10 Total
4 High severity
6 Medium severity
0 Low severity
Summary

This document establishes OnlyFans' practices for collecting, processing, and sharing personal information from both content creators and users. The policy authorizes collection of government-issued identification documents, facial imagery for age and identity verification, payment and banking details, and all user communications and platform activity. For creators, the policy permits collection of residential address, tax identification numbers, bank account information, and government ID, with transmission of specified data to third-party verification and payment processors.

Technical / Legal Breakdown

This privacy policy, published by Fenix International Limited (operator of OnlyFans), governs the processing of personal data for Creators, Fans, and Content Collaborators under a data controller framework, citing contract performance, legal obligation, legitimate interests, and consent as lawful bases under GDPR. The policy states that OnlyFans collects an extensive range of data categories including government identity documents, selfie-based age verification (including biometric-adjacent face estimation data for some users), financial data (bank account details, tax forms including W-9 and 1099 forms), technical and usage data, and communications content such as chat messages; the terms also authorize sharing this data with third-party service providers, payment processors, identity verification vendors, advertising partners, and law enforcement. Notably, the policy explicitly carves out 'Face Recognition Data' as a distinct category separate from general onboarding data, suggesting awareness of biometric data regulation, and it discloses age estimation processing for Fans via third-party providers, a practice that may engage biometric or sensitive data obligations depending on jurisdiction; the policy asserts that aggregated or de-identified data falls outside its scope, which is an assertion that may require evaluation under regulations such as CCPA where re-identification risk standards apply. The policy engages GDPR (as Fenix International Limited is a UK-registered entity), UK GDPR post-Brexit, CCPA and other U.S. state privacy laws (addressed in a dedicated Section 18), and potentially Illinois BIPA and similar state biometric laws given the face estimation and identity verification processes described; compliance considerations include the adequacy of consent mechanisms for biometric-adjacent data, the lawfulness of international data transfers, and the sufficiency of data subject rights mechanisms for users across multiple jurisdictions.

Institutional Analysis

Institutional analysis available with Compliance

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Compliance.

Start Compliance free trial
High — 4 provisions
Medium — 6 provisions

Monitoring

OnlyFans has updated this document before.

Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →

Compliance Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Compliance includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Compliance free trial

Cross-platform context

See how other platforms handle Behavioral and Usage Data Collection and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
COPPA
United States Federal
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured May 5, 2026 06:42 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000724
Version ID CA-V-001353
SHA-256 9ceccbe0e248e2cb72629bd6efc3f879a65d624e823bb629dd8808b5267c11fc
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans