Bank of America shares your personal information with government agencies, law enforcement, and fraud prevention organizations as required by law or to protect against fraud — and you cannot opt out of this sharing.
This analysis describes what Bank of America's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The clause establishes that certain disclosures occur outside the scope of customer privacy elections, grounding the bank's authority in statutory requirements (Gramm-Leach-Bliley Act) and standard business operations. This defines the baseline of information sharing that applies irrespective of customer preference selections.
Consumers' sensitive financial information, including account details and transaction histories, may be disclosed to law enforcement and regulatory bodies without advance notice or the ability to object, which is standard under GLBA but material to understand.
How other platforms handle this
Protect us, our business, our users, and others, for example to enforce our terms of service, prevent spam or other unwanted communications, and investigate or protect against fraud
we may use, retain or share information with law enforcement or others in circumstances where a person's vital interests require protection, such as in the case of emergencies.
Any such de-identified genetic information and phenotypic information we share with third parties for research purposes is done in accordance with Part 46 (beginning with Section 46.101) of Title 45 of the Code of Federal Regulations.
"Under the Gramm-Leach-Bliley Act, we are permitted to share with third parties, without regard to the customer choices, in connection with situations where we are required to disclose information, such as responding to subpoenas or tax reporting, and for typical business activities, such as sharing to identify or prevent fraud, to resolve customer disputes and enforce our rights, in connection with sale of all or part of a business or with consent.Excerpt from Bank of America's Privacy Notice
Mandatory disclosure provisions for fraud prevention and legal compliance are standard under GLBA and BSA/AML frameworks; legal teams should confirm that internal data governance policies align disclosure procedures with applicable subpoena, court order, and SAR …
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
ConductAtlas detected a major restructuring of Meta’s privacy policy that removed detailed consumer rights disclosures and relocated them to separate documents.
Your genetic data may be transferred to a new owner as a business asset. Here is what the Terms of Service actually say and what you can do right now.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
The clause establishes that certain disclosures occur outside the scope of customer privacy elections, grounding the bank's authority in statutory requirements (Gramm-Leach-Bliley Act) and standard business operations. This defines the baseline of information sharing that applies irrespective of customer preference selections.
Consumers' sensitive financial information, including account details and transaction histories, may be disclosed to law enforcement and regulatory bodies without advance notice or the ability to object, which is standard under GLBA but material to understand.
ConductAtlas has identified this type of provision across 288 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Bank of America.