A Daily Network publication
Explore the network
Retirement Capital Daily
Independent Intelligence on Retirement Assets
Friday, August 28, 2026The Morning Brief →Sign in
Policy & ERISA

GAO asks DOL to define retirement data privacy rules

A 31-provider audit finds marketing permissions and unspecified data-selling rules in plan privacy disclosures, and the GAO wants the Labor Department to set limits.

The Government Accountability Office has asked the Department of Labor to draw a line between the participant data a retirement plan service provider may use and the data it must leave alone, after an audit of 31 privacy disclosures found 15 providers explicitly permitting marketing use and 17 leaving the rules for selling that data unspecified. The GAO posted its findings this week; PLANADVISER first reported them.

Requested by Senator Bernie Sanders, Senator Patty Murray, and Representative Bobby Scott, the GAO's performance audit ran from January 2024 through February 2026 and examined whether participants' data are used beyond plan administration and shared with third parties. The GAO recommends the department clarify what information about participants should be treated as private and the circumstances in which providers must obtain written permission before using or sharing it.

Millions of retirement savers supply that information to their employers and plan service providers on the assumption that it is safe, an assumption the GAO's sample puts under pressure. A privacy disclosure that permits marketing use or leaves selling undefined is a document written in the provider's interest, and the GAO's count suggests that is the common case.

Thirty-one privacy policies

Of the 31 sampled disclosures, 15 allowed participant data to be used for marketing, and 17 left their rules for selling that data unspecified, while only two providers prohibited sharing personally identifiable information for marketing and 14 disallowed selling the data to third parties. More than half the sampled providers have left the selling question open, and roughly half have written themselves permission to use participant data for something other than running the plan.

The sample is narrow, but it is the evidence a government auditor has placed in front of DOL, and the report says selected service provider policy disclosures do not incorporate leading privacy practices. It cites the Fair Information Practice Principles, a set of protections first proposed by a U.S. government advisory committee in 1973 and later adopted internationally, which emphasize transparency and restrictions on unauthorized uses. Those principles are a useful yardstick precisely because they are not new; the disclosures have had half a century to catch up.

Experian reported last month that U.S. losses from fraud and identity theft reached more than $15.8 billion in 2025, up more than 24% from 2024. The GAO's report states the risk plainly: “As more entities gain access to participant data, the chance that their information may be inadvertently exposed increases, putting participants at greater risk of identity theft or other fraudulent activity.” A privacy policy that permits marketing use or leaves selling undefined is not a neutral legal clause when the losses traceable to stolen personal information are climbing.

What DOL has to define

The substance of the GAO's recommendation is a consent standard: clarifying what information is private and when written permission is required would separate plan administration from product marketing and give plan sponsors a benchmark for judging providers. The request lands in the same stretch of rulemaking where Treasury and the IRS have already proposed electronic-first rollover standards under SECURE 2.0, a change that will move more participant data through more systems, not less.

For plan sponsors, the report is a reminder that the privacy disclosures attached to provider agreements are contract documents, not marketing materials, and because the GAO reviewed written policies, its findings are about what service providers reserve the right to do, not what they have done. As this publication has argued, data usage is the next front in fee litigation. A provider that monetizes participant data is being paid from a source the sponsor may not have evaluated; the sponsor that never asked what its providers do with personal information will have a harder time defending the arrangement as prudent.

Plan sponsors do not have to wait for DOL to act: the GAO's numbers give them a two-question due-diligence test, namely does the provider's policy permit marketing use, and does it permit selling participant data? A provider that cannot answer those questions directly from its own disclosure is a provider whose policy needs to be rewritten before it is relied on.

The recommendation leaves the department deciding whether to define the limits of participant data use or leave every provider to keep writing its own. The providers that already sell data will be watching for the exception clause in whatever guidance arrives; plan sponsors should be watching for the same thing.

Sources & further reading
PLANADVISER
More from Retirement Capital Daily
Policy & ERISA

Middle-class savings are being outrun by debt, report finds

The median middle-class household has $64,000 in retirement accounts, and debt repayment outranks retirement saving as a financial priority.
Policy & ERISA

DOL watchdog embeds with DOJ fraud center

The Labor Department's inspector general signed on to the National Fraud Detection Center, putting investigators alongside federal prosecutors in a shift from reactive referrals to embedded detection.
The Wrap

Debt sends retirement M&A into the contribution layer

With managed accounts posting a measurable contribution lift and debt outranking saving, buyers are moving past recordkeepers to the feature that answers the squeeze.
Elsewhere in the networkAll titles →
Every weekday · 6:30 a.m. ET

The Morning Brief

The private wealth industry in four minutes, every weekday at 6:30 a.m. ET. Free.