CA-C-001371
SoFi — SoFi Privacy Notice
Entity
Date detected
April 21, 2026
Effective date
April 21, 2026
Severity
Direction
Positive
Affected users
all users US users
Taxonomy
Transparency removal
Changes
+3 sentences added · −3 sentences removed · 12 sentences modified
Share 𝕏 Share in Share 🔒 PDF
Watch SoFi Get alerts when this policy changes.
Watch — Free

Event Summary

SoFi substantially revised the cookie and tracking technology section of its Privacy Notice on April 21, 2026. The prior language stated that SoFi shares tracking information with social media, advertising, and analytics partners, and that non-selection constitutes agreement to these technologies. The updated language introduces a Privacy Preference Center, describes cookie categories (Functional, Performance, Strictly Necessary), explains that blocking cookies may impact site functionality, and provides explicit mechanism to manage consent preferences by category rather than opting into all tracking by default.

MEDIUM

Consumer Impact

The updated Privacy Notice replaces a consent model where non-selection meant acceptance of all tracking technologies with a granular preference system organized by cookie category. Under the revised terms, you can now access a Privacy Preference Center to manage Functional Cookies and Performance Cookies separately, while Strictly Necessary Cookies remain non-optional for site operation. The updated language discloses that blocking certain cookies may impact site functionality and services offered. You can access the Privacy Preference Center to select which cookie categories to enable.

Governance Analysis

The updated terms establish a granular consent mechanism that moves away from implied consent by silence toward explicit, category-based preference management. This change affects how SoFi collects and uses tracking data by allowing users to disable non-essential cookies while maintaining transparency about the functional consequences of doing so. The shift aligns with regulatory expectations under GDPR and state privacy laws that require affirmative, informed consent for non-essential data processing.

Available Actions

Access the Privacy Preference Center when visiting SoFi's website to select which cookie categories (Functional, Performance) you wish to enable

Review the disclosure explaining that blocking certain cookies may affect site functionality before disabling preferences

If No Action Is Taken

If you do not actively manage cookie preferences, the default settings as established by SoFi will apply

Depending on which cookies you allow, certain site features or services may not function as expected

Key Clauses Affected

Privacy Preference Center

Introduces granular, category-based cookie consent management allowing users to enable or disable Functional and Performance Cookies while preserving Strictly Necessary Cookies as mandatory.

Consent-by-silence removal

Removes prior language stating non-selection constitutes agreement; shifts from implicit to explicit consent model for non-essential tracking.

Functional impact disclosure

Adds explicit language that blocking certain cookies may impair site functionality and service delivery, creating transparency around tradeoff between privacy and usability.

Full clause-by-clause analysis available with Professional.
These clauses may change again. Get alerted when they do. Watch SoFi — Free

This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology

Evidence Verification

✓ Verified
Previous Version
7e3b86d9a9d25a42d6adc3c47649049e92242e4b30059cee9e850144c87e3f45
April 19, 2026 06:08 UTC
✓ Verified
Current Version
3dfa2aeb56d30d09c89593ed147e0be052f4572888a8c1afe658dcc7bb6c40b1
April 21, 2026 11:16 UTC
✓ Verified
Change Detected
April 21, 2026 11:16 UTC
Analysis Methodology
✓ Verified
Source Document
https://www.sofi.com/privacy-policy/
Citation Record
Entity: SoFi
Document: SoFi Privacy Notice
Record ID: CA-C-001371
Captured: 2026-04-21 11:16:46 UTC
URL: https://conductatlas.com/change/2026-04-21-sofi-sofi-privacy-notice-1371/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.

Impact Summary

2
New obligations
1
Expanded
1
Protection removed
Consumers Added

You now have the ability to control different types of cookies separately rather than accepting or rejecting all tracking at once.

Consumers Added

The terms now explain that turning off some cookies could mean certain website features may not work properly.

+ 2 more obligation changes. Full breakdown available with Watcher.

Track changes →
For legal and compliance teams

Institutional Analysis

Assessment

SoFi revised its cookie consent mechanism from implicit acceptance (silence as consent) to explicit granular preference management through a Privacy Preference Center. The change aligns with transparency expectations under GDPR, CCPA, and state privacy laws by offering category-based opt-out rather than all-or-nothing consent. The removal of the prior 'non-selection constitutes agreement' language and introduction of an explicit management interface may reduce regulatory exposure related to consent validity under EU ePrivacy Directive and comparable US state frameworks. Organizations using SoFi services should assess whether this change affects their own privacy disclosures or vendor governance if they reference or rely on SoFi's consent mechanisms.

Regulatory Exposure

GDPR (Articles 4, 7, 13), EU ePrivacy Directive (Directive 2002/58/EC), CCPA (California Civil Code sections 1798.100-1798.199), COPPA (15 U.S.C. 6501-6506), state privacy laws (Virginia, Colorado, Connecticut, Utah, Montana privacy acts)

Full compliance analysis

Obligation analysis, escalation trigger, board language, and recommended action.

Watcher $9.99/mo Professional $149/mo

Watcher: regulatory citations + obligations. Professional: full compliance memo.

ConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-001371.

Full Changes

See the full side-by-side comparison of every sentence added, removed, and modified.

🔒 Full diff — Watcher

Document Context

Version history → Policy drift analysis → Document page →
Document
SoFi Privacy Notice
Entity
SoFi
Captured
April 21, 2026
Source URL
https://www.sofi.com/privacy-policy/
Other changes to SoFi Privacy Notice
Next change Apr 23, 2026
SoFi updated its Privacy Notice on April 23, 2026 to clarify its tracking technology practices and consent model. The updated …
Medium Negative
View full version history →
More from SoFi
May 7, 2026 Medium
SoFi Privacy Notice

SoFi revised its cookie and tracking technology disclosure on May 7, 2026. The previous language stated that SoFi uses pixels …

May 6, 2026 Medium
SoFi Privacy Notice

SoFi updated its Privacy Notice on May 6, 2026 to reorganize and clarify how it collects and shares tracking data. …

May 5, 2026 Low
SoFi Terms of Service

SoFi updated its Terms of Service on May 5, 2026, making primarily formatting and navigation changes to the document structure. …

Track SoFi policy changes

Get alerted when this policy changes again — including what changed and why it matters.

Prefer a weekly summary instead?

Get the biggest policy changes across 320+ platforms every Sunday.