Provision record
Plaid · Plaid End User Privacy Policy [SPA-QUARANTINE: needs human capture] · View original document ↗

International Data Transfers

Medium severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Plaid changes these terms. Follow Plaid →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Plaid Monitor emails you the same day this changes. The archive stays free.
Follow Plaid →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy states that Plaid transfers data from the EEA and UK to the United States and stores data in AWS regions in the United States, relying on adequacy decisions, standard contractual clauses, or other approved mechanisms for these transfers. Plaid states it conducts transfer impact assessments and implements supplementary measures prior to EEA or UK transfers.

This analysis describes what Plaid's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision discloses that sensitive financial data from EEA and UK users is transferred to and stored in US-based AWS infrastructure, and describes the legal mechanisms Plaid relies upon for compliance with GDPR Chapter V transfer requirements; the availability of standard contractual clauses for inspection upon request is a disclosure that EEA and UK users and their legal representatives can operationalize.

Recent Activity

This document changed recently

High Apr 21, 2026

End consumers may see their financial data accessed by a broader range of people under developer accounts, but Plaid now requires developers to formally designate and manage these 'Authorized Users' and take responsibility for their conduct. The introduction of session replay and activity monitoring means developer interactions with your financial data may be recorded for audit or security purposes. The policy does not specify what data is covered by monitoring or how long recordings are retained, which creates operational uncertainty for developers handling sensitive consumer financial information.

View change record →
Medium Apr 19, 2026

Plaid's updated terms establish a new direct relationship with you through the Plaid Account and introduce a monitoring service that operates through a web app. The terms now authorize Plaid to share financial information needed for third-party apps to initiate payments to or from you, which is a broader statement of data-sharing scope than the previous language. This means Plaid's role shifts from primarily facilitating connections to third-party apps toward directly providing account services, including monitoring. The effective date is April 14, 2026, though the change was detected on April 19, 2026. Review your Plaid Account settings to understand what data Plaid holds and how the monitoring service works.

View change record →
Medium Apr 3, 2026

The updated terms clarify that Plaid may request and collect phone numbers, email addresses, and other contact information when you connect financial accounts or verify your identity through a Plaid-connected application. The terms no longer describe a separate Plaid Monitoring Service or Plaid Web-App. The Plaid Account is now framed primarily as a tool to accelerate onboarding and use of third-party applications rather than as a standalone service for monitoring and alerts. The updated language authorizes Plaid to store identity verification data within your Plaid Account if you choose to do so.

View change record →

Clause Stability Stable

0
Changes
3
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Consumer impact (what this means for users)

Under these terms, personal and financial data from EEA and UK users is transferred to and stored in the United States using AWS infrastructure, with Plaid relying on standard contractual clauses and transfer impact assessments as the legal basis for transfer. EEA and UK users can request a copy of the applicable standard contractual clauses by contacting privacy@plaid.com.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Export Your Data
    Email privacy@plaid.com to request a copy of the standard contractual clauses Plaid uses for EEA or UK data transfers, or to exercise data portability rights for your personal data.

Cross-platform context

See how other platforms handle International Data Transfers and similar clauses.

Compare across platforms →

Monitoring

Plaid has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Follow Plaid → Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
We operate internationally, and so we transfer the data we collect about you across international borders for processing and storage (for example, we transfer data from the EEA and UK to the United States and store data in AWS regions located in the United States). When we transfer data to a different country or territory, we follow applicable data protection laws in doing so. In particular, when we transfer data from the EEA or UK across other international borders, we rely on adequacy decisions, data transfer agreements, or other EU Commission- or UK Secretary of State-approved (as applicable) mechanisms for such transfers, including standard contractual clauses. You can ask for a copy of these standard contractual clauses by contacting us as set out below. Prior to transferring data from the EEA or UK, we carry out transfer impact assessments and implement any supplementary measures to ensure any data transferred will be maintained in accordance with EEA and UK requirements.

Excerpt from Plaid's End User Privacy Policy [SPA-QUARANTINE: needs human capture]

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: This provision directly engages GDPR Chapter V (Articles 44-49) governing transfers of personal data to third countries, including the standard contractual clauses mechanism approved by the European Commission. The EU-US Data Privacy Framework adequacy decision may also be relevant for certain transfers. For UK users, the UK International Data Transfer Agreement (IDTA) or UK addendum to EU standard contractual clauses applies. The European Data Protection Board and the Information Commissioner's Office are the relevant supervisory authorities for EEA and UK transfers respectively. 2. GOVERNANCE EXPOSURE: Medium. The disclosure that transfer impact assessments are conducted and supplementary measures are implemented is consistent with post-Schrems II requirements; however, the practical adequacy of these measures depends on the substance of the assessments, which are not disclosed in the policy text. Organizations relying on Plaid for EEA or UK user data processing should request and review the applicable transfer impact assessments and standard contractual clauses as part of their GDPR Article 28 vendor due diligence. 3. JURISDICTION FLAGS: EEA users (particularly those in jurisdictions with active data protection authorities, such as Ireland, Germany, France, and the Netherlands) and UK users face the most direct exposure from US-based data transfers. The adequacy of US data protection for personal financial data transferred from the EEA remains subject to ongoing legal and regulatory developments. 4. CONTRACT AND VENDOR IMPLICATIONS: Organizations that are GDPR controllers using Plaid as a data processor should confirm that data processing agreements with Plaid include appropriate transfer mechanism documentation and that standard contractual clauses have been executed. The policy's statement that standard contractual clauses are available upon request creates a due diligence trigger for procurement teams. 5. COMPLIANCE CONSIDERATIONS: Legal teams should request copies of Plaid's standard contractual clauses and transfer impact assessments to confirm that EEA and UK data transfer requirements are met under their specific processing arrangements. Any organization subject to sector-specific data localization requirements (such as certain financial services regulators in the EEA) should assess whether US-based AWS storage is consistent with applicable requirements.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Applicable agencies

  • FTC
    The FTC enforces compliance with the EU-US Data Privacy Framework for US-based companies that have self-certified, and has general authority over cross-border data transfer representations.
    File a complaint →

Provision details

Document information
Document
Plaid End User Privacy Policy [SPA-QUARANTINE: needs human capture]
Entity
Plaid
Document last updated
May 5, 2026
Tracking information
First tracked
May 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-014837
Document ID
CA-D-00169
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
0a8d827572962cc5012319c796e08d8fb49190be40484061ff10c08cf6718f4b
Analysis generated
May 9, 2026 15:51 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Plaid
Document: Plaid End User Privacy Policy [SPA-QUARANTINE: needs human capture]
Record ID: CA-P-014837
Captured: 2026-05-09 15:51:01 UTC
SHA-256: 0a8d827572962cc5…
URL: https://conductatlas.com/platform/plaid/plaid-end-user-privacy-policy-spa-quarantine-needs-human-capture/provision/CA-P-014837/international-data-transfers/
Accessed: July 26, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention

Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.

Frequently Asked Questions

What does Plaid's International Data Transfers clause do?

This provision discloses that sensitive financial data from EEA and UK users is transferred to and stored in US-based AWS infrastructure, and describes the legal mechanisms Plaid relies upon for compliance with GDPR Chapter V transfer requirements; the availability of standard contractual clauses for inspection upon request is a disclosure that EEA and UK users and their legal representatives can …

How does this clause affect you?

Under these terms, personal and financial data from EEA and UK users is transferred to and stored in the United States using AWS infrastructure, with Plaid relying on standard contractual clauses and transfer impact assessments as the legal basis for transfer. EEA and UK users can request a copy of the applicable standard contractual clauses by contacting privacy@plaid.com.

Is ConductAtlas affiliated with Plaid?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Plaid.