Bank of America · Bank of America Privacy Notice · View original document ↗

Sharing with Affiliates for Everyday Business Purposes

Medium severity High confidence Explicitdocumentlanguage Unique · 0 of 325 platforms
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Bank of America Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

Bank of America shares your financial information — including account balances, transaction history, and credit data — with companies it owns or controls for standard banking operations, and you cannot opt out of this sharing.

This analysis describes what Bank of America's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes the scope of internal data sharing across the Bank of America corporate group for operational functions. The non-restrictable nature of this sharing means consumers cannot opt out of affiliate access for these specified business functions.

Consumer impact (what this means for users)

Your Social Security number, account balances, payment history, and credit information are shared across the Bank of America corporate family for business operations, and there is no opt-out right for this category of sharing under the notice's stated terms.

Cross-platform context

See how other platforms handle Sharing with Affiliates for Everyday Business Purposes and similar clauses.

Compare across platforms →

Monitoring

Bank of America has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Reasons we can share your personal information: For our everyday business purposes — such as to process your transactions, maintain your account(s), respond to court orders and legal investigations, or report to credit bureaus. Does Bank of America share? Yes. Can you limit this sharing? No.

— Excerpt from Bank of America's Bank of America Privacy Notice

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

REGULATORY LANDSCAPE: This provision reflects the GLBA Regulation P framework (12 CFR Part 1016), which permits sharing for everyday business purposes within a financial institution's corporate family without requiring an opt-out. The CFPB is the primary enforcement authority. GLBA preempts many state laws on this point, but California's CFIPA may impose additional restrictions on intra-affiliate sharing of certain information types, and compliance teams should evaluate whether CFIPA carve-outs apply. GOVERNANCE EXPOSURE: Medium. While this sharing is GLBA-compliant as stated, the breadth of data covered (SSNs, transaction history, credit history, account balances) creates operational risk if data minimization practices are not documented. Regulators have scrutinized overly broad intra-affiliate data flows under both GLBA and unfair/deceptive practice standards. JURISDICTION FLAGS: California residents face heightened exposure under CFIPA, which may impose opt-in or opt-out requirements for certain categories of financial information shared with affiliates beyond what GLBA requires. Legal teams should confirm whether the bank's California-specific notice addresses this distinction. CONTRACT AND VENDOR IMPLICATIONS: Intra-affiliate data sharing agreements should be reviewed to confirm they are limited to the purposes described in this notice. Any affiliate using shared data for purposes beyond everyday business operations would need separate legal basis and disclosure. COMPLIANCE CONSIDERATIONS: Compliance teams should maintain a current inventory of affiliated entities receiving this data, document the specific purposes for each data type shared, and confirm that data retention and access controls align with Regulation P and applicable state law requirements.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Watcher free for 14 days

Free: track 1 platform + weekly digest. Watcher: 10 platforms + same-day alerts. No credit card required.

Applicable agencies

  • CFPB
    The CFPB enforces Regulation P under GLBA, which governs affiliate data sharing practices by consumer financial institutions
    File a complaint →

Provision details

Document information
Document
Bank of America Privacy Notice
Entity
Bank of America
Document last updated
May 5, 2026
Tracking information
First tracked
April 27, 2026
Last verified
May 9, 2026
Record ID
CA-P-007245
Document ID
CA-D-00054
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
1d4e65e734a0b2e8cc01b0312c42f36950c5e1ea1c03ab56dfa173a8ebefa627
Analysis generated
April 27, 2026 11:40 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Bank of America
Document: Bank of America Privacy Notice
Record ID: CA-P-007245
Captured: 2026-04-27 11:40:46 UTC
SHA-256: 1d4e65e734a0b2e8…
URL: https://conductatlas.com/platform/bank-of-america/bank-of-america-privacy-notice/sharing-with-affiliates-for-everyday-business-purposes/
Accessed: May 20, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Professional Governance Intelligence

Need to monitor specific governance provisions?

Professional includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Professional free trial

Or start with Watcher →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Bank of America's Sharing with Affiliates for Everyday Business Purposes clause do?

This provision establishes the scope of internal data sharing across the Bank of America corporate group for operational functions. The non-restrictable nature of this sharing means consumers cannot opt out of affiliate access for these specified business functions.

How does this clause affect you?

Your Social Security number, account balances, payment history, and credit information are shared across the Bank of America corporate family for business operations, and there is no opt-out right for this category of sharing under the notice's stated terms.

Is ConductAtlas affiliated with Bank of America?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Bank of America.