CA-C-001284
Gusto — Gusto Privacy Policy
Entity
Date detected
April 16, 2026
Effective date
April 14, 2026
Severity
Direction
Positive
Affected users
business accounts employers EU users UK users organizations subject to data protection laws
Changes
+60 sentences added · 1 sentence modified
Share 𝕏 Share in Share 🔒 PDF
Watch Gusto Get alerts when this policy changes.
Watch — Free

Event Summary

Gusto updated its Data Processing Addendum on April 16, 2026, adding 60 sentences that clarify how the company handles employer data under data protection laws. The new language specifies the scope of the addendum (it applies only to employers subject to data protection laws), defines key terms, establishes when the agreement becomes binding, and clarifies that the addendum takes precedence over the base service agreement if there is a conflict. For employers, this means clearer rules about how their employee and payroll data is processed and protected.

MEDIUM

Consumer Impact

The updated addendum provides employers with clearer rules about when data protection obligations apply and how Gusto will process payroll and employee data. The new language establishes that the addendum only applies to employers subject to data protection laws (such as GDPR or UK GDPR), and specifies that the addendum takes precedence over the base service agreement if there is a conflict. Employers subject to data protection laws should review the full updated addendum to confirm it aligns with their legal obligations regarding employee data handling.

Governance Analysis

The updated addendum clarifies Gusto's data protection obligations and under what legal circumstances they apply. For employers subject to GDPR, UK GDPR, or state privacy laws, this update refines the contractual framework governing how employee and payroll data is processed, which is critical for regulatory compliance and vendor accountability.

Available Actions

Confirm whether your organization is subject to applicable data protection laws (GDPR, UK GDPR, state privacy laws, etc.)

Retrieve the full Addendum Version 3.0 from Gusto and review it against your jurisdiction's data processing agreement requirements

If required provisions are missing, request amendments or supplemental agreements from Gusto

If No Action Is Taken

Data processing compliance gaps may go undetected if the addendum lacks required terms for your jurisdiction

Regulatory exposure may increase if your data protection obligations are not fully addressed in the updated contract

Key Clauses Affected

Subject Matter and Scope

Addendum applies only to employers subject to applicable data protection laws; clarifies that commitment is conditional on legal applicability.

Precedence Clause

Addendum takes precedence over base service agreement in case of conflict, establishing hierarchy of contract terms.

Duration and Binding Effect

Clarifies addendum becomes binding on agreement effective date or later signing; data processing continues until relationship terminates per base agreement.

Full clause-by-clause analysis available with Professional.
These clauses may change again. Get alerted when they do. Watch Gusto — Free

This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology

Evidence Verification

✓ Verified
Previous Version
76881f2024d14f9e996879cd02ed06524957e0c2f9d73f4fb49afc96c16c447f
March 22, 2026 06:07 UTC
✓ Verified
Current Version
f56de72310d457b0b74b985f28c2c03143c452689525b5390dc7ff3d5aeff402
April 16, 2026 06:06 UTC
✓ Verified
Change Detected
April 16, 2026 06:06 UTC
Analysis Methodology
✓ Verified
Source Document
https://gusto.com/about/privacy
Citation Record
Entity: Gusto
Document: Gusto Privacy Policy
Record ID: CA-C-001284
Captured: 2026-04-16 06:06:16 UTC
URL: https://conductatlas.com/change/2026-04-16-gusto-gusto-privacy-policy-1284/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
For legal and compliance teams

Institutional Analysis

Assessment

Gusto introduced Version 3.0 of its Data Processing Addendum on April 16, 2026, adding substantial clarifying language on scope, duration, definitions, and data handling commitments. The new text explicitly conditions the addendum's application to employers subject to applicable data protection laws and establishes that the addendum governs the processing of 'Company Personal Data' in connection with Gusto's services. The update also clarifies contractual precedence (addendum over base agreement) and the timing of binding effect. For organizations using Gusto as a payroll processor, this change likely requires review to confirm alignment with internal data protection compliance frameworks, vendor management policies, and any applicable data processing agreements (DPAs) or contractual requirements under GDPR, UK GDPR, state privacy laws, or industry standards.

Regulatory Exposure

GDPR (EU General Data Protection Regulation), UK GDPR, CCPA (California Consumer Privacy Act), state privacy laws (Colorado, Connecticut, Virginia, Utah, Montana, Delaware, etc.), industry-specific regulations (HIPAA if health data is processed, FINRA if financial services context applies)

Full compliance analysis

Obligation analysis, escalation trigger, board language, and recommended action.

Watcher $9.99/mo Professional $149/mo

Watcher: regulatory citations + obligations. Professional: full compliance memo.

ConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-001284.

Full Changes

See the full side-by-side comparison of every sentence added, removed, and modified.

🔒 Full diff — Watcher

Document Context

Version history → Policy drift analysis → Document page →
Document
Gusto Privacy Policy
Entity
Gusto
Captured
April 16, 2026
Source URL
https://gusto.com/about/privacy
Other changes to Gusto Privacy Policy
Next change Apr 19, 2026
Gusto updated contact email addresses in its privacy policy on April 19, 2026. Arbitration opt-out requests now go to legal-opt-outs@gusto.com …
Low Neutral
View full version history →
More from Gusto
May 9, 2026 Low
Gusto Privacy Policy

Gusto's privacy policy was updated on May 9, 2026 to add two new document references in its table of contents: …

May 9, 2026 Low
Gusto Terms of Service

Gusto updated its Terms of Service on May 9, 2026 with five technical corrections. The changes include updating contact email …

May 6, 2026 Low
Gusto Terms of Service

Gusto updated two email addresses in their Terms of Service contact sections on May 6, 2026. The opt-out form submission …

Track Gusto policy changes

Get alerted when this policy changes again — including what changed and why it matters.

Prefer a weekly summary instead?

Get the biggest policy changes across 320+ platforms every Sunday.