Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
Intuit states it collects biometric personal information through certain parts of its platform, and the policy requires that notice be provided and consent obtained before collection, with detailed practices disclosed in a separate Biometric Notice.
This analysis describes what Intuit's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision discloses biometric information collection across parts of the Intuit Platform, subject to a notice-and-consent requirement and a separate Biometric Notice. Legal teams should assess compliance with Illinois BIPA, Texas CUBI, Washington's biometric law, and other state biometric statutes, which impose specific retention schedules, destruction requirements, and written release requirements beyond general consent.
Interpretive note: The Biometric Notice is referenced but not included in the document text provided, so the specific biometric data types, retention schedules, and destruction timelines cannot be assessed from this document alone.
The updated terms establish new procedures for handling personal data complaints related to international data transfers under the EU-U.S., UK Extension, and Swiss-U.S. Data Privacy Frameworks. Users from these jurisdictions now have access to defined complaint and dispute resolution mechanisms, including referral to TRUSTe as an alternative dispute provider at no cost, and binding arbitration under certain conditions. Additionally, the policy now requires that before personal data is used for a materially new purpose or shared with external parties not covered as processors, Mailchimp will offer users the opportunity to opt out through appropriate means or collect opt-in consent.
View change record →Under this provision, Intuit collects biometric information from users of certain platform features, conditioned on prior notice and consent. The specific types of biometric information collected, retention periods, and destruction schedules are disclosed in a separate Biometric Notice referenced but not reproduced in this document.
Cross-platform context
See how other platforms handle Biometric Information Collection and similar clauses.
Compare across platforms →Monitoring
Intuit has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Certain parts of the Intuit Platform make use of biometric personal information (" Biometric Information "). We will not collect your Biometric Information without first providing notice and obtaining your consent. For more details about how we use Biometric Information, please see our Biometric Notice.Excerpt from Intuit's Privacy Statement
(1) REGULATORY LANDSCAPE: This provision directly engages Illinois BIPA, which imposes strict requirements including written informed consent, public retention schedules, destruction timelines, and a private right of action with statutory damages. Texas CUBI, Washington's HB 1493, and emerging biometric statutes in other states impose analogous requirements. GDPR treats biometric data as a special category requiring explicit consent under Article 9. Relevant enforcement authorities include State AGs, private plaintiffs under BIPA, and EU supervisory authorities. (2) GOVERNANCE EXPOSURE: High. BIPA litigation risk for companies collecting biometric data on financial platforms is well-established, with statutory damages of $1,000 to $5,000 per violation available to private plaintiffs in Illinois. The reference to a separate Biometric Notice rather than full disclosure within this document means compliance assessment requires review of that supplemental document, which was not included in the text provided. (3) JURISDICTION FLAGS: Illinois users face the highest exposure given BIPA's private right of action. Texas, Washington, and New York users face state-specific biometric privacy obligations. EU and UK users are subject to GDPR Article 9 explicit consent requirements for biometric data as a special category. The document does not specify which Intuit platform features collect biometric information, creating uncertainty about the geographic and product scope of this provision. (4) CONTRACT AND VENDOR IMPLICATIONS: If biometric collection is performed or processed by third-party identity verification providers referenced elsewhere in this policy, data processing agreements with those providers should be reviewed for BIPA-compliant contractual terms including destruction schedules and prohibition on secondary use. B2B customers whose employees use Intuit products with biometric features should confirm whether employer consent obligations arise under applicable state law. (5) COMPLIANCE CONSIDERATIONS: Compliance teams should obtain and review the full Biometric Notice referenced in this provision to assess retention schedules, destruction timelines, and consent mechanism design against BIPA and analogous state requirements. If biometric collection occurs in Illinois, a publicly available written retention and destruction policy is required by statute. Consent mechanisms should be audited to confirm they satisfy written informed consent standards under BIPA rather than general privacy consent.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision discloses biometric information collection across parts of the Intuit Platform, subject to a notice-and-consent requirement and a separate Biometric Notice. Legal teams should assess compliance with Illinois BIPA, Texas CUBI, Washington's biometric law, and other state biometric statutes, which impose specific retention schedules, destruction requirements, and written release requirements beyond general consent.
Under this provision, Intuit collects biometric information from users of certain platform features, conditioned on prior notice and consent. The specific types of biometric information collected, retention periods, and destruction schedules are disclosed in a separate Biometric Notice referenced but not reproduced in this document.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Intuit.