GAO Report on Retirement Plans and Data Privacy
A recent report from the Government Accountability Office (GAO) raises concerns that personal information from Americans’ retirement plans could be shared or sold for marketing financial products and services.
According to the GAO, there are over 126 million Americans enrolled in employer-sponsored retirement plans, like 401(k)s, with their total assets surpassing $9 trillion. These plans are often managed by external financial service providers, which means that employers regularly share certain identifiable information with them, including details such as birth dates, Social Security numbers, and account balances.
The report highlights that while these service providers can leverage this data for marketing purposes, there’s a risk that they might, at times, sell it to third parties. This raises concerns about potential unauthorized exposure of sensitive information.
Interestingly, the GAO analyzed the privacy policies of 31 different service providers and found that 29 of them either permit data sharing or do not clearly specify whether participant data can be shared for marketing. Alarmingly, over half—17 of the 31—do not restrict selling participant data to data brokers or outside entities.
Only 12 out of the 31 service providers provide options for plan participants to opt-out of data sharing, which, I think we can agree, is rather concerning.
The GAO has recommended that the Labor Department offer more comprehensive guidance regarding data privacy in retirement plans. They suggested that the Labor Secretary should outline what participant information is deemed private and clarify when written consent is necessary before this information can be used or shared. Such guidelines could also promote best practices for giving participants some control over how their personal data is handled.
The Labor Department responded to the GAO’s findings, expressing support for protecting personal information of plan participants and beneficiaries. However, they did not take a definitive stance on the report’s recommendations. They did reference a cybersecurity guidance issued in 2021, discussing the importance of data privacy as a duty for service providers, noting that contracts should clearly outline these obligations.
As concerns about data privacy continue to grow, this report shines a light on the ways that personal information might be at risk in the world of retirement planning.






