If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what data is collected, request deletion of your data, and opt out of the sale of your personal information.
This analysis describes what Bank of America's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This clause operationalizes Bank of America's CCPA compliance obligations by defining permissible information-sharing categories and restricting external disclosure. It establishes the bank's consent-based sharing model and creates a framework for limiting affiliate data exchange consistent with California statutory requirements.
California residents can exercise CCPA rights to access, delete, or restrict use of their personal information held by Bank of America, providing materially stronger control over their financial data than federal law alone affords.
How other platforms handle this
If you are a California resident, you have the right to know what personal information we collect, use, and disclose about you; the right to request deletion of your personal information; the right to opt out of the sale or sharing of your personal information; the right to correct inaccurate person...
Depending on where you are located, you may have certain rights regarding your personal information, including the right to access, correct, delete, or restrict processing of your personal information, the right to data portability, and the right to object to or withdraw consent for certain processi...
We may also collect your personal data from other people or companies.
Monitoring
Bank of America has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"California: Under California law, we will not share information we collect about you with companies outside of Bank of America, unless the law allows. For example, we may share information with your consent, to service your accounts, or to provide rewards or benefits you are entitled to. We will limit sharing among our companies to the extent required by California law.— Excerpt from Bank of America's Bank of America Privacy Notice
CCPA compliance for financial institutions requires a layered approach given the partial GLBA exemption — data not covered by GLBA's privacy provisions (e.g., online behavioral data, marketing profiles) remains fully subject to CCPA; compliance teams should audit which data categories fall within each regime.
Full compliance analysis
Regulatory citations, enforcement risk, and due diligence action items.
Free: track 1 platform + weekly digest. Monitor: 25 platforms + same-day alerts. No credit card required.
Search "[your state] attorney general consumer complaint" to find your state's direct complaint form
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This clause operationalizes Bank of America's CCPA compliance obligations by defining permissible information-sharing categories and restricting external disclosure. It establishes the bank's consent-based sharing model and creates a framework for limiting affiliate data exchange consistent with California statutory requirements.
California residents can exercise CCPA rights to access, delete, or restrict use of their personal information held by Bank of America, providing materially stronger control over their financial data than federal law alone affords.
ConductAtlas has identified this type of provision across 1 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Bank of America.