Gusto shares your personal data including payroll and financial information with external companies that help deliver its services, as well as business partners who may offer additional products.
This analysis describes what Gusto's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
Your most sensitive data, including payroll figures and bank account details, flows to multiple third parties, expanding the number of entities that hold and could potentially expose your information.
Interpretive note: The distinction between service provider sharing and business partner sharing for promotional purposes has different legal implications under CPRA; the policy does not clearly delineate the boundaries between these categories for all data flows.
The updated policy explicitly discloses that Gusto sells or shares personal information (defined under state privacy laws) with third parties including business, advertising, and technology partners. The company describes 'sale' as providing information in exchange for valuable consideration, and 'share' as providing information for cross-context behavioral advertising. This disclosure formalizes practices that may have been permitted under previous language but were not explicitly described. You can opt out of sales or sharing of personal information through the Cookies, Analytics, and Other Tracking Technologies section.
View change record →The updated Privacy Policy now explicitly states it covers retirement account management (401k, SEP IRA, IRA accounts) and adds Stripe alongside Plaid as a third-party service provider that collects financial institution data. The policy restructures how it describes Gusto's role in different contexts: when Gusto acts as a service provider processing payroll or other data on behalf of employers, when it acts as an employer itself, or when it operates as a co-employer under a professional organization (PEO) arrangement, with separate privacy notices applying in each case. The policy introduces a new commitment that de-identified data will not be re-identified except to verify compliance with applicable law. If you connect a bank account through Stripe, that data will be treated under Stripe's Privacy Policy, which you should review separately.
View change record →Severity downgraded from high to medium; previous version had empty excerpt while current version specifies categories of third parties (vendors, service providers, business partners, financial institutions) and their purposes.
View full change record →Your payroll, tax, and financial account data is shared with third-party financial service providers and business partners by design, meaning data security risks are not limited to Gusto itself but extend across its vendor and partner network.
How other platforms handle this
We share Personal Data with vendors, service providers, and agents who work on our behalf and provide us with services related to the purposes described in this Privacy Policy or our Terms of Service.
We will disclose personal information to companies that help us run our business to detect, prevent, or otherwise address fraud, deception, illegal activity, misuse of Adobe Services and Software, and security or technical issues.
We also require these service providers to protect your personal information to at least the same standards that we do.
"We may share your personal information with third-party vendors and service providers that perform services on our behalf, such as payment processing, data analysis, email delivery, hosting services, customer service, and marketing assistance. We may share your information with our business partners to offer you certain products, services, or promotions. We disclose personal information to third-party financial service providers to facilitate payroll, tax, and other financial services.Excerpt from Gusto's Privacy Policy
1) REGULATORY LANDSCAPE: Third-party data sharing with financial service providers engages GLBA and its Safeguards Rule, which requires financial institutions to oversee service provider data security.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
ConductAtlas detected a major restructuring of Meta’s privacy policy that removed detailed consumer rights disclosures and relocated them to separate documents.
Your genetic data may be transferred to a new owner as a business asset. Here is what the Terms of Service actually say and what you can do right now.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
Your most sensitive data, including payroll figures and bank account details, flows to multiple third parties, expanding the number of entities that hold and could potentially expose your information.
Your payroll, tax, and financial account data is shared with third-party financial service providers and business partners by design, meaning data security risks are not limited to Gusto itself but extend across its vendor and partner network.
ConductAtlas has identified this type of provision across 288 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Gusto.