If you import your phone or email contacts into PayPal, you are certifying that those contacts have given you permission to share their data with PayPal — even though most contacts likely do not know this is happening.
This analysis describes what PayPal's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The clause creates an operational framework for contact data processing and establishes a contractual certification requirement. The user's certification of third-party permission authorization places responsibility on the user to ensure compliance with applicable data protection obligations before submitting contact information.
If you sync your contacts with PayPal, the policy places legal responsibility on you for obtaining those contacts' consent — but your contacts likely have no idea their name, phone number, and email are now in PayPal's systems.
How other platforms handle this
We may receive information, including the following, from third party sources and combine it with information we already directly collect from you. We will handle the information in accordance with this Privacy Policy. Game, social media, or other information, from those third parties or services yo...
We may share your personal information with our affiliates, meaning entities that control, are controlled by, or are under common control with Consensys. We also share information with service providers who assist in operating our services, subject to confidentiality obligations.
At Ledger, earning and maintaining our users' trust is a top priority. That's why we are deeply committed not only to protecting your privacy and securing your personal data, but also to being fully transparent about how we handle it.
Monitoring
PayPal has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Process information about your contacts. We may use Personal Information in order to make it easy for you to find and connect your contacts, improve payment accuracy and suggest connections with people you may know. By providing us with information about your contacts you certify that you have permission to provide that information to PayPal for the purposes described in this Privacy Statement.— Excerpt from PayPal's PayPal Privacy Statement
REGULATORY FRAMEWORK: CCPA/CPRA §1798.100 applies to personal information collected about third parties; collecting contact data about non-users without their knowledge may trigger notice-at-collection obligations for those individuals. GDPR Arts. 13–14 require notice to individuals whose data is collected, including from third-party sources; contact import without notice to the data subject raises compliance concerns. COPPA 16 C.F.R. Part 312 applies if contact lists include children's data. FTC Act Section 5 applies to practices that shift responsibility for third-party data collection to consumers without meaningful disclosure.
Full compliance analysis
Regulatory citations, enforcement risk, and due diligence action items.
Free: track 1 platform + weekly digest. Monitor: 25 platforms + same-day alerts. No credit card required.
ConductAtlas detected a major restructuring of Meta’s privacy policy that removed detailed consumer rights disclosures and relocated them to separate documents.
Your genetic data may be transferred to a new owner as a business asset. Here is what the Terms of Service actually say and what you can do right now.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
The clause creates an operational framework for contact data processing and establishes a contractual certification requirement. The user's certification of third-party permission authorization places responsibility on the user to ensure compliance with applicable data protection obligations before submitting contact information.
If you sync your contacts with PayPal, the policy places legal responsibility on you for obtaining those contacts' consent — but your contacts likely have no idea their name, phone number, and email are now in PayPal's systems.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by PayPal.