Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that privacy rights requests including deletion and access may be denied in part when the Personal Information is subject to federal financial laws that are exempt from U.S. state privacy law requirements, and directs personal account users to a separate Consumer Financial Privacy Notice.
This analysis describes what Mercury's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that GLBA-regulated data held for personal banking accounts may fall outside the scope of CCPA and similar state privacy law rights requests, which means users seeking deletion or access to federally regulated financial data may receive partial or denied responses.
Interpretive note: The precise boundary of GLBA exemption applicability to specific data categories held by Mercury depends on regulatory interpretation and may vary based on the nature of the financial product and applicable state law, creating potential for inconsistent application across user account types.
Under this provision, personal account holders who submit deletion or access requests may receive partial denials where the requested data is subject to federal financial regulation; the policy directs affected users to the Mercury Consumer Financial Privacy Notice for additional information.
Cross-platform context
See how other platforms handle Federal Financial Regulation Exemption from State Privacy Requests and similar clauses.
Compare across platforms →Monitoring
Mercury has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Please note that certain requests may be denied where permitted by law. For example, for personal accounts, some Personal Information we may process may be subject to federal laws that are exempt from U.S. state privacy laws. As a result, some requests may be denied in part based on the applicability of these exemptions. For more information on personal accounts, please refer to the Mercury Consumer Financial Privacy Notice to learn more about how we treat your Personal Information.Excerpt from Mercury's Privacy Policy
1) REGULATORY LANDSCAPE: This provision engages the Gramm-Leach-Bliley Act (GLBA), which governs the privacy of nonpublic personal information held by financial institutions, and CCPA's GLBA exemption, which excludes GLBA-covered data from CCPA deletion and access rights. Similar exemptions exist in other U.S. state comprehensive privacy laws. The CFPB has authority over GLBA compliance for non-bank financial institutions. State attorneys general may have concurrent jurisdiction over state privacy law rights not preempted by federal law. 2) GOVERNANCE EXPOSURE: Medium. The application of the GLBA exemption to specific categories of user data requires precise data mapping to determine which Personal Information in a given account is GLBA-covered and which is subject to state privacy law. Incorrect application of the exemption to deny requests for non-GLBA-covered data could create regulatory exposure under CCPA and similar state laws. 3) JURISDICTION FLAGS: California creates the primary exposure point, as the CCPA's GLBA exemption scope has been subject to regulatory interpretation. Users in states with comprehensive privacy laws including Colorado, Connecticut, and Virginia face similar exemption structures but with potentially different scope. The policy's reference to a separate Mercury Consumer Financial Privacy Notice suggests the GLBA framework is operationally implemented for personal banking products. 4) CONTRACT AND VENDOR IMPLICATIONS: The policy places responsibility on business customers to ensure lawful basis for providing Personal Information to Mercury for processing on their behalf. B2B contracts should clearly delineate which data categories are subject to GLBA and which are governed by Mercury's business customer agreements, to support accurate response to privacy rights requests from business account users. 5) COMPLIANCE CONSIDERATIONS: Legal and compliance teams should maintain a data inventory that maps Personal Information categories to applicable legal frameworks (GLBA, state privacy law, or both) to support accurate and legally defensible responses to privacy rights requests. The Mercury Consumer Financial Privacy Notice should be reviewed alongside this policy to assess the completeness of disclosure for personal banking customers. Request response workflows should include a step to evaluate GLBA exemption applicability before issuing a denial.
This provision establishes that GLBA-regulated data held for personal banking accounts may fall outside the scope of CCPA and similar state privacy law rights requests, which means users seeking deletion or access to federally regulated financial data may receive partial or denied responses.
Under this provision, personal account holders who submit deletion or access requests may receive partial denials where the requested data is subject to federal financial regulation; the policy directs affected users to the Mercury Consumer Financial Privacy Notice for additional information.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Mercury.