PayPal · PayPal Privacy Statement

Disclosure to Authorities and Law Enforcement

Medium severity
Share 𝕏 Share in Share

What it is

PayPal will share your personal and financial data with law enforcement, courts, and regulators when required by law, and also when PayPal itself judges it 'reasonably necessary' to prevent harm or investigate user agreement violations.

Consumer impact (what this means for users)

PayPal can share your full financial history, account details, and transaction records with law enforcement and regulators based on its own assessment that disclosure is 'reasonably necessary' — not only when a court order or subpoena requires it.

How other platforms handle this

Google Gemini Medium

For users who are under 18, Gemini Apps Activity is saved for 18 months by default and can only be changed to 3 months. Conversations with Gemini apps from users under 13 are not saved to their Google Account by default.

Salesforce Medium

We may share your Personal Data as follows: Service providers; Salesforce affiliates; event sponsors; partners; customers with whom you are affiliated and/or the applicable partner responsible for access to your services; contest and promotion sponsors; third-party networks and websites; Salesforce-...

Apple Medium

Apple may disclose information, including personal data, to companies who provide services on our behalf. Apple requires them to protect any personal data they receive from Apple and to use it only for the specific service they are providing. Apple may share personal data with Apple-affiliated compa...

See all platforms with this clause type →
Need full compliance memos? See Professional →

Why it matters (compliance & risk perspective)

PayPal reserves the right to disclose your financial data to authorities not only when legally compelled but also based on its own reasonable necessity judgment, which is a broad standard that goes beyond strict legal compulsion.

View original clause language
Authorities. We may disclose Personal Information with authorities if compelled by a subpoena, court order, or similar legal procedure, when necessary to comply with law, or where the disclosure of Personal Information is reasonably necessary to prevent physical harm or financial loss, report suspected illegal activity, or investigate violations of the relevant agreement, or as otherwise required by law. Such authorities include courts, governments, law enforcement, and regulators. We may also be required to provide other third parties information about your use of our Services, for example, to comply with card association rules, to investigate or enforce violations of our user agreement, or to prevent physical harm or illegal activity.

Institutional analysis (Compliance & legal intelligence)

REGULATORY FRAMEWORK: Electronic Communications Privacy Act (ECPA) 18 U.S.C. §2701 et seq. governs voluntary disclosures of stored communications to law enforcement; financial records are subject to Right to Financial Privacy Act (RFPA) 12 U.S.C. §3401. BSA/AML 31 U.S.C. §5311 requires SARs and CTRs. GDPR Art. 6(1)(c) provides lawful basis for legally required disclosures; voluntary disclosures to law enforcement require Art. 6(1)(f) legitimate interest assessment. FTC Act Section 5 applies to deceptive descriptions of the scope of voluntary disclosure practices.

🔒

Compliance intelligence locked

Regulatory citations, enforcement risk, and due diligence action items.

Watcher $9.99/mo Professional $149/mo

Watcher: regulatory citations. Professional: full compliance memo.

Applicable agencies

  • CFPB
    The CFPB enforces RFPA and financial privacy obligations relating to disclosure of consumer financial records to third parties including authorities.
    File a complaint →

Applicable regulations

BIPA
Illinois, USA
CCPA/CPRA
California, USA
COPPA
United States Federal
CAN-SPAM
United States Federal
DMA
European Union
FCRA
United States Federal
GDPR
European Union
GLBA
United States Federal
HIPAA
United States Federal
UK GDPR
United Kingdom

Provision details

Document information
Document
PayPal Privacy Statement
Entity
PayPal
Document last updated
March 24, 2026
Tracking information
First tracked
March 6, 2026
Last verified
April 10, 2026
Record ID
CA-P-002677
Document ID
CA-D-00045
Evidence Provenance
Source URL
Wayback Machine
SHA-256
a5efa287f0b43a6a87f7dfc939ccb3c8edfb0ea67f476b2afeddf66fffa27690
Verified
✓ Snapshot stored   ✓ Change verified
How to Cite
ConductAtlas Policy Archive
Entity: PayPal | Document: PayPal Privacy Statement | Record: CA-P-002677
Captured: 2026-03-06 20:34:43 UTC | SHA-256: a5efa287f0b43a6a…
URL: https://conductatlas.com/platform/paypal/paypal-privacy-statement/disclosure-to-authorities-and-law-enforcement/
Accessed: April 29, 2026
Classification
Severity
Medium
Categories

Other provisions in this document

Related Analysis