Your 401(k) Data May Be for Sale, Federal Watchdog Warns

Retirement saver reviewing his 401(k) as personal financial data flows to third-party servers.

More than 126 million Americans trust employer-sponsored retirement plans with their savings. A new federal report warns that some of those plans’ service providers may also be using, sharing or selling participants’ personal and financial information.

The Privacy Risk Inside America’s Retirement System

Americans collectively held more than $9 trillion in defined-contribution retirement plans as of 2023, according to the Government Accountability Office.

Managing those accounts requires employers to provide outside companies with significant amounts of participant information. Record keepers, asset managers and payroll processors may receive Social Security numbers, birth dates, account balances, contribution histories and other financial details.

That access is often necessary. Providers need accurate information to process contributions, maintain account records, execute transactions and distribute retirement benefits.

The problem begins when companies use the same information for purposes unrelated to administering the plan.

After reviewing the privacy disclosures of 31 retirement-plan service providers, the GAO found that 29 either explicitly allowed participant data to be shared for marketing or failed to specify whether such sharing was prohibited.

More than half of the disclosures, 17 out of 31, did not limit the provider’s ability to sell participant data to brokers or other third parties.

Only 12 of the 31 disclosures said participants could opt out of at least some forms of data sharing for marketing.

The GAO’s sample included 21 record keepers and 10 asset managers. The agency cautioned that the group was nongeneralizable, meaning the results cannot automatically be applied to every retirement provider in the country. Even so, the findings expose a potentially significant weakness inside a financial system holding trillions of dollars and some of the most sensitive information Americans possess.

Your Retirement Account Is Also a Valuable Data Profile

A retirement account can reveal far more than an investor’s current balance.

Contribution rates may indicate income and savings behavior. Asset allocations can reveal risk tolerance. Withdrawals may signal financial stress. Age, employment status and account size can help companies estimate when someone may retire, roll over a 401(k), purchase an annuity or seek financial advice.

When combined with information gathered from credit bureaus, social media, insurance companies and other sources, retirement data can become the foundation of a highly detailed consumer profile.

The GAO found that 28 of the 31 providers disclosed that they could collect information from sources beyond the participant’s employer. Twenty-four said they could collect data from other third parties, potentially including financial advisers, insurance companies and healthcare providers.

Marketing was a stated reason for outside data collection in 15 of the 31 disclosures. Research was cited by 13.

This creates an economic incentive that most employees may never consider. A service provider can earn fees from administering retirement assets while potentially using its privileged access to identify customers for loans, insurance, annuities, investment advice and other financial products.

In that sense, a plan participant may represent two valuable assets: a retirement account generating administrative or investment revenue and a detailed financial profile capable of generating additional sales.

The Regulatory Gap Behind the Warning

The Employee Retirement Income Security Act, better known as ERISA, establishes fiduciary standards for most private-sector retirement plans. It requires covered fiduciaries to act prudently and in the interests of plan participants.

However, ERISA was enacted in 1974 and does not explicitly address modern data privacy.

That omission leaves employers and service providers operating across a patchwork of federal financial regulations, state privacy laws, contractual restrictions and voluntary practices.

The Labor Department issued cybersecurity guidance in 2021 directing plan fiduciaries to consider how service providers protect participant information. The guidance recommended that contracts clearly describe a provider’s obligation to safeguard private data.

The GAO concluded that the existing guidance offers insufficient detail about when participant information may be used or shared for secondary purposes.

It recommended that the Labor Department clarify which information should be treated as private and when providers should obtain written permission before using, sharing or selling it. The agency also suggested giving participants greater control over how their information is handled whenever practical.

The Labor Department said it “fully supports the goal of appropriately protecting the personal information of participants and beneficiaries of plans.” It neither agreed nor disagreed with the GAO’s recommendation, although it said it would consider whether supplemental guidance should be issued as resources permit.

Why Investors Should Pay Attention

Record Keepers Face a New Compliance Risk

The largest retirement-plan administrators sit at the center of an enormous financial-data network. Clearer Labor Department standards could force record keepers and asset managers to rewrite contracts, change data-retention policies, improve consent systems and restrict cross-selling practices.

Those changes would create additional compliance expenses. They could also reduce the value of participant data as a marketing tool.

For major financial institutions, the immediate financial effect may be manageable. The larger risk involves litigation, reputational damage and the possibility that employers reconsider service-provider relationships.

Employers Could Face Greater Fiduciary Scrutiny

Employers choose the companies that administer their retirement plans. If participant privacy becomes part of the fiduciary standard, plan sponsors may be expected to evaluate data practices with the same seriousness applied to fees, investment options and cybersecurity.

Large employers often have the legal resources and bargaining power to negotiate detailed privacy protections. Smaller companies may rely more heavily on standard provider contracts.

The GAO found that only two of the six employer privacy disclosures it reviewed mentioned limitations placed on contractors’ collection or use of employee data. Industry participants also told the agency that smaller plans frequently lack the detailed privacy agreements used by larger sponsors.

That disparity could produce a new compliance divide. Retirement providers capable of offering strong, transparent privacy protections may gain a competitive advantage among employers trying to reduce fiduciary and legal exposure.

Data Breaches Become More Dangerous as Information Spreads

Every additional company with access to retirement information creates another potential point of failure.

A stolen password can be changed. A Social Security number, birth date and long-term financial history cannot be replaced so easily.

The danger also extends beyond direct theft from a retirement account. Criminals can use detailed financial profiles to conduct identity theft, impersonate trusted institutions or design convincing phishing attacks around rollovers and retirement withdrawals.

The GAO cited Justice Department estimates showing that roughly 24 million Americans age 16 or older experienced identity theft during a 12-month period, producing $16.4 billion in financial losses during 2021.

That figure covers identity theft broadly, but it illustrates the potential cost when sensitive financial information escapes its intended environment.

Privacy Could Become a Competitive Product Feature

Retirement-plan competition has traditionally focused on fees, investment selection, performance, digital tools and employee education. Data governance may soon join that list.

Providers that offer simple opt-out controls, limited data collection and contractual restrictions on third-party sales could use privacy as a selling point. Companies with vague disclosures may face pressure from employers, regulators and participants to explain their practices.

This could create opportunities for cybersecurity firms, consent-management platforms and compliance specialists serving the retirement industry.

Targeted Services Can Still Benefit Participants

Some uses of retirement data can help savers.

Providers may use account information to identify workers who are contributing too little, carrying costly debt or approaching retirement without a clear withdrawal strategy. Personalized education and financial-wellness programs can encourage better decisions.

The danger comes from limited transparency and control. A participant may reasonably welcome customized retirement education while rejecting the sale of personal information to an outside marketer.

Clear consent rules could preserve beneficial services while giving participants greater authority over unrelated commercial uses. That balance may prove more practical than attempting to prohibit every secondary use of retirement information.

About Author

Leave a Reply