Participant Data Faces Increased Regulatory Scrutiny

Retirement plan sponsors are well accustomed to fiduciary obligations around investment selection, fee reasonableness, and plan administration. Increasingly, however, another consideration has been drawing regulatory attention: how participants’ personal and financial data is collected, used, and shared by the service providers that help run the plan.

What a GAO Report Found In a February 2026 report, the U.S. Government Accountability Office (GAO) examined how retirement plan service providers, including recordkeepers and asset managers, handle the personal information of the roughly 126 million Americans participating in private-sector defined contribution retirement plans.

After reviewing the privacy disclosures of 31 retirement plan service providers, GAO found many use participant data not just to administer the plan but also to market other financial products and services and, in some cases, sell that information to third parties. Service providers told GAO that the data helps them tailor products and services to participants’ needs. However, GAO noted that the broader use of participant data may also increase the risk of inadvertent exposure, potentially leading to identity theft or fraud.

GAO evaluated the disclosures against widely recognized privacy standards known as the Fair Information Practice Principles, which call for transparency and clear limits on how personal data can be used. All 31 service providers clearly disclosed their data collection and use practices. However, 19 of the 31 disclosures did not indicate that the provider would seek additional consent before using or sharing participant data for purposes beyond what was originally disclosed.

The report also notes that the Department of Labor (DOL) has not taken enforcement action against any retirement plan over data-sharing practices. Although ERISA itself doesn’t explicitly address data privacy, DOL officials told GAO they believe ERISA’s existing fiduciary duties of prudence and loyalty should be sufficient to deter plan sponsors and service providers from making unauthorized use of participant data.

GAO also suggested that additional DOL guidance could help plan sponsors and service providers better understand what constitutes appropriate use of participant data and when consent should be obtained, particularly given that state privacy laws can add another layer of complexity.

Why This Matters for Plan Sponsors Even without additional DOL guidance, plan sponsors may elect to take a closer look at how participant data flows through their plan’s service arrangements by:

  • Understanding what’s being shared. Sponsors can ask recordkeepers and other service providers what participant data they collect, how it’s used, and whether it’s shared with or sold to third parties for marketing or other purposes.

  • Reviewing privacy disclosures. Many service providers publish privacy policies, but these documents can be dense and vary widely in what they promise. Comparing disclosures carefully across providers may help identify gaps or areas of concern.

  • Revisiting provider selection and monitoring practices. Just as plan sponsors evaluate fees and investment performance as part of their fiduciary oversight, data privacy and security practices also may be relevant factors to consider when selecting or reviewing recordkeepers and other providers.

Sources:

https://www.gao.gov/products/gao-26-107271

https://401kspecialistmag.com/why-cybersecurity-matters-more-than-ever-for-plan-sponsors-and-401k-plans/

Leave a Reply

Your email address will not be published. Required fields are marked *