Mercury · Mercury Privacy Policy · View original document ↗

Federal Financial Regulation Exemption from State Privacy Requests

Medium severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Mercury changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Mercury recorded 3 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for Mercury Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy states that privacy rights requests including deletion and access may be denied in part when the Personal Information is subject to federal financial laws that are exempt from U.S. state privacy law requirements, and directs personal account users to a separate Consumer Financial Privacy Notice.

This analysis describes what Mercury's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes that GLBA-regulated data held for personal banking accounts may fall outside the scope of CCPA and similar state privacy law rights requests, which means users seeking deletion or access to federally regulated financial data may receive partial or denied responses.

Interpretive note: The precise boundary of GLBA exemption applicability to specific data categories held by Mercury depends on regulatory interpretation and may vary based on the nature of the financial product and applicable state law, creating potential for inconsistent application across user account types.

Consumer impact (what this means for users)

Under this provision, personal account holders who submit deletion or access requests may receive partial denials where the requested data is subject to federal financial regulation; the policy directs affected users to the Mercury Consumer Financial Privacy Notice for additional information.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Submit a privacy request to [email protected] specifying the data you wish to access or delete. If your request is denied, you may appeal by emailing the same address with 'Privacy Request Appeal' in the subject line.

Cross-platform context

See how other platforms handle Federal Financial Regulation Exemption from State Privacy Requests and similar clauses.

Compare across platforms →

Monitoring

Mercury has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Please note that certain requests may be denied where permitted by law. For example, for personal accounts, some Personal Information we may process may be subject to federal laws that are exempt from U.S. state privacy laws. As a result, some requests may be denied in part based on the applicability of these exemptions. For more information on personal accounts, please refer to the Mercury Consumer Financial Privacy Notice to learn more about how we treat your Personal Information.

Excerpt from Mercury's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1) REGULATORY LANDSCAPE: This provision engages the Gramm-Leach-Bliley Act (GLBA), which governs the privacy of nonpublic personal information held by financial institutions, and CCPA's GLBA exemption, which excludes GLBA-covered data from CCPA deletion and access rights. Similar exemptions exist in other U.S. state comprehensive privacy laws. The CFPB has authority over GLBA compliance for non-bank financial institutions. State attorneys general may have concurrent jurisdiction over state privacy law rights not preempted by federal law. 2) GOVERNANCE EXPOSURE: Medium. The application of the GLBA exemption to specific categories of user data requires precise data mapping to determine which Personal Information in a given account is GLBA-covered and which is subject to state privacy law. Incorrect application of the exemption to deny requests for non-GLBA-covered data could create regulatory exposure under CCPA and similar state laws. 3) JURISDICTION FLAGS: California creates the primary exposure point, as the CCPA's GLBA exemption scope has been subject to regulatory interpretation. Users in states with comprehensive privacy laws including Colorado, Connecticut, and Virginia face similar exemption structures but with potentially different scope. The policy's reference to a separate Mercury Consumer Financial Privacy Notice suggests the GLBA framework is operationally implemented for personal banking products. 4) CONTRACT AND VENDOR IMPLICATIONS: The policy places responsibility on business customers to ensure lawful basis for providing Personal Information to Mercury for processing on their behalf. B2B contracts should clearly delineate which data categories are subject to GLBA and which are governed by Mercury's business customer agreements, to support accurate response to privacy rights requests from business account users. 5) COMPLIANCE CONSIDERATIONS: Legal and compliance teams should maintain a data inventory that maps Personal Information categories to applicable legal frameworks (GLBA, state privacy law, or both) to support accurate and legally defensible responses to privacy rights requests. The Mercury Consumer Financial Privacy Notice should be reviewed alongside this policy to assess the completeness of disclosure for personal banking customers. Request response workflows should include a step to evaluate GLBA exemption applicability before issuing a denial.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Professional · $99/mo Start with Monitor · $29/mo

Applicable agencies

  • CFPB
    The CFPB has authority over GLBA compliance for financial institutions and the handling of nonpublic personal financial information
    File a complaint →
  • State AG
    State attorneys general enforce CCPA and similar state privacy laws governing the scope of permissible exemptions to consumer privacy rights requests
    File a complaint →

Provision details

Document information
Document
Mercury Privacy Policy
Entity
Mercury
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-015754
Document ID
CA-D-00530
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
f8b49beb208e6c3f2b9fb8ddafa22b88d22bbef9e6d3e086c87840d1d5a282f8
Analysis generated
July 9, 2026 08:43 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Mercury
Document: Mercury Privacy Policy
Record ID: CA-P-015754
Captured: 2026-07-09 08:43:59 UTC
SHA-256: f8b49beb208e6c3f…
URL: https://conductatlas.com/platform/mercury/mercury-privacy-policy/provision/CA-P-015754/federal-financial-regulation-exemption-from-state-privacy-requests/
Accessed: July 24, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Professional · $99/mo Start with Monitor · $29/mo

Frequently Asked Questions

What does Mercury's Federal Financial Regulation Exemption from State Privacy Requests clause do?

This provision establishes that GLBA-regulated data held for personal banking accounts may fall outside the scope of CCPA and similar state privacy law rights requests, which means users seeking deletion or access to federally regulated financial data may receive partial or denied responses.

How does this clause affect you?

Under this provision, personal account holders who submit deletion or access requests may receive partial denials where the requested data is subject to federal financial regulation; the policy directs affected users to the Mercury Consumer Financial Privacy Notice for additional information.

Is ConductAtlas affiliated with Mercury?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Mercury.