GAO Asks DOL to Clarify Permissible Participant Data-Sharing Practices

A Government Accountability Office report found that most of the 31 service providers it examined did not follow ‘leading privacy practices.

Millions of retirement savers provide their personally identifiable information to their employers and to the service providers for their plans under the assumption it is safe—but ever-present marketing tactics and sales to third parties beg to differ.

In response to a request from Senator Bernie Sanders, I-Vermont, Senator Patty Murray, D-Washington, and Representative Bobby Scott, D-Virginia, the Government Accountability Office issued a report earlier this year examining how plan participants’ data are used and shared by service providers. The GAO investigated whether the data are used beyond purposes of plan administration and potentially shared with third parties.

In a post on its website this week, the GAO wrote about “why retirement plans share data and what’s being done to protect [participants’] personal information.”

Want the latest retirement plan adviser news and insights? Sign up for PLANADVISER newsletters.

Credit reporting bureau Experian reported last month that losses in the U.S. from fraud and identity theft, which can involve the use of personal information, reached more than $15.8 billion in 2025, up more than 24% from 2024.

The GAO conducted its performance audit from January 2024 through February 2026. In a sample of 31 service providers’ privacy disclosures, the GAO found 15 providers had policies permitting the sharing of participant data for marketing, and 17 had unspecified rules about selling participant information. Only two providers prohibited sharing PII for marketing, while fewer than half (14) disallowed selling the data to third parties.

At the conclusion of its investigation, the GAO recommended to the Department of Labor that it issue additional guidance about acceptable uses of participant data. More specifically, the GAO requested that the secretary of labor clarify what information should be considered private and the circumstances in which providers should obtain written permission before using or sharing that information.

“As more entities gain access to participant data, the chance that their information may be inadvertently exposed increases, putting participants at greater risk of identity theft or other fraudulent activity,” the report stated.

Selected service provider policy disclosures reviewed by the GAO did not “incorporate leading privacy practices,” the report stated. Fair Information Practice Principles, a set of privacy protection principles first proposed by a U.S. government advisory committee in 1973 and subsequently widely adopted internationally, “emphasize key data privacy protection principles, such as transparency in data practices and restrictions to prevent unauthorized uses of personal information,” the GAO report stated.

Most disclosures the GAO examined (19) did not indicate that additional consent would be sought before sharing or otherwise using PII beyond originally specified purposes, contrary to an FIPP principle related to data usage limitations, the report found.

What the DOL Can Do

Lisa Gomez, a former assistant secretary of labor for the Employee Benefits Security Administration and now president of LMG Collaborative Consulting Solutions, says that while the retirement industry lacks specific rules governing sharing of participant data, it could learn from rules promulgated in the banking and health industries. The Health Insurance Portability and Accountability Act of 1996 is one law the DOL could use as a model.

“So many [aspects of] HIPAA’s [data sharing policy] could be applied to the retirement plan structure,” Gomez explains. “It discusses what kind of data is private, what types of protections need to be attached, what types of transparency are needed and under what circumstances healthcare providers can share your data.”

Gomez says that while there is a privacy regulation gap between the health and retirement industries, it is surmountable.

“I think if the [DOL] wanted to put out more guidance, it’s more of a question of [from whom] the authority [derives],” Gomez says. “With HIPAA, it’s [Congress] implementing a law, [whereas] there’s nothing in ERISA that governs this issue.”

According to the GAO report, the DOL has not penalized plans for sharing participant data. As Gomez notes, the Employee Retirement Income Security Act—the primary federal law governing most private sector employer-sponsored retirement plans—does not explicitly address data privacy.

The GAO also shared that 19 states had enacted “comprehensive data privacy laws as of November 2025” that provide “consumers with the right to opt out of having certain personal information sold or shared.” However, the GAO noted that on other legal issues, ERISA generally supersedes state law.

ERISA requires that plan fiduciaries use plan assets exclusively to provide plan benefits or to defray certain administrative costs. Some participants have sued in recent years, arguing participant data should be considered a plan asset under ERISA and that service providers that exercise authority and control over the management and disposition of data should be held responsible. However, courts that have ruled on the issue rejected the argument that participant data should be considered a plan asset.

The GAO report acknowledged that the DOL’s Employee Benefits Security Administration issued in 2021—updated in 2024—cybersecurity guidance for plan sponsors. However, the DOL’s guidance did not include information about “good practices for sharing data about plan participants,” the report stated.

Gomez adds that while protecting participant data is important, the DOL should consider both the benefits and risks of data sharing.

Marketing products could “annoy” participants and feel like an intrusion, Gomez says. But there are products, people and other resources participants would never otherwise come into contact with if not for having been solicited by a marketer. Financial advisers, financial wellness providers and student loan repayment tools could “open up paths” for participants to make better retirement decisions, Gomez says.

“The [DOL shouldn’t] put something out that is going to be too restrictive,” Gomez says. “That might be the safest thing for individuals, but it’s not necessarily going to be the best thing for them.”

In its response to the report, the DOL neither agreed nor disagreed with the GAO’s recommendation, noting that the agency will “will carefully consider, as resources permit, whether supplemental guidance aligned with the recommendation could or should be issued.”

Gomez says she believes the DOL’s neutral response likely stems from a “resource issue,” citing the DOL’s “full plate” of business, budget cuts and staff reductions over the past year.

«