7 Total
2 High severity
4 Medium severity
1 Low severity
Summary

This is Bank of America's official privacy notice explaining what personal financial data they collect — including your account balances, transaction history, credit scores, and income — and who they share it with. The most important thing to know is that Bank of America shares your financial data with both its affiliated companies and nonaffiliated third-party marketing partners, and you can opt out of some — but not all — of this sharing. To limit sharing with nonaffiliated third parties for marketing purposes, you can call 1-888-341-5000 or visit your account settings online.

Technical Summary

This document is Bank of America's US Consumer Privacy Notice, governing the collection, use, and sharing of personal financial information under the Gramm-Leach-Bliley Act (GLBA) and applicable state privacy laws, including the California Consumer Privacy Act (CCPA). The notice discloses that Bank of America collects categories of personal information including account balances, transaction history, credit history, and income data, and shares this information with affiliates and certain nonaffiliated third parties for joint marketing and everyday business purposes. Notably, the document provides consumers with limited opt-out rights for certain sharing practices — specifically sharing with nonaffiliated third parties for marketing and sharing among affiliates for marketing — but explicitly states that consumers cannot opt out of sharing necessary for everyday business purposes, which encompasses a broad range of third-party disclosures. The notice engages the GLBA Privacy Rule (16 CFR Part 313), CCPA (Cal. Civ. Code §1798.100 et seq.), and federal financial privacy regulations enforced by the CFPB and OCC; California residents receive enhanced rights including the right to know, delete, and opt out of sale of personal information. Material compliance considerations include ensuring opt-out mechanisms are operational and accessible, that joint marketing agreements with nonaffiliated partners are documented under GLBA, and that CCPA-required response timelines (45 days) are met for verified consumer requests.

Evidence Provenance
Captured April 19, 2026 06:04 UTC
Document ID CA-D-000054
Version ID CA-V-000656
Wayback Machine View archived versions →
SHA-256 dfddc979b6ac57411236f97b2625edab871ef63f8c204ec9e3ccc0f28bee9d90
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Cryptographically signed
Institutional Analysis

🔒 Institutional analysis locked

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.

Upgrade to Professional — $149/mo
Change Timeline
View full version history (0 captures) →
High Severity — 2 provisions
Medium Severity — 4 provisions
Low Severity — 1 provision

Cross-platform context

See how other platforms handle Categories of Personal Information Collected and similar clauses.

Compare across platforms →

Applicable Regulations

CCPA/CPRA
California, USA
CFAA
United States Federal
CAN-SPAM
United States Federal
FCRA
United States Federal
GLBA
United States Federal
TCPA
United States Federal

Related Analysis

Consumer Rights · April 9, 2026
Bank of America Arbitration Provision 2026: How to Opt Out

Bank of America added a mandatory arbitration clause to its Deposit Agreement. Here's what it means, how to opt out, and the deadline.