Close Menu
Your Life After RetirementYour Life After Retirement
  • Home
  • Retirement News
  • Lifestyle
  • Fitness
  • Wellness
  • Senior Health
  • Finance
  • Medicare & Insurance
Top Post

Apple’s New Foldable iPhone Duo Poised for Strong Sales

September 12, 2026

Will There Be ‘The Secret Lives of Mormon Wives’ Season 6?

September 12, 2026

Warren presses insurance regulators for answers on private credit ties as Walter probe widens

September 11, 2026
Facebook X (Twitter) Instagram
Trending
  • Apple’s New Foldable iPhone Duo Poised for Strong Sales
  • Will There Be ‘The Secret Lives of Mormon Wives’ Season 6?
  • Warren presses insurance regulators for answers on private credit ties as Walter probe widens
  • How Advisers Can Build Up the Industry’s Appeal
  • 9 Easy Breakfast Ideas for Type 2 Diabetes
  • The best stain removers for clothing (and the worst) | Life and style
  • Kalli Locklear Set to Make Her Mark on Olympia Weekend
  • FHA Loans: How They Work and Who They’re Best For
Saturday, September 12
Your Life After Retirement
  • Home
  • Retirement News
  • Lifestyle
  • Fitness
  • Wellness
  • Senior Health
  • Finance
  • Medicare & Insurance
Your Life After Retirement
Home»Retirement News»GAO Asks DOL to Clarify Permissible Participant Data-Sharing Practices
Retirement News

GAO Asks DOL to Clarify Permissible Participant Data-Sharing Practices

yourlifeafterretirementBy yourlifeafterretirementAugust 27, 2026
GAO Asks DOL to Clarify Permissible Participant Data-Sharing Practices
Share
Facebook Twitter LinkedIn

Millions of retirement savers provide their personally identifiable information to their employers and to the service providers for their plans under the assumption it is safe—but ever-present marketing tactics and sales to third parties beg to differ.

In response to a request from Senator Bernie Sanders, I-Vermont, Senator Patty Murray, D-Washington, and Representative Bobby Scott, D-Virginia, the Government Accountability Office issued a report earlier this year examining how plan participants’ data are used and shared by service providers. The GAO investigated whether the data are used beyond purposes of plan administration and potentially shared with third parties.

In a post on its website this week, the GAO wrote about “why retirement plans share data and what’s being done to protect [participants’] personal information.”

For more stories like this, sign up for the PLANADVISERdash daily newsletter. 

Credit reporting bureau Experian reported last month that losses in the U.S. from fraud and identity theft, which can involve the use of personal information, reached more than $15.8 billion in 2025, up more than 24% from 2024.

The GAO conducted its performance audit from January 2024 through February 2026. In a sample of 31 service providers’ privacy disclosures, the GAO found 15 providers had policies permitting the sharing of participant data for marketing, and 17 had unspecified rules about selling participant information. Only two providers prohibited sharing PII for marketing, while fewer than half (14) disallowed selling the data to third parties.

At the conclusion of its investigation, the GAO recommended to the Department of Labor that it issue additional guidance about acceptable uses of participant data. More specifically, the GAO requested that the secretary of labor clarify what information should be considered private and the circumstances in which providers should obtain written permission before using or sharing that information.

“As more entities gain access to participant data, the chance that their information may be inadvertently exposed increases, putting participants at greater risk of identity theft or other fraudulent activity,” the report stated.

Selected service provider policy disclosures reviewed by the GAO did not “incorporate leading privacy practices,” the report stated. Fair Information Practice Principles, a set of privacy protection principles first proposed by a U.S. government advisory committee in 1973 and subsequently widely adopted internationally, “emphasize key data privacy protection principles, such as transparency in data practices and restrictions to prevent unauthorized uses of personal information,” the GAO report stated.

Most disclosures the GAO examined (19) did not indicate that additional consent would be sought before sharing or otherwise using PII beyond originally specified purposes, contrary to an FIPP principle related to data usage limitations, the report found.

What the DOL Can Do

Lisa Gomez, a former assistant secretary of labor for the Employee Benefits Security Administration and now president of LMG Collaborative Consulting Solutions, says that while the retirement industry lacks specific rules governing sharing of participant data, it could learn from rules promulgated in the banking and health industries. The Health Insurance Portability and Accountability Act of 1996 is one law the DOL could use as a model.

“So many [aspects of] HIPAA’s [data sharing policy] could be applied to the retirement plan structure,” Gomez explains. “It discusses what kind of data is private, what types of protections need to be attached, what types of transparency are needed and under what circumstances healthcare providers can share your data.”

Gomez says that while there is a privacy regulation gap between the health and retirement industries, it is surmountable.

“I think if the [DOL] wanted to put out more guidance, it’s more of a question of [from whom] the authority [derives],” Gomez says. “With HIPAA, it’s [Congress] implementing a law, [whereas] there’s nothing in ERISA that governs this issue.”

According to the GAO report, the DOL has not penalized plans for sharing participant data. As Gomez notes, the Employee Retirement Income Security Act—the primary federal law governing most private sector employer-sponsored retirement plans—does not explicitly address data privacy.

The GAO also shared that 19 states had enacted “comprehensive data privacy laws as of November 2025” that provide “consumers with the right to opt out of having certain personal information sold or shared.” However, the GAO noted that on other legal issues, ERISA generally supersedes state law.

ERISA requires that plan fiduciaries use plan assets exclusively to provide plan benefits or to defray certain administrative costs. Some participants have sued in recent years, arguing participant data should be considered a plan asset under ERISA and that service providers that exercise authority and control over the management and disposition of data should be held responsible. However, courts that have ruled on the issue rejected the argument that participant data should be considered a plan asset.

The GAO report acknowledged that the DOL’s Employee Benefits Security Administration issued in 2021—updated in 2024—cybersecurity guidance for plan sponsors. However, the DOL’s guidance did not include information about “good practices for sharing data about plan participants,” the report stated.

Gomez adds that while protecting participant data is important, the DOL should consider both the benefits and risks of data sharing.

Marketing products could “annoy” participants and feel like an intrusion, Gomez says. But there are products, people and other resources participants would never otherwise come into contact with if not for having been solicited by a marketer. Financial advisers, financial wellness providers and student loan repayment tools could “open up paths” for participants to make better retirement decisions, Gomez says.

“The [DOL shouldn’t] put something out that is going to be too restrictive,” Gomez says. “That might be the safest thing for individuals, but it’s not necessarily going to be the best thing for them.”

In its response to the report, the DOL neither agreed nor disagreed with the GAO’s recommendation, noting that the agency will “will carefully consider, as resources permit, whether supplemental guidance aligned with the recommendation could or should be issued.”

Gomez says she believes the DOL’s neutral response likely stems from a “resource issue,” citing the DOL’s “full plate” of business, budget cuts and staff reductions over the past year.

Tags

Reported by

Reprints

Please contact Industry Intel at Industry Intel.

Asks Clarify DataSharing DOL GAO Participant Permissible Practices
Share. Facebook Twitter Pinterest LinkedIn Email
Previous ArticleHip Abductor Machine: Glute Benefits, Myths, Research & Programming Guide
Next Article Liberty Mutual says 1996 buyback ended its California toxic-site coverage
yourlifeafterretirement
  • Website

Related Posts

Retirement News

How Advisers Can Build Up the Industry’s Appeal

September 11, 2026
Retirement News

Products & Services Launches – 9/10/2026

September 11, 2026
Retirement News

August Saw Record Slow Trading in 401(k) Accounts, per Alight

September 10, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Lizzo’s Cherry Red Manicure Screams “Bad B*tch”

June 5, 20260 Views

Ryan Rozicki Reveals His Knockout Strategy Ahead of Chris Billam-Smith Clash at Zuffa Boxing 7

June 6, 20260 Views

How Scleral Lenses Provide Relief for Severe Dry Eye Disease

June 6, 20260 Views

Team Daly/Allen makes birdie on No. 14 at American Family Insurance Championship

June 6, 20260 Views
Most Popular

How to Watch ‘I Kissed a Girl’ Season 2 in the U.S.

July 1, 202613 Views

No One Likes Medicare Advantage

June 4, 202612 Views
Trending

Alyssa McElheny’s HYROX Tips for Athletes with a Running Background

June 4, 2026

The Muscle-Building Starter Pack: Train Hard, Eat Enough, Recover Right

June 4, 2026
Latest post

Apple’s New Foldable iPhone Duo Poised for Strong Sales

September 12, 2026

Will There Be ‘The Secret Lives of Mormon Wives’ Season 6?

September 12, 2026
Facebook X (Twitter) Instagram YouTube LinkedIn
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
yourlifeafterretirement All Rights Reserved 2026

Type above and press Enter to search. Press Esc to cancel.