Track 1 platform and get the weekly governance digest. No credit card required.
This page describes what the document states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability may vary by jurisdiction. Methodology
This is Equifax's privacy policy, covering how the company collects, uses, and shares personal information including credit history, Social Security numbers, financial records, device identifiers, and browsing behavior across its websites, apps, and data products. The policy authorizes sharing personal information with affiliates, service providers, marketing partners, and third-party data recipients, and discloses that Equifax sells or shares certain personal data for cross-context behavioral advertising, with opt-out rights available for California residents and other qualifying state residents. The policy also discloses that Equifax retains personal information for as long as necessary to fulfill business, legal, and regulatory purposes, without specifying fixed retention periods for most data categories.
This document is Equifax's consumer-facing privacy policy, governing the collection, use, sharing, and retention of personal information across Equifax's websites, mobile applications, and data services, with stated legal bases including consent, legitimate interest, and legal obligation depending on jurisdiction. The policy states that Equifax collects identifiers, financial data, credit history, Social Security numbers, device information, browsing activity, geolocation data, and inferences derived from consumer profiles, and authorizes sharing this information with affiliates, service providers, business partners, data brokers, marketing partners, and government or law enforcement entities. Notably, as a consumer reporting agency, Equifax occupies a dual role: it is both a data collector subject to general privacy law and a regulated furnisher and user of consumer report data under the Fair Credit Reporting Act, creating a layered compliance structure that the policy acknowledges but does not fully delineate in terms of which rights apply under which framework. The policy references compliance with CCPA and CPRA for California residents, GDPR for EU and UK data subjects, and state-specific frameworks including Virginia, Colorado, Connecticut, and Texas; enforcement and applicability of stated rights depend on the jurisdiction of the consumer and the specific Equifax entity involved.
Institutional analysis available with Compliance
Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Compliance.
Start Compliance free trial1 important change detected
2 versions captured · Last updated: May 2026
Monitoring
Equifax has updated this document before.
Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
Compliance Governance Intelligence
Need provision-level monitoring and regulatory mapping?
Compliance includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.
Start Compliance free trialCross-platform context
See how other platforms handle Biometric Data Collection and similar clauses.
Compare across platforms →Governance Monitoring
Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.