Equifax · Equifax Privacy Policy · View original document ↗

Sensitive Personal Information Categories

High severity High confidence Explicitdocumentlanguage Unique · 0 of 325 platforms
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Equifax Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

Equifax discloses that it may collect categories of information classified as sensitive under California law, including your Social Security number, financial account credentials, precise location, racial or ethnic origin, and biometric data.

This analysis describes what Equifax's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

These are the most sensitive categories of personal data and their collection by any entity, particularly a data broker that has experienced significant data breaches historically, creates meaningful risk if data is misused or exposed.

Consumer impact (what this means for users)

Equifax holds some of the most sensitive categories of personal information about you, including government identifiers and financial credentials, and California residents have the right under CPRA to limit how this sensitive personal information is used, including for marketing and profiling purposes. You can exercise this right through the Equifax privacy rights portal.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Export Your Data
    Submit a data access request through the Equifax privacy rights portal to understand what sensitive personal information Equifax holds about you, then submit a limitation request if you wish to restrict its use for non-essential purposes.

Cross-platform context

See how other platforms handle Sensitive Personal Information Categories and similar clauses.

Compare across platforms →

Monitoring

Equifax has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Sensitive personal information: Social Security number, driver's license number, state identification card number, passport number; Account log-in, financial account, debit card, or credit card number in combination with any required security or access code, password, or credentials allowing access to an account; Precise geolocation; Racial or ethnic origin, religious or philosophical beliefs, or union membership; Contents of a consumer's mail, email, and text messages unless we are the intended recipient of the communication; Genetic data; Biometric information processed for the purpose of uniquely identifying a consumer.

— Excerpt from Equifax's Equifax Privacy Policy

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

REGULATORY LANDSCAPE: CPRA establishes a distinct category of sensitive personal information (SPI) and grants California consumers the right to limit its use and disclosure to purposes reasonably necessary to provide requested services. SPI under CPRA includes many categories Equifax discloses collecting: Social Security numbers, financial credentials, precise geolocation, racial origin, and biometric data. FCRA separately governs some of these categories when used in consumer reports but does not limit collection or secondary use as comprehensively as CPRA. The Social Security number as a data element is also subject to federal and state identity theft protection statutes. GOVERNANCE EXPOSURE: High. The breadth of SPI categories Equifax discloses collecting, combined with its role as a data broker and its historical data breach exposure (the 2017 Equifax breach affected approximately 147 million consumers), creates significant governance and reputational risk. Regulators are likely to scrutinize SPI handling practices for entities of this scale. JURISDICTION FLAGS: California (CPRA SPI limitation right), Texas, Colorado, Virginia, and Connecticut with comparable SPI frameworks. Federal law also imposes obligations for specific SPI elements such as Social Security numbers under various identity theft and financial privacy statutes. CONTRACT AND VENDOR IMPLICATIONS: Service providers that access or process SPI on Equifax's behalf must be subject to contracts that restrict use to specified purposes and prohibit secondary use or sale. Data security obligations for SPI should be heightened relative to non-sensitive data categories. COMPLIANCE CONSIDERATIONS: A dedicated SPI inventory should be maintained separate from general personal information records. CPRA's limitation right must be operationalized with a clear and accessible mechanism. Data security controls for SPI categories including SSNs and financial credentials should be subject to enhanced access controls and monitoring. Breach response procedures should prioritize SPI breach notification given the heightened statutory obligations triggered by exposure of these categories.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Watcher free for 14 days

Free: track 1 platform + weekly digest. Watcher: 10 platforms + same-day alerts. No credit card required.

Applicable agencies

  • CFPB
    The CFPB has authority over consumer financial data including financial account credentials and Social Security numbers in the context of consumer reporting and financial services
    File a complaint →
  • FTC
    The FTC has authority over data security and privacy practices for data brokers including the handling of sensitive personal information categories
    File a complaint →

Provision details

Document information
Document
Equifax Privacy Policy
Entity
Equifax
Document last updated
May 5, 2026
Tracking information
First tracked
May 8, 2026
Last verified
May 11, 2026
Record ID
CA-P-010378
Document ID
CA-D-00591
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
a763bcb4921c4fbb345d76dfa0c84dc0451d890793ef3b8d244674596ec31df4
Analysis generated
May 8, 2026 15:21 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Equifax
Document: Equifax Privacy Policy
Record ID: CA-P-010378
Captured: 2026-05-08 15:21:58 UTC
SHA-256: a763bcb4921c4fbb…
URL: https://conductatlas.com/platform/equifax/equifax-privacy-policy/sensitive-personal-information-categories/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Professional Governance Intelligence

Need to monitor specific governance provisions?

Professional includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Professional free trial

Or start with Watcher →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Equifax's Sensitive Personal Information Categories clause do?

These are the most sensitive categories of personal data and their collection by any entity, particularly a data broker that has experienced significant data breaches historically, creates meaningful risk if data is misused or exposed.

How does this clause affect you?

Equifax holds some of the most sensitive categories of personal information about you, including government identifiers and financial credentials, and California residents have the right under CPRA to limit how this sensitive personal information is used, including for marketing and profiling purposes. You can exercise this right through the Equifax privacy rights portal.

Is ConductAtlas affiliated with Equifax?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Equifax.