Jump to content

Data protection at Elo

Elo’s task is to manage the statutory pension security of employees and entrepreneurs in accordance with the Employees Pensions Act (TyEL) and the Self-Employed Persons’ Pensions Act (YEL), and, for this purpose, manage the accrued funds profitably, safely and responsibly. In order to carry out this task, we need to process personal data. In addition, Elo processes personal data relating to persons belonging to its various stakeholder groups and to its potential customers and business partners. 

We ensure the protection of our customers’ privacy and process their personal data in accordance with currently applicable legislation and in a secure manner. 

Why does Elo process your personal data?

The collection and processing of personal data is a necessary part of Elo’s statutory duties. Personal data is needed so that insurance contributions can be determined in the correct amount, the amount of pension accrued to insured persons can be calculated, and pension applications can be decided. Legislation also requires the maintenance of various registers, the purpose of which is, among other things, to ensure transparency in the company’s administration or to prevent money laundering. 

Contact with representatives of cooperation partners and other stakeholders ensures functional services and dialogue with societal actors in the development of the pension system. In our investment activities, we maintain continuous dialogue with contact persons of existing and potential investment targets so that pension funds are invested productively and securely. In addition, in the marketing of insurance and in connection with the management of insurance, we process the contact details of company representatives and entrepreneurs. 

The data collected is also used secondarily to ensure operational continuity, to develop Elo’s own operations and services, and to produce reports. 

 

What personal data of mine does Elo process and for what purposes? 

The data processed is determined according to the roles in which you interact with Elo and the purposes for which you do so. Elo collects personal data only to the extent necessary to achieve the objectives of each purpose of use. 

As a rule, we obtain data related to earnings-related pension insurance and the administration of pension cover from you yourself, from various authorities, from healthcare operators, and from the employer acting as the TyEL policyholder. Elo’s right to obtain data from sources other than you yourself in these tasks is based on law. We also use commercial operators, such as Suomen Asiakastieto, as data sources, particularly in the processing of personal data related to policyholders, potential customers and investment targets. 

More detailed information about the processing of personal data at Elo is available in the privacy statements: 

The collected data may also be used for other purposes in a manner compatible with the original purposes of use. This means, for example, that: 

  • we analyse the use of services, the frequency of use, service channels and customers’ contacts with us in order to better understand our customers’ wishes and needs and to develop the functionality of our services, clarify processes, improve the customer experience and strengthen customer engagement 
  • we use the collected data in statistical analyses, studies and modelling through which we identify, among other things, phenomena and development needs relating to the use of services and benefits, customer relationships and risks of work disability, and we use this information to improve and enhance our operations 
  • we seek to anticipate the development of customer relationships and to adapt customer-specific measures accordingly 
  • we carry out various quality assurance measures, controls and cross-checks in databases in order to ensure that the data is accurate and up to date and that it is transferred correctly between systems 
  • we may, to a limited extent, use the data for the development, testing and deployment of information systems in order to ensure their secure and reliable operation 
  • we produce statistics and analyses that are used in the planning, management and reporting of Elo’s own operations 
  • we report on our operations to the Finnish Centre for Pensions and the Financial Supervisory Authority 
  • we produce statistical reports to support TyEL policyholders in managing the risk of work disability; these reports are based on data collected and generated in connection with insurance activities and pension decision-making 

For these purposes, the data is processed primarily in aggregated, anonymised or pseudonymised form whenever possible. 

To whom does Elo disclose or transfer my data?

Data related to earnings-related pension insurance and benefits is confidential. Elo may disclose personal data of pension and insurance customers only with the person’s consent, or where the person has authorised a third party to handle matters on their behalf, and where the recipient has a statutory right to obtain data from Elo. Such recipients include, among others, various social security authorities and the tax administration. The employer of the insured employee also has the right to obtain information on granted pensions for purposes specified in more detail in the Employees Pensions Act. 

In its operations, such as tasks related to the maintenance and development of information systems and the administration of insurance, Elo uses external service providers, which then process personal data on behalf of Elo. The service providers are mainly located in the EU/EEA area, but in the case of some of them, data is also processed in other countries. In transfers of data outside the EU/EEA, the existence of appropriate transfer mechanisms is ensured and, in addition, personal data is protected wherever possible, for example by pseudonymisation. 

How is my data protected? 

The most important principle of Elo’s information security is responsible operation. The objective of information security is to safeguard the reliability, usability and availability of the data processed at Elo and to prevent confidential data from falling into the wrong hands. 

Information security is an essential part of the quality of Elo’s operations and services, overall security, and the daily processing of data. Our information security policy defines the roles and responsibilities for ensuring information security. We have invested in our processes so that data protection risks can be assessed in advance and avoided, and we continuously develop data protection and information security. Elo’s entire personnel is trained in data protection and information security matters, and we have appointed a Data Protection Officer. 

We also require a high level of information security from our service suppliers and conduct information security audits of information systems, as well as maintain close cooperation with our various ICT service suppliers and information security partners. As a company critical to security of supply, Elo also cooperates with various authorities and takes cybersecurity best practices into account in its operations. 

Profiling and automated decision-making 

We issue automated decisions regarding pensions other than discretionary pensions and regarding YEL insurance. Automated decision-making is based on predefined rules and, where necessary, an application is referred for human handling. Once you have received an automated decision, you have the right to demand that the application be reconsidered in a non-automated procedure and to appeal the decision. You can read more about automated decision-making at Elo on the website General notifications and implementation decisions. 

In order to ensure quality and a consistent decision-making practice, assistive profiling may be used to support the decision-making work relating to disability pension and rehabilitation decisions. Profiling is based on the data of the matter being processed and on decision statistics. Automated decisions are not made in relation to these benefits on the basis of profiling. 

Artificial intelligence may be used in assistive tasks to support processes. However, administrative decisions are not made by means of artificial intelligence. 

What rights do I have? 

You have the rights to your personal data that are provided for in data protection legislation. The scope of these rights varies depending on the basis on which Elo processes your data. For example, as a rule there is no right to have data collected for Elo’s statutory duties erased, because other legislation requires Elo to retain this data for a specified period. The justified rights of other persons or companies, such as privacy protection or trade secrets, may also limit your rights. 

If you wish to exercise your data protection rights, you can identify yourself in our online service and send us your request there. For general data protection questions, or if you are not an Elo customer, you may also send a message to our Data Protection Officer by email at tietosuoja@elo.fi. 

Log in to the online service

<noscript><iframe src="https://www.googletagmanager.com/ns.html?id=GTM-P23HWQ" height="0" width="0" style="display:none;visibility:hidden"></iframe></noscript>
<noscript><img src="https://tracking.superlines.io?tid=sl_bt_n7ibi9ajj1nli4ca29cvmfp1vd93vldn" width="1" height="1" style="position:absolute;left:-9999px;visibility:hidden" alt=""></noscript>