Data Is the New ERISA Section 404

Ary Rosenbaum - The Rosenbaum Law Firm P.C.
Contact

Ary Rosenbaum - The Rosenbaum Law Firm P.C.

When I started in this business, plan sponsors worried about lost checks. Now, they should be worried about lost data. Back then, if a participant’s address was wrong, you mailed a letter and hoped for the best. Today, if a hacker gets your payroll feed, you’re not mailing letters—you’re calling your cyber insurer and your lawyer.

ERISA’s Section 404 talks about acting prudently and solely in the interest of participants. That used to mean watching fees, monitoring investments, and keeping minutes. But in 2025, prudence means locking down your participant data like it’s Fort Knox. Every Social Security number, every date of birth, every account balance—those are plan assets in digital form.

The Department of Labor isn’t subtle about it anymore. Cybersecurity is a fiduciary issue. If your TPA or recordkeeper treats data protection like an afterthought, that’s your problem too. Because if participant data gets breached, no one’s pointing fingers at the IT guy—they’re pointing them at you, the plan sponsor.

So, ask questions. Demand documentation of your providers’ security protocols. Review your internal controls. Don’t let an intern email participant data unencrypted. You wouldn’t leave plan assets in a shoebox under your desk, so don’t leave sensitive data floating around in Outlook.

Fiduciary prudence used to mean “protecting the money.” Now it also means protecting the information about the money. Data is the new 404—and unlike plan assets, once it’s leaked, you can’t roll it back into the trust.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations. Attorney Advertising.

© Ary Rosenbaum - The Rosenbaum Law Firm P.C.

Written by:

Ary Rosenbaum - The Rosenbaum Law Firm P.C.
Contact
more
less

What do you want from legal thought leadership?

Please take our short survey – your perspective helps to shape how firms create relevant, useful content that addresses your needs:

Ary Rosenbaum - The Rosenbaum Law Firm P.C. on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide