PayPal · PayPal Privacy Statement

Business Profile Public Disclosure

Medium severity
Share 𝕏 Share in Share

What it is

If you have a PayPal business profile, certain financial and business data — including how many unique customers paid you in the past year — is automatically made visible to all other PayPal users by default.

Change history

removed Apr 18, 2026

Removal of specific business profile disclosure provision eliminates explicit transparency about what information is publicly displayed to other users, reducing clarity for business account holders.

View full change record →

Consumer impact (what this means for users)

PayPal business account holders have their customer volume and sales activity data automatically disclosed to all other PayPal users, which may reveal commercially sensitive information they did not intend to make public.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Log into your PayPal business account and navigate to your business profile settings to review and restrict which information is publicly displayed to other users, including transaction volume metrics.

How other platforms handle this

Dropbox Medium

Dropbox uses certain trusted third parties (for example, providers of customer support and IT services) for the business purposes of helping us provide, improve, protect, and promote our Services. These third parties will access your information to perform tasks on our behalf, and we'll remain respo...

Bank of America Medium

Under the Gramm-Leach-Bliley Act, we are permitted to share with third parties, without regard to the customer choices, in connection with situations where we are required to disclose information, such as responding to subpoenas or tax reporting, and for typical business activities, such as sharing ...

LinkedIn Medium

Our Services allow messaging and sharing of information in many ways, such as your profile, social actions you take, videos, and so on. Information and content that you share or post may be seen by other Members, Visitors or others (including off of our Services). Where we have made settings availab...

See all platforms with this clause type →
Need full compliance memos? See Professional →

Why it matters (compliance & risk perspective)

Business account holders may not realize that PayPal publicly discloses transaction volume metrics (unique paying customers per year) to all other users without explicit opt-in, which could reveal sensitive competitive business information.

View original clause language
Other Users if you have a business profile. If you have a business profile, we will display a payment link and disclose certain information about you to other Users, including your name or business name, profile picture or logo, and the city associated with your PayPal account, as well as total time selling with us, total number of followers, and total number of unique Users that have paid you in the past year. If you have a business profile, you can choose to display other information to other Users, such as your street address, phone number, email and website, in accordance with your business profile settings.

Institutional analysis (Compliance & legal intelligence)

REGULATORY FRAMEWORK: CCPA/CPRA applies to personal information of sole proprietors and small business owners who may be natural persons. GDPR applies to personal data of individual business operators in EU/EEA. FTC Act Section 5 applies to deceptive defaults that result in unintended public disclosure of business performance data. State unfair business practice statutes may apply where default disclosure of competitive metrics causes economic harm.

🔒

Compliance intelligence locked

Regulatory citations, enforcement risk, and due diligence action items.

Watcher $9.99/mo Professional $149/mo

Watcher: regulatory citations. Professional: full compliance memo.

Applicable agencies

  • FTC
    The FTC has authority over deceptive default settings that result in unintended public disclosure of personal or business data under FTC Act Section 5.
    File a complaint →

Applicable regulations

BIPA
Illinois, USA
CCPA/CPRA
California, USA
COPPA
United States Federal
CAN-SPAM
United States Federal
DMA
European Union
FCRA
United States Federal
GDPR
European Union
GLBA
United States Federal
HIPAA
United States Federal
UK GDPR
United Kingdom

Provision details

Document information
Document
PayPal Privacy Statement
Entity
PayPal
Document last updated
March 24, 2026
Tracking information
First tracked
March 6, 2026
Last verified
April 10, 2026
Record ID
CA-P-002678
Document ID
CA-D-00045
Evidence Provenance
Source URL
Wayback Machine
SHA-256
a5efa287f0b43a6a87f7dfc939ccb3c8edfb0ea67f476b2afeddf66fffa27690
Verified
✓ Snapshot stored   ✓ Change verified
How to Cite
ConductAtlas Policy Archive
Entity: PayPal | Document: PayPal Privacy Statement | Record: CA-P-002678
Captured: 2026-03-06 20:34:43 UTC | SHA-256: a5efa287f0b43a6a…
URL: https://conductatlas.com/platform/paypal/paypal-privacy-statement/business-profile-public-disclosure/
Accessed: April 29, 2026
Classification
Severity
Medium
Categories

Other provisions in this document

Related Analysis