GAO Finds 17 of 31 Retirement Plan Providers Do Not Limit Selling Participant Data to Brokers
A new government review reveals that over half of major retirement plan providers place no restrictions on selling participant data to third-party brokers. The findings expose a significant regulatory gap in how the $9 trillion 401(k) industry handles sensitive financial information.
By Bo Feng
- Privacy Advocates
- Argue that sensitive financial data should never be monetized without explicit, opt-in consent from the participant.
- Plan Administrators
- Maintain that data sharing is functionally necessary to operate complex retirement plans and provide participants with holistic financial services.
- Regulatory Analysts
- Focus on the outdated nature of ERISA and the need for the Department of Labor to issue modernized, explicit privacy guidelines.
Most Americans assume their 401(k) data is locked down by strict federal privacy laws, much like their medical records or primary bank accounts. They believe the sensitive information handed to their employer—salary details, contribution rates, and personal identifiers—stays strictly within a closed loop between the company and the asset manager. The evidence, however, shows a far more porous ecosystem where financial privacy is routinely traded.[3]
A newly released Government Accountability Office (GAO) review of 31 major retirement plan service providers reveals that 17 of them place no contractual limits on their ability to sell participant data to third-party data brokers. The findings highlight a systemic vulnerability in how the retirement industry handles the personal information of millions of workers.[1]
The scale of this exposure is massive. More than 126 million Americans are currently enrolled in employer-sponsored retirement plans, representing a collective pool of over $9 trillion in assets. To administer these accounts, employers must transmit highly sensitive personally identifiable information to a web of external service providers.[1]
This ecosystem includes payroll providers who process the deductions, recordkeepers who track individual account balances, and asset managers who execute the trades. The data payload moving across these networks routinely includes birth dates, Social Security numbers, home addresses, and exact, real-time account balances.[1]
While this sharing is functionally necessary to administer the plan, the data rarely stops at the administrative level. The GAO's analysis of privacy disclosures found that 29 of the 31 reviewed providers either explicitly allow this data to be shared for marketing purposes or fail to specify any restrictions against it.[1]
More concerning to privacy advocates is the outright monetization of this data. The fact that over half of the reviewed providers can legally sell this information to data brokers means that a worker's retirement balance and contact information can be packaged and sold to external financial marketers without the worker's knowledge or consent.[1][2]
For participants looking to protect their information, the options are severely limited. The GAO found that only 12 of the 31 service providers even offer privacy disclosures that include a mechanism for participants to opt out of data sharing, leaving the majority of savers with no recourse.[1]
For participants looking to protect their information, the options are severely limited.
The root of this exposure lies in outdated federal law. The Employee Retirement Income Security Act (ERISA), the foundational 1974 law governing most U.S. employer-sponsored retirement plans, was written decades before the modern data broker industry existed. While ERISA imposes strict fiduciary duties on plan sponsors to act in the best financial interest of participants, it lacks explicit, modern privacy provisions regarding the monetization of participant data.[1][3]
In an attempt to modernize oversight, the Department of Labor issued cybersecurity guidance in 2021. This guidance stated that plan sponsors should clearly address their service providers' obligations to keep private information secure and prevent disclosure without written permission.[1]
However, the GAO report highlights a critical flaw in the 2021 guidance: it fails to explicitly define what specific participant data qualifies as "private." Furthermore, it does not clearly outline the circumstances under which written authorization is legally required before a provider can use or disclose the information.[1]
This regulatory ambiguity creates a gray area where service providers can argue that using participant data for cross-selling other financial products—such as IRAs, life insurance, or wealth management services—does not violate their fiduciary duties. The GAO warned that as more entities gain access to this data, the mathematical probability of inadvertent exposure increases.[1]
Beyond the nuisance of unwanted marketing, this expanded access elevates the risk of targeted identity theft and sophisticated financial fraud. Data brokers compile comprehensive profiles that can be exploited if they fall into the wrong hands, posing a direct threat to retirement security.[1][2]
To close these loopholes, the GAO formally recommended that the Secretary of Labor issue supplemental guidance. This new framework would need to explicitly define protected participant information and mandate strict parameters for when written consent is required before data can be shared or sold.[1]
In its official response to the report, the Department of Labor stated that it fully supports the goal of appropriately protecting participant information. The agency noted it will consider issuing supplemental guidance as resources permit, though it stopped short of committing to a specific timeline or regulatory mandate.
Until federal regulations catch up, the burden falls largely on employers. Plan sponsors have the leverage to negotiate stricter privacy clauses in their contracts with recordkeepers and asset managers, demanding that participant data be used solely for plan administration and explicitly prohibiting third-party sales.[3]
What to know
- A GAO review found 17 of 31 retirement plan providers do not limit their ability to sell participant data to third-party brokers.
- 29 of the 31 providers either allow data sharing for marketing purposes or fail to specify any restrictions.
- Only 12 of the reviewed service providers offer participants a mechanism to opt out of data sharing.
- The data routinely shared includes Social Security numbers, birth dates, and exact account balances.
- The GAO has recommended the Department of Labor issue supplemental guidance to explicitly define protected participant data.
Key terms
- Data Broker
- A business that collects personal information about consumers from various sources and sells that data to other organizations for marketing or risk assessment.
- ERISA
- The Employee Retirement Income Security Act of 1974, a federal law that sets minimum standards for most voluntarily established retirement and health plans in private industry.
- Fiduciary Duty
- A legal obligation requiring plan sponsors and certain service providers to act solely in the best financial interest of the plan's participants.
- Recordkeeper
- A financial service provider that tracks individual participant balances, processes contributions, and maintains the administrative platform for a retirement plan.
- Personally Identifiable Information (PII)
- Any data that could potentially identify a specific individual, such as a Social Security number, birth date, or exact account balance.
Sources
[1]U.S. Government Accountability OfficePrivacy AdvocatesRetirement Plans Could Be Sharing Your Personal Data. Are You at Risk?
Read on U.S. Government Accountability Office →
[2]CyberGuyPrivacy AdvocatesData brokers endangering retirement security
Read on CyberGuy →
[3]Factlen Editorial TeamRegulatory AnalystsSynthesis by Factlen editorial team
Read on Factlen Editorial Team →
Comments
Every angle. Every day.
Get finance stories with full source coverage and perspective breakdowns delivered to your inbox.


