GAO Reports on Participant Privacy Risks
The Government Accountability Office (GAO) recently published a blog post “Retirement Plans Could Be Sharing Your Personal Data. Are You at Risk?”, highlighting findings from a GAO report released in March following a congressional request to examine retirement plan data privacy.
The blog notes that while participant data must often be shared to administer retirement plans, broader access to that information may increase the risk of fraud, misuse, or unauthorized disclosure. Drawing from the March report, GAO highlighted several key findings.
Marketing Use of Participant Data. GAO reviewed the privacy disclosures of 31 retirement plan service providers and found that 29 either expressly permitted sharing participant data for marketing purposes or did not clearly state whether they restricted such sharing.
Sale of Participant Data. More than half of the service providers reviewed did not limit their ability to sell participant data to data brokers or other third parties.
Participant Opt-Out Rights. Some participants could opt out of having their information used for marketing purposes, while others could not. Only 12 of the 31 service providers reviewed provided an opt-out mechanism in their privacy disclosures.
GAO noted that ERISA does not contain explicit provisions governing participant data privacy in today's digital age. Although the Department of Labor (DOL) issued cybersecurity guidance in 2021, GAO observed that the guidance does not define what participant information should be treated as private or address when service providers should obtain written consent before using or disclosing that information. According to the report, DOL officials indicated that the agency believes that ERISA’s fiduciary duties of prudence and loyalty provide meaningful protection against unauthorized uses of participant data by plan sponsors and service providers.