29 of 31 Retirement Plan Providers Do Not Limit Sharing Participant Data for Marketing
The GAO reviewed the privacy disclosures behind $9 trillion of defined-contribution savings and found no clear rule on who may use participant information. Its recommendation to the Labor Department is still open.

The short answer
- GAO report GAO-26-107271 reviewed the privacy disclosures of 31 retirement plan service providers — 21 recordkeepers and 10 asset managers — plus 6 plan sponsors.
- 29 of the 31 did not limit sharing participants' personal information for marketing: 14 explicitly allowed it and 15 did not specify. 17 of 31 did not limit their ability to sell participant data to third parties.
- Only 12 of the 31 offered participants an opt-out, and 19 did not indicate that additional consent would be required before expanded or secondary uses.
- GAO's single recommendation — that the Secretary of Labor clarify what participant information is private and when written permission is needed — remains open. DOL neither agreed nor disagreed, saying it will consider supplemental guidance as resources permit.
To run a 401(k), a recordkeeper needs your name, your date of birth, your salary, your contribution rate, your balance, your beneficiaries and often your address and phone number. That is a detailed financial portrait, assembled for one purpose. What the firm holding it is permitted to do with it afterwards turns out not to be clearly settled.
What GAO looked at
GAO-26-107271, Retirement Plans: Department of Labor Guidance Could Mitigate Privacy Risks for Participants, was published on February 26, 2026 and publicly released on March 30. It is a report to congressional requesters, among them Senator Bernard Sanders, ranking member of the Senate HELP committee, and Representative Robert C. Scott, ranking member of the House Education and Workforce committee. GAO revisited it in a WatchBlog post in late August, which drew a second round of trade and general-press coverage.
GAO reviewed the privacy disclosures of 31 service providers — 21 recordkeepers and 10 asset managers — along with those of six plan sponsors. GAO describes the sample as nongeneralizable, which matters: these are not percentages of the industry, they are counts within a set GAO chose.
What the disclosures said
- 29 of 31 did not limit sharing participants' personal information for marketing. Of those, 14 explicitly allowed it and 15 simply did not specify.
- 17 of 31 did not limit their ability to sell participant data to third parties.
- 12 of 31 offered participants an opt-out provision.
- 19 of 31 did not indicate that additional consent would be required before expanded or secondary uses of the information.
The scale behind those counts: more than 126 million Americans were in defined contribution plans holding over $9 trillion in assets as of 2023.
Why ERISA does not settle it
ERISA governs the handling of plan assets in exhaustive detail. It does not clearly govern the handling of participant data, and GAO reports that the Labor Department has not taken enforcement action against plans for sharing it. What has grown into the gap is state law: GAO counted 19 states with comprehensive data privacy statutes as of November 24, 2025. A participant's protection therefore depends substantially on where they live, which is not how the rest of retirement plan regulation works.
The recommendation, and where it sits
GAO made one recommendation: that the Secretary of Labor provide additional guidance about participant data privacy for plan sponsors and service providers, clarifying what participant information should be considered private and the circumstances in which service providers should obtain written permission before using or sharing it. GAO added that such guidance could also identify best practices, including giving individual participants choice, to the extent practicable, about how their personal information may be used, sold or shared.
The recommendation is recorded as open. GAO reports that DOL neither agreed nor disagreed, noting that the Department will carefully consider, as resources permit, whether supplemental guidance aligned with the recommendation could or should be issued.
What a participant can actually check
The disclosures GAO reviewed are public documents. A plan's recordkeeper publishes a privacy notice, and the two questions GAO used are the ones worth asking of it: does it limit use of personal information for marketing, and does it say anything about selling data to third parties. Where GAO found silence rather than permission — the 15 that did not specify — silence is the finding. There is no default rule filling it in.
Sources
- Retirement Plans: Department of Labor Guidance Could Mitigate Privacy Risks for Participants (GAO-26-107271) — U.S. Government Accountability Office
- GAO-26-107271, full report and highlights — U.S. Government Accountability Office
- GAO Urges DOL to Clarify Acceptable Uses of Participant Data — PLANSPONSOR
- GAO Flags 401(k) Participant Data Privacy Risks — 401(k) Specialist
Spotted an error? Tell our corrections desk.
How this article was produced
- Responsible desk:
- Retirement
- Published:
- 31 Aug 2026, 06:20 UTC
- Last updated:
- 31 Aug 2026, 06:20 UTC
- Verification:
- Figures and quotations checked against primary sources under our fact-checking policy and editorial standards.
- Independence:
- No advertiser or affiliate partner had any involvement in this article — see editorial independence and how we make money.
- Corrections:
- Report a factual error.
This article is general financial information and journalism, not personalised financial, investment, tax or legal advice.
