More than half of retirement plan service providers don't restrict their ability to sell participant data to third parties, a Government Accountability Office review found.
More than half of retirement plan service providers don't restrict their ability to sell participant data to third parties, a Government Accountability Office review found.

A GAO review found 17 of 31 retirement plan service providers don't limit selling participant data to data brokers, exposing personal information of 126 million Americans enrolled in employer-sponsored plans.
The GAO said the labor secretary "should clarify what participant information should be considered private and the circumstances in which service providers should obtain written permission before using or sharing this information."
Of the 31 providers reviewed, 29 either explicitly allowed data sharing or didn't specify whether participant data could be shared for marketing purposes. Just 12 of the 31 have privacy disclosures allowing participants to opt out. The data at risk includes birth dates, Social Security numbers, account numbers and balances.
With more than $9 trillion in assets across employer-sponsored retirement plans, the exposure extends to the majority of American workers. The Labor Department said it "fully supports the goal" of protecting participant information but neither agreed nor disagreed with the recommendations, leaving the regulatory path uncertain.
The GAO's review examined privacy disclosures from 31 service providers that administer employer-sponsored retirement plans, including 401(k) accounts. Employers routinely share personally identifiable information with asset managers, payroll providers and record keepers who manage investments and process contributions. That data can be used to market financial products and services, and in some cases, sold to third parties, increasing the risk of inadvertent exposure.
The report builds on the Labor Department's 2021 cybersecurity guidance, which already addresses data privacy as a component of service providers' fiduciary responsibilities. That guidance states that contracts should spell out the provider's obligation to protect private information. However, the GAO found that the existing framework doesn't go far enough to protect participants, noting that the 2021 guidance doesn't specify which data elements should be treated as private or when written consent is required.
Data Sharing Practices Widespread Across Providers
The findings highlight a gap between what participants expect and what providers can legally do with their information. While 12 of the 31 providers offer opt-out provisions, the remaining 19 either don't offer that option or don't specify whether participants can restrict data sharing. The GAO's recommendation would require written permission before service providers use or share participant information, a standard that would significantly tighten current practices.
The timing is notable given that Americans' 401(k) balances hit record levels in 2025, according to Fidelity data. Higher balances mean more valuable data for marketers and data brokers, and potentially greater financial exposure for participants if that information falls into the wrong hands. The GAO noted that data sharing creates the potential for bad actors accessing retirement plan participants' information.
Labor Department Stops Short of New Rules
The Labor Department's response acknowledged the goal of protecting participant information but stopped short of committing to new guidance. The agency said it will "carefully consider whether supplemental guidance aligned with the recommendation could or should be issued," as resources permit. This leaves retirement plan sponsors and service providers without clear direction on what constitutes private participant data and when written consent is required.
For the 126 million Americans with employer-sponsored retirement accounts, the practical implications are significant. Personal data sold to data brokers can fuel unsolicited marketing for financial products, and in the worst cases, increase exposure to fraud and identity theft. Participants who want to limit data sharing should review their plan provider's privacy disclosures and exercise any available opt-out options. Plan sponsors, meanwhile, face the challenge of negotiating contracts that adequately protect participant data without clear regulatory guidance on what protections are required.
This article is for informational purposes only and does not constitute investment advice.