Companies found to have breached data protection law by selling people's pension pot details face fines of up to £500,000, the information commissioner has warned.
Christopher Graham said claims that millions of individuals' data is being sold and ending up in the hands of criminals were "very serious".
An investigation has been launched by the privacy watchdog into the allegations published by the Daily Mail.
The newspaper reports that pensioners' salaries, the value of their investments and the size of their pensions are being sold for as little as 5p without their consent.
The financial details are allegedly being bought by fraudsters and cold-calling firms.
The paper said its undercover reporters were sold pension pot details for 15,000 people without any checks being made on who they were and what they wanted the data for.
Responding to the claims, Mr Graham told BBC Radio 4's Today programme: "I think it is very serious and we have immediately launched an investigation.
"We are in touch with the pensions regulator, the Financial Conduct Authority and the police b ecause this looks like a very serious breach of the Data Protection Act.
"If it is a breach of the Data Protection Act, then the companies involved are facing serious civil monetary penalties of up to half a million pounds.
"If we establish it's criminal activity by individuals, then they are in deep trouble too."
The investigation comes ahead of next week's pension reforms, which will give savers the chance to access their full retirement pots.
Experts at the Information Commissioner's Office (ICO) have previously warned that the pension reforms on April 6 could result in a flood of scams on the scale of "the next PPI scandal".
Steve Eckersley, head of enforcement at the ICO, described the revelations as "very worrying indeed".
He said: "It suggests a frequent disregard of laws that are in place specifically to protect consumers.
"We're aware of allegations raised against several companies involved in the cold-calling sector, and will be making inquiries to establish whether there have been any breaches of the Data Protection Act or Privacy and Electronic Communications Regulations.
"The ICO has powers to issue companies with fines of up to £500,000 for the most serious breaches of the Data Protection Act, while we can also pursue criminal prosecutions around unlawfully obtaining or accessing personal data."
An ICO spokesman said it appeared that some firms were getting their hands on pension details because some people do not read the terms and conditions of contracts they sign, leaving them open to having their personal data accessed.
He said it appeared that some companies were getting and selling on the information unlawfully.
Some details appear to have been stolen, while other firms appear to have kept personal information when they should have deleted it.
Discussing the pension reforms, Mr Eckersley said: "The information we've been shown supports the work we've been doing to target the shady industry that operates behind the nuisance of cold calls and spam texts.
"We're already aware of the potential for a huge spike in the number of scam texts and calls linked to pensions when the law changes in April, and have already taken action against a company that was sending out misleading messages.
"What we've seen here confirms those fears. Personal data is such a valuable asset, particularly financial information.
"The worst-case scenario here is this information getting into the wrong hands and being used to target individuals at a critical point in their financial lives."
Shadow work and pensions secretary Rachel Reeves said: "Today's revelations that personal data is being passed on to those looking to make a quick buck out of pensioners' savings are shocking.
"This is further evidence of the Government's total failure to protect more than 300,000 savers who could start accessing their pensions in just over a week's time.
"Ministers have ignored warning after warning about the threats to savers from fraudsters, but they must now act quickly to protect savers from these serious threats to people's hard-earned retirement income.
"Labour supports greater flexibility on retirement, and will take swift action to protect savers, with a cross-government task force to stamp out scams, and caps on pension fees and charges, including for retirement products, so that savers get the most out of their money."
One company named in the Daily Mail's report said it would welcome an ICO investigation and would co-operate fully with it.
In a statement, B2C Data Limited said: "B2C Data Limited is registered with the Information Commissioner's Office and is a member of the Direct Marketing Association. It operates an entirely legitimate and legally-compliant data business.
"It complies with all its legal requirements. Importantly, it does not receive or process information other than in respect of those customers of its members who have opted in. Equally, it does not sell 'highly sensitive details of ... salaries, investments and pensions'.
"The company is appalled by today's reporting in the Daily Mail which contains numerous factual errors and exaggerations.
"While B2C is consulting with its legal advisers, it welcomes an investigation by the ICO into these matters and it will co-operate fully with any investigation. B2C Data takes its legal obligations very seriously and will continue to do so."