Provision record
Plaid · Plaid End User Privacy Policy [SPA-QUARANTINE: needs human capture] · View original document ↗

Data Sharing with Developers and Third Parties

Medium severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Plaid changes these terms. Follow Plaid →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Plaid Monitor emails you the same day this changes. The archive stays free.
Follow Plaid →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy authorizes sharing user data with app developers and as directed by developers, financial institutions, service providers, partners, agents, contractors, professional advisors, fraud prevention services, identity verification services, cloud storage providers, Plaid affiliates, and governmental authorities when legally required. For US users, the policy states that sharing with non-affiliated third parties is limited to what is permitted under GLBA's Regulation P (12 C.F.R. §§ 1016.13, 1016.14, and 1016.15).

This analysis describes what Plaid's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision authorizes a broad range of data sharing recipients, including that developers may direct sharing of user data, which means the scope of third-party access to user financial data depends in part on the practices of individual app developers; compliance teams should assess whether developer-directed sharing is subject to adequate contractual controls and whether disclosures to users are sufficient to satisfy applicable law.

Recent Activity

This document changed recently

High Apr 21, 2026

End consumers may see their financial data accessed by a broader range of people under developer accounts, but Plaid now requires developers to formally designate and manage these 'Authorized Users' and take responsibility for their conduct. The introduction of session replay and activity monitoring means developer interactions with your financial data may be recorded for audit or security purposes. The policy does not specify what data is covered by monitoring or how long recordings are retained, which creates operational uncertainty for developers handling sensitive consumer financial information.

View change record →
Medium Apr 19, 2026

Plaid's updated terms establish a new direct relationship with you through the Plaid Account and introduce a monitoring service that operates through a web app. The terms now authorize Plaid to share financial information needed for third-party apps to initiate payments to or from you, which is a broader statement of data-sharing scope than the previous language. This means Plaid's role shifts from primarily facilitating connections to third-party apps toward directly providing account services, including monitoring. The effective date is April 14, 2026, though the change was detected on April 19, 2026. Review your Plaid Account settings to understand what data Plaid holds and how the monitoring service works.

View change record →
Medium Apr 3, 2026

The updated terms clarify that Plaid may request and collect phone numbers, email addresses, and other contact information when you connect financial accounts or verify your identity through a Plaid-connected application. The terms no longer describe a separate Plaid Monitoring Service or Plaid Web-App. The Plaid Account is now framed primarily as a tool to accelerate onboarding and use of third-party applications rather than as a standalone service for monitoring and alerts. The updated language authorizes Plaid to store identity verification data within your Plaid Account if you choose to do so.

View change record →

Clause Stability Stable

0
Changes
3
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Consumer impact (what this means for users)

Under these terms, financial data, identifiers, transaction histories, and other personal data may be shared with app developers and as directed by those developers, as well as with financial institutions, service providers, fraud prevention services, identity verification services, and Plaid affiliates. The policy states that for US users, sharing with non-affiliated third parties is limited to what Regulation P permits.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Use Plaid Portal at my.plaid.com to terminate connections between specific apps and your financial accounts, which limits further developer-directed sharing for those connections; then submit a data deletion request through Plaid's online form or at privacy@plaid.com.

Cross-platform context

See how other platforms handle Data Sharing with Developers and Third Parties and similar clauses.

Compare across platforms →

Monitoring

Plaid has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Follow Plaid → Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
As permitted by law, we may share your data as follows: With the developer of the app you are using and as directed by that developer; With the financial institutions you connect to Plaid or to an app using Plaid; To enforce any contract with you; With our data processors and other service providers, partners, agents, or contractors in connection with the services they perform for us or developers; If we believe in good faith that disclosure is appropriate or required to comply with applicable law, regulation, or legal process (like a court order or subpoena); In connection with a change in ownership or control of all or a part of our business (like a merger, acquisition, reorganization, or bankruptcy)... (For US users) We do not share your data with non-affiliated third parties except as permitted by law (as authorized by 12 C.F.R. § 1016.13, 1016.14, and 1016.15).

Excerpt from Plaid's End User Privacy Policy [SPA-QUARANTINE: needs human capture]

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: This provision engages the Gramm-Leach-Bliley Act and its implementing Regulation P (12 C.F.R. §§ 1016.13, 1016.14, and 1016.15) for US users, which governs the sharing of nonpublic personal information by financial institutions with nonaffiliated third parties. GDPR Articles 13 and 14 (transparency obligations), Article 26 (joint controllers), and Article 28 (processor requirements) are relevant for EEA and UK users depending on the legal relationship between Plaid and data recipients. The CCPA's disclosure requirements for categories of third parties with whom personal information is shared are also implicated. 2. GOVERNANCE EXPOSURE: Medium. The authorization for developers to direct data sharing creates a structure in which the scope of third-party data access is partially determined by individual developer decisions rather than by Plaid's policy alone. The policy's disclosure that data may be shared in connection with a merger, acquisition, or bankruptcy is a standard commercial provision but may affect user expectations about the stability of data handling commitments. 3. JURISDICTION FLAGS: EEA and UK users are entitled to specific transparency about data recipients under GDPR, and organizations acting as controllers or joint controllers in the Plaid ecosystem should confirm that GDPR-compliant disclosures are in place. California users retain CCPA rights to know the categories of third parties with whom their personal information is shared. The GLBA citation for US users suggests Plaid treats itself as subject to Regulation P, which compliance teams at Plaid-integrated financial institutions should verify is consistent with their own regulatory classification. 4. CONTRACT AND VENDOR IMPLICATIONS: Organizations deploying Plaid should ensure that their developer agreements with Plaid specify the permissible scope of developer-directed data sharing and confirm that data processing agreements with Plaid satisfy GDPR Article 28 requirements. The provision authorizing sharing in connection with a change in business ownership should be evaluated in M&A due diligence contexts to assess whether data handling commitments are contractually binding on acquirers. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should map all data sharing flows authorized under this provision against applicable privacy law disclosure and consent requirements in each jurisdiction. Developer agreements should specify data use limitations to prevent developer-directed sharing that exceeds user consent or regulatory permissions. Data subject request workflows should account for data that has been shared with developers or service providers and establish mechanisms for downstream deletion or correction.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Applicable agencies

  • CFPB
    The CFPB enforces Regulation P (12 C.F.R. § 1016) governing sharing of nonpublic personal financial information, which the policy explicitly cites as the basis for US data sharing limitations.
    File a complaint →
  • FTC
    The FTC has authority over unfair or deceptive data sharing practices and may review whether third-party sharing disclosures and developer-directed sharing practices are consistent with representations made to consumers.
    File a complaint →

Provision details

Document information
Document
Plaid End User Privacy Policy [SPA-QUARANTINE: needs human capture]
Entity
Plaid
Document last updated
May 5, 2026
Tracking information
First tracked
May 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-014836
Document ID
CA-D-00169
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
0a8d827572962cc5012319c796e08d8fb49190be40484061ff10c08cf6718f4b
Analysis generated
May 9, 2026 15:51 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Plaid
Document: Plaid End User Privacy Policy [SPA-QUARANTINE: needs human capture]
Record ID: CA-P-014836
Captured: 2026-05-09 15:51:01 UTC
SHA-256: 0a8d827572962cc5…
URL: https://conductatlas.com/platform/plaid/plaid-end-user-privacy-policy-spa-quarantine-needs-human-capture/provision/CA-P-014836/data-sharing-with-developers-and-third-parties/
Accessed: July 26, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention

Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.

Frequently Asked Questions

What does Plaid's Data Sharing with Developers and Third Parties clause do?

This provision authorizes a broad range of data sharing recipients, including that developers may direct sharing of user data, which means the scope of third-party access to user financial data depends in part on the practices of individual app developers; compliance teams should assess whether developer-directed sharing is subject to adequate contractual controls and whether disclosures to users are sufficient …

How does this clause affect you?

Under these terms, financial data, identifiers, transaction histories, and other personal data may be shared with app developers and as directed by those developers, as well as with financial institutions, service providers, fraud prevention services, identity verification services, and Plaid affiliates. The policy states that for US users, sharing with non-affiliated third parties is limited to what Regulation P permits.

Is ConductAtlas affiliated with Plaid?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Plaid.