21st April 2011

Data Protection and Retention of Data.

One of the more unusual responses to the Panacea FOS survey was from a firm who was concerned that keeping client information indefinitely was arguably necessary given the lack of a 15 year longstop, but could be in breach of the Data Protection Act 1998 (DPA).

Under the DPA the fifth Data Protection Principle states:

“Personal data processed for any purpose or purposes shall not be kept for longer than is necessary for that purpose or those purposes.”

Upon making an enquiry to the Information Commissioner Panacea were told that keeping information “just in case” a claim arises may be deemed to be a breach of Principle 5 by the Information Commissioner. If correct this would leave firms in the unenviable position of being compelled to dispose of client files knowing that this could leave them very vulnerable to claims and complaints in the future. This could be a particular concern for firms exiting the industry in some way and whom have no run-off PI cover and no ongoing relationship with a particular client that requires them to retain the information.

So what is the position?

Firstly, FSA rules require firms to retain certain client records for certain minimum periods, depending upon the type of business. Note that they are minimum periods however, so firms cannot be criticised by the FSA for retaining records for longer than those periods and it cannot be the case that firms are compelled by the DPA to dispose of those records immediately upon expiry of the minimum retention period specified by the FSA rules if it is reasonable for them to maintain them for a longer period of time.

Secondly, the Information Commissioner’s own website appears to contradict the advice given to Panacea as it states:

“It may well be necessary in some cases to retain certain information to enable the data controller to defend legal claims, which may be made in the future. Unless there is some other reason for keeping them, the personal data should be deleted when the possibility of a claim arising no longer exists i.e when the relevant statutory time limit has expired.”; and

“..you may need to keep some personal data about the customer so that you can deal with any complaints they might make about the services you provided.”

As there is no statutory time limit for FOS complaints, on the basis of the above statement long term retention of client records is potentially permitted and endorsed by the Information Commissioner.

It is unlikely to be that simple however and indefinite retention of all client data would almost certainly leave firms with some exposure under the DPA.  Whilst there are mixed messages coming from the Information Commissioner’s office, it would therefore be sensible to take some basic steps to mitigate the risks arising from long term retention of client data if you consider that this may be an issue for your firm.

One way to deal with this would be to state at the outset in your terms of business/client agreement that you will retain personal data after the client relationship has ended for the purposes of dealing with any queries or complaint from the client. Whilst overtly mentioning complaints may ring alarm bells, all firms are required to refer to their internal complaints procedure and the FOS in  their terms of business/client agreement anyway, so this should not increase the risk of receiving complaints and in reality clients are very unlikely to object to such wording or raise any queries.

It would also be sensible for firms to consider having a “Retention of Data/Documentation” policy where some thought is given to which records are kept for how long and the justification for keeping such documents for a longer period, if this is the case. For some lower risk business, firms could consider disposing of data at some point after the FSA minimum retention periods have expired, whilst for higher risk business firms may seek to retain the records for a much longer period. The fact that a firm has addressed its mind to the issue and set it out in a policy, that is adhered to, makes it more likely to stand up to scrutiny.

If a firm does not want to address this issue at the outset of a client relationship as described above, or even if it has, another option is to write to clients after a set period has elapsed since your last contact with them (and perhaps once the FSA minimum retention periods have expired), stating that you intend to retain their files for a stated period in order to deal with any queries or complaints in the future. Any such communication could mention the long term nature of financial products to justify the data retention.

If adopting any of the above, firms should also write to any client whose data they are about to dispose of and warn them of the impending disposal, so that clients have the opportunity to ask the firm to retain the data (or send it to the client) if they wish to do so.

Firms may need to be particularly careful when seeking to retain “sensitive personal data” on clients for extended periods. “Sensitive personal data” is defined under the DPA and includes information about the client’s racial or ethnic origin, physical or mental health or sexual life (but does not include financial information). The DPA imposes more onerous duties on those processing “sensitive personal data” and as financial advisers may well hold such data on clients, particularly when advising on life policies, particular case needs to be taken when retaining such data for extended periods – both in ensuring that such retention is justified, making it clear to the client that such data will be retained and ensuring that the manner in which the data is stored is sufficiently secure (there is useful guidance on data security within the “Smaller Firms” section of the FSA website at http://www.fsa.gov.uk/smallfirms/resources/factsheets/pdfs/data_security.pdf and http://www.fsa.gov.uk/smallfirms/resources/one_minute_guides/info_gathering/data_security.shtml).

In summary some clarification of the position from the Information Commissioner would be useful for firms but in the meantime there are steps that firms can take to ensure that they are able to retain personal data to deal with any client complaints and justify such retention if challenged. Indefinite retention of all data is unlikely to be permissible in all but the most unusual of circumstances, but if a little more thought is given to the issue the key risks to the business may be able to be addressed.

The other thing to remember is that the best way to avoid ongoing liabilities for complaints following retirement is to incorporate if you currently trade as a partnership or sole trader. You cannot divest yourself of personal liabilities already incurred but to can draw a line in the sand and avoid incurring future liabilities.

Alan Hughes, associate and Marlene Howels, associate, Foot Anstey – alan.hughes@footanstey.com and marlene.howels@footanstey.com

This bulletin is provided for information purposes only. Its contents do not constitute legal advice and should not be regarded as a substitute for specific professional advice. © Foot Anstey 2011 All Rights Reserved.

 

Regulation

Registration

Free Registration and CPD

Related Articles_

YouGov: Are Consumers Getting Better Outcomes as a Result of the Consumer Duty?


Nearly three years after the introduction of Consumer Duty, are firms delivering the improved outcomes the FCA intended? Drawing on insights from more than 65,000 UK consumer interviews, this on-demand webinar from YouGov explores how perceptions of financial services have evolved since implementation. Discover which sectors and brands are leading the way, where gaps remain, and how different customer groups, including vulnerable consumers and younger generations, view their experiences today. Gain valuable insight into the latest Consumer Duty trends and what they could mean for firms looking to strengthen customer outcomes.

Read More

Panacea Conversations - Beyond the Questionnaire: Rethinking Attitude to Risk


Attitude to Risk is one of the foundations of good financial planning, yet it’s often reduced to a questionnaire and a risk score. In the latest episode of Panacea Conversations, compliance expert Tony Catt explains why the real value lies in the conversations behind the questionnaire. We explore adviser bias, client psychology, capacity for loss, vulnerability, and why risk shouldn’t be viewed solely through an investment lens. If you want to strengthen your Attitude to Risk process, this is a conversation worth hearing.

Read More

Panacea Conversations - Beyond the Questionnaire: Rethinking Attitude to Risk


In this episode of Panacea Conversations, we explore one of the most fundamental, and often misunderstood, aspects of the advice process: Attitude to Risk.

Read More

Login

Not yet registered?

Please complete this form to join our community

Name
Email
Company
Select your role:
Password
Confirm Password