technical service desk.

No sensitive or special category data, such as information relating to gender, sexuality or religion, for example, is processed by us as part of operating the central digital architecture for pensions dashboards.

We need to process your personal data:

1. (For PBCs and PTCs only) So that we can verify your identity and register you as a PBC/PTC to begin connection of your organisation. Without this processing, we would not be able to connect your organisation. The legal basis for this processing is ‘public task’ – that is, we are undertaking it in the exercise of official authority.

2. (For vouching scheme checks only) So that we can be assured that the third-party connection provider is genuinely acting for a regulated pension provider or scheme, with their authority and therefore has a legitimate reason to connect. Without this processing, we would not be able to connect the third-party connection provider connecting to the ecosystem on behalf of your pension provider/scheme. The legal basis for this processing is ‘public task’ – that is, we are undertaking it in the exercise of official authority.

3. (For voluntary connection applications only) So that we can receive and process applications for voluntary connection, and liaise with TPR. The legal basis for this processing is ‘public task’ – that is, we are undertaking it in the exercise of official authority.

4. To provide helpdesk query support. Without this processing, we would not be able to provide connection-related support to your organisation. The legal basis for this processing is ‘public task’ – that is, we are undertaking it in the exercise of official authority.

5. (For notifications of change in connection date – see guidance on changing connection plans) To notify TPR and FCA of changed connection plans, so they can update their communications. The legal basis for this processing is ‘public task’ – that is, we are undertaking it in the exercise of official authority.

6. We might also need to process your personal data if there is a re-organisation of MaPS, a transfer of its functions to another body or MaPS delegates provision of the central digital architecture to another body, and we need to transfer your information as part of that.  If we needed to do this, the legal basis for the processing would also be public task.  

7. We may need to process your personal data to report matters to TPR and FCA and law enforcement agencies. The legal basis for this processing would be ‘public task’, ‘legitimate interests’ or legal obligation, depending on the circumstances’.

8. On occasion, to comply with legal obligations we are subject to.  The legal basis for this processing would be ‘legal obligations’.      

Who do we share your personal data with?

We may share your personal data where necessary with the parties set out below for the purposes set out in the section entitled “Purpose of processing (why we need your data) and our legal basis for doing so”:

  • our IT and digital service providers including Capgemini UK, Salesforce Cloud (the connection portal), Atlassian (Jira service support tool) and ServiceNow (IT helpdesk) – they are processors of your personal data
  • TPR, for applications to connect voluntarily
  • TPR or FCA, for notifications of change in connection date, or where required to assist regulator compliance and enforcement activity
  • law enforcement agencies on request by them or where we are aware of a matter which would be of interest to them, and it is lawful for us to do so

Our IT and digital service providers process your personal data on our behalf, and as such the details relating to the processing of your personal data by them is set out in this notice.  We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions. 

Other than the above, we will never share your personal data. We will never share your personal data with anyone for marketing purposes. 

How long we keep your data

For connecting party required role holders, we retain names and contact information on the connection portal of Salesforce for the duration of your holding of that role and delete them after 2 years following the ending of this role.

For PBCs and PTCs, we receive your identity information from GOV.UK One Login to verify your identity but, having done that, we don’t store that information ourselves.

For trustee/manager/SMF-16 vouching scheme checks, we receive your names and contact information from TPR/FCA but delete them immediately after use in the vouching scheme check. Upon deletion, emails will be retained in the online exchange and still recoverable for 30 days; encrypted and isolated backups may be retained for up to 12 months.

For voluntary connection applications, we retain names and contact information of applicants and names of the trustee(s) that authorised the application for 2 years.

For all support tickets logged via Jira and ServiceNow, we retain names and contact information for 2 years from the ticket being raised, after which personal data will be deleted.

For notifications of change in pension provider/scheme connection date, we retain contact information until the legislative deadline of 31 October 2026 only – after which the notification process becomes redundant and personal data is deleted.

Where we store your information

We store all information in the UK only.

How we keep your data secure

We are committed to doing all we can to ensure your personal data is kept secure. We have set up systems and processes to protect it from loss, misuse and unauthorised access or disclosure – for example, we protect your data using encryption. Our systems have been designed and developed based on National Cyber Security Centre best practice guidance.

We have data processing agreements with our suppliers, to make sure your personal data is secure and protected. Our employees and suppliers are all subject to a duty of confidentiality.

We also run regular IT testing and scanning activities to ensure the security of our systems.

Read our cookie policy.

Your rights

We respect your right to privacy and the protection of your personal data. We have a responsibility to protect this information and ensure its confidentiality, integrity and availability. We also want you to be in control of your personal data and respect your data protection rights. You have the right to: 

  1. Be informed – we will always explain to you why, and how, personal data about you is being processed.  
  2. Access your data – you can request access to the data we process about you on the details below.
  3. Rectify any data errors, though we may need to verify the accuracy of the new data you provide to us.
  4. Request restriction of processing of your personal data in certain circumstances. 
  5. Object – you have the right to object to us processing your personal data .

You can exercise your rights by contacting using the contact details set out in this notice.  

We do not use automated decision-making and we do not profile people.  

You will not have to pay a fee to access your personal data (or to exercise any of your other UK GDPR rights). However, we may charge a reasonable fee if we think your request is unfounded, repetitive or excessive. Alternatively, we could refuse to comply with your request in these circumstances. 

Complaints 

If you have any queries about how we use your personal data that are not answered here, or if you wish to complain to our Data Protection Officer, please contact us on the details set out at the beginning of this notice.  

We hope that we can address any concerns you may have, but you can always contact the Information Commissioner’s Office (ICO). 

Changelog

3 September 2026

  • Presentational enhancements to improve clarity of MaPS' processing of industry stakeholders' personal data.
  • Addition of process-specific data processing details including the specific data processed, purpose and retention details.
  • Addition of more details on who we share data with.