Your 401(k) Provider Might Be Selling Your Personal Data — and You Can't Stop Them

Your 401(k)’s privacy policy might not provide as much protection as you’d expect. In fact, it actually might pose a problem.
A government watchdog finds that the companies entrusted with overseeing some 126 million Americans’ $9 trillion in retirement savings give themselves wide latitude to share and even sell workers’ personal information.
Must Read
In a new report that analyzes the privacy disclosures of 31 major retirement plan administrators, the nonpartisan Government Accountability Office (GAO) finds that only two have a specific prohibition against sharing customer data for marketing purposes. On the other hand, half of the policies explicitly permit those companies to share user data for marketing purposes.
Further complicating things, millions of these retirement savers have no recourse if they don’t want their data exposed in this manner. Fewer than 40% of the disclosures analyzed provide consumers with the opportunity to opt out of having their data used for marketing.
More concerning: Nearly 55% of the policies don’t contain any language that would prohibit the companies from selling personal user information to data brokers or other, unspecified third parties.
Why policies that allow share, sale of data are risky
The potential issues this raises are myriad, the watchdog group notes in its report.
One concern is that there’s a chance that your information could be shared with companies that target you with marketing for products you don’t want and aren’t a good fit for your financial circumstances. The bigger worry, though, is that if your information is shared with a third party and then exposed in a data breach, you could be at risk of identity theft and fraudulent activity.
Even if a plan provider only shares 401(k) data internally, consumers could be at a disadvantage. If a worker gets a marketing solicitation from their 401(k) administrator's sales department, for instance, they might mistakenly believe that product is recommended for their specific financial circumstances.
"That’s the kind of dicey part of this — is it really appropriate?" says Steve Parrish, professor of practice in retirement planning at the American College of Financial Services.
Earlier research found that the retirement plan industry is rife with possible conflicts of interest, because the big financial firms companies hire to manage their retirement plans have so many subsidiaries and affiliates that the same firm can effectively wind up playing multiple roles. And not all of them are required to meet the fiduciary standard that protects investors.
"Large firms with multiple lines of business and various affiliates can create potential conflicts... despite obligations to mitigate and eliminate" them, the GAO's new report notes.
Must Read
What retirement savers can do now
If you're wondering how you can prevent your 401(k) provider from using your data for marketing or profit, the short version is: not much.
“I just don't know there's a lot you can do,” Parrish says.
Of course, if you have the option to decline having your data used for other purposes, electing to opt out is probably your best bet. But Parrish acknowledges that it can be challenging trying to find out what privacy rights you have under your employer’s 401(k) plan: “Trying to research it is tricky,” he notes.
In 2021, U.S. Department of Labor published cybersecurity guidelines instructing employers to prevent workers’ information from being shared or used without written permission. But these guidelines don’t specify what information is considered private, or what constitutes adequate permission.
In its new report, the GAO suggests tightening the privacy security and disclosure regulations around retirement savers’ personal data, but it’s not clear when or if the Labor Department might act on these recommendations.
While you might not be able to stop companies from marketing to you, you can be careful about what you buy or invest in. If you don’t understand what you’re being pitched, Parrish recommends consulting an advisor who is a fiduciary (such as a certified financial planner). These professionals are legally required to act in your best financial interest.
When it comes to the threat of having your personal information exposed in a data breach, vigilance is a multifaceted exercise: Use multifactor authentication for all of your financial accounts, don’t share your login credentials with anyone and be wary of unsolicited messages. If your information is compromised, contact your financial institution right away, change your passwords and consider freezing your credit (or signing up for credit monitoring).
The frustrating reality is that we don't have a lot of control over how and with whom our personal information is shared digitally.
"The breadth and depth of information that data brokers have is astonishing," cybersecurity expert Bruce Schneier told Money earlier. "You can’t do anything. That’s the fundamental problem.”