Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that PayPal may collect biometric data including voice identification, photo identification, and face scans when users consent through the user experience, for account authentication purposes. Biometric data is retained for up to three years after account closure unless applicable law requires otherwise.
This analysis describes what PayPal's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that PayPal may collect and retain biometric identifiers and biometric information, and that the retention period extends up to 3 years after account closure. State biometric privacy laws including Illinois BIPA impose specific written consent, retention schedule, and destruction requirements that may not be fully addressed by a general policy-level consent disclosure.
Interpretive note: The adequacy of the consent mechanism described and the compatibility of the 3-year post-closure retention period with Illinois BIPA and equivalent state statutes depends on the specific implementation details of the in-experience consent flow, which are not fully described in this policy.
This clause establishes that biometric data such as face scans and voice identification will be collected upon consent for authentication purposes and retained for up to three years after account closure. Users in jurisdictions with state biometric privacy laws may have additional rights regarding consent, retention, and deletion of this data.
Cross-platform context
See how other platforms handle Biometric Data Collection and Retention and similar clauses.
Compare across platforms →Monitoring
PayPal has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Biometric data : Such as voice identification, photo identification, or face scans, which we may collect when you consent in the user experience to authenticate you for certain actions related to your account, including, for example, to verify your identity before you access accounts and Services, recover passwords, update profile information, manage payments and payment methods, lift account limitations, and initiate cryptocurrency transfers. We retain biometric data for as long as needed or permitted given the purpose for which it was collected and no more than 3 years after your account closes, unless otherwise required by applicable law.Excerpt from PayPal's Privacy Statement
(1) REGULATORY LANDSCAPE: This provision directly engages the Illinois Biometric Information Privacy Act (BIPA), which requires written consent, a publicly available retention policy, and prohibits sale of biometric data; Texas CUBI and Washington MYPD impose similar requirements. The policy's consent-based collection framework and three-year post-closure retention period may require evaluation against the specific procedural requirements of each applicable state statute. The FTC Act applies to deceptive or unfair biometric data practices at the federal level. (2) GOVERNANCE EXPOSURE: High. Biometric data represents a sensitive data category with heightened regulatory exposure across multiple U.S. states and under GDPR Article 9 as special category data in EU/EEA jurisdictions. The policy authorizes biometric collection for a list of account actions including cryptocurrency transfers and lifting account limitations, which may expand the practical scope of collection beyond initial authentication use cases. (3) JURISDICTION FLAGS: Illinois presents the highest litigation exposure given BIPA's private right of action and statutory damages structure. Texas and Washington impose regulatory enforcement mechanisms. EU/EEA users are covered by GDPR Article 9 requirements for explicit consent for biometric data as special category data. The policy states that EU/EEA processing relies on explicit and voluntary consent for biometric data provision. (4) CONTRACT AND VENDOR IMPLICATIONS: The policy discloses that biometric data may be shared with service providers for authentication processing. Vendor contracts governing biometric data processing should specify retention, deletion, and security requirements consistent with applicable state biometric privacy statutes and GDPR Article 28 processor obligations. (5) COMPLIANCE CONSIDERATIONS: Compliance teams should audit whether the in-experience consent mechanism for biometric data collection satisfies the written consent and specific notice requirements of applicable state biometric privacy statutes. Data mapping should track biometric data separately given its distinct retention period and heightened regulatory status. Deletion procedures upon account closure should be documented and tested against the three-year outer limit stated in the policy.
This provision establishes that PayPal may collect and retain biometric identifiers and biometric information, and that the retention period extends up to 3 years after account closure. State biometric privacy laws including Illinois BIPA impose specific written consent, retention schedule, and destruction requirements that may not be fully addressed by a general policy-level consent disclosure.
This clause establishes that biometric data such as face scans and voice identification will be collected upon consent for authentication purposes and retained for up to three years after account closure. Users in jurisdictions with state biometric privacy laws may have additional rights regarding consent, retention, and deletion of this data.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by PayPal.