A new report by the Government Accountability Office (GAO) warns Americans’ retirement plans may be sharing or selling personal information that can be used to market financial products and services.

Over 126 million Americans are enrolled in employer-sponsored retirement plans, such as a 401(k) or similar account, with total assets in those plans exceeding $9 trillion, according to the GAO.

Those plans are typically administered by external providers of financial services and the report explained that employers share some personally identifiable information with asset managers, payroll providers and record keepers who manage the investment and processing of contributions.

Personal data that employers may share with those service providers can include information like a birth date, Social Security number, account numbers and balances, as well as other data.

The GAO noted that while service providers can use that data to market financial products and services, they may, in some cases, sell that data to third parties, which can increase the risk of inadvertent exposure.

MOST AMERICANS STILL TRUST FINANCIAL ADVISORS OVER AI TOOLS FOR MAJOR MONEY DECISIONS, STUDY FINDS

GAO’s analysis included a review of privacy disclosures from 31 service providers, of which 29 either explicitly allowed data sharing or didn’t specify whether participant data could be shared for marketing purposes.

Additionally, over half of the financial service providers – 17 of the 31 – didn’t limit their ability to sell participant data to data brokers or other third parties.

It also found that just 12 of the 31 service providers have privacy disclosures allowing plan participants to opt out of data sharing.

AMERICANS’ 401(K) BALANCES HIT RECORD LEVELS IN 2025

401k pension stock market

The GAO’s report included a recommendation that the Labor Department provide additional guidance about data privacy for participants in retirement plans for sponsors and service providers.

In particular, GAO said that the labor secretary “should clarify what participant information should be considered private and the circumstances in which service providers should obtain written permission before using or sharing this information.”

“Such guidance could also identify best practices including for providing individual participants with choice, to the extent practicable, about how their personal information may be used, sold or shared,” GAO added.

FIDELITY ESTIMATES RETIREES WILL SPEND $185,500 ON HEALTHCARE AND MEDICAL EXPENSES IN RETIREMENT

A hacker using a phone and computer.

The Labor Department provided a response to the GAO’s analysis that said it “fully supports the goal of appropriately protecting the personal information of participants and beneficiaries of plans” though it neither agreed nor disagreed with the report’s recommendations.

The agency noted the GAO report’s discussion of a 2021 guidance on cybersecurity that discussed data privacy as a component of service providers’ fiduciary responsibilities to plan participants, which states that contracts should spell out the provider’s obligation to protect private information.

The Labor Department’s response added that while it believes the 2021 guidance makes it clear to fiduciaries that they’re obligated to include data privacy considerations in their contracts, as resources permit, the agency will “carefully consider whether supplemental guidance aligned with the recommendation could or should be issued.”

Share.
Leave A Reply