Provision record
Plaid · Plaid End User Privacy Policy · View original document ↗

AI Development and Training Using Financial Data

High severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Plaid changes these terms. Follow Plaid →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Plaid Monitor emails you the same day this changes. The archive stays free.
Follow Plaid →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy authorizes Plaid to use collected data including transaction histories, financial data, and app-connection data to develop, train, test, and deploy AI systems, and to develop insights shared with financial institutions and app developers. The policy does not specify whether this use is subject to a separate opt-out mechanism.

This analysis describes what Plaid's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision authorizes secondary use of sensitive financial data for AI model development, a purpose that may extend beyond the primary purpose for which users connected their accounts; compliance teams should assess whether the consent or legitimate interest basis asserted for this use satisfies GDPR proportionality requirements and CCPA secondary use disclosure obligations.

Interpretive note: The policy does not specify which lawful basis (legitimate interests or consent) applies to AI training specifically, nor whether a separate opt-out mechanism exists for this secondary use; the regulatory treatment of AI training as a compatible secondary purpose under GDPR remains an area of active interpretation.

Recent Activity

This document changed recently

High Apr 21, 2026

End consumers may see their financial data accessed by a broader range of people under developer accounts, but Plaid now requires developers to formally designate and manage these 'Authorized Users' and take responsibility for their conduct. The introduction of session replay and activity monitoring means developer interactions with your financial data may be recorded for audit or security purposes. The policy does not specify what data is covered by monitoring or how long recordings are retained, which creates operational uncertainty for developers handling sensitive consumer financial information.

View change record →
Medium Apr 19, 2026

Plaid's updated terms establish a new direct relationship with you through the Plaid Account and introduce a monitoring service that operates through a web app. The terms now authorize Plaid to share financial information needed for third-party apps to initiate payments to or from you, which is a broader statement of data-sharing scope than the previous language. This means Plaid's role shifts from primarily facilitating connections to third-party apps toward directly providing account services, including monitoring. The effective date is April 14, 2026, though the change was detected on April 19, 2026. Review your Plaid Account settings to understand what data Plaid holds and how the monitoring service works.

View change record →
Medium Apr 3, 2026

The updated terms clarify that Plaid may request and collect phone numbers, email addresses, and other contact information when you connect financial accounts or verify your identity through a Plaid-connected application. The terms no longer describe a separate Plaid Monitoring Service or Plaid Web-App. The Plaid Account is now framed primarily as a tool to accelerate onboarding and use of third-party applications rather than as a standalone service for monitoring and alerts. The updated language authorizes Plaid to store identity verification data within your Plaid Account if you choose to do so.

View change record →

Clause Stability Stable

0
Changes
3
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Consumer impact (what this means for users)

Under these terms, transaction data, financial data, and app-connection data collected through Plaid-powered connections may be used to develop and train AI systems and to generate insights that Plaid shares with financial institutions and app developers. The policy does not identify a specific opt-out mechanism for this use separate from general data deletion or consent withdrawal.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Email privacy@plaid.com to request deletion of your personal data or to withdraw consent for data processing; you may also submit a request through Plaid's online data rights form linked from the privacy policy.

Cross-platform context

See how other platforms handle AI Development and Training Using Financial Data and similar clauses.

Compare across platforms →

Monitoring

Plaid has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Follow Plaid → Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Develop New Services: To develop new products, features, technologies and services that benefit you and the apps you use, including to develop, train, test, and deploy artificial intelligence ("AI") systems. Develop Insights: To develop insights based on the data we've collected about you. This includes your transaction data, other financial data, data about which financial accounts you have connected to which apps, and data from other sources, to help us, your financial institutions, and the developers of your connected apps provide services and/or a better user experience to you.

Excerpt from Plaid's End User Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: This provision may require evaluation under the EU AI Act, depending on the risk classification of AI systems developed using financial data; high-risk AI systems (such as those used for credit scoring or financial eligibility assessments) are subject to specific transparency, explainability, and data governance requirements. GDPR Articles 5 (purpose limitation and data minimization), 6 (lawful basis), and 22 (automated decision-making) are relevant where AI systems process personal financial data or generate outputs affecting users. The FTC has issued guidance on AI and automated systems that may apply to this use. The CFPB has also indicated interest in AI use in financial services contexts. 2. GOVERNANCE EXPOSURE: High. The use of transaction and financial data to train AI systems represents a secondary processing purpose that may be difficult to reconcile with the primary purpose limitation principle under GDPR Article 5(1)(b). The policy asserts legitimate interests as one lawful basis but does not specify which AI development activities rely on this basis versus consent, creating potential ambiguity in compliance documentation. 3. JURISDICTION FLAGS: EEA and UK users face the highest exposure given GDPR purpose limitation and data minimization requirements; the legitimate interests basis asserted for AI development may face challenge if the processing is not demonstrably necessary and balanced against user interests. California users retain CCPA rights to know about secondary uses of their personal data and to request deletion, which may interact with AI training data practices. Illinois BIPA may apply if biometric data is incorporated into AI training datasets. 4. CONTRACT AND VENDOR IMPLICATIONS: Organizations deploying Plaid should assess whether their own privacy disclosures adequately inform end users that their financial data may be used by Plaid for AI development and insight generation, as this purpose may not be apparent from the developer app's own disclosures. Data processing agreements with Plaid should specify whether AI training constitutes a controller or processor activity and which party bears disclosure obligations. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should evaluate whether the AI development use case is supported by a sufficiently specific lawful basis under GDPR and whether a legitimate interests assessment has been conducted and documented. Organizations subject to EU AI Act obligations should assess whether Plaid's AI systems that process their users' data fall within regulated risk categories and whether transparency obligations have been met.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Applicable agencies

  • FTC
    The FTC has issued guidance on AI and automated systems and has authority over unfair or deceptive data practices, including secondary use of consumer financial data for AI training without adequate disclosure.
    File a complaint →
  • CFPB
    The CFPB has signaled regulatory interest in AI use in financial services and may review secondary processing of consumer financial data by data aggregators.
    File a complaint →

Provision details

Document information
Document
Plaid End User Privacy Policy
Entity
Plaid
Document last updated
May 5, 2026
Tracking information
First tracked
May 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-014833
Document ID
CA-D-00169
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
0a8d827572962cc5012319c796e08d8fb49190be40484061ff10c08cf6718f4b
Analysis generated
May 9, 2026 15:51 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Plaid
Document: Plaid End User Privacy Policy
Record ID: CA-P-014833
Captured: 2026-05-09 15:51:01 UTC
SHA-256: 0a8d827572962cc5…
URL: https://conductatlas.com/platform/plaid/plaid-end-user-privacy-policy/provision/CA-P-014833/ai-development-and-training-using-financial-data/
Accessed: July 25, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention

Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.

Frequently Asked Questions

What does Plaid's AI Development and Training Using Financial Data clause do?

This provision authorizes secondary use of sensitive financial data for AI model development, a purpose that may extend beyond the primary purpose for which users connected their accounts; compliance teams should assess whether the consent or legitimate interest basis asserted for this use satisfies GDPR proportionality requirements and CCPA secondary use disclosure obligations.

How does this clause affect you?

Under these terms, transaction data, financial data, and app-connection data collected through Plaid-powered connections may be used to develop and train AI systems and to generate insights that Plaid shares with financial institutions and app developers. The policy does not identify a specific opt-out mechanism for this use separate from general data deletion or consent withdrawal.

Is ConductAtlas affiliated with Plaid?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Plaid.