126 Million Retirement Accounts, $9 Trillion in Assets, and No Regulator Who Says It’s Their Job

126 Million Retirement Accounts, $9 Trillion in Assets, and No Regulator Who Says It’s Their Job

126 Million Retirement Accounts, $9 Trillion in Assets, and No Regulator Who Says It’s Their Job
Share This:

A federal watchdog report examining how the companies that run America’s 401(k) plans handle participant data found that most of the privacy policies it reviewed placed no limit on selling or sharing that information for marketing  and that four separate federal agencies each explained why enforcement was not their responsibility.

The Government Accountability Office published the findings in February 2026 and released them publicly on March 30. The report, GAO-26-107271, was requested by Sen. Bernie Sanders, Rep. Robert C. “Bobby” Scott and Sen. Patty Murray. Its central recommendation to the Department of Labor remains open. The Labor Department neither agreed nor disagreed with it.

The scale is not marginal. About 126 million Americans participated in private-sector defined contribution retirement plans as of 2023, the most recent Form 5500 data available, holding more than $9 trillion in assets.

Background

To run a 401(k), an employer has to hand over information about its employees.

Plan sponsors  usually the employer  share participant data with the outside firms that administer the plan. Recordkeepers manage accounts, process contributions and withdrawals, and run the participant-facing website. Asset managers invest the contributions. Payroll providers move the money. Each of them needs identifying information to do the work: names, birth dates, Social Security numbers, account numbers, balances.

In simple terms: the data has to move for the plan to function. The question the GAO set out to answer was what happens to it after it arrives.

The auditors reviewed publicly available privacy disclosures from 31 service providers  21 recordkeepers drawn from the SPARK Institute membership list, and the 10 largest asset managers by institutional assets. They also reviewed employee-facing privacy disclosures from six large plan sponsors, interviewed 26 stakeholders, and met with officials at the Labor Department, the Consumer Financial Protection Bureau, the Securities and Exchange Commission and the Federal Trade Commission. The audit ran from January 2024 to February 2026.

The GAO is explicit that the 31-provider sample is nongeneralizable  it cannot be used to draw conclusions about the recordkeeping industry as a whole. Thirteen additional recordkeepers were dropped from the review because they did not respond to the GAO’s attempts to confirm which privacy policy applied to their recordkeeping business.

What the Report Found

Of the 31 disclosures reviewed, 29 did not limit the provider’s ability to share participant data for marketing. Fourteen explicitly permitted it. Fifteen were silent on the question.

More than half  17 of 31  did not limit the provider’s ability to sell participant data outright.

Twelve of the 31 told participants they could opt out of having their data shared for marketing. The remaining 19 either offered no opt-out or scoped it narrowly. One disclosure quoted in the report tells participants that state law permits the company to share information with its affiliates and that “You may not opt out of these disclosures.”

The finding that has drawn the least attention may be the most consequential. Twenty-eight of the 31 providers said they independently collect information about participants from sources other than the employer  credit reporting agencies, social media, and unspecified third parties that the GAO notes could include insurance companies, financial advisors or healthcare providers. Twenty-four of the 31 named that last category. Fifteen said the primary purpose of that outside collection was marketing.

In simple terms: your recordkeeper is not only handling what your employer gave it. It is also buying and gathering information about you from elsewhere, and then combining the two.

The GAO measured the disclosures against the Fair Information Practice Principles, an eight-part framework developed by the OECD that underpins privacy law in much of the world and formed the basis of the U.S. Privacy Act of 1974. The results were uneven:

  • Transparency and security: all 31 disclosures addressed both.
  • Use limitation: 19 of 31 did not state that additional consent would be sought before using data beyond the originally disclosed purpose.
  • Collection limitation: 26 of 31 did not clearly describe any limit on what they collect.
  • Purpose specification: 28 of 31 lacked clarity on why data was collected or whether use was confined to those purposes.
  • Accountability: 23 of 31 were silent on who inside the organization is responsible for data protection.

On the employer side, the picture was similar. Of the six plan sponsors whose employee privacy disclosures the GAO reviewed, two mentioned any collection or use limits imposed on third-party contractors handling employee data.

The Regulatory Gap

The more striking portion of the report is not what the companies do. It is what happens when you ask who is supposed to be watching.

The Labor Department oversees retirement plans under ERISA. But ERISA, enacted in 1974, contains no explicit data privacy provisions. DOL officials told the GAO they have brought no enforcement action against any plan sponsor or service provider over participant data use, in part for that reason. The agency’s position is that ERISA’s existing duties of prudence and loyalty should be enough to deter misuse.

The CFPB is statutorily barred. Federal law specifies that retirement plans are not consumer financial products or services, and separately prohibits the bureau from exercising rulemaking or enforcement authority over employee benefit plans. Officials confirmed to the GAO that retirement plans fall outside the agency’s jurisdiction.

The SEC has authority over some service providers  registered investment advisers and broker-dealers  under Regulation S-P. It has limited authority over plan sponsors.

The FTC told the GAO that the laws it enforces do not apply specifically to retirement plans and may not reach all the parties involved. The Gramm-Leach-Bliley Act, which restricts how financial institutions share nonpublic personal information, may not cover plan sponsors or recordkeepers performing mostly administrative functions.

The states are uncertain. As of Nov. 24, 2025, 19 states had enacted comprehensive data privacy laws in effect or taking effect in 2026. All 19 give consumers the right to opt out of the sale of personal information. But officials in California, Colorado and Virginia  the three states whose laws have been in force longest  told the GAO they do not know whether those laws reach retirement plans, because ERISA generally supersedes state laws that “relate to” an employee benefit plan. None of the three has taken enforcement action against a plan sponsor or service provider.

The courts have closed one door already. Participants argued that their data should count as a plan asset under ERISA, which would make its handling a fiduciary matter automatically. Courts rejected the theory in Divane v. Northwestern University (N.D. Ill. 2018) and Harmon v. Shell Oil Co. (S.D. Tex. 2021). A separate fiduciary duty  the employer’s obligation to prudently select and monitor the vendors it hires  survives that ruling untouched, and is examined below.

Sidebar: Why “Fiduciary Duty” Doesn’t Reach Your Data

A 401(k) is the most heavily regulated financial relationship most Americans have. It comes with a fiduciary standard  the highest duty in American law, requiring that a fiduciary act solely in the interest of participants. So how does any of the above survive it?

The answer is that ERISA’s fiduciary standard is partial, not global.

Section 3(21)(A) makes someone a fiduciary “to the extent” they do one of three things: exercise discretionary authority over plan management, exercise any authority or control over plan assets, or render investment advice for a fee. Fiduciary status attaches to specific conduct, not to a company. The same firm can be a fiduciary for one function and an ordinary vendor for another, in the same plan, on the same day.

Recordkeeping generally falls on the vendor side. Under DOL’s longstanding interpretive bulletin at 29 C.F.R. § 2509.75-8, a party performing purely ministerial functions  maintaining participant records, preparing employee communications, calculating benefits  within a framework set by someone else is not a fiduciary, because it exercises no discretion. That describes the recordkeeper’s job.

This is why participants suing over data use had to argue that participant data is itself a plan asset: the second prong of the fiduciary test has no discretion requirement, so merely handling a plan asset confers fiduciary status automatically. Courts rejected the theory. ERISA never defines “plan asset,” and DOL’s regulations addressing the question say nothing about data, so courts fall back on ordinary notions of property rights. In Divane, the court acknowledged the compiled data has real value but held it was not property the plan could sell or lease to fund benefits. *Harmon* followed.

But that is not the end of the analysis, and it is where the GAO report becomes most pointed.

Employers owe a separate and undisputed fiduciary duty to prudently select and monitor the service providers they hire. That duty does not depend on data being a plan asset. And DOL has already applied it to data: its 2021 guidance instructs plan fiduciaries to ensure service contracts contain clear provisions on the use and sharing of information, and to prevent the use or disclosure of confidential information without written permission.

In simple terms: the Labor Department has already said that vetting what a recordkeeper does with employee data is part of an employer’s fiduciary job.

Two things hollow that out in practice.

First, the guidance never defines its own terms. It does not say what participant information should be treated as private, or what uses are acceptable. That omission is the specific basis for GAO’s recommendation.

Second, and more consequentially, fiduciary prudence is measured against prevailing practice among similarly situated fiduciaries. GAO found that 29 of 31 provider disclosures placed no limit on sharing participant data for marketing, and that only two of six plan sponsors reviewed imposed any collection or use limits on contractors handling employee data. Where permissive terms are the norm, an employer who negotiates nothing is doing what most employers do.

That dynamic raises a question the report does not address: where permissive terms are the industry norm, it becomes harder to characterize any individual employer as imprudent for accepting them.

The GAO’s own findings suggest where that leads. Industry research cited in the report found participant data privacy was a greater concern to large plan sponsors than to smaller ones, and recordkeepers told auditors that smaller employers typically lack the privacy addendums larger firms negotiate. The practical result is a two-tier standard set by bargaining power rather than by law.

None of this requires reopening the plan-asset question. DOL could define private information and acceptable uses within its existing service-provider guidance and leave the case law untouched. That is, in substance, what GAO recommended. The recommendation is open.

Examples

Litigation has produced more movement than regulation. The GAO identified at least 11 lawsuits filed in federal court between 2009 and 2024 alleging that plan sponsors breached their ERISA fiduciary duty by failing to stop service providers from using participant data for their own purposes and subjecting participants to unwanted marketing.

Seven had settled as of December 2024. None included a finding of liability. But five settlements included agreements by the employer to add contract language barring service providers from using participant data for marketing.

That pattern points to where the leverage actually sits. Employers can contractually restrict what a recordkeeper does with employee data  and the GAO found that some large sponsors do exactly that, inserting standard language into every service contract. Research from the SPARK Institute found participant data privacy was a greater concern to large sponsors than to small and mid-sized ones. Two of the five recordkeepers the GAO interviewed agreed, with one noting that smaller employers typically lack the privacy addendums larger firms negotiate.

The practical consequence: whether a worker’s 401(k) data is contractually protected may depend less on any law than on the size of their employer.

Impact

The GAO frames the risk in terms of exposure surface. Every additional entity holding participant data is another point at which it can be breached, leaked or misused. The report cites Justice Department figures estimating that about 24 million U.S. residents aged 16 and older were victims of identity theft in a 12-month period, with financial losses of $16.4 billion, based on 2021 data.

There is a counterargument, and the report gives it space. Recordkeepers told the GAO that broader use of participant data lets them target products and services more effectively  financial wellness programs, targeted education on investing and budgeting, and referrals to advisers. Sharing data with researchers can produce insight into participant behavior and plan design. The GAO does not dismiss these benefits, and DOL officials cautioned that any new guidance would need to preserve data sharing that genuinely helps participants.

The tension is real. The report’s position is not that the data should stop moving. It is that participants should know where it goes and have some say in it.

Follow the Money: The Data Isn’t Sold, It’s Converted

The GAO report establishes that most providers reserve the right to share and sell participant data. It does not attempt to quantify what that permission is worth, and no service provider discloses a participant-data revenue line. There is no public figure for what a data broker pays for a 401(k) record.

But the business model is not a secret, and it explains why the permission exists.

Recordkeeping is a loss leader. Administrative fees have compressed to roughly $45 to $80 per participant per year, and large plans now negotiate asset-based pricing in the single-digit basis points. One university plan’s fee disclosure shows recordkeeping priced at 10.25 basis points for one provider and 4.4 basis points for another  the latter works out to 44 cents per $1,000 in the account.

The industry has consolidated accordingly. The number of recordkeepers fell from roughly 440 in 2010 to about 243 in 2023, a decline of 45 percent.

In simple terms: nobody is getting rich administering the plan.

The research firm Cerulli Associates has described the dynamic directly, noting that the ancillary revenue recordkeepers generate by converting plan participants into wealth-management clients is what allows them to price plan-level services competitively. A widely circulated industry white paper by the Multnomah Group identifies five ways providers monetize recordkeeping: proprietary investment management, managed accounts, IRA rollovers, cross-selling retail financial products, and annuitization.

Each of those requires knowing who the participant is, what they hold, and  critically  when they are about to leave.

The rollover market is where the value sits. Investors rolled approximately $682 billion into IRAs in 2023, across nearly 6 million people, according to IRS data. Cerulli estimated that about $845 billion moved out of defined contribution plans in 2022, with 63 percent of it reaching IRAs through a financial advisor. The firm projects roughly $941 billion in rollovers during 2026, rising toward $1.3 trillion by 2031. Individual retirement accounts held about $19.2 trillion at the end of 2025  nearly double the roughly $10.1 trillion held in 401(k) plans.

Consider the arithmetic from a single provider’s perspective. A participant with a $100,000 balance paying a $65 flat recordkeeping fee generates $65 a year. Capture that same balance into a proprietary IRA charging 50 basis points, and the relationship generates $500 a year  recurring, and rising as the balance grows.

One captured rollover is worth roughly seven to eight years of recordkeeping fees on that participant, and it pays every year afterward. (Illustrative calculation, using published fee ranges; individual pricing varies widely.)

That math reframes the GAO’s finding. The relevant question is not why a recordkeeper would sell a participant list to a data broker  that transaction earns very little. It is why a recordkeeper would want unrestricted use of a file that identifies exactly which customers are approaching a rollover decision, what they are worth, and how to reach them.

The litigation record points the same direction. The settlements that resolved these cases did not restrict data brokerage. They restricted solicitation  barring the recordkeeper from contacting participants about non-plan products unless the participant asked first. The remedy the plaintiffs accepted was a restriction on solicitation, not on data brokerage.

What cannot be sourced. Whether any of the 31 providers actually sold participant data to third parties, and for how much, is not established by the GAO report or by any public filing reviewed for this article. Form 5500 Schedule C requires larger plans to report indirect compensation paid to service providers, but it does not isolate data-related revenue. Empower, Principal, Voya and Ascensus file public financial statements; Fidelity and Vanguard, two of the largest recordkeepers in the country, are privately held and disclose the least.

The absence of a number is not evidence that the practice is small. It is evidence that nobody is required to report it.

Analysis

One detail in the footnotes deserves more weight than it received. The CFPB proposed a rule in December 2024 aimed at limiting data brokers’ ability to sell sensitive personal and financial information about consumers. The bureau withdrew that proposed rule in May 2025.

That withdrawal matters here because the GAO report identifies data brokers  described as businesses that collect and sell personal information about consumers with whom they have no direct relationship  as recipients of participant information from plan service providers. The one federal action that might have reached the downstream buyer was abandoned, in the same period that this audit was underway.

There is also a question the report raises without resolving. The industry itself has asked for rules. The SPARK Institute study found that plan sponsors and recordkeepers wanted the Labor Department to establish data privacy standards, citing the absence of a comprehensive federal privacy law, inconsistent state requirements, and exposure to litigation. All five recordkeepers the GAO interviewed said additional DOL guidance would be helpful.

That is an unusual alignment. The regulated parties, the congressional requesters and the auditors all want the same thing. The agency’s answer was that it will consider whether supplemental guidance could or should be issued, as resources permit.

Finally, a note on what this report is not. The 31 disclosures are a nongeneralizable sample, weighted toward firms large enough to appear on an industry membership list or an institutional-assets ranking. Thirteen recordkeepers were excluded for not responding. The findings describe what companies say in their privacy policies  not audited evidence of what they do. A policy that permits selling data is not proof that data was sold. That distinction is worth holding onto, and it cuts in both directions: silence in a disclosure is not evidence of restraint either.

Conclusion

The GAO recommended that the Secretary of Labor issue guidance clarifying what participant information should be treated as private, when service providers should obtain written permission before using or sharing it, and what choices participants should have about how their data is used, sold or shared.

The Labor Department neither agreed nor disagreed. The recommendation remains open.

For the roughly 126 million Americans with a workplace retirement account, the operative fact is not that any single company has been found to have misused their data. It is that the disclosures governing that data are largely permissive, the framework meant to constrain them predates the commercial data market by decades, and every agency with a plausible claim to jurisdiction has explained why the matter belongs to someone else.

Key Takeaways

  • The finding: 29 of 31 retirement plan service provider privacy disclosures reviewed by the GAO did not limit sharing participant data for marketing; 17 of 31 did not limit selling it. Only 12 offered an opt-out.
  • The second finding: 28 of 31 providers said they independently collect participant data from outside sources  credit bureaus, social media, third parties  with marketing named as the primary purpose by 15 of them.
  • The gap: DOL says ERISA doesn’t address privacy. CFPB is statutorily excluded. SEC’s authority reaches only some providers. FTC says its statutes may not apply. State officials say ERISA preemption makes their laws’ reach uncertain. No agency has taken enforcement action.
  • The blocked route: Federal courts have rejected the argument that participant data is a plan asset under ERISA, foreclosing the theory that would have made recordkeepers fiduciaries automatically.
  • The route that survives: An employer’s duty to prudently select and monitor service providers does not depend on that question, and DOL’s 2021 guidance already applies it to data terms  but the guidance defines neither “private information” nor acceptable uses, and prudence is judged against prevailing practice, which GAO found to be permissive.
  • Follow the money: Recordkeeping is a loss leader at $45–$80 per participant, while roughly $941 billion is projected to roll from workplace plans into IRAs in 2026. The participant file identifies who is about to roll over  which is worth far more than any list sale.
  • What has worked: Five of seven settled lawsuits produced contract language restricting provider use of participant data  meaning employer contracts, not regulation, have delivered the concrete restrictions to date.
  • The caveat: The 31-provider sample is nongeneralizable and reflects stated policy, not audited practice.
  • Status: GAO-26-107271, published Feb. 26, 2026, publicly released Mar. 30, 2026. Recommendation open. DOL neither agreed nor disagreed.

Sources

1. U.S. Government Accountability Office, Retirement Plans: Department of Labor Guidance Could Mitigate Privacy Risks for Participants, GAO-26-107271, published Feb. 26, 2026, publicly released Mar. 30, 2026. gao.gov

2. Full report text, 45 pages. files.gao.gov

3. U.S. Department of Labor, EBSA, Private Pension Bulletin, Abstract of 2023 Form 5500 Annual Reports, September 2025  participant and asset totals.

4. U.S. Department of Labor, EBSA cybersecurity guidance, April 2021; updated September 2024.

5. GAO, Defined Contribution Plans: Federal Guidance Could Help Mitigate Cybersecurity Risks in 401(k) and Other Retirement Plans, GAO-21-25, February 2021. gao.gov

6. Department of Justice, Bureau of Justice Statistics, Victims of Identity Theft, 2021, October 2023.

7. SPARK Institute, Understanding Data Privacy Sensitivities Across the Defined Contribution Industry, April 2023 (with DCIIA Retirement Research Center).

8. IAPP, US State Privacy Legislation Tracker, Nov. 24, 2025.

9. ERISA § 3(21)(A), 29 U.S.C. § 1002(21)(A)  definition of fiduciary.

10. 29 C.F.R. § 2509.75-8 (DOL Interpretive Bulletin 75-8), Q&A D-2  ministerial functions and fiduciary status. ecfr.gov

11. 29 C.F.R. §§ 2510.3-101, 2510.3-102  plan asset regulations.

12. Divane v. Northwestern University, No. 16 C 8157 (N.D. Ill. May 25, 2018), aff’d on other grounds, 953 F.3d 980 (7th Cir. 2020), vacated and remanded on unrelated fee claims sub nom. Hughes v. Northwestern University, 595 U.S. 170 (2022).

13. Harmon v. Shell Oil Co., No. 3:20-cv-00021 (S.D. Tex. Mar. 30, 2021). Opinion PDF

14. 12 U.S.C. § 5517(g)  CFPB jurisdictional exclusion for employee benefit plans.

15. Cerulli Associates, U.S. Retirement Edition  DC-to-IRA rollover flow estimates. cerulli.com

16. Investment Company Institute  IRA and 401(k) aggregate asset totals, year-end 2025, via InvestmentNews.

17. Internal Revenue Service  IRA rollover contribution data, 2023, via CNBC.

18. NEPC Defined Contribution Plan and Fee Survey  per-participant recordkeeping fee ranges.

19. Multnomah Group, Fee Compression: Five Ways Providers Monetize Recordkeeping. multnomahgroup.com

20. Eric Revell, “Retirement plans may be sharing or selling Americans’ personal data, watchdog warns,” Fox Business, Aug. 25, 2026. foxbusiness.com

Share This: