Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
Chase may disclose account information and transaction data to third parties in five categories: to complete transactions, to investigate customer-initiated claims, to comply with legal process and litigation-related requests, with written customer permission, and as authorized by the Chase Privacy Notice.
This analysis describes what Chase's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The scope of disclosure permitted under the Privacy Notice category is not defined within the agreement itself and requires reference to the separate Privacy Notice incorporated into the document. The category 'requests received in connection with threatened or pending litigation' is broader than a formal court order and may encompass pre-litigation information requests.
Interpretive note: The full scope of third-party sharing authorized under the Privacy Notice category cannot be assessed from the agreement text alone; the Privacy Notice is incorporated by reference but not fully reproduced in the provided document.
Under this provision, Chase may share account and transaction information with third parties in the stated categories, including as authorized by the separately incorporated Privacy Notice. The full scope of sharing permitted under the Privacy Notice is not reproduced in this agreement section.
Cross-platform context
See how other platforms handle Disclosure of Account Information to Third Parties and similar clauses.
Compare across platforms →Monitoring
Chase has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Information about your account or the transactions you made will be disclosed to third parties: As necessary to complete transactions; In connection with the investigation of any claim you initiate; To comply with government agency, arbitration or court orders (including subpoenas), or requests received in connection with threatened or pending litigation; In accordance with your written permission; As permitted by our Privacy Notice and other relevant privacy notices and disclosures.Excerpt from Chase's Deposit Account Agreement
1. REGULATORY LANDSCAPE: Financial institution information sharing is primarily governed by the Gramm-Leach-Bliley Act (GLBA) and its implementing regulations, including Regulation P, which establishes opt-out rights for certain categories of information sharing with non-affiliated third parties. The CFPB and federal banking regulators supervise GLBA compliance. The Privacy Notice incorporated into this agreement is required to satisfy Regulation P disclosure standards. 2. GOVERNANCE EXPOSURE: Medium. The 'as permitted by our Privacy Notice' category creates an open-ended disclosure authorization that depends on the content of the Privacy Notice, which is incorporated by reference. The 'threatened or pending litigation' category for legal disclosure is broader than a formal subpoena or court order and may warrant legal review for scope. 3. JURISDICTION FLAGS: California CCPA and CPRA apply to California resident personal information not governed by GLBA; the agreement separately directs California business account holders to the CCPA Disclosure. EU and UK data protection frameworks would apply if Chase accounts are held by EU or UK data subjects, though the agreement does not address this explicitly. 4. CONTRACT AND VENDOR IMPLICATIONS: Third parties involved in transaction completion and claim investigation should be assessed as service providers under GLBA and applicable state privacy law. Data processing agreements with these vendors should be reviewed for consistency with the Privacy Notice's disclosed sharing practices. 5. COMPLIANCE CONSIDERATIONS: The Privacy Notice should be reviewed to confirm it satisfies Regulation P annual notice requirements and that opt-out mechanisms are functional. The 'threatened or pending litigation' disclosure category should be reviewed by legal teams to confirm it is applied with appropriate internal approval processes.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
The scope of disclosure permitted under the Privacy Notice category is not defined within the agreement itself and requires reference to the separate Privacy Notice incorporated into the document. The category 'requests received in connection with threatened or pending litigation' is broader than a formal court order and may encompass pre-litigation information requests.
Under this provision, Chase may share account and transaction information with third parties in the stated categories, including as authorized by the separately incorporated Privacy Notice. The full scope of sharing permitted under the Privacy Notice is not reproduced in this agreement section.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Chase.