Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The agreement states that federal law requires Gusto, as a financial institution, to collect, verify, and monitor identity information for the Employer entity, each Administrator, and the designated signatory, including government-issued identification documents, taxpayer IDs, and business ownership documentation.
This analysis describes what Gusto's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes Gusto's Customer Identification Program obligations under the Bank Secrecy Act and FinCEN regulations, requiring collection of sensitive identity documentation from Employer entities and individual administrators. The data collected includes personally identifiable information for multiple individuals associated with the Employer Account.
Developers integrating with Gusto's platform are now bound by mandatory arbitration and class action waiver provisions, meaning they cannot join or file class actions against Gusto and must resolve disputes through individual, binding arbitration. The updated terms also grant Gusto the right to modify, update, or discontinue developer tools at its sole discretion without notice or liability, which could disrupt integrations and require developers to absorb costs of upgrading to new versions. Developers should review Section 19 of the updated terms carefully before creating or maintaining integrations with Gusto's platform, and consider whether the arbitration and modification provisions align with their business and legal risk tolerance.
View change record →This addition implements Anti-Money Laundering and Bank Secrecy Act compliance requirements, requiring extensive identity verification and ongoing monitoring of all administrators.
View full change record →The agreement requires Employers to provide full names, dates of birth, taxpayer IDs, business ownership documentation, and government-issued identification for the entity, administrators, and designated signatories as a condition of platform access. This information is collected and monitored in accordance with federal AML and anti-terrorism financing obligations.
How other platforms handle this
When creating or updating your Account or purchasing a Subscription, you must provide true, accurate and complete information, including contact details which allow us to contact you easily and quickly.
If you are approved for a product offered through Affirm by one of our Bank Partners, or through other partnerships with Bank Partners, your non-public personal information will be subject to the following privacy notices...
Checking Disclosure
Monitoring
Gusto has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"To help the government fight the funding of terrorism and money laundering activities, federal law requires financial institutions like Gusto to obtain, verify, record, and monitor information that identifies Employer's business entity, each Administrator authorized to access and/or manage the Employer Account, and Employer's designated responsible party... This information may include (but is not limited to) full name, address, date of birth, Employer taxpayer ID, telephone number, email address, business entity ownership documentation, and other information that will allow us to identify Employer, Employer's signatory, and/or Employer's Administrators ("Identification Information"). We may also require Employer to provide identifying documentation about Employer's business entity, Administrators and signatory, which may include passports, drivers licenses, or other government issued identification ("Identification Documents").Excerpt from Gusto's Terms of Service
1. REGULATORY LANDSCAPE: This provision directly implicates the Bank Secrecy Act, FinCEN's Customer Due Diligence rules, and the USA PATRIOT Act requirements for financial institutions to implement Customer Identification Programs. The collection of beneficial ownership information also engages FinCEN's Beneficial Ownership Rule. Data protection obligations for the collected identity documentation may engage state privacy laws including CCPA for California-based administrators. 2. GOVERNANCE EXPOSURE: Medium. The requirement to provide government-issued identification for all administrators, including third-party accountant administrators, creates a data governance obligation for the Employer to ensure that sensitive personal data of individual administrators is handled appropriately both by Gusto and within the Employer's own HR and onboarding processes. 3. JURISDICTION FLAGS: California-based administrators whose personal information is collected under this provision may have CCPA rights with respect to that data, depending on whether Gusto treats administrator individuals as 'consumers' under the CCPA framework. Employers with EU-based administrators should assess whether GDPR applies to the collection of identification documents from those individuals. 4. CONTRACT AND VENDOR IMPLICATIONS: Organizations should review Gusto's Privacy Notice and Employer Data Processing Addendum to confirm how Identification Information and Identification Documents are stored, retained, and shared. Vendor risk assessments should evaluate Gusto's data security certifications relevant to storage of government-issued identification documents. 5. COMPLIANCE CONSIDERATIONS: HR and legal teams should ensure that Administrator onboarding processes include informed consent from individuals whose government-issued identification is collected and shared with Gusto. Data mapping exercises should capture the flow of administrator PII to Gusto as a third-party processor. Retention and deletion procedures for this category of sensitive data should be confirmed with Gusto.
Regulatory citations, enforcement risk, and due diligence action items.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
This provision establishes Gusto's Customer Identification Program obligations under the Bank Secrecy Act and FinCEN regulations, requiring collection of sensitive identity documentation from Employer entities and individual administrators. The data collected includes personally identifiable information for multiple individuals associated with the Employer Account.
The agreement requires Employers to provide full names, dates of birth, taxpayer IDs, business ownership documentation, and government-issued identification for the entity, administrators, and designated signatories as a condition of platform access. This information is collected and monitored in accordance with federal AML and anti-terrorism financing obligations.
ConductAtlas has identified this type of provision across 278 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Gusto.