Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
Intuit may retain personal information after a user submits a deletion request or after the contractual relationship ends, for purposes including legal or regulatory compliance, defending legal claims, and fraud prevention, with retention periods varying by information type.
This analysis describes what Intuit's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that deletion requests do not result in immediate or complete deletion of all personal information, as legal, regulatory, and fraud-related retention obligations may continue to apply. Legal teams should assess whether stated retention bases satisfy GDPR Article 17 exemptions and CCPA deletion rights provisions, and whether the broad fraud prevention exception is adequately scoped.
The updated terms establish new procedures for handling personal data complaints related to international data transfers under the EU-U.S., UK Extension, and Swiss-U.S. Data Privacy Frameworks. Users from these jurisdictions now have access to defined complaint and dispute resolution mechanisms, including referral to TRUSTe as an alternative dispute provider at no cost, and binding arbitration under certain conditions. Additionally, the policy now requires that before personal data is used for a materially new purpose or shared with external parties not covered as processors, Mailchimp will offer users the opportunity to opt out through appropriate means or collect opt-in consent.
View change record →The updated privacy statement removes detailed disclosures about how Intuit uses cookies, pixels, and tracking technologies to deliver targeted advertising. Previously, the policy explicitly stated that Intuit and advertising partners may disclose information like IP addresses and device identifiers to show more relevant ads, and that users could opt-out through 'Customize Settings'. The revised statement now references only a separate Cookies Policy without reproducing this information inline. Users seeking specifics on cookie consent options and advertising data sharing must consult the linked Cookies Policy document.
View change record →The updated privacy policy removes prior explicit disclosures about third-party advertising cookies and opt-out mechanisms that were previously available to users. Specifically, the policy no longer states that users can decline third-party advertising cookies through a 'Customize Settings' option, nor does it describe how advertising partners may receive limited personal information like IP addresses and device identifiers for ad targeting. The footer now contains only a general reference to cookie management without the prior transparency on advertising partner data sharing. You can review Intuit's full Cookies Policy for current information on how cookies and advertising technologies are used.
View change record →Under this provision, the agreement states that personal information including transaction records may be retained after a deletion request is submitted, where Intuit determines retention is necessary for legal compliance, claim defense, or fraud prevention purposes. The document does not specify maximum retention periods for each category.
Cross-platform context
See how other platforms handle Data Retention After Deletion Request and similar clauses.
Compare across platforms →Monitoring
Intuit has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"Even if you submit a deletion request or if our contractual relationship has ended, we may be required to maintain your personal information for as long as necessary to: comply with our legal or regulatory compliance needs (e.g., maintaining records of transactions you have made with us); to exercise, establish or defend legal claims; and/or to protect against fraudulent or abusive activity on our service. This means we may keep different information for different periods.Excerpt from Intuit's Privacy Statement
(1) REGULATORY LANDSCAPE: This provision engages GDPR Article 17, which establishes the right to erasure subject to specific exemptions including legal obligations and legal claim defense, and CCPA, which similarly provides exemptions from deletion for legal compliance and security purposes. The document's reliance on a broad fraud prevention exception may require evaluation under GDPR's proportionality principle. Relevant enforcement authorities include EU supervisory authorities, the UK ICO, the FTC, and State AGs. (2) GOVERNANCE EXPOSURE: Medium. The breadth of the fraud prevention and legal claim defense exceptions, without specified maximum retention periods, creates potential exposure under GDPR's storage limitation principle (Article 5(1)(e)) and analogous state law requirements. The document acknowledges that full deletion, anonymization, or de-identification may not be technically possible in some cases, with a commitment to secure isolation as an alternative. (3) JURISDICTION FLAGS: EU and UK users have the strongest rights regarding post-deletion retention, as GDPR Article 17 exemptions are interpreted narrowly by supervisory authorities. California residents have CCPA deletion rights subject to specific statutory exceptions. The document does not specify jurisdiction-differentiated retention schedules, which may create compliance gaps for users in jurisdictions with strict storage limitation requirements. (4) CONTRACT AND VENDOR IMPLICATIONS: Service providers and processors receiving personal information from Intuit should be contractually required to apply equivalent retention limitations and to honor deletion instructions consistent with Intuit's stated retention policy. B2B customers should confirm that employee or customer data retained by Intuit post-deletion is subject to equivalent security and access controls. (5) COMPLIANCE CONSIDERATIONS: Compliance teams should develop and document data retention schedules that specify maximum retention periods for each data category and legal basis for each retention exception. For EU and UK users, retention based on legitimate interests or legal claim defense should be documented with specificity rather than relying on broadly stated exceptions. Technical deletion verification procedures should be established to confirm data is deleted or isolated as stated when deletion requests are processed.
This provision establishes that deletion requests do not result in immediate or complete deletion of all personal information, as legal, regulatory, and fraud-related retention obligations may continue to apply. Legal teams should assess whether stated retention bases satisfy GDPR Article 17 exemptions and CCPA deletion rights provisions, and whether the broad fraud prevention exception is adequately scoped.
Under this provision, the agreement states that personal information including transaction records may be retained after a deletion request is submitted, where Intuit determines retention is necessary for legal compliance, claim defense, or fraud prevention purposes. The document does not specify maximum retention periods for each category.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Intuit.