Data protection at Elo
Elo’s task is to manage the statutory pension security of employees and entrepreneurs in accordance with the Employees Pensions Act (TyEL) and the Self-Employed Persons’ Pensions Act (YEL), and, for this purpose, manage the accrued funds profitably, safely and responsibly. In order to carry out this task, we need to process personal data.
Elo ensures the protection of its customers’ privacy and processes their personal data in accordance with the currently valid legislation, including pension legislation, the EU General Data Protection Regulation (hereinafter GDPR), the national data protection legislation and legislation governing the insurance industry and credit institutions as well as provisions concerning investment funds.
Why does Elo process personal data?
Elo collects and processes data for the purposes of performing its designated tasks. Our field and activities are defined within the relevant legislation. Our tasks include the provision of statutory pension security for employees and entrepreneurs and the management of the funds accrued for this purpose.
All self-employed persons are obligated to take YEL insurance in accordance with the Self-employed Persons’ Pensions Act, which serves as the foundation for the pension and social security of self-employed persons. The insurance is required by law. In order to manage the insurance matters of self-employed persons, Elo must process information related to its self-employed customers and their companies. Some of this information is personal data concerning the self-employed individuals.
Elo manages the funds accrued for pension security in a manner that ensures the benefits inherent to the insurances. As part of our investment activities, Elo provides its customer companies with financing solutions and opportunities to lease premises in real properties owned and managed by Elo. Elo outsources its leasing and property management activities to external service providers who maintain a register containing information about the lessees and relevant service providers.
Information about loan recipients and pledgers are stored in a loan register to assist in credit management.
Elo offers its customers online services comprised of Elo’s public website (Elo.fi) and Elo’s Online Service that customers can access by logging in.
Elo’s website utilises cookies for the purposes of collecting information about the use of the website and related transactions. More information about the cookies is available at elo.fi/Terms of use.
We utilise data derived from the use of Elo's email and website so that we can offer Elo’s customers interesting information about Elo’s services and topical issues as well as to further market our services to insurance and pension customers. The contact information is also used for the issuing of customer feedback surveys.
The processing of personal data is also necessary for the development of Elo’s own operations, so that we can offer our customers competitive services and ensure the high quality of our customer services. As part of the development of our operations, we use data collected for the management of statutory insurance and compensation matters for the additional purpose of conducting analyses on transaction methods, and of evaluating and reporting on the efficiency of our activities and communications.
We provide automated decisions concerning old-age and partial early old-age pensions and YEL insurance. Upon receiving an automated decision, registered individuals have the right to demand a manual reprocessing of their application. As a means of ensuring quality, Elo may utilise profiling to support the making of pension disability decisions. The profiling is based on the data concerning the matter being processed and statistics on relevant decisions. Profiling is not used as the basis for automated decisions.
Data is collected from our chat and phone services for the purposes of documenting customer service situations and of ensuring the legal protection of the customers. Calls can be recorded and stored.
What personal data is processed by Elo?
Elo only collects personal data to the extent that is necessary for the implementation of its designated tasks.
For this purpose, we collect our customers’ name, personal ID and contact information. Through our activities, we also collect, for example, payroll and pension information and information concerning the ownership of our company customers. Health information is processed in connection with the handling of disability and rehabilitation matters. As part of our investment activities, Elo offers its customer companies financing solutions and real estate space. For the purposes of leasing and management of our real estate properties, we process information, such as the name and contact information, of our lessees and relevant service providers. For the purposes of credit management, we also require information about loan recipients and pledgers (credit information).
More detailed information about the personal data processed by Elo is available from our privacy policy statements
- Privacy statement for pension insurance policyholders, partners and service providers
- Privacy statement for insured persons and applicants or recipients of pensions or rehabilitation benefits
- Privacy statement for recipients of fees, employees of contractual partners and external board professionals
- Privacy statement for investment operations
- Privacy statement for job applicants
- Privacy statement for the visitors of Elo’s office building and camera surveillance
- Privacy statement for Elo’s residential tenants
What are Elo's sources of information?
Elo gets information directly from the registered individuals. Elo may also request personal data from sources from which Elo is entitled by law to request information (e.g., institutions managing statutory social insurance or health care providers).
The employers of the insured provide us with regular payroll and other employment-related information for insurance purposes and compensation decisions. In order to maintain and verify customer contact information, we acquire data from, among others, Posti Group Oy and the Population Information System. As concerns loan customers and policyholders, and the recovery of benefits, Elo also acquires information from credit records
To whom does Elo disclose information?
Information is disclosed if the recipient has a right by virtue of the law to receive information from Elo. These rights concern, for example, institutions managing statutory social insurance, the tax authorities and distraint authorities, who need such information to carry out their own tasks. The employer has the right to receive information about granted pensions, e.g., for the adjustment of the insurance contribution. Elo may also disclose personal data to other countries by virtue of the international law treaties to which Elo is bound and EU legislation, in cases where such actions are necessary for the realisation of pension security. For the management of its support tasks and investment activities in accordance with the valid employment pension legislation, Elo also uses external service providers, which will then process the personal data on behalf of Elo. Payment transactions take place through banks operating in Finland, whereby personal data is transferred to the banks.
Elo primarily uses companies located within the EU/EEA area to implement tasks related to the maintenance and development of its information systems. If Elo uses companies located outside of the EU/EEA area, Elo only discloses personal data that is necessary for the implementation of the aforementioned tasks and the personal data will be adequately protected.
Elo will not, without the consent of the registered individual, disclose information to other external parties. It is possible to withdraw the given consent at any time.
How is my personal data protected?
Acting responsibly is the most important principle of Elo's data security. The objective of data security is to safeguard the reliability, usability and availability of the data processed by Elo and to prevent confidential information from falling into the wrong hands.
Data security is an integral part of the quality of Elo’s operations and services, overall security and the daily processing of data by Elo employees. Our data security policy comprehensively specifies the roles and responsibilities of each Elo employee with regard to the implementation of data security.
We have invested in our processes in order to assess and avoid data protection risks. Elo’s entire personnel is trained in data protection, and we have appointed a Data Protection Officer. We continuously develop our operations with regard to data protection. We also require our service providers to maintain a high level of data protection, and this is part of our standard contractual requirements.
Data security work is coordinated by the Data Security Manager working in IT administration. We ensure the high level of data security through continuous training and data security audits of different systems. baData security is included in the induction of every new Elo employee, and the online course on data security is mandatory for all Elo employees. In addition, we provide the different functions with training geared to their specific tasks.
We closely co-operate with our various IT service providers and data security partners. Elo also cooperates with various authorities as a company critical to emergency supply.
Where do I find information about the processing of my personal data?
Information about the processing of data at Elo is available from these pages. Any enquiries about our data protection can be sent by email to Elo’s Data Protection Officer at tietosuoja@elo.fi.
In accordance with data protection legislation, you have the right of access to any personal data concerning you that Elo has recorded and stored. You have a right, among other things, to know what personal information Elo has about you. If you wish to exercise your right of access, you can contact our Data Protection Officer. Please note that you will be required to identify yourself prior to gaining access to your personal data. If you feel that any information Elo has concerning you is incorrect, you can demand that the information be rectified.
When Elo is processing information for the purpose of managing statutory pension security, the related rights are limited by legislation. In other words, the legislation limits the right to have personal data removed or transferred to another system or to object to the processing of information.
Elo’s document publicity description
In order to implement the publicity principle, Elo Mutual Pension Insurance Company maintains a description of its information pools. This description is called a document publicity description. The aim of the description is to help Elo’s insurance and pension customers when they wish to submit a request for information concerning Elo’s documents.
The document publicity description describes the information pools that Elo processes when performing public administrative tasks or exercising public authority. An information pool means an entity containing datasets that is processed through information systems or manually. The document publicity description is based on the statutes of the Act on Information Management in Public Administration.
Elo registers the information concerning matters being processed, case processing and documentation. This information is in Elo’s operative information systems and on paper, from which it is archived in accordance with regulations. The information related to Elo’s case processing is located in three information pools. These are the information pools for the Self-employed person’s employment pension insurance, Pension processes and Employer’s employment pension insurance.
Elo’s information pools
Purpose of the information pool
The purpose of the information pool for the Self-employed person’s employment pension insurance is the management and development of the employment pension insurance activities specified in employment pension legislation and the related customer service. The information pool is also used to manage storage, reporting and inquiries in accordance with legal obligations and orders issued by authorities and the Finnish Centre for Pensions.
Datasets
The information pool stores information about the validity of a pension insurance policy in accordance with the Self-employed Persons’ Pensions Act (Yrittäjän eläkelaki 22.12.2006/1272, YEL) as well as the confirmed income in order to determine pension insurance contributions and calculate pension amounts. The information collected during the management of the pension insurance is also stored. In addition, the management of insurance activities requires information about invoicing and the collection of insurance contributions.
Information pool contains the following datasets:
- Basic information of the policy holder and responsible person
- Basic information of the policy holder’s stakeholders
- Customer identification information
- Turnover and ownership information
- Bank account number
- Insurance applications
- Insurance and confirmed income decisions
- Bonus information
- Information about decision appeals
- Confirmed income reductions
- Policy holder’s line of business
- Contribution discount
- Negligence fee
- Customer contact logs and documents, for example, electronic messages
- Internal memos
- Tax information
- Online service agreement and electronic service choice as well as marketing authorisation
- Customer feedback
- E-mails and telephone call records and information
Invoicing and collection datasets contain the following data groups:
- Basic information of the policy holder and payer
- Information on insurance contribution calculations
- Invoicing information, for example, amount, due date, invoice method, invoice number, e-invoice information
- Payment plans
- Debt enforcement information and other information on external debt collection
- Customer contact logs and documents
- Internal memos
- Collection status
- Method of remittance
- Information on bankruptcy and restructuring
- Customer feedback
- E-mails and telephone call recordings and logs
Information systems
The datasets for Self-employed person’s employment pension insurance and invoicing and collection are registered in different systems. These include the customer system, customer relationship management system, document management, invoicing system and collection system as well as network services. Other information systems used are the customer feedback storage systems and the telephone system.
Making a request for information
Keywords that information can be searched with are
- Business ID
- Name of self-employed person or company
- Personal identity code
- Customer number
- Insurance number
- Invoice number
- Telephone number
The policy holder or their authorised person has access to the online service where they can view the insurance and invoice information. If the online service does not have the desired document or if the online service is not in use, a request for information can be sent by e-mail to yel@elo.fi.
Purpose of the information pool
Data is processed in order to manage the tasks and services related to payment activities in accordance with pension legislation as well as the related customer service. The information pool is also used to manage storage, reporting and inquiries in accordance with legal obligations and orders issued by authorities and the Finnish Centre for Pensions. The information in the information pool is also used to process the insurance matters of employers who have taken out an insurance policy in accordance with the Employees Pensions Act 19.5.2006/395 (TyEL) and to provide services to such employers.
Datasets
The information pool stores data required for advance counselling, pension decisions and pension payment activities.
The information pool contains the following data groups:
- Basic information of the insured and the beneficiary
- Basic information of the authorised person
- Pension and benefit applications and reimbursements and the related appendices
- Decisions and calculations
- Earnings that the pension is based on and other information affecting pension calculations
- Medical records
- Insurance doctor’s medical assessments
- Information about decision appeals
- Bank account number
- Information about the technical provisions of pensions
- Paid and recovered pensions
- Withholding tax information
- Withheld payments and debt enforcement information
- Customer contact logs and documents, for example, electronic messages
- Internal memos
- Estimate calculations and other documents related to customer counselling
- Service provider invoices
- Customer feedback
- Telephone call recordings and logs
Information systems
The payment activities information systems include the customer system, pension processing system, pension payment system and document management. Other information systems are the customer feedback storage systems and the telephone system.
Making a request for information
Keywords that information can be searched with are
- Name
- Personal identity code
- Telephone number
The insured person has access to the online service where they can, for example, view their pension record, manage their pension matters and receive pension decisions. If the online service does not have the desired document or if the online service is not in use, a request for information can be made by sending a contact request by e-mail to elakeasiakirjat@elo.fi.
Purpose of the information pool
The purpose of the information pool for the Employer’s employment pension insurance is the management and development of the employment pension insurance activities specified in employment pension legislation and the related customer service. The information pool is also used to manage storage, reporting and inquiries in accordance with legal obligations and orders issued by authorities and the Finnish Centre for Pensions.
The information pool stores information about the validity of a pension insurance policy in accordance with the Employees Pensions Act 19.5.2006/395 (TyEL) as well as salary/wage information in order to determine pension insurance contributions and calculate pension amounts. The information collected during the management of the pension insurance is also stored.
In addition, the information pool contains information about invoicing and the collection of insurance contributions required to manage insurance activities.
The insurance information pool contains the following datasets:
- Basic information of the policy holder and responsible person
- Basic information of the policy holder’s stakeholders
- Customer identification information
- Turnover and ownership information
- Bank account number
- Insurance applications
- Employee wage/salary information
- Bonus information
- Information about decision appeals
- Policy holder’s line of business
- Negligence fee
- Customer contact logs and documents, for example, electronic messages
- Internal memos
- Tax information
- Online service agreement and electronic service choice
- Customer feedback
- E-mails and telephone call recordings and logs
Invoicing and collection datasets contain the following data groups:
- Basic information of the policy holder and payer
- Invoicing information, for example, amount, due date, invoice method, invoice number, e-invoice information
- Payment plans
- Debt enforcement information and other information on external debt collection
- Customer contact logs and documents
- Internal memos
- Collection status
- Method of remittance
- Information on bankruptcy and restructuring
- Customer feedback
- E-mails and telephone call recordings and logs
Information systems
The datasets for insurance, invoicing and collection are registered in different systems. These include the customer system, earnings system, customer relationship management system, document management, invoicing system and collection system as well as network services. Other information systems used are the customer feedback storage systems and the telephone system.
Making a request for information
Keywords that information can be searched with are
- Business ID
- Name of company
- Personal identity code
- Customer number
- Insurance number
- Invoice number
- Telephone number
The policy holder or their authorised person has access to the online service where they can view the insurance and invoice information. If the online service does not have the desired document or if the online service is not in use, a request for information can be sent by e-mail to tyel@elo.fi.