Bank of America shares your personal information with certain third parties — such as for fraud prevention, servicing your account, and legal compliance — and you cannot opt out of this type of sharing.
This analysis describes what Bank of America's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The clause establishes that certain data sharing activities are permitted as standard operational practice and do not require customers to take action to prevent disclosure. This reflects the regulatory framework under the Gramm-Leach-Bliley Act, which permits financial institutions to share information for such purposes without opt-out rights.
Consumers have no right to prevent Bank of America from sharing their sensitive financial data for core operational purposes, including with service providers, government agencies, and fraud prevention organizations, which is a mandatory aspect of holding any Bank of America account.
How other platforms handle this
Protect us, our business, our users, and others, for example to enforce our terms of service, prevent spam or other unwanted communications, and investigate or protect against fraud
If we're involved in a reorganization, merger, acquisition, sale of some or all of our assets or other business transaction, depending on the circumstances, we may disclose any of the information described in Section 2 above...
Any such de-identified genetic information and phenotypic information we share with third parties for research purposes is done in accordance with Part 46 (beginning with Section 46.101) of Title 45 of the Code of Federal Regulations.
"For our everyday business purposes — such as to process your transactions, maintain your account(s), respond to court orders and legal investigations, or report to credit bureaus. Yes. No.Excerpt from Bank of America's Privacy Notice
Under GLBA Regulation P, operational sharing exceptions — including servicing, fraud prevention, legal compliance, and third-party service providers acting on the bank's behalf — are exempt from opt-out requirements; institutions must ensure these exceptions are …
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
ConductAtlas detected a major restructuring of Meta’s privacy policy that removed detailed consumer rights disclosures and relocated them to separate documents.
Your genetic data may be transferred to a new owner as a business asset. Here is what the Terms of Service actually say and what you can do right now.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
The clause establishes that certain data sharing activities are permitted as standard operational practice and do not require customers to take action to prevent disclosure. This reflects the regulatory framework under the Gramm-Leach-Bliley Act, which permits financial institutions to share information for such purposes without opt-out rights.
Consumers have no right to prevent Bank of America from sharing their sensitive financial data for core operational purposes, including with service providers, government agencies, and fraud prevention organizations, which is a mandatory aspect of holding any Bank of America account.
ConductAtlas has identified this type of provision across 288 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Bank of America.