8 Total
2 High severity
4 Medium severity
2 Low severity
Summary

Gusto's Privacy Notice establishes how the company collects, processes, and shares personal information including Social Security numbers, bank account details, salary information, and health benefits data on behalf of employers that use Gusto's payroll and HR platform. The document authorizes disclosure of this information to third-party service providers, financial institutions, and government agencies as part of standard service operations. The document establishes that California residents and other qualifying users may submit requests to access, correct, or delete their personal data through privacy.gusto.com.

Technical / Legal Breakdown

This document is Gusto's Privacy Notice governing the collection, use, and disclosure of personal information for individuals who interact with Gusto's HR, payroll, and benefits platform, operating under applicable U.S. federal and state privacy laws. The notice states that Gusto collects a broad range of personal data including Social Security numbers, bank account details, payroll and compensation information, health and benefits enrollment data, and government-issued identification, and the terms authorize sharing this data with third-party service providers, financial institutions, government agencies, and business partners for purposes including payroll processing, benefits administration, and product improvement. Notably, the policy covers both employer-customers ('Employers') and their employees ('Team Members'), creating a layered data relationship in which employees may have limited direct control over how their employer-submitted data is handled, and the document asserts broad use of de-identified and aggregated data for product and business analytics with no opt-out described for that use. The notice engages CCPA/CPRA for California residents (providing explicit rights to know, delete, correct, and opt out of sale or sharing), and the sensitive nature of payroll, financial, and health data implicates GLBA, HIPAA where applicable to benefits data, and FTC Act jurisdiction over data security and unfair practices; compliance obligations will vary materially by jurisdiction and the specific Gusto products a customer deploys. Employers using Gusto as a data processor for employee data should evaluate whether Gusto's data practices align with their own privacy program obligations, particularly regarding employee notice requirements and data retention.

Institutional Analysis

Institutional analysis available with Compliance

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Compliance.

Start Compliance free trial

17 important changes detected

20 versions captured · Last updated: June 2026

June 1, 2026

medium
What changed Gusto updated its Privacy Policy effective June 1, 2026, to clarify scope and expand disclosure of data collection practices. The policy now explicitly covers retirement accounts (401k and SEP IRA/IRA accounts), restructures how it describes data processing across different roles (service provider, employer, co-employer), adds Stripe as a third-party financial data collector alongside Plaid, and introduces a commitment to maintain de-identified data without re-identification. These changes establish clearer boundaries between when the Privacy Notice applies versus when separate notices govern, and specify new service providers users should be aware of.
Why this matters The updated Privacy Policy now explicitly states it covers retirement account management (401k, SEP IRA, IRA accounts) and adds Stripe alongside Plaid as a third-party service provider that collects financial institution data. The policy restructures how it describes Gusto's role in different contexts: when Gusto acts as a service provider processing payroll or other data on behalf of employers, when it acts as an employer itself, or when it operates as a co-employer under a professional organization (PEO) arrangement, with separate privacy notices applying in each case. The policy introduces a new commitment that de-identified data will not be re-identified except to verify compliance with applicable law. If you connect a bank account through Stripe, that data will be treated under Stripe's Privacy Policy, which you should review separately.
View full change record →

May 28, 2026

unknown
What changed Gusto updated their Gusto Privacy Policy on May 28, 2026. Change detected: 1 sentence(s) modified. Document contained 120 sentences after update.
View full change record →

May 21, 2026 low

Gusto updated its Privacy Policy on May 21, 2026 to change the email address listed for privacy inquiries and data requests from privacy@gusto.com to a masked email format displayed as …

View change record →
May 19, 2026 low

The diff provided shows Gusto's Privacy Notice with minimal substantive changes. One sentence was modified, though the visible change in the diff context appears to be a character encoding issue …

View change record →
May 19, 2026 low

Gusto's Privacy Notice was updated on May 19, 2026, with one sentence modified in the table of contents or related reference materials. The change appears to be a minor addition …

View change record →
May 14, 2026 low

Gusto's privacy policy was updated on May 14, 2026 to correct a grammatical error in the list of purposes for which personal information is used. The text 'our partners��� programs' …

View change record →
May 9, 2026 low

Gusto's privacy policy was updated on May 9, 2026 to add two new document references in its table of contents: 'Gusto Handbook & Policy Compliance Scanner Beta Terms' and 'Handbook …

View change record →
May 1, 2026 low

Gusto updated contact email addresses in its privacy policy and related terms. The company replaced several branded email addresses (legal-opt-outs@gusto.com and support@gusto.com) with a generic inbox address ([email protected]). This …

View change record →
May 1, 2026 medium

Gusto updated its Background Checks Terms of Service on May 1, 2026, elevating it from Version 6.0 to Version 7.0 and changing the effective date to April 29, 2026. The …

View change record →
April 30, 2026 low

Gusto added a new promotion offering 40 free licenses to Gumloop's AI-powered Firm Growth Agents tools to eligible Accountant Partners. The promotion runs from April 29, 2026 through June 29, …

View change record →
April 29, 2026 high

Gusto updated its Developer Terms of Service on April 29, 2026, introducing a new version (2.0) with substantially expanded terms governing access to its API and developer tools. The document …

View change record →
April 26, 2026 low

Gusto added a new service called Gusto Business Compliance (GBC) to its platform on April 26, 2026. The GBC Service helps employers with state and local tax registrations, filings, and …

View change record →
April 25, 2026 high

Gusto added 408 sentences of new language to its Employer Terms of Service on April 25, 2026, including expanded definitions of key terms like 'Employer' and 'Member', clarification of who …

View change record →
April 23, 2026 low

Gusto updated contact email addresses in its Privacy Policy on April 23, 2026. The policy now directs users to email legal-opt-outs@gusto.com for arbitration opt-outs and legal notices, and support@gusto.com for …

View change record →
April 22, 2026 low

Gusto updated contact email addresses throughout its Privacy Policy on April 22, 2026. The document replaced multiple instances of 'legal-opt-outs@gusto.com' and 'support@gusto.com' with a generic masked email address '[email protected]'. …

View change record →
April 19, 2026 low

Gusto updated contact email addresses in its privacy policy on April 19, 2026. Arbitration opt-out requests now go to legal-opt-outs@gusto.com instead of a previous address, and general inquiries now route …

View change record →
April 16, 2026 medium

Gusto updated its Data Processing Addendum on April 16, 2026, adding 60 sentences that clarify how the company handles employer data under data protection laws. The new language specifies the …

View change record →

Recent Provision Changes Jun 1, 2026

8 provisions unchanged.

View full change record →
High — 2 provisions
Medium — 4 provisions
Low — 2 provisions

Monitoring

Gusto has updated this document before.

Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →

Compliance Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Compliance includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Compliance free trial

Cross-platform context

See how other platforms handle Behavioral Advertising and Third-Party Tracking Technologies and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured June 1, 2026 00:44 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000294
Version ID CA-V-003235
SHA-256 edd0c960e1d6bddae41368383818976d27632c1cad38f2e0148846f863cbf94a
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans