A plan fiduciary may have an obligation to protect plan-related information separate and apart from ERISA based on the type of data that is at issue. Each information privacy statute tends to define its own particular concept of personal information.6 These laws include the Fair Credit Reporting Act, Fair and Accurate Credit Transactions Act, the Gramm-Leach-Bliley Act, state identity theft laws, state data breach notification laws, state information security laws, state laws protecting Social Security numbers, and state laws requiring proper disposal of personal information.