PayPal · PayPal User Agreement

Multi-Factor Authentication Compliance Attestation

High severity
Share 𝕏 Share in Share 🔒 PDF
Watch PayPal Get alerts when this provision or policy changes.
Watch — $9.99/mo

Why it matters (compliance & risk perspective)

By accepting this provision, business account holders are making a legal attestation of regulatory compliance — if your MFA implementation doesn't actually meet NY DFS Part 500 or FTC Safeguards Rule standards, you may be in breach of both this agreement and the underlying regulations.

Change history

added Apr 18, 2026

This new provision shifts compliance burden to users for specific security standards (NY DFS Part 500 and federal safeguarding regulations) and requires users to attest and provide proof of MFA compliance.

View full change record →

Consumer impact (what this means for users)

PayPal's User Agreement significantly affects your financial rights and access to funds — PayPal can place holds on your money for up to 180 days and limit or suspend your account at its discretion. You waive the right to participate in class action lawsuits and must resolve all disputes through individual binding arbitration, which is generally more costly and less accessible for small-dollar claims. You can opt out of the arbitration agreement by sending a written notice to PayPal's Legal Department at 2211 North First Street, San Jose, CA 95131 within 30 days of first accepting the User Agreement.

How other platforms handle this

Amazon Medium

Reporting. If you become aware of any violation of this Policy, you will immediately notify us and provide us with assistance, as requested, to stop or remedy the violation. To report any violation of this Policy, please contact us at https://aws.amazon.com/forms/report-abuse.

Square Medium

Except where prohibited by law, you may not, nor may you permit any third party, directly or indirectly to: export the Services, which may be subject to export restrictions imposed by US law, including US Export Administration Regulations (15 C.F.R. Chapter VII); engage in any activity that may be i...

Bumble Medium

be at least 18 years old or the age of majority to legally enter into a contract under the laws of your home country if that happens to be greater than 18; and be legally permitted to use the App by the laws of your home country. Please note that we monitor for underage use and we will terminate, su...

See all platforms with this clause type →

This clause could change without notice.

Get alerted when PayPal updates this policy — with plain-language summaries and severity ratings.

Watch PayPal Need compliance memos? Professional →
View original clause language
If you, or any other person associated with your account, use SAML SSO (Security Assertion Markup Language Single Sign-On) to allow access to your accounts with PayPal, you attest that you are compliant with applicable state and Federal Multi-Factor Authentication ("MFA") regulations (e.g., NY DFS Part 500 and 16 CFR Part 314: Standards For Safeguarding Customer Information).

Applicable regulations

CFAA
United States Federal
DMCA
United States Federal
DSA
European Union

Provision details

Document information
Document
PayPal User Agreement
Entity
PayPal
Document last updated
April 29, 2026
Tracking information
First tracked
March 6, 2026
Last verified
April 9, 2026
Record ID
CA-P-002260
Document ID
CA-D-00044
Evidence Provenance
Source URL
Wayback Machine
SHA-256
787aedff80f89f2d9da4fd79756bbd226f8a5338c9e19c15b2a2fa0d01f59a90
Verified
✓ Snapshot stored   ✓ Change verified
How to Cite
ConductAtlas Policy Archive
Entity: PayPal | Document: PayPal User Agreement | Record: CA-P-002260
Captured: 2026-03-06 20:26:28 UTC | SHA-256: 787aedff80f89f2d…
URL: https://conductatlas.com/platform/paypal/paypal-user-agreement/multi-factor-authentication-compliance-attestation/
Accessed: May 4, 2026
Classification
Severity
High
Categories

Other risks in this policy

Don't miss changes to this clause.

PayPal has updated this policy before. Get alerted on the next change.

Watch PayPal

Frequently Asked Questions

What does PayPal's Multi-Factor Authentication Compliance Attestation clause do?

By accepting this provision, business account holders are making a legal attestation of regulatory compliance — if your MFA implementation doesn't actually meet NY DFS Part 500 or FTC Safeguards Rule standards, you may be in breach of both this agreement and the underlying regulations.

Is ConductAtlas affiliated with PayPal?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by PayPal.