A plan fiduciary should not assume that the service provider will assume any obligations that the plan may have to protect sensitive personal information.
Some service providers may function in a regulated industry requiring them to develop security methodologies to protect personally identifiable information. however, others do not. Service providers often do not operate in the same industry as the plan fiduciary nor are they likely to be subject to the same compliance obligations.