The breadth of sensitive data collected — particularly Social Security numbers and detailed financial histories — creates significant risk if shared broadly or in the event of a data breach, and consumers should understand the full scope of what is held.
Consumer impact
Bank of America collects highly sensitive financial data including your Social Security number, account balances, transaction history, and credit information, and shares this data with affiliated companies and nonaffiliates for marketing purposes without requiring your prior consent. Federal law limits but does not eliminate this sharing, meaning some data flows to third parties unless you actively opt out. You can limit marketing-related data sharing by calling 1-888-341-5000 or visiting the Bank of America privacy choices page to submit an opt-out request.
What you can do
⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
Export Your Data
Visit Bank of America's privacy page and submit a data access request to understand what personal information is held about you. California residents can use the CCPA request form available on the privacy page.
Applicable agencies
Consumer Financial Protection Bureau (cfpb)
Regulates consumer financial products and services. Can investigate companies for unfair, deceptive, or abusive financial practices including improper fees, billing errors, and data misuse.
Who can file: Anyone who has used a consumer financial product or service in the US
What you need: Account number or details, dates of transactions or events, description of the issue, and any supporting documents
What to expect: The company must respond within 15 days. The CFPB forwards your complaint and may use it in enforcement actions. Individual compensation is possible in some cases.
ConductAtlas Policy Archive
Entity: Bank of America | Document: Bank of America Privacy Notice | Record: CA-P-000467
Captured: 2026-03-06 19:33:25 UTC | SHA-256: 0579b728c8274563…
URL: https://conductatlas.com/platform/bank-of-america/bank-of-america-privacy-notice/collection-of-sensitive-financial-data/
Accessed: April 4, 2026