The case for outside 401(k) advice ends at the login
Pontera's webinar with former EBSA chief Lisa Gomez makes the legal argument for participant-chosen advisers; Fidelity's December access cutoff shows who still controls the account.
Lisa Gomez told a webinar audience Thursday that the retirement system handed workers responsibility for their own savings and never updated the rules around it, and the corollary matters as much for the advice business: the law does not stop a participant from choosing an outside adviser.
Pontera, a fintech that advertises 401(k) plan management, hosted the session with 401(k) Specialist under the title "Who Gets a Say in the 401(k)? Technology, Trust and the Future of Advice," where the panel took up whether savers may authorize outside advisers to reach their plan assets and data.
Gomez, the former assistant secretary of labor for the Employee Benefits Security Administration, rested the point on Interpretive Bulletin 96-1, which distinguishes financial professionals participants select independently from advisers an employer makes available. The department has repeatedly said plan sponsors generally are not liable for the acts of independently chosen professionals provided the sponsor neither endorses nor arranges the service.
The weight behind those words comes from Pontera's dispute with Fidelity Investments, which said in December 2025 that it had restricted data access after some participants and advisers reported losing online account access tied to Pontera's platform, citing credential-sharing risks and noting that third-party access sat outside its security measures and the plan sponsor's oversight. Pontera and allied advocates argue the participant should decide whether account information goes to an outside adviser rather than the recordkeeper, a position Pontera has been building out operationally, adding a non-discretionary route into held-away accounts in August.
Interpretive Bulletin 96-1 settles a question of permission, but the mechanics are somebody else's problem, and they belong to the recordkeeper, who holds the login; Fidelity's stated security concern and its commercial position sit on the same side of the question, and no bulletin separates them. As this publication has argued, digital experience has become a plan retention asset, and held-away access is that asset seen from the adviser's side, which makes an unanswered access request a retention question as well as a security one.
Dan Murphy, founder of Sunset Park Advisory and a former open banking program manager at the Consumer Financial Protection Bureau, told the panel the U.S. has no comprehensive national privacy framework for financial data portability, leaving protections largely sector-based.
A participant's right to choose an adviser is settled; the right to move the data that makes the choice usable remains open, and the bulletin speaks to the first while saying nothing about the second. "The legal and regulatory system and structure has not caught up," in Gomez's words; the GAO asked the Labor Department in August to define retirement data privacy rules after a 31-provider audit found marketing permissions and unspecified data-selling provisions in plan disclosures. If the department answers, portability leaves the terms-of-service layer and enters a rulemaking docket, a bigger outcome than the access cut that prompted the question.