“When, Not If” - A privacy discipline for modern families

modern families
  • Blog
  • 10 minute read
  • 07/09/26
Lisa Cornwell

Lisa Cornwell

Partner, Leader Private Clients and Family Offices, PwC Switzerland

In a world where data leaks are increasingly common, families need to rethink their approach to privacy and treat it as an ongoing discipline to manage, rather than a fixed state to assume. 

The question is no longer if a data breach will happen, but when and where the next one will occur

Over the past decade, the privacy that many families once took for granted has been steadily weakened. The Panama Papers (2016), the Paradise Papers (2017) and the Pandora Papers (2021) exposed ownership information on a global scale. More recently, we have seen data breaches at national tax authorities, cases of incorrect information being shared by financial institutions under the automatic exchange of information and ongoing attempts by hackers to obtain data to embarrass, blackmail or otherwise compromise the family. Most recently, Liechtenstein's Register of Beneficial Owners (VwbP) was attacked. These are not isolated incidents. For families, for whom privacy is a key asset - often the most prized one - it is now clear that privacy can no longer be assumed. 

Why this matters to families

For families with legitimate privacy concerns — whether that’s personal security, protection from kidnapping or extortion, defense against predatory litigation, or a clear wish to keep their financial affairs out of the public eye— a leak is damaging and, crucially, permanent. Information cannot ever be “unleaked.”

At PwC, we see a deeper challenge beyond any single breach. It is that most families do not have a clear view of where their data actually sits, who can access it, or where the vulnerabilities lie. A compromised register – as we saw recently - is just one of many ways in which privacy can fail; and rarely the one families are watching most closely.

What happened

The VwbP is a non-public statutory register, accessible through defined statutory routes to competent authorities and certain obliged entities rather than to the general public. Copies of data relating to around 31,000 legal entities were unlawfully accessed and exfiltrated.

What was leaked

•  Legal entity name

•  Surname and first name of each beneficial owner

•  Date of birth, nationality and country of residence

•  Where applicable, the basis on which the person is a beneficial owner (ownership, control or role), not the value of any interest

What was NOT leaked

The Government has confirmed the VwbP holds no addresses or telephone numbers and no financial data (revenues, assets or dividends). No conclusions about wealth can be drawn from the exfiltrated data itself.

A useful distinction

The VwbP is an AML beneficial-ownership register. It is distinct from CRS/FATCA, which concern the automatic exchange of financial-account and tax information. Families are often exposed under both through different channels and with different data, and should map each separately.

A privacy framework for families

If your family holds sensitive ownership information through structures in any jurisdiction - which is now the reality for most families - this framework gives you a clear, practical way to understand your exposure and take control of how you manage it.

1.  Conduct a data audit

Start by mapping the landscape:

  • Which jurisdictions hold Ultimate Beneficial Owner (UBO) data on your family?

  • Which registers have been completed — corporate registries, trust registries, UBO registers, land registries, and tax-authority databases via automatic exchange?

  • What was provided to each source — names, addresses, passport copies, source-of-wealth narratives?

  • Which intermediaries hold your data (law firms, trust companies, banks, accountants, family offices) and to what storage standards?

  • What is held electronically versus in hard copy?

Before undertaking any technical deep dive, review the true online presence of each family member. Time and again, a family takes elaborate steps to protect identities, assets and locations, only for someone to post a photograph from the family yacht, instantly revealing ownership and location.

2. Distinguish mandatory from voluntary disclosure

We often find that not everything shared was legally required. Families sometimes provide more detail than they need to, either to be helpful or to satisfy an over-cautious compliance officer. It is worth establishing:

  • Was the information legally mandated, or simply requested by an intermediary?

  • Where have you provided personal data beyond what the regulation required?

  • Have you consented to data-sharing that you could withdraw?

Going forward, adopt a clear principle: share the minimum required to comply and confirm what that minimum actually is, every time, before disclosing anything.

3. Assess your jurisdictional exposure

Different jurisdictions carry very different risk profiles. Consider:

  • Is the UBO register public, restricted, or non-public?

  • What is the jurisdiction's track record on data protection?

  • Is there a risk of regime change that could alter disclosure norms?

  • Is the jurisdiction under pressure to increase transparency as international standards evolve?

As a general rule: the more data held in one place, the more attractive a target it becomes.

4. Review your nominees and layering

Where structures use nominee directors, nominee shareholders or professional trustees, be clear about what each layer actually achieves:

  • Nominees are not effective against UBO registers, which look through to the ultimate beneficial owner.

  • Nominees may still serve a purpose in certain public-facing documents.

  • Does the structure make sense on every level — not only for asset protection and tax efficiency, but also for privacy?

5. Know and use your data-protection rights

Where GDPR applies (across the EU and the EEA, including Liechtenstein), data subjects generally have rights. These are not absolute and may be limited by statutory AML-register rules, but they remain a practical tool:

  • Right of access - confirm what data is held about you.

  • Right to rectification - correct inaccurate data.

  • Right to erasure - request deletion where data is no longer necessary for its original purpose.

  • Right to restriction of processing - limit how your data is used.

  • Right to object - object to processing in certain circumstances.

Families should consider exercising applicable rights actively and regularly, while recognising that statutory AML-register exemptions and limitations will apply. We do not see this right being actively and consistently exercised yet, but believe in future it will be. 

6. Revisit your security architecture

Legal structure is only one dimension of privacy. In practice, operational security matters more:

  • What addresses are used for correspondence — personal residential addresses, or registered offices?

  • Is sensitive information discussed over email? (In our experience, this is the single biggest risk in most families.)

  • Where are documents stored, physically and digitally, and who has access?

  • Which individuals at your service providers can see your data, and what vetting, training and confidentiality obligations apply? Are they contractually obliged to notify you of a breach?

7. Plan for the worst

Assume that any data you have provided to a register, intermediary or institution could one day become public. Then ask:

  • If this information were published tomorrow, what would the consequences be?

  • Does disclosure of your identity, address or wealth create physical risk?

  • Could the information be used by adverse parties in existing or future disputes?

  • Is there anything that would be embarrassing or easily mischaracterised if reported in the press?

  • Would disclosure create issues within the family, for example, beneficiaries discovering the extent of family wealth?

For each identified risk, develop a response plan now, not after the next leak.

In summary

Privacy is a discipline. It calls for active, ongoing control over what data exists, where it sits, who can access it and what happens if those controls fail. Today, families need to treat their personal data with the same rigour they apply to their investments: actively managed, regularly reviewed, and ready to adapt as risks change.

Get in touch if you would like to discuss this further. At PwC, our multidisciplinary family office team can consider your position from every angle — legal, tax, regulatory and operational – to help you act with confidence.


Contact me

Lisa Cornwell

Partner, Leader Private Clients and Family Offices, PwC Switzerland

+41 58 792 25 93

Email