Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that PayPal retains Personal Information for the duration of the user relationship plus ten years after the relationship ends, or longer if required or permitted by applicable law, including for litigation, investigations, audits, and AML compliance purposes.
This analysis describes what PayPal's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes a default ten-year post-relationship retention period for Personal Information, with open-ended extensions permitted for legal and compliance purposes. The extended retention period applies even after account closure and may interact with user deletion rights under GDPR and CCPA/CPRA.
⚠ Personal Information will be retained for ten years after the end of the user relationship as stated in the policy, subject to applicable legal exemptions, regardless of account closure
Cross-platform context
See how other platforms handle Ten-Year Post-Relationship Data Retention and similar clauses.
Compare across platforms →Monitoring
PayPal has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"Personal Information used for the ongoing relationship between you and PayPal is stored for the duration of the relationship plus a period of 10 years or such period as mandated by any applicable local law once our relationship comes to an end, unless we need to keep it longer to the extent permitted by applicable law, such as: When consistent with a legal obligation to which we are subject, or when permitted under applicable law, such as under applicable bankruptcy laws and AML obligations. In connection with litigation, investigations, audit and compliance practices, or to protect against legal claims.Excerpt from PayPal's Privacy Statement
(1) REGULATORY LANDSCAPE: This provision engages GDPR Article 5(1)(e) (storage limitation principle), which requires Personal Information to be kept no longer than necessary for the purposes for which it was collected. The policy grounds the ten-year period in AML obligations, bankruptcy law, and litigation protection, which are recognized bases for extended retention under GDPR recitals and applicable EU financial regulation. The CCPA/CPRA does not impose a specific maximum retention period but requires disclosure of retention periods or the criteria used to determine them, which this policy provides. U.S. AML record-keeping requirements under the Bank Secrecy Act may independently mandate multi-year retention of financial transaction records. (2) GOVERNANCE EXPOSURE: Medium. The ten-year default retention period is grounded in stated legal and regulatory obligations, which provides a defensible basis under GDPR and CCPA. However, the open-ended extension clause (as long as permitted by applicable law) may be evaluated by data protection authorities as insufficiently specific under the GDPR storage limitation principle. (3) JURISDICTION FLAGS: EU/EEA supervisory authorities may scrutinize whether the ten-year period is proportionate for all categories of Personal Information or whether it is calibrated to specific regulatory obligations. California residents retain the right to request deletion subject to the stated exemptions, and compliance teams should document which exemptions apply to which data categories. (4) CONTRACT AND VENDOR IMPLICATIONS: Service providers processing PayPal user data under contract should ensure their own retention schedules are consistent with PayPal's stated ten-year period and that deletion obligations upon contract termination are addressed in data processing agreements. (5) COMPLIANCE CONSIDERATIONS: Data mapping should associate each Personal Information category with the specific legal basis for the ten-year retention period, distinguishing between data retained for AML compliance, data retained for litigation purposes, and data retained for general business purposes. Privacy impact assessments should evaluate whether the ten-year period is proportionate for lower-sensitivity data categories such as preference and behavioral data.
This provision establishes a default ten-year post-relationship retention period for Personal Information, with open-ended extensions permitted for legal and compliance purposes. The extended retention period applies even after account closure and may interact with user deletion rights under GDPR and CCPA/CPRA.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by PayPal.