Provision record
PayPal · PayPal Privacy Statement · View original document ↗

EEA Third-Party Disclosure List with Quarterly Update and Deemed Consent

High severity Unique · 0 of 352 platforms
Stay ahead of the changes
Track PayPal and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF
Document Record

What it is

For EEA users, PayPal maintains a published list of third-party recipients of personal information, updated quarterly. Users who do not object within 30 days of a quarterly update are stated to have accepted the new disclosures, with account closure as the stated alternative to acceptance.

This analysis describes what PayPal's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes a deemed consent mechanism for third-party data disclosure changes in the EEA, under which silence within a 30-day window following a quarterly list update constitutes acceptance of new data sharing arrangements. The interaction between this deemed consent mechanism and GDPR's requirements for explicit consent for certain processing activities may require evaluation, particularly given that GDPR supervisory authorities have expressed skepticism toward implied consent mechanisms in digital service contexts.

If You Do Nothing

Failure to object within 30 days of a quarterly third-party list publication is stated by the terms to constitute acceptance of the updated data sharing arrangements for EEA users

Cross-platform context

See how other platforms handle EEA Third-Party Disclosure List with Quarterly Update and Deemed Consent and similar clauses.

Compare across platforms →
▸ View Original Clause Language DOCUMENT RECORD
"
By accepting this Privacy Statement and maintaining an account with PayPal, you expressly agree to the transfer of your Personal Information to those third parties for the purposes listed. PayPal may update the list of third parties referred to above on the first business day of every quarter (January, April, July and October). PayPal will only start transferring any Personal Information to any of the new entities or for the new purposes or Personal Information types indicated in each update after 30 days from the date when that list is made public through this Privacy Statement. You should review the list each quarter on the PayPal website on the dates stated above. If you do not object to the new Personal Information disclosure, within 30 days after the publication of the updated list of third parties, you are deemed to have accepted the changes to the list and to this Privacy Statement. If you do not agree with the changes, you may close your account and stop using our services.

Excerpt from PayPal's Privacy Statement

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1.

Insight

Unlock the full institutional analysis

Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.

Applicable agencies

  • State AG
    EEA supervisory authorities, including Luxembourg's CNPD as PayPal's lead authority, have enforcement jurisdiction over this provision under GDPR, though these are not US state agencies; State_AG is the closest available category for regional regulatory authority
    File a complaint →

Provision details

Document information
Document
PayPal Privacy Statement
Entity
PayPal
Document last updated
May 5, 2026
Tracking information
First tracked
Sept. 5, 2026
Last verified
Sept. 5, 2026
Record ID
CA-P-00045008
Document ID
CA-D-00045
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
fde8a24bf5ca4ca5b9a3d100953e755767b80806013c664f784af3e36652738a
Analysis generated
September 5, 2026 02:03 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: PayPal
Document: PayPal Privacy Statement
Record ID: CA-P-00045008
Captured: 2026-09-05 02:03:15 UTC
SHA-256: fde8a24bf5ca4ca5…
URL: https://conductatlas.com/platform/paypal/paypal-privacy-statement/eea-third-party-disclosure-list-with-quarterly-update-and-deemed-consent/
Accessed: Sept. 8, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does PayPal's EEA Third-Party Disclosure List with Quarterly Update and Deemed Consent clause do?

This provision establishes a deemed consent mechanism for third-party data disclosure changes in the EEA, under which silence within a 30-day window following a quarterly list update constitutes acceptance of new data sharing arrangements. The interaction between this deemed consent mechanism and GDPR's requirements for explicit consent for certain processing activities may require evaluation, particularly given that GDPR supervisory authorities …

Is ConductAtlas affiliated with PayPal?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by PayPal.