On August 25, 2026, the Government Accountability Office (GAO), on its WatchBlog, posted a piece highlighting findings from its February 26, 2026, report “Department of Labor Guidance Could Mitigate Privacy Risks for Participants,” targeting plan provider use and sharing of participant data.
In this article, we provide a brief review of this issue, including GAO findings and recommendations, best practice standards, DOL’s (2021) guidance on data privacy and its response to GAO’s concerns, and recent litigation on the issue.
In a February 2026 report (RETIREMENT PLANS: Department of Labor Guidance Could Mitigate Privacy Risks for Participants), GAO found that:
Plan sponsors share participant PII [personally identifiable information] and financial information with service providers so that the providers can perform essential plan functions.
Some service providers, however, may also sell or use PII and other information to market financial products and services such as loans, annuities, life insurance, and investment advice.
Of the [service provider privacy] disclosures that [GAO] reviewed, 29 of 31 did not limit the service provider’s ability to share participant data for marketing because they either explicitly allowed it … or did not specify whether they would share participant data for this purpose …. More than half of the selected disclosures (17 of 31) did not limit the service provider’s ability to sell participant data.
In 1980, the Organisation for Economic Co-operation and Development (OECD) adopted eight Fair Information Practice Principles (FIPP) that are (according to GAO) “widely used by organizations to address privacy considerations in their business practices and are also the basis of privacy laws and related policies in many countries, including the United States.” These are, however, just principles and (unless codified in a federal or state law or regulation) are not legal requirements.
As noted above, critical to, e.g., 401(k) plan administration is the sharing of participant “personally identifiable information” and confidential information with plan providers, e.g., recordkeepers. Critical to the issue we are focusing on – specifically, what the participant is told about the information being shared and what the recordkeeper does with that information – are the following “best practices” on purpose and use:
The purposes for the collection of personal information should be disclosed before collection and upon any change to those purposes, and the use of the information should be limited to those purposes and compatible purposes.
Personal information should not be disclosed or otherwise used for other than a specified purpose without consent of the individual or legal authority.
For its February 2026 report:
GAO reviewed a non-generalizable sample of publicly available privacy disclosures … from 21 record keepers and 10 asset managers for a total of 31. … We reviewed each of these disclosures to identify the types of data being collected, the stated sources of this information …, and the extent to which record keepers and asset managers stated that they used, shared, or sold participant data for targeted marketing.
As noted, GAO found that 29 of the 31 ERISA plan providers it reviewed did not limit the provider's ability to share participant data for marketing purposes.
Moreover, GAO found that “DOL has not provided sufficient guidance on retirement plans’ use of participant data.” In that regard, GAO recommended that DOL should –
[P]rovide additional guidance about participant data privacy for retirement plan sponsors and service providers. In particular, [it] should clarify what participant information should be considered private and the circumstances in which service providers should obtain written permission before using or sharing this information. Such guidance could also identify best practices including for providing individual participants with choice, to the extent practicable, about how their personal information may be used, sold, or shared.
In responding to this GAO recommendation, DOL stated that it “believes that the general principles articulated in the 2021 [fiduciary] guidance make clear that ERISA’s fiduciary provisions obligate fiduciaries to, among other things, include data privacy considerations in the contracting process for service providers. However, as resources permit, [DOL] will carefully consider whether supplemental guidance aligned with the recommendation could or should be issued.”
In this response, DOL was referring to the statement in its 2021 “Tips for Hiring a Service Provider” suggesting that the fiduciary selecting/contracting with a service provider “try to include terms in the contract that would enhance cybersecurity protection for the Plan and its participants, such as”:
Clear Provisions on the Use and Sharing of Information and Confidentiality. The contract should spell out the service provider’s obligation to keep private information private, prevent the use or disclosure of confidential information without written permission, and meet a strong standard of care to protect confidential information against unauthorized access, loss, disclosure, modification, or misuse.
This guidance is (it can be argued) a little ambiguous. It’s unclear whether this is a mere suggestion (“should try to”) or a hard rule (“[t]he contract should spell out”).
There have been several cases that have raised participant data privacy issues – in one way or another – the most significant of which is the ongoing case of Williams-Linzey et al. v. Empower. The complaint in that case alleges, among other things, that Empower breached its duty as an ERISA fiduciary when it “improperly appropriated … confidential [participant] information, using its access to this confidential information to aggressively market its high-cost Non-Plan Products, and thereby generate profits for itself at participants’ expense.”
Empower is a case in which plaintiffs are suing a plan provider as an ERISA fiduciary for (among other things) misuse of participant data, and plan sponsors are not being sued. That’s an innovation: in the typical ERISA fiduciary case, the plan sponsor is nearly always a defendant. Why? Because proving a service provider (such as Empower) is an ERISA fiduciary is a stretch, but there is generally no question that the plan sponsor is one.
In the circumstances of the Empower litigation, however, plaintiffs’ lawyers (presumably) found it more useful to target Empower (and allege that it is an ERISA fiduciary), effectively aggregating litigation that would otherwise have to be brought employer-by-employer.
But obviously, plan sponsors are not immune from this sort of claim. And, indeed, the plaintiffs’ complaint in the Empower litigation specifically alleges that the related plan sponsors (Empower’s fiduciary/plan sponsor clients) “failed to monitor and investigate Empower’s conduct and compensation and implement restrictions to protect participants from being duped into high-cost rollovers that would deplete their hard-earned retirement savings.” That conduct (if proved) is clearly grounds for an ERISA fiduciary claim against the plan sponsors.
At this point, this is an “emerging issue.” GAO’s recent blog post is apparently an attempt to “nudge” it to the front burner.
We will have to see whether the Empower plaintiffs succeed with their claim and/or whether DOL comes out with further guidance. In the meantime, sponsors may want to review their contracts with their providers to see whether the issue of participant data privacy is adequately dealt with.
We will continue to follow this issue
* * *
This is a publication of O3 Plan Advisory Services. If you have any comments or have questions about regulatory developments, please contact your relationship manager or Mike Barry at mbarry@octoberthree.com.
The information, analyses and opinions set out herein are for general information only and are not intended to provide specific advice or recommendations for any individual or entity. Nothing herein constitutes or should be construed as a legal opinion or advice. You should consult your own attorney, accountant, financial or tax advisor or other planner or consultant with regard to your own situation or that of any entity which you represent or advise.
Information set out or referred to above has been obtained from sources believed to be reliable. However, neither O3 Plan Advisory Services nor any of its affiliates has verified the accuracy or completeness of any such information. All information is provided “as is” and O3 Plan Advisory Services and its affiliates expressly disclaim all express and implied warranties regarding the information. Neither O3 Plan Advisory Services nor any of its affiliates shall have any liability for any use of the information set out or referred to herein.