7 Total
2 High severity
4 Medium severity
1 Low severity
Summary

This is Bank of America's privacy notice explaining what personal information they collect about you and who they share it with. They collect sensitive financial data like your Social Security number, account history, and credit information, and they share some of it with affiliated companies and outside businesses for marketing purposes — though you can opt out of some of this sharing. California residents have additional rights including the ability to request deletion of their data.

Technical Summary

Bank of America's U.S. Consumer Privacy Notice (last updated January 2026) governs the collection, use, and sharing of personal information for retail banking customers in compliance with the Gramm-Leach-Bliley Act (GLBA). The notice discloses that Bank of America shares consumer data across multiple categories including affiliates for marketing purposes, nonaffiliates for joint marketing, and third parties for everyday business operations. Consumers retain limited opt-out rights for certain sharing activities — specifically affiliate marketing and nonaffiliate sharing for marketing purposes — but have no right to limit sharing for core operational purposes such as servicing accounts, fraud prevention, and legal compliance. The document also references California Consumer Privacy Act (CCPA) rights for California residents, including the right to know, delete, and opt out of the sale of personal information. Collected data includes Social Security numbers, employment information, account balances, transaction history, credit information, assets, and investment experience.

Institutional Analysis

This notice is structured to satisfy Gramm-Leach-Bliley Act (GLBA) annual privacy notice requirements and Regulation P disclosure obligations, covering all sharing categories mandated by the model pr…

This notice is structured to satisfy Gramm-Leach-Bliley Act (GLBA) annual privacy notice requirements and Regulation P disclosure obligations, covering all sharing categories mandated by the model privacy form. Compliance teams should note the dual-track opt-out framework — GLBA opt-outs for affili…

🔒

Compliance intelligence locked

Regulatory exposure, material risk, and due diligence action items.

Evidence Provenance
Captured March 6, 2026 18:27 UTC
Document ID CA-D-000054
Version ID CA-V-000041
Wayback Machine View archived versions →
SHA-256 4da218bfd09bd30c3a02f001a3cabab094d8f1d21e974e79d205419ebcf748f6
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Cryptographically signed
Change Timeline
High Severity — 2 provisions
Medium Severity — 4 provisions
Low Severity — 1 provision