ADP may collect and process highly sensitive personal information including health data, biometric identifiers, racial or ethnic origin, and union membership when required to deliver services, when you have consented, or for legal purposes.
This analysis describes what ADP's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
These are among the most sensitive categories of personal information recognized under privacy law globally. Payroll and HR platforms often require some of this data, but its collection by a single provider at scale creates elevated risk if data is breached or misused.
ADP deleted the cookie preference management tool that previously allowed users to understand and control which cookies were placed on their devices, including functional, analytics, and advertising cookies. The removal eliminates the transparency mechanism through which users could consent to or opt out of different cookie categories. The practical effect depends on whether ADP has replaced this functionality elsewhere or whether cookies continue to be placed without equivalent granular user control.
View change record →Employees whose employers use ADP for benefits administration or workforce management may have health data, biometric data, or other highly sensitive personal information processed through ADP's platform, which carries elevated privacy risk and triggers heightened regulatory protections in many jurisdictions.
How other platforms handle this
If you choose to reveal any personal information about yourself to other users, you do so at your own risk. We strongly encourage you to use caution in disclosing any personal information online.
to request that your data be transferred to a third party (data portability)
Your organization may allow you to access and export your data in order to back it up or transfer it to a service outside of Google.
"We may collect and use sensitive data where permitted or required by applicable law, where you have given your explicit consent, or where it is necessary for us to establish, exercise or defend legal claims. Sensitive data includes: racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data (where used for identification purposes), data concerning health, and data concerning a person's sex life or sexual orientation.Excerpt from ADP's Privacy Statement
REGULATORY LANDSCAPE: GDPR Article 9 designates these as special categories of personal data requiring explicit consent or another specific legal basis such as employment law necessity.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Search "[your state] attorney general consumer complaint" to find your state's direct complaint form
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
These are among the most sensitive categories of personal information recognized under privacy law globally. Payroll and HR platforms often require some of this data, but its collection by a single provider at scale creates elevated risk if data is breached or misused.
Employees whose employers use ADP for benefits administration or workforce management may have health data, biometric data, or other highly sensitive personal information processed through ADP's platform, which carries elevated privacy risk and triggers heightened regulatory protections in many jurisdictions.
ConductAtlas has identified this type of provision across 289 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by ADP.