Retirement Plan Service Providers’ Data Sharing: What You Should Know
The Government Accountability Office (GAO) warns that personal information shared or sold by American retirement plans may be used to market financial products and services. In this article, we will explore how this happens, and what measures can be taken to prevent it.
Retirement Plan Participation and Personal Information
Over 126 million Americans are enrolled in employer-sponsored retirement plans, such as a 401(k) or similar account. Total assets in these plans exceed $9 trillion. External financial services providers typically administrate these plans, and employers share personally identifiable information with asset managers, payroll providers, and record keepers who manage the contributions.
Employers may share personal data such as birth dates, Social security numbers, account numbers, and balances with these service providers. The GAO warns that this data could potentially be sold to third parties, increasing the risk of exposure.
Privacy Disclosures and Data Sharing
The GAO’s investigation included a review of 31 service providers’ privacy policies. Of these, 29 either explicitly permitted data sharing or failed to specify whether participant data can be used for marketing purposes. Furthermore, over half of these financial service providers did not limit their ability to sell participant data to data brokers or other third parties.
Protection of Personal Data
The GAO recommends that the Labor Department should provide additional guidance about data privacy for participants in retirement plans for sponsors and service providers. This guidance should clarify what participant information is considered private and under what circumstances service providers should obtain written permission before using or sharing this information.
The Labor Department responded to the GAO’s analysis stating it “fully supports the goal of adequately protecting the personal information of participants and beneficiaries of plans.” However, it did not agree or disagree with the report’s recommendations. Instead, it referred to a 2021 guidance on cybersecurity as part of service providers’ fiduciary responsibilities to plan participants.
The Department added that while it believes the 2021 guidance makes it clear to fiduciaries that they’re obligated to include data privacy considerations in their contracts, as resources permit, the agency will “carefully consider whether supplemental guidance aligned with the recommendation could or should be issued.”
For more resources and updates on this topic, visit FOX Business.
Read More US Economic News