Provision record
Plaid · Plaid End User Privacy Policy [SPA-QUARANTINE: needs human capture] · View original document ↗

Data Deletion Exceptions Upon Developer Disconnection

Medium severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Plaid changes these terms. Follow Plaid →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Plaid Monitor emails you the same day this changes. The archive stays free.
Follow Plaid →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy states that Plaid's systems are designed to automatically delete personal data when a developer disconnects a user's app connection, but identifies six enumerated exceptions under which data may be retained, including active connections with other developers, fraud prevention purposes, legal retention requirements, and aggregated or de-identified data.

This analysis describes what Plaid's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes the conditions under which automatic data deletion applies and the circumstances under which retention continues despite developer disconnection; the breadth of exception (d), which permits retention for fraud prevention, provide support, or investigate misuse, may interact with GDPR data minimization and storage limitation principles and CCPA deletion rights, and compliance teams should evaluate whether these exceptions are proportionate and documented.

Interpretive note: Exception (d) permitting retention for fraud prevention, support, and investigation of misuse is broadly stated and its application in specific cases may depend on Plaid's internal determinations; the scope of this exception relative to GDPR Article 17 erasure rights and CCPA deletion rights may vary by jurisdiction and regulatory interpretation.

Recent Activity

This document changed recently

High Apr 21, 2026

End consumers may see their financial data accessed by a broader range of people under developer accounts, but Plaid now requires developers to formally designate and manage these 'Authorized Users' and take responsibility for their conduct. The introduction of session replay and activity monitoring means developer interactions with your financial data may be recorded for audit or security purposes. The policy does not specify what data is covered by monitoring or how long recordings are retained, which creates operational uncertainty for developers handling sensitive consumer financial information.

View change record →
Medium Apr 19, 2026

Plaid's updated terms establish a new direct relationship with you through the Plaid Account and introduce a monitoring service that operates through a web app. The terms now authorize Plaid to share financial information needed for third-party apps to initiate payments to or from you, which is a broader statement of data-sharing scope than the previous language. This means Plaid's role shifts from primarily facilitating connections to third-party apps toward directly providing account services, including monitoring. The effective date is April 14, 2026, though the change was detected on April 19, 2026. Review your Plaid Account settings to understand what data Plaid holds and how the monitoring service works.

View change record →
Medium Apr 3, 2026

The updated terms clarify that Plaid may request and collect phone numbers, email addresses, and other contact information when you connect financial accounts or verify your identity through a Plaid-connected application. The terms no longer describe a separate Plaid Monitoring Service or Plaid Web-App. The Plaid Account is now framed primarily as a tool to accelerate onboarding and use of third-party applications rather than as a standalone service for monitoring and alerts. The updated language authorizes Plaid to store identity verification data within your Plaid Account if you choose to do so.

View change record →

Clause Stability Stable

0
Changes
3
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Consumer impact (what this means for users)

Under these terms, disconnecting an app from Plaid does not automatically result in full deletion of personal data if any of the six listed exceptions apply, including if the user has any other active Plaid connection or if Plaid determines retention is needed for fraud prevention or support purposes. Data that has been aggregated or de-identified is explicitly excluded from deletion obligations under this clause.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Log in to Plaid Portal at my.plaid.com, navigate to your connected accounts dashboard, use the controls to terminate all app connections, and then submit a separate data deletion request through Plaid's online form or by emailing privacy@plaid.com.

Cross-platform context

See how other platforms handle Data Deletion Exceptions Upon Developer Disconnection and similar clauses.

Compare across platforms →

Monitoring

Plaid has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Follow Plaid → Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
If a developer removes your connection from their app to your data, Plaid's systems are designed to automatically delete your personal data, subject to certain exceptions where we may still retain your information. The exceptions to this may be if: (a) you've established a connection with another developer's app through Plaid that is still active; (b) Plaid needs your data to continue providing you with a Plaid product or service you requested; (c) Plaid is required by law to keep your data; (d) Plaid needs your data to help protect against or prevent fraud or protect privacy, provide support, or investigate misuse and misconduct; (e) Plaid has aggregated, de-identified, or anonymized your data such that it cannot be reasonably reidentified; or (f) we request - and you specifically agree - to allow us to retain your data longer.

Excerpt from Plaid's End User Privacy Policy [SPA-QUARANTINE: needs human capture]

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: This provision engages GDPR Articles 5(1)(e) (storage limitation), 17 (right to erasure), and 18 (right to restriction of processing) for EEA and UK users, as the enumerated exceptions to deletion must each correspond to a recognized GDPR ground for continued processing. The CCPA grants California consumers the right to request deletion of personal information, subject to enumerated exceptions; the overlap between Plaid's stated exceptions and CCPA's statutory exceptions should be documented and auditable. The CFPB's open banking rulemaking under Section 1033 may also address data retention practices of financial data aggregators. 2. GOVERNANCE EXPOSURE: Medium. The six enumerated exceptions are individually identifiable and correspond to recognized legal bases, but exception (d) (fraud prevention, support, and investigation of misuse) is broad and may be applied to retain data beyond what is strictly necessary for the stated purpose. Exception (e), covering aggregated or de-identified data, is consistent with standard industry practice but may require evaluation against GDPR's standard for anonymization that cannot be reasonably reidentified. 3. JURISDICTION FLAGS: EEA and UK users have the most explicit statutory rights under GDPR Article 17 to erasure, and any retention under exceptions must be documented with a specific lawful basis. California users have CCPA deletion rights, and the interaction between Plaid's exception (d) and CCPA's fraud prevention exception should be mapped. Illinois and Texas users with biometric data subject to BIPA or CUBI should note that those statutes' destruction requirements may impose obligations independent of this policy's deletion framework. 4. CONTRACT AND VENDOR IMPLICATIONS: Organizations deploying Plaid should confirm in their developer agreements with Plaid what data retention practices apply after they disconnect users, and whether they can independently trigger deletion on behalf of their users. The statement that Plaid's systems are designed to automatically delete does not create an absolute guarantee of deletion, and vendor contracts should specify obligations and timelines. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should map each of the six deletion exceptions against applicable statutory deletion rights in each jurisdiction where users are located, and document the legal basis for each exception. Data retention schedules and audit logs should be maintained to demonstrate compliance with storage limitation obligations. Where exception (e) is applied, organizations should assess whether the de-identification standard meets GDPR's anonymization threshold.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Applicable agencies

  • FTC
    The FTC has authority over unfair or deceptive data retention practices and may review whether Plaid's deletion exceptions are consistent with representations made to consumers about data control.
    File a complaint →
  • CFPB
    The CFPB's open banking rulemaking under Dodd-Frank Section 1033 addresses data retention and deletion practices of financial data aggregators, making this provision relevant to CFPB oversight.
    File a complaint →

Provision details

Document information
Document
Plaid End User Privacy Policy [SPA-QUARANTINE: needs human capture]
Entity
Plaid
Document last updated
May 5, 2026
Tracking information
First tracked
May 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-014835
Document ID
CA-D-00169
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
0a8d827572962cc5012319c796e08d8fb49190be40484061ff10c08cf6718f4b
Analysis generated
May 9, 2026 15:51 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Plaid
Document: Plaid End User Privacy Policy [SPA-QUARANTINE: needs human capture]
Record ID: CA-P-014835
Captured: 2026-05-09 15:51:01 UTC
SHA-256: 0a8d827572962cc5…
URL: https://conductatlas.com/platform/plaid/plaid-end-user-privacy-policy-spa-quarantine-needs-human-capture/provision/CA-P-014835/data-deletion-exceptions-upon-developer-disconnection/
Accessed: July 26, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention

Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.

Frequently Asked Questions

What does Plaid's Data Deletion Exceptions Upon Developer Disconnection clause do?

This provision establishes the conditions under which automatic data deletion applies and the circumstances under which retention continues despite developer disconnection; the breadth of exception (d), which permits retention for fraud prevention, provide support, or investigate misuse, may interact with GDPR data minimization and storage limitation principles and CCPA deletion rights, and compliance teams should evaluate whether these exceptions are …

How does this clause affect you?

Under these terms, disconnecting an app from Plaid does not automatically result in full deletion of personal data if any of the six listed exceptions apply, including if the user has any other active Plaid connection or if Plaid determines retention is needed for fraud prevention or support purposes. Data that has been aggregated or de-identified is explicitly excluded from …

Is ConductAtlas affiliated with Plaid?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Plaid.