CA-C-001421
Gusto — Gusto Privacy Policy
Entity
Date detected
April 24, 2026
Effective date
April 23, 2026
Severity
Direction
Positive
Affected users
all users employees of gusto customers business customers
Taxonomy
Vendor disclosure shift
Changes
+120 sentences added · 1 sentence modified
Share 𝕏 Share in Share 🔒 PDF
Watch Gusto Get alerts when this policy changes.
Watch — Free

Event Summary

Gusto updated its Privacy Policy on April 24, 2026 with significant new language clarifying how the policy applies and when it does not. The policy now explicitly states it applies when you access Gusto's platform, create an account, or communicate with Gusto, but does not apply when Gusto processes data on behalf of customer employers. The update also adds contact information for privacy questions and acknowledges that the policy will be updated as practices change.

MEDIUM

Consumer Impact

The updated policy clarifies an important boundary: if you access Gusto through your employer's account for payroll processing, Gusto's Privacy Policy may not govern how your personal information is handled in that context. Instead, you would need to direct privacy concerns to your employer rather than to Gusto directly. The policy now provides a clear contact method (privacy@gusto.com) for users who have privacy questions about Gusto's direct practices, making it easier to understand who to contact depending on your relationship with Gusto.

Governance Analysis

This change clarifies a critical boundary in data responsibility: if you access Gusto through your employer's payroll account, Gusto's Privacy Policy may not protect you directly because Gusto acts as a processor, not controller, of your data. Understanding this distinction is essential for knowing whether to contact Gusto or your employer with privacy concerns, and for employers to understand their own data governance obligations.

Available Actions

Determine whether you access Gusto as a direct user (creating your own account) or through your employer's account for payroll processing.

If accessing through your employer's payroll account, direct privacy questions and concerns to your employer's HR or privacy team rather than to Gusto at privacy@gusto.com.

If accessing Gusto as a direct user, you can contact privacy@gusto.com with privacy questions.

If No Action Is Taken

If you send privacy inquiries to Gusto regarding payroll data processed through your employer's account, Gusto may redirect you to your employer, delaying resolution.

Your employer may not have adequately communicated to you that they, not Gusto, control your payroll data privacy, leaving you uncertain about your rights.

Historical Context

ConductAtlas has recorded 2 material changes to this document (since April 2026). An additional minor or cosmetic changes were excluded.

Key Clauses Affected

Scope and Applicability Carve-Out

Privacy Policy does not apply when Gusto processes data as a processor on behalf of customer employers; employer becomes primary responsible party for employee privacy.

User Acknowledgment by Access

Accessing or using Gusto's platform now constitutes acknowledgment that you have read the Privacy Notice and agree to its practices.

Privacy Contact Method

Adds explicit contact information (privacy@gusto.com) for privacy inquiries and clarifies circumstances under which users should contact their employer instead.

Full clause-by-clause analysis available with Professional.
These clauses may change again. Get alerted when they do. Watch Gusto — Free

This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology

Evidence Verification

✓ Verified
Previous Version
84a44c0654684bda02b857b5cec489b4676a977de56e71991e491dd7b0805570
April 23, 2026 06:28 UTC
✓ Verified
Current Version
768d3930b0aa03177e5f86914b22403e95d767a16288c0640a7099e7c8debf4d
April 24, 2026 06:26 UTC
✓ Verified
Change Detected
April 24, 2026 06:26 UTC
Analysis Methodology
✓ Verified
Source Document
https://gusto.com/about/privacy
Citation Record
Entity: Gusto
Document: Gusto Privacy Policy
Record ID: CA-C-001421
Captured: 2026-04-24 06:26:54 UTC
URL: https://conductatlas.com/change/2026-04-24-gusto-gusto-privacy-policy-1421/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.

Impact Summary

2
New obligations
Users Added

Using Gusto's services counts as your agreement to how they handle your data according to their Privacy Notice.

Businesses Added

If you're an employee accessing Gusto through your employer, your employer, not Gusto, controls your payroll data and should answer your privacy questions.

For legal and compliance teams

Institutional Analysis

Assessment

Gusto substantially expanded its Privacy Policy on April 24, 2026 by adding 120 sentences clarifying scope, applicability, and contact procedures. The most significant substantive addition is an explicit carve-out: the Privacy Policy does not apply when Gusto acts as a data processor on behalf of customers (employers). This distinction aligns with GDPR and CCPA frameworks that differentiate between data controller and processor roles. Employers using Gusto become the primary data controller for employee information, while Gusto may act as processor under a data processing agreement. Organizations that include Gusto in their vendor ecosystem should verify that data processing agreements (DPAs) are in place and clearly allocate controller and processor responsibilities, particularly for payroll and employee data. The policy expansion also establishes new user acknowledgment language (accessing the platform constitutes agreement to privacy practices), which may trigger consent-management review.

Regulatory Exposure

GDPR (Articles 4(7), 4(8), 28 regarding controller/processor distinction), CCPA (distinction between business and service provider roles), state privacy laws (similar controller/processor frameworks)

Full compliance analysis

Obligation analysis, escalation trigger, board language, and recommended action.

Watcher $9.99/mo Professional $149/mo

Watcher: regulatory citations + obligations. Professional: full compliance memo.

ConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-001421.

Full Changes

See the full side-by-side comparison of every sentence added, removed, and modified.

🔒 Full diff — Watcher

Document Context

Version history → Policy drift analysis → Document page →
Document
Gusto Privacy Policy
Entity
Gusto
Captured
April 24, 2026
Source URL
https://gusto.com/about/privacy
Other changes to Gusto Privacy Policy
Previous change Apr 23, 2026
Gusto updated contact email addresses in its Privacy Policy on April 23, 2026. The policy now directs users to email …
Low Neutral
Next change Apr 25, 2026
Gusto added 408 sentences of new language to its Employer Terms of Service on April 25, 2026, including expanded definitions …
High Negative
View full version history →
More from Gusto
May 9, 2026 Low
Gusto Privacy Policy

Gusto's privacy policy was updated on May 9, 2026 to add two new document references in its table of contents: …

May 9, 2026 Low
Gusto Terms of Service

Gusto updated its Terms of Service on May 9, 2026 with five technical corrections. The changes include updating contact email …

May 6, 2026 Low
Gusto Terms of Service

Gusto updated two email addresses in their Terms of Service contact sections on May 6, 2026. The opt-out form submission …

Track Gusto policy changes

Get alerted when this policy changes again — including what changed and why it matters.

Prefer a weekly summary instead?

Get the biggest policy changes across 320+ platforms every Sunday.