Skip to main content

Making workplace pensions work

Menu

Information asset register and/or Record of processing activities

FOI-reference - FOI-475
Date - 11 June 2026

Request

  1. A copy of The Pension Regulator’s current Information Asset Register and/or Record of Processing Activities (ROPA). 
  2. The name of the software, platform, or system used to maintain the Information Asset Register and/or Record of Processing Activities (for example, whether this is maintained in a specialist governance tool, spreadsheet, SharePoint, Microsoft Lists, or another system). 
  3. Any guidance, procedures, training materials, templates, manuals, or instructions provided to staff regarding: 
    • Information Asset Owners (IAOs); 
    • Information Asset Administrators (IAAs) or equivalent roles; 
    • Completion and maintenance of the Information Asset Register; 
    • Completion and maintenance of the Record of Processing Activities; 
    • Review and assurance processes relating to information assets and processing activities. 
  4. Any policy, standard, framework, or governance document that describes how information assets and records of processing activities are managed within the organisation.

Response

I confirm that we hold some of the information you have requested. However, some of the information you have requested is exempt from disclosure.

  1. A copy of TPR’s current Information asset register and/or Record of processing activities (ROPA)
    • Information asset register – Information not held. 
      The Information asset register has been developed as a tool but not yet populated with information.
    • ROPA – We hold a Record of Processing Activities. We are disclosing a copy of this, with some information redacted.
  2. The name of the software, platform, or system used to maintain the Information Asset Register and/or Record of Processing Activities (for example, whether this is maintained in a specialist governance tool, spreadsheet, SharePoint, Microsoft Lists, or another system)
    • Information Asset Register: The Information Asset register was built in Power Apps and is hosted in Dynamics 365.
    • ROPA: The Record of Processing Activities is maintained within Sharepoint Lists.
  3. Any guidance, procedures, training materials, templates, manuals, or instructions provided to staff.
    • Information Asset Owners (IAOs) and Information Asset Administrators (IAAs) or equivalent roles: Information Asset Owners and Information Asset Administrators are not used in TPR. Guidance about Data and Information Owners and Data and Information Stewards has been provided.
    • Completion and maintenance of the Information Asset Register: Information not held.
    • Completion and maintenance of the Record of Processing Activities: Guidance about completion and maintenance of the Record of Processing Activities has been provided. Please note that redactions have been applied to the “ROPA Guidance” document. This information is exempt from disclosure under Section 40 of the FoIA.
    • Review and assurance processes relating to information assets and processing activities: Information not held.
  4. Any policy, standard, framework, or governance document that describes how information assets and records of processing activities are managed within the organisation
    • Information not held.

The following information has been redacted from the ROPA and guidance documents:

Names of internal contact and data owners

This information is exempt from disclosure under Section 40 of the FoIA. This is because the information constitutes personal data as defined in the UK General Data Protection Regulations (UK GDPR). Disclosing this would not comply with the data protection principles set out in the UK GDPR, in particular the requirement for processing to be fair, lawful and transparent (Article 5 (1)(a)), as well as to comply with one of the lawful bases for processing in Article 6.

Entries in relation to our processing for intelligence gathering and pension regulation cases that can often lead to criminal prosecutions

Section 31(1)(g) & (2)(b)-(c) provides that:

"Information which is not exempt information by virtue of section 30 is exempt information if its disclosure under this Act would, or would be likely to, prejudice–

(g) the exercise by any public authority of its functions for any of the purposes specified in subsection (2).

(2)(b) the purpose of ascertaining whether any person is responsible for any conduct which is improper, (2)(c) the purpose of ascertaining whether circumstances which would justify regulatory action in pursuance of any enactment exist or may arise."

Our objectives under Section 5 of the Pensions Act 2004 include the protection of members’ benefits under occupational and personal pension schemes; to reduce the risk of circumstances arising in which claims may be made on the Pension Protection Fund; and to promote and improve the understanding and good administration of work-based pension schemes.

In exercising our functions with this objective in mind we conduct investigations, obtain advice and launch formal action. Releasing to the public at large the level of detail about our investigation and related discussions would reveal unpublished information regarding our risk model. Releasing details of our risk methodology, tactics and other strategic decisions is not in the public interest as it could enable persons to take undue advantage of this information to try and evade regulatory action. Disclosure would have an adverse effect on our ability to effectively carry out our statutory duties. This would not be in the interest of schemes or their members.

The exemption at section 31(1)(g) of the FoIA is a qualified exemption which requires a public interest test be carried out. The ‘public interest’ means the ‘public good’ and not just what is of interest to the public or the private interests of particular requesters.

We recognise the general public interest in promoting transparency, accountability and public understanding in how we carry out our functions. We also acknowledge the public interest in knowing that we manage our data responsibly and that this is protected by appropriate security.

In this case the public interest factors in favour of disclosing the information are as follows:

The public interest factors in maintaining the exemption are as follows:

  • There is a public interest in the TPR’s internal systems operating in a way which does not leave it vulnerable to cyber-attacks.
  • The disclosure of internal security checks is not a critical part of the accountability tracker and the information of primary relevance to the request is not affected by its exemption.
  • By gathering and analysing information, we can monitor risks and emerging trends. Where appropriate, we step in to prevent these from crystallising or to minimise their effect. Identifying our sources of information may risk our approach to regulating defined benefit, master trusts or broader defined contribution schemes and public service pension schemes. Further information on how we regulate can be found on our website. 

Having considered all of these factors we have taken the decision that the public interest in withholding the security and order reference number outweighs the public interest in disclosing this information.

Is this page useful?

Thanks for your feedback.