Intuit may retain personal information after a user submits a deletion request or after the contractual relationship ends, for purposes including legal or regulatory compliance, defending legal claims, and fraud prevention, with retention periods varying by information type.
This analysis describes what Intuit's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that deletion requests do not result in immediate or complete deletion of all personal information, as legal, regulatory, and fraud-related retention obligations may continue to apply. Legal teams should assess whether stated retention bases satisfy GDPR Article 17 exemptions and CCPA deletion rights provisions, and whether the broad fraud prevention exception is adequately scoped.
The updated terms establish new procedures for handling personal data complaints related to international data transfers under the EU-U.S., UK Extension, and Swiss-U.S. Data Privacy Frameworks. Users from these jurisdictions now have access to defined complaint and dispute resolution mechanisms, including referral to TRUSTe as an alternative dispute provider at no cost, and binding arbitration under certain conditions. Additionally, the policy now requires that before personal data is used for a materially new purpose or shared with external parties not covered as processors, Mailchimp will offer users the opportunity to opt out through appropriate means or collect opt-in consent.
View change record →Under this provision, the agreement states that personal information including transaction records may be retained after a deletion request is submitted, where Intuit determines retention is necessary for legal compliance, claim defense, or fraud prevention purposes. The document does not specify maximum retention periods for each category.
Cross-platform context
See how other platforms handle Data Retention After Deletion Request and similar clauses.
Compare across platforms →"Even if you submit a deletion request or if our contractual relationship has ended, we may be required to maintain your personal information for as long as necessary to: comply with our legal or regulatory compliance needs (e.g., maintaining records of transactions you have made with us); to exercise, establish or defend legal claims; and/or to protect against fraudulent or abusive activity on our service. This means we may keep different information for different periods.Excerpt from Intuit's Privacy Statement
(1) REGULATORY LANDSCAPE: This provision engages GDPR Article 17, which establishes the right to erasure subject to specific exemptions including legal obligations and legal claim defense, and CCPA, which similarly provides exemptions from deletion for …
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes that deletion requests do not result in immediate or complete deletion of all personal information, as legal, regulatory, and fraud-related retention obligations may continue to apply. Legal teams should assess whether stated retention bases satisfy GDPR Article 17 exemptions and CCPA deletion rights provisions, and whether the broad fraud prevention exception is adequately scoped.
Under this provision, the agreement states that personal information including transaction records may be retained after a deletion request is submitted, where Intuit determines retention is necessary for legal compliance, claim defense, or fraud prevention purposes. The document does not specify maximum retention periods for each category.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Intuit.