Privacy and Identity Theft Prevention Act (2003). From what I've read from a number of sources, they are allowed to do that... they're not allowed to make that information public, but there's no law preventing them from what they did (this only applies to the SSN, though... don't know about DOB and the rest, but I doubt it).