Provision record
Plaid · Plaid End User Privacy Policy [SPA-QUARANTINE: needs human capture] · View original document ↗

User Data Rights and Access Controls

Low severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Plaid changes these terms. Follow Plaid →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Plaid Monitor emails you the same day this changes. The archive stays free.
Follow Plaid →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy states that Plaid will honor data access, rectification, erasure, restriction, objection, consent withdrawal, and portability rights for all users regardless of location, subject to limitations and exceptions provided by law. Users can submit requests through Plaid's online form or by contacting privacy@plaid.com.

This analysis describes what Plaid's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision extends baseline GDPR-style data subject rights to all users globally, not only to EEA or UK residents, which may create broader operational obligations for Plaid's data rights request management workflows than strictly required by US law; however, the policy notes that rights are subject to limitations and exceptions provided by law, meaning the practical scope of rights exercisable by US users may differ from those of EEA or UK users.

Recent Activity

This document changed recently

High Apr 21, 2026

End consumers may see their financial data accessed by a broader range of people under developer accounts, but Plaid now requires developers to formally designate and manage these 'Authorized Users' and take responsibility for their conduct. The introduction of session replay and activity monitoring means developer interactions with your financial data may be recorded for audit or security purposes. The policy does not specify what data is covered by monitoring or how long recordings are retained, which creates operational uncertainty for developers handling sensitive consumer financial information.

View change record →
Medium Apr 19, 2026

Plaid's updated terms establish a new direct relationship with you through the Plaid Account and introduce a monitoring service that operates through a web app. The terms now authorize Plaid to share financial information needed for third-party apps to initiate payments to or from you, which is a broader statement of data-sharing scope than the previous language. This means Plaid's role shifts from primarily facilitating connections to third-party apps toward directly providing account services, including monitoring. The effective date is April 14, 2026, though the change was detected on April 19, 2026. Review your Plaid Account settings to understand what data Plaid holds and how the monitoring service works.

View change record →
Medium Apr 3, 2026

The updated terms clarify that Plaid may request and collect phone numbers, email addresses, and other contact information when you connect financial accounts or verify your identity through a Plaid-connected application. The terms no longer describe a separate Plaid Monitoring Service or Plaid Web-App. The Plaid Account is now framed primarily as a tool to accelerate onboarding and use of third-party applications rather than as a standalone service for monitoring and alerts. The updated language authorizes Plaid to store identity verification data within your Plaid Account if you choose to do so.

View change record →

Clause Stability Stable

0
Changes
3
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Consumer impact (what this means for users)

Under these terms, all users regardless of location may submit requests to access, correct, delete, restrict processing of, or receive a portable copy of their personal data, and may withdraw consent for consent-based processing. Requests can be submitted through Plaid's online form or by emailing privacy@plaid.com, and the policy states responses will be provided within a reasonable period of time consistent with applicable law.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Email privacy@plaid.com or use Plaid's online data rights request form (linked from the privacy policy) to submit requests to access, correct, delete, restrict, or receive a portable copy of your personal data; you may be asked to verify your identity before Plaid processes the request.

Cross-platform context

See how other platforms handle User Data Rights and Access Controls and similar clauses.

Compare across platforms →

Monitoring

Plaid has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Follow Plaid → Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Regardless of where you live, we will honor the following rights related to your personal data, subject to some limitations and exceptions provided by law, and you will not be discriminated against for exercising them: Access data collected about you; Request access to more details about the categories and specific pieces of personal information we may have collected about you in the last 12 months (including personal information disclosed for business purposes); Request, under certain circumstances, that we rectify or update your data that is inaccurate or incomplete; Request, under certain circumstances, that we erase or restrict the processing of your data; Object to our processing of your data under certain conditions provided by law; Where processing of your data is based on consent, withdraw that consent; Request that we provide data collected about you in a structured, commonly used and machine-readable format so that you can transfer it to another company, where technically feasible.

Excerpt from Plaid's End User Privacy Policy [SPA-QUARANTINE: needs human capture]

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: This provision engages GDPR Articles 15-21 (data subject rights) for EEA and UK users, CCPA Sections 1798.100-1798.125 for California residents, and state privacy laws in Virginia, Colorado, Connecticut, and other US states with enacted comprehensive privacy legislation. The policy's extension of rights to all global users may also engage consumer protection frameworks in other jurisdictions where Plaid operates. The relevant supervisory authorities are the EDPB (EEA), the ICO (UK), and State Attorneys General (US). 2. GOVERNANCE EXPOSURE: Low. The provision is consistent with standard data rights frameworks and the policy discloses a clear mechanism for submitting requests. The qualification that rights are subject to limitations and exceptions provided by law is consistent with GDPR and CCPA frameworks. The 12-month lookback period referenced for access requests is consistent with CCPA requirements. 3. JURISDICTION FLAGS: EEA and UK users have the broadest statutory rights under GDPR, including the right to object to processing based on legitimate interests and the right to erasure under Article 17. California users have CCPA-specific rights including the right to know, delete, and opt out of sale. US users in states without comprehensive privacy legislation have more limited statutory rights, and the scope of Plaid's voluntary extension of rights to these users depends on Plaid's internal policies. 4. CONTRACT AND VENDOR IMPLICATIONS: Organizations that deploy Plaid as a data processor must confirm that data subject requests received by the developer organization are forwarded to Plaid in a timely manner, as required by GDPR Article 28(3)(e). Developer agreements should specify response timelines and obligations for handling data subject requests that affect data held by Plaid. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should confirm that Plaid's identity verification requirements for processing data subject requests are proportionate and do not create undue barriers to rights exercise. The policy's provision that authorized agents may submit requests on behalf of users (requiring evidence of written authority) should be evaluated against CCPA's authorized agent provisions, which specify the acceptable mechanisms for establishing agent authority.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Applicable agencies

  • FTC
    The FTC has authority over representations about consumer data rights and may review whether Plaid's rights request processes are consistent with disclosures made to consumers.
    File a complaint →
  • State AG
    State Attorneys General in California and other states with comprehensive privacy laws have enforcement authority over compliance with consumer data rights under CCPA and analogous state statutes.
    File a complaint →

Provision details

Document information
Document
Plaid End User Privacy Policy [SPA-QUARANTINE: needs human capture]
Entity
Plaid
Document last updated
May 5, 2026
Tracking information
First tracked
May 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-014838
Document ID
CA-D-00169
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
0a8d827572962cc5012319c796e08d8fb49190be40484061ff10c08cf6718f4b
Analysis generated
May 9, 2026 15:51 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Plaid
Document: Plaid End User Privacy Policy [SPA-QUARANTINE: needs human capture]
Record ID: CA-P-014838
Captured: 2026-05-09 15:51:01 UTC
SHA-256: 0a8d827572962cc5…
URL: https://conductatlas.com/platform/plaid/plaid-end-user-privacy-policy-spa-quarantine-needs-human-capture/provision/CA-P-014838/user-data-rights-and-access-controls/
Accessed: July 26, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Low
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention

Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.

Frequently Asked Questions

What does Plaid's User Data Rights and Access Controls clause do?

This provision extends baseline GDPR-style data subject rights to all users globally, not only to EEA or UK residents, which may create broader operational obligations for Plaid's data rights request management workflows than strictly required by US law; however, the policy notes that rights are subject to limitations and exceptions provided by law, meaning the practical scope of rights exercisable …

How does this clause affect you?

Under these terms, all users regardless of location may submit requests to access, correct, delete, restrict processing of, or receive a portable copy of their personal data, and may withdraw consent for consent-based processing. Requests can be submitted through Plaid's online form or by emailing privacy@plaid.com, and the policy states responses will be provided within a reasonable period of time …

Is ConductAtlas affiliated with Plaid?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Plaid.