Retirement plans may be sharing or selling Americans' personal data, watchdog warns
Over half of 31 service providers reviewed didn't limit their ability to sell participant data to third parties, GAO found
Retirement anxiety grows as Americans fear running out of money
MetLife president and CEO Michel Khalaf analyzes the retirement savings gap, group life insurance demand, and how A.I. is personalizing insurance services, on The Claman Countdown.
A new report by the Government Accountability Office (GAO) warns Americans' retirement plans may be sharing or selling personal information that can be used to market financial products and services.
Over 126 million Americans are enrolled in employer-sponsored retirement plans, such as a 401(k) or similar account, with total assets in those plans exceeding $9 trillion, according to the GAO.
Those plans are typically administered by external providers of financial services and the report explained that employers share some personally identifiable information with asset managers, payroll providers and record keepers who manage the investment and processing of contributions.
Personal data that employers may share with those service providers can include information like a birth date, Social Security number, account numbers and balances, as well as other data.
The GAO noted that while service providers can use that data to market financial products and services, they may, in some cases, sell that data to third parties, which can increase the risk of inadvertent exposure.
MOST AMERICANS STILL TRUST FINANCIAL ADVISORS OVER AI TOOLS FOR MAJOR MONEY DECISIONS, STUDY FINDS

The GAO warned that not all retirement plan service providers limit their ability to share plan participants' data for marketing purposes. (Istock)
GAO's analysis included a review of privacy disclosures from 31 service providers, of which 29 either explicitly allowed data sharing or didn't specify whether participant data could be shared for marketing purposes.
Additionally, over half of the financial service providers – 17 of the 31 – didn't limit their ability to sell participant data to data brokers or other third parties.
It also found that just 12 of the 31 service providers have privacy disclosures allowing plan participants to opt out of data sharing.
AMERICANS' 401(K) BALANCES HIT RECORD LEVELS IN 2025

Retirement plan service providers require access to personal data for investing and processing contributions to 401(k) and similar accounts. (Angela Weiss / AFP for Getty Images)
The GAO's report included a recommendation that the Labor Department provide additional guidance about data privacy for participants in retirement plans for sponsors and service providers.
In particular, GAO said that the labor secretary "should clarify what participant information should be considered private and the circumstances in which service providers should obtain written permission before using or sharing this information."
"Such guidance could also identify best practices including for providing individual participants with choice, to the extent practicable, about how their personal information may be used, sold or shared," GAO added.
FIDELITY ESTIMATES RETIREES WILL SPEND $185,500 ON HEALTHCARE AND MEDICAL EXPENSES IN RETIREMENT

The GAO report warned that data sharing creates the potential for bad actors accessing retirement plan participants' information. (Getty Images)
The Labor Department provided a response to the GAO's analysis that said it "fully supports the goal of appropriately protecting the personal information of participants and beneficiaries of plans" though it neither agreed nor disagreed with the report's recommendations.
The agency noted the GAO report's discussion of a 2021 guidance on cybersecurity that discussed data privacy as a component of service providers' fiduciary responsibilities to plan participants, which states that contracts should spell out the provider's obligation to protect private information.
GET FOX BUSINESS ON THE GO BY CLICKING HERE
The Labor Department's response added that while it believes the 2021 guidance makes it clear to fiduciaries that they're obligated to include data privacy considerations in their contracts, as resources permit, the agency will "carefully consider whether supplemental guidance aligned with the recommendation could or should be issued."




















