PayPal · PayPal Privacy Statement · View original document ↗

Biometric Data Collection and Retention

High severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time PayPal changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity PayPal recorded 4 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for PayPal Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy states that PayPal may collect biometric data including voice identification, photo identification, and face scans when users consent through the user experience, for account authentication purposes. Biometric data is retained for up to three years after account closure unless applicable law requires otherwise.

This analysis describes what PayPal's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes that PayPal may collect and retain biometric identifiers and biometric information, and that the retention period extends up to 3 years after account closure. State biometric privacy laws including Illinois BIPA impose specific written consent, retention schedule, and destruction requirements that may not be fully addressed by a general policy-level consent disclosure.

Interpretive note: The adequacy of the consent mechanism described and the compatibility of the 3-year post-closure retention period with Illinois BIPA and equivalent state statutes depends on the specific implementation details of the in-experience consent flow, which are not fully described in this policy.

Clause Stability Stable

0
Changes
4
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Consumer impact (what this means for users)

This clause establishes that biometric data such as face scans and voice identification will be collected upon consent for authentication purposes and retained for up to three years after account closure. Users in jurisdictions with state biometric privacy laws may have additional rights regarding consent, retention, and deletion of this data.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Log into your PayPal account, navigate to Data and Privacy settings, and submit a deletion request specifying biometric data. Alternatively, call PayPal Customer Service at 1-888-221-1161.

Cross-platform context

See how other platforms handle Biometric Data Collection and Retention and similar clauses.

Compare across platforms →

Monitoring

PayPal has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Biometric data : Such as voice identification, photo identification, or face scans, which we may collect when you consent in the user experience to authenticate you for certain actions related to your account, including, for example, to verify your identity before you access accounts and Services, recover passwords, update profile information, manage payments and payment methods, lift account limitations, and initiate cryptocurrency transfers. We retain biometric data for as long as needed or permitted given the purpose for which it was collected and no more than 3 years after your account closes, unless otherwise required by applicable law.

Excerpt from PayPal's Privacy Statement

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

(1) REGULATORY LANDSCAPE: This provision directly engages the Illinois Biometric Information Privacy Act (BIPA), which requires written consent, a publicly available retention policy, and prohibits sale of biometric data; Texas CUBI and Washington MYPD impose similar requirements. The policy's consent-based collection framework and three-year post-closure retention period may require evaluation against the specific procedural requirements of each applicable state statute. The FTC Act applies to deceptive or unfair biometric data practices at the federal level. (2) GOVERNANCE EXPOSURE: High. Biometric data represents a sensitive data category with heightened regulatory exposure across multiple U.S. states and under GDPR Article 9 as special category data in EU/EEA jurisdictions. The policy authorizes biometric collection for a list of account actions including cryptocurrency transfers and lifting account limitations, which may expand the practical scope of collection beyond initial authentication use cases. (3) JURISDICTION FLAGS: Illinois presents the highest litigation exposure given BIPA's private right of action and statutory damages structure. Texas and Washington impose regulatory enforcement mechanisms. EU/EEA users are covered by GDPR Article 9 requirements for explicit consent for biometric data as special category data. The policy states that EU/EEA processing relies on explicit and voluntary consent for biometric data provision. (4) CONTRACT AND VENDOR IMPLICATIONS: The policy discloses that biometric data may be shared with service providers for authentication processing. Vendor contracts governing biometric data processing should specify retention, deletion, and security requirements consistent with applicable state biometric privacy statutes and GDPR Article 28 processor obligations. (5) COMPLIANCE CONSIDERATIONS: Compliance teams should audit whether the in-experience consent mechanism for biometric data collection satisfies the written consent and specific notice requirements of applicable state biometric privacy statutes. Data mapping should track biometric data separately given its distinct retention period and heightened regulatory status. Deletion procedures upon account closure should be documented and tested against the three-year outer limit stated in the policy.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Professional · $99/mo Start with Monitor · $29/mo

Applicable agencies

  • FTC
    The FTC has authority over unfair or deceptive practices in biometric data collection and retention, and has issued guidance on biometric privacy in commercial contexts.
    File a complaint →
  • State AG
    State attorneys general in Illinois, Texas, Washington, and other states with biometric privacy statutes have enforcement authority over biometric data collection and retention practices.
    File a complaint →

Provision details

Document information
Document
PayPal Privacy Statement
Entity
PayPal
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 23, 2026
Record ID
CA-P-013848
Document ID
CA-D-00045
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
323a171a636780ae11796995ce3314342502ac7d4a05f085477133259b344eb1
Analysis generated
July 9, 2026 04:08 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: PayPal
Document: PayPal Privacy Statement
Record ID: CA-P-013848
Captured: 2026-07-09 04:08:48 UTC
SHA-256: 323a171a636780ae…
URL: https://conductatlas.com/platform/paypal/paypal-privacy-statement/provision/CA-P-013848/biometric-data-collection-and-retention/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Professional · $99/mo Start with Monitor · $29/mo

Frequently Asked Questions

What does PayPal's Biometric Data Collection and Retention clause do?

This provision establishes that PayPal may collect and retain biometric identifiers and biometric information, and that the retention period extends up to 3 years after account closure. State biometric privacy laws including Illinois BIPA impose specific written consent, retention schedule, and destruction requirements that may not be fully addressed by a general policy-level consent disclosure.

How does this clause affect you?

This clause establishes that biometric data such as face scans and voice identification will be collected upon consent for authentication purposes and retained for up to three years after account closure. Users in jurisdictions with state biometric privacy laws may have additional rights regarding consent, retention, and deletion of this data.

Is ConductAtlas affiliated with PayPal?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by PayPal.