Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy authorizes ADP to share personal data including bank account information with business partners in the context of referral validation and related commercial transactions, subject to the condition that the individual has purchased from, interacted with, or authorized sharing with that partner.
This analysis describes what ADP's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision authorizes disclosure of bank account information to third-party business partners for referral validation purposes, which may engage financial data protection requirements under the Gramm-Leach-Bliley Act and applicable state financial privacy statutes depending on the nature of the business relationship.
Interpretive note: Whether GLBA applies to ADP in this context depends on whether ADP qualifies as a financial institution under the statute's definition, which is not established by this document alone.
ADP deleted the cookie preference management tool that previously allowed users to understand and control which cookies were placed on their devices, including functional, analytics, and advertising cookies. The removal eliminates the transparency mechanism through which users could consent to or opt out of different cookie categories. The practical effect depends on whether ADP has replaced this functionality elsewhere or whether cookies continue to be placed without equivalent granular user control.
View change record →Under this clause, ADP may share an individual's contact information and bank account information with business partners for referral validation where the individual has interacted with or been referred by that partner. The policy does not specify the technical or contractual safeguards applied to bank account information shared with business partners in this context.
Cross-platform context
See how other platforms handle Business Partner Data Sharing Including Bank Account Information and similar clauses.
Compare across platforms →Monitoring
ADP has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"Our business partners, but only to the extent you have purchased product or service from such partner, interacted with such partner, or otherwise authorized the sharing. For example, if you are referred to ADP from a business partner website, we may provide that partner with your contact information and certain economic and financial information, such as bank account information, to validate the referral.Excerpt from ADP's Privacy Statement
REGULATORY LANDSCAPE: Disclosure of bank account information to third parties may engage the Gramm-Leach-Bliley Act (GLBA) if ADP is a financial institution under that statute's definition, requiring notice and opt-out rights for sharing with non-affiliated third parties. The FTC and applicable state financial regulators enforce GLBA. State privacy laws including CCPA and the California Financial Information Privacy Act may impose additional restrictions on sharing of financial account information. GOVERNANCE EXPOSURE: Medium. The policy conditions sharing on prior interaction, purchase, or authorization, which narrows the scope. However, the lack of detail regarding the contractual obligations imposed on business partners receiving bank account information, and the absence of an explicit opt-out mechanism for this specific sharing category, may warrant review. JURISDICTION FLAGS: California imposes heightened requirements on sharing of financial information under CCPA, where bank account numbers qualify as sensitive personal information. EU and EEA individuals whose bank account data is shared with business partners outside the EEA would require a lawful transfer mechanism beyond the BCR, depending on whether the business partner is itself subject to BCR obligations. CONTRACT AND VENDOR IMPLICATIONS: Organizations whose employees or contacts may have bank account information disclosed to ADP business partners should assess whether this sharing is consistent with their own data protection obligations to employees and customers. Vendor agreements with ADP should specify the categories of financial data that may be shared and the safeguards applied. COMPLIANCE CONSIDERATIONS: Legal teams should assess whether ADP qualifies as a financial institution under GLBA and, if so, whether GLBA notice and opt-out requirements have been satisfied. Data mapping should identify whether bank account information flows to business partners constitute onward transfers requiring additional safeguards under applicable law.
This provision authorizes disclosure of bank account information to third-party business partners for referral validation purposes, which may engage financial data protection requirements under the Gramm-Leach-Bliley Act and applicable state financial privacy statutes depending on the nature of the business relationship.
Under this clause, ADP may share an individual's contact information and bank account information with business partners for referral validation where the individual has interacted with or been referred by that partner. The policy does not specify the technical or contractual safeguards applied to bank account information shared with business partners in this context.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by ADP.