Millions of Americans with 401(k)s and other workplace retirement accounts may not know how their personal information is being used by companies managing their plans.

The Government Accountability Office published a WatchBlog post Tuesday explaining findings from its review of retirement-plan service providers and warning that participant data may be shared for marketing or sold to third parties.

More than 126 million Americans participated in employer-sponsored retirement plans with more than $9 trillion in assets as of 2023, according to the GAO. Employers typically share participant information with outside service providers, including asset managers and record keepers, to administer retirement plans.

The information can include birth dates, Social Security numbers, account numbers and balances. Service providers may also use the data to market financial products and services or potentially sell it to data brokers and other third parties.

Providers' Privacy Rules Raise Questions

GAO reviewed privacy disclosures from 31 retirement-plan service providers. It found that 29 either explicitly allowed data sharing for marketing or did not specify whether they restricted it.

Seventeen of the 31 providers did not specify whether they would sell participant data to data brokers or other third parties. Only 12 providers had privacy disclosures allowing participants to opt out of data sharing.

The findings come as retirement accounts are already receiving greater attention from regulators and financial professionals. Recent IRS guidance sought to make 401(k) rollovers easier, while advisers have warned savers to understand the costs and consequences of moving retirement assets between plans and IRAs.

GAO Seeks Clearer Privacy Rules

The GAO said the Employee Retirement Income Security Act governs most employer-sponsored retirement plans, but does not contain explicit provisions addressing data privacy.

The watchdog recommended that the Labor Department clarify what participant information should be considered private and when service providers should obtain written permission before using or sharing it. GAO also said additional guidance could give participants more choice over how their information is used, sold or shared.

The Labor Department said it "fully supports the goal of appropriately protecting the personal information of participants and beneficiaries of plans," but did not agree or disagree with the recommendations, according to FOX Business.

The department pointed to 2021 cybersecurity guidance that says retirement-plan contracts should address service providers' responsibility to protect private information. It said it will "carefully consider whether supplemental guidance aligned with the recommendation could or should be issued."

The GAO said stronger privacy protections could reduce unwanted marketing and give retirement-plan participants more control over their information.