The U.S. Government Accountability Office found that service providers for employer-sponsored retirement plans may share or sell participants’ sensitive personal and financial data for marketing or to data brokers. Of 31 providers whose privacy disclosures GAO reviewed, 29 either allowed such marketing-related sharing or did not say whether it was restricted, and 17 did not limit sales of participant data to brokers or other third parties. The affected information can include Social Security numbers, account details, and retirement-account balances for a population of more than 126 million participants holding over $9 trillion in assets.
GAO warned that expanded access to this data raises risks of unwanted marketing, identity theft, and fraud. It said the Employee Retirement Income Security Act lacks explicit modern privacy provisions, while the Labor Department’s 2021 cybersecurity guidance does not clearly define protected participant data or when written authorization is necessary for its use or disclosure. GAO recommended that the Department of Labor clarify both requirements; the department said it supports protecting participant information and will consider issuing supplemental guidance.

See the reporting duties and controls this puts on the clock.
3 events from the most recent confirmed update back to the earliest known activity.
GAO published a WatchBlog post discussing report GAO-26-107271, finding that 29 of 31 reviewed retirement-plan service providers allowed or did not specify limits on marketing-related data sharing, and that more than half did not limit sales to data brokers or other third parties. GAO recommended that the Department of Labor clarify what data is private and when written permission is required for its use or disclosure.
The U.S. Department of Labor issued cybersecurity guidance for retirement plans that called for service-provider obligations to protect private information and prevent use or disclosure without written permission.
The Department of Labor said it supports appropriate protection of retirement-plan participant and beneficiary information and would consider issuing supplemental guidance aligned with GAO's recommendations as resources permit. The department neither agreed nor disagreed with the recommendations.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.