Provision record
Ledger · Ledger Privacy Policy · View original document ↗

2020 Data Breach Disclosure

High severity Common · 288 of 352 platforms
Stay ahead of the changes
Track Ledger and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF
Document Record

What it is

Ledger discloses that in 2020 their e-commerce database was breached, exposing over one million customer email addresses and approximately 272,000 customers' full name, phone number, and postal address.

This analysis describes what Ledger's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

Data breach notification provisions create operational requirements for entities to communicate security incidents to affected parties, establishing a procedural framework for incident response and regulatory compliance. This mechanism serves to ensure timely informational delivery regarding unauthorized access or compromise of personal data.

Recent Activity

This document changed recently

High Apr 19, 2026

The updated policy removes explicit language stating that Ledger Recover and Ledger Multisig services are excluded from this privacy policy. Previously, users were directed to separate privacy policies for those services; that direction is now absent. This creates ambiguity about whether this policy now covers those services or whether separate policies still apply. The dramatic reduction in policy length (from 224 to 36 sentences) suggests substantial content was removed, though the specific implications depend on what other sections were condensed or eliminated. You should review the full updated policy to confirm what data practices and service exclusions remain in effect for all Ledger services you use.

View change record →
Medium Apr 2, 2026

Ledger removed language explicitly stating that this privacy policy does not cover Ledger Recover and Ledger Multisig services, and eliminated references to dedicated privacy policies for those services. This creates ambiguity about whether those services are now governed by the main privacy policy or whether separate policies exist but are no longer disclosed in this document. If you use Ledger Recover or Ledger Multisig, you should review the privacy disclosures for those specific services directly, as it is no longer clear from the main privacy policy whether separate protections apply.

View change record →

Clause Stability Stable

0
Changes
5
Months Monitored
Apr 3, 2026
First Seen
Apr 10, 2026
Last Seen
This clause type exists across 4430 other provisions on other platforms.

Change history

removed Jul 23, 2026

Removal of specific reference to a historical data breach indicates either that the incident is no longer disclosed or that Ledger has removed historical breach documentation from the current privacy policy.

View full change record →

Consumer impact (what this means for users)

Customers who purchased Ledger products before July 2020 may have had their personal data exposed, and this information has been circulated online, posing ongoing identity and security risks.

How other platforms handle this

Tinder Medium

we may share data between our affiliates for the safety and security of our users and may take necessary actions if we believe you have violated these Terms, including banning you from our Services and/or our affiliates' services...

Skillshare Medium

Protect us, our business, our users, and others, for example to enforce our terms of service, prevent spam or other unwanted communications, and investigate or protect against fraud

Webull Medium

disclosure is required by a third-party to complete a transaction initiated by the user

See all platforms with this clause type →
ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

The breach triggers mandatory notification obligations under GDPR Article 33-34 and represents material compliance exposure; legal teams should assess whether remediation measures described in the policy meet regulatory adequacy standards.

Insight

Unlock the full institutional analysis

Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.

Applicable agencies

  • Federal Trade Commission (ftc)
    Oversees unfair or deceptive business practices and can investigate companies that mislead consumers about data collection, sharing, or use.
    Who can file: Anyone affected by the company's practices (US or international)
    What you need: Your account details, a timeline of relevant events, and a description of the specific issue
    What to expect: Complaints inform FTC enforcement priorities and investigations but do not result in individual resolution or compensation
    File a complaint →

Applicable regulations

Connecticut Data Privacy Act Amendments
US-CT
FTC Act Section 5
United States Federal
GDPR
European Union
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
Ledger Privacy Policy
Entity
Ledger
Document last updated
May 5, 2026
Tracking information
First tracked
March 20, 2026
Last verified
March 20, 2026
Record ID
CA-P-001463
Document ID
CA-D-00278
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
c75d6e4bcb2997d48e8c0bb89a1ca1dc4347f8de57f584825d2699f987d08a1b
Analysis generated
March 20, 2026 10:46 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Ledger
Document: Ledger Privacy Policy
Record ID: CA-P-001463
Captured: 2026-03-20 10:46:12 UTC
SHA-256: c75d6e4bcb2997d4…
URL: https://conductatlas.com/platform/ledger/ledger-privacy-policy/provision/CA-P-001463/2020-data-breach-disclosure/
Accessed: Sept. 8, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Related Analysis

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does Ledger's 2020 Data Breach Disclosure clause do?

Data breach notification provisions create operational requirements for entities to communicate security incidents to affected parties, establishing a procedural framework for incident response and regulatory compliance. This mechanism serves to ensure timely informational delivery regarding unauthorized access or compromise of personal data.

How does this clause affect you?

Customers who purchased Ledger products before July 2020 may have had their personal data exposed, and this information has been circulated online, posing ongoing identity and security risks.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 288 platforms. See the full comparison.

Is ConductAtlas affiliated with Ledger?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Ledger.