Never miss a story — sign up for PLANADVISER newsletters to keep up on the latest retirement plan adviser news.
Pontera, Supporters Make Case Against Recordkeepers Restricting 401(k) Access
Industry leaders argued in a webinar that participant consent, rather than recordkeeper approval, should determine access to retirement account data and assets.
As retirement savings shifted from defined benefit pensions to defined contribution plans, workers assumed greater responsibility for saving and investing for retirement.
“We went from a system that was built for long-term employment and a job-based pension to one where workers are moving from job to job,” said Lisa Gomez, former assistant secretary of labor for the Employee Benefits Security Administration, on Thursday during a webinar hosted by fintech company Pontera Solutions Inc., which advertises 401(k) plan management. “They have much more responsibility for saving for retirement, and the legal and regulatory system and structure has not caught up with that.”
The webinar, “Who Gets a Say in the 401(k)? Technology, Trust and the Future of Advice,” was hosted by Pontera in collaboration with 401(k) Specialist. Panelists discussed whether retirement savers should be able to authorize outside advisers to access their retirement plan assets and data.
According to Gomez, participants have the right to seek advice from financial professionals of their choosing.
“The law does not prohibit participants from choosing an outside adviser or for an outside adviser [to provide] that advice,” she said.
Gomez cited the Department of Labor’s Interpretive Bulletin 96-1, which distinguishes between financial professionals independently selected by plan participants and advisers made available through an employer. The DOL has repeatedly stated that plan sponsors generally are not liable for the actions of professionals independently chosen by participants, provided the sponsor neither endorses nor arranges for those services.
Data Access Debate
The discussion comes months after a dispute between Pontera and Fidelity Investments over third-party access to retirement plan participant data. In December 2025, some Fidelity 401(k) participants and advisers reported losing online account access tied to Pontera’s platform, and Fidelity stated that it restricted data access to protect accounts from credential-sharing risks.
Fidelity raised concerns that third-party access was not protected by its security measures and could not be overseen by the plan sponsor. Pontera and other industry advocates have argued that participants, rather than recordkeepers, should determine whether their personal retirement account information can be shared with third-party advisers.
Dan Murphy, founder of Sunset Park Advisory and a former open banking program manager at the Consumer Financial Protection Bureau, said as part of the discussion that the U.S. lacks a comprehensive national privacy framework governing financial data portability. He said privacy protections remain largely sector-based, with separate frameworks governing industries such as healthcare, financial services and education.
“Healthcare has HIPAA, financial services [has the] Gramm-Leach-Bliley [Act], there’s [the Family Educational Rights and Privacy Act] for [federally funded] education … but a lot of those are quite old,” Murphy said. “If you look at the state level, you see a lot of broad data privacy frameworks at the state level.”
Murphy noted that Section 1033 of the Dodd-Frank Act establishes consumer rights to access and share certain financial information, though its scope falls under consumer finance regulations administered by the CFPB.
“If we’re talking about consumer-permissioned data or consumer data-sharing, consent obviously just has to be a part of that,” Murphy said. “The consumer has to be asking for something and giving their consent for data to be shared.”
At the same time, Murphy cautioned that consent alone does not eliminate obligations for companies handling consumer data.
“It is OK to recognize that, as we’ve moved along and learned more about the digital economy and how consumers’ data have been used—and sometimes misused—consent doesn’t always necessarily mean the end of the road with respect to a third party’s obligations,” he said.
Still, Penny Lee, president and CEO of the Financial Technology Association, argued that consumers should retain ultimate control over their financial information.
“There’s a clear understanding that the consumer owns the data,” Lee said.
Asked who can act now to facilitate consumer-permissioned data-sharing, Lee said financial institutions already have the authority they need.
“There is already statutory authority to accept consumer-permissioned data,” Lee said. “They do not need any more legislation or Congress to enable them. They just need to choose to do it.”You Might Also Like:
DC Account Balances Reach Record Highs in Q2
GAO Asks DOL to Clarify Permissible Participant Data-Sharing Practices

