STEPS TO TAKE
In light of the foregoing considerations, the plan fiduciary should consider taking the following steps when selecting and contracting with service providers that will handle sensitive personal information of participants and beneficiaries:
Conduct Effective Due Diligence
The starting point for defining service provider privacy requirements is to understand the plan fiduciary’s own privacy and data security