Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
For EEA users, PayPal may update its list of third-party recipients quarterly, with a 30-day notice period before new transfers begin. Failure to object within 30 days of publication is deemed acceptance of the updated list; the only remedy for disagreement is account closure.
This analysis describes what PayPal's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes a deemed acceptance mechanism for EEA users whereby silence within 30 days of a quarterly third-party list update constitutes consent to new data disclosures. The adequacy of this mechanism under GDPR consent requirements, which generally require freely given, specific, informed, and unambiguous affirmative action, may require evaluation by legal teams.
⚠ Failure to object within 30 days of a quarterly third-party list update results in deemed acceptance of new data sharing arrangements as stated in the policy; the only stated remedy for disagreement is account closure
Cross-platform context
See how other platforms handle EEA Quarterly Third-Party List Update and Deemed Acceptance and similar clauses.
Compare across platforms →Monitoring
PayPal has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"PayPal may update the list of third parties referred to above on the first business day of every quarter (January, April, July and October). PayPal will only start transferring any Personal Information to any of the new entities or for the new purposes or Personal Information types indicated in each update after 30 days from the date when that list is made public through this Privacy Statement. You should review the list each quarter on the PayPal website on the dates stated above. If you do not object to the new Personal Information disclosure, within 30 days after the publication of the updated list of third parties, you are deemed to have accepted the changes to the list and to this Privacy Statement. If you do not agree with the changes, you may close your account and stop using our services.Excerpt from PayPal's Privacy Statement
(1) REGULATORY LANDSCAPE: This provision engages GDPR requirements for valid consent and the right to object to processing. GDPR Article 7 requires that consent be freely given, specific, informed, and indicated by an unambiguous affirmative act; deemed acceptance through silence may not satisfy this standard for processing activities that require consent as a lawful basis. However, the policy frames this mechanism in the context of Luxembourg banking secrecy obligations requiring higher transparency, and the transfer to listed third parties may be grounded in contractual necessity or legitimate interests rather than consent alone. (2) GOVERNANCE EXPOSURE: High for EEA operations. The deemed acceptance mechanism for changes to the third-party disclosure list may be scrutinized by the Luxembourg CNPD or other EEA supervisory authorities as inconsistent with GDPR consent standards. The policy's acknowledgment that Luxembourg laws require a higher degree of transparency than most EU laws suggests awareness of the heightened regulatory context. (3) JURISDICTION FLAGS: This provision applies specifically to EEA users processed under Luxembourg law. The lead supervisory authority is the Luxembourg National Commission for Data Protection (CNPD). EEA users have the right to lodge complaints with their local supervisory authority if they believe the deemed acceptance mechanism is inconsistent with GDPR. (4) CONTRACT AND VENDOR IMPLICATIONS: Institutional users and merchants in the EEA should monitor quarterly third-party list updates and establish processes to review and object within the 30-day window if new disclosures are material to their own compliance obligations. The policy's statement that third parties are limited by law or contract from using information for secondary purposes should be verified against actual data processing agreements. (5) COMPLIANCE CONSIDERATIONS: Legal teams advising EEA-based institutional PayPal users should establish a quarterly calendar review of the third-party list and document objection procedures. The adequacy of the deemed acceptance mechanism under GDPR should be assessed in light of current CNPD and EDPB guidance on consent and legitimate interests in financial services contexts.
This provision establishes a deemed acceptance mechanism for EEA users whereby silence within 30 days of a quarterly third-party list update constitutes consent to new data disclosures. The adequacy of this mechanism under GDPR consent requirements, which generally require freely given, specific, informed, and unambiguous affirmative action, may require evaluation by legal teams.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by PayPal.