Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy discloses that Plaid may collect photographs, videos, and facial geometry scans for identity verification purposes, and that this data may constitute biometric data in certain jurisdictions. For Illinois and Texas residents specifically, the policy states facial geometry data will be stored for no longer than three years unless otherwise required by law.
This analysis describes what Plaid's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision discloses biometric data collection practices that are subject to specific statutory requirements in Illinois under BIPA and in Texas under the Capture or Use of Biometric Identifier Act; compliance with these statutes requires written consent prior to collection, specified retention schedules, and destruction obligations, and the three-year retention period stated in the policy should be evaluated against each statute's requirements.
Interpretive note: The policy's three-year retention period for biometric data may not align with BIPA's earliest-date destruction standard (destruction upon fulfillment of purpose or within three years of last interaction, whichever is earlier); the practical application of the retention period depends on how Plaid defines the fulfillment of the collection purpose.
End consumers may see their financial data accessed by a broader range of people under developer accounts, but Plaid now requires developers to formally designate and manage these 'Authorized Users' and take responsibility for their conduct. The introduction of session replay and activity monitoring means developer interactions with your financial data may be recorded for audit or security purposes. The policy does not specify what data is covered by monitoring or how long recordings are retained, which creates operational uncertainty for developers handling sensitive consumer financial information.
View change record →Plaid's updated terms establish a new direct relationship with you through the Plaid Account and introduce a monitoring service that operates through a web app. The terms now authorize Plaid to share financial information needed for third-party apps to initiate payments to or from you, which is a broader statement of data-sharing scope than the previous language. This means Plaid's role shifts from primarily facilitating connections to third-party apps toward directly providing account services, including monitoring. The effective date is April 14, 2026, though the change was detected on April 19, 2026. Review your Plaid Account settings to understand what data Plaid holds and how the monitoring service works.
View change record →The updated terms clarify that Plaid may request and collect phone numbers, email addresses, and other contact information when you connect financial accounts or verify your identity through a Plaid-connected application. The terms no longer describe a separate Plaid Monitoring Service or Plaid Web-App. The Plaid Account is now framed primarily as a tool to accelerate onboarding and use of third-party applications rather than as a standalone service for monitoring and alerts. The updated language authorizes Plaid to store identity verification data within your Plaid Account if you choose to do so.
View change record →Under these terms, Plaid may collect facial photographs or video and derive biometric identifiers (facial geometry scans) for identity verification, and this data may be retained for up to three years for Illinois and Texas residents. The policy refers users to a separate Biometric Policy and Release document for additional details on how this data is treated.
Cross-platform context
See how other platforms handle Biometric Data Collection and Retention and similar clauses.
Compare across platforms →Monitoring
Plaid has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"We may also collect certain documentation that contains your photograph or we may require you to verify your identity by providing a photograph or video of yourself, for more information please see Plaid's Biometric Policy and Release. Data collected in this context may be considered biometric data in some states or countries. Special Biometric Data Notice for Illinois and Texas Residents For residents of Illinois or Texas, if we require you to provide us with any document that contains your photograph or if you need to verify your identity by providing a photograph or video of yourself, the data derived from your face that we collect and process, and that our service providers collect and process on our behalf, may be considered biometric data in some places. Your data will be stored no longer than three years, unless otherwise required by law.Excerpt from Plaid's End User Privacy Policy
1. REGULATORY LANDSCAPE: This provision directly implicates the Illinois Biometric Information Privacy Act (BIPA) and the Texas Capture or Use of Biometric Identifier Act (CUBI), both of which impose written consent, retention schedule, and destruction requirements for biometric data. BIPA provides a private right of action with statutory damages, making it a material litigation risk for companies collecting facial geometry data from Illinois residents. GDPR Article 9 governs biometric data as a special category of personal data for EEA users, requiring explicit consent or another Article 9(2) exception as a lawful basis. 2. GOVERNANCE EXPOSURE: High. The collection of facial geometry data from identity verification processes creates specific statutory compliance obligations in Illinois and Texas, where non-compliance can result in significant statutory damages under BIPA's private right of action. The policy's three-year retention limit for Illinois and Texas residents should be evaluated against BIPA's requirement that biometric data be destroyed when the purpose for collection has been fulfilled or within three years of last interaction, whichever is earlier. 3. JURISDICTION FLAGS: Illinois presents the highest litigation exposure due to BIPA's private right of action; class actions under BIPA have resulted in substantial settlements in the financial and technology sectors. Texas CUBI does not provide a private right of action but is enforceable by the Texas Attorney General. Other US states including Washington and potentially California may also regulate facial geometry or biometric data, and the policy's disclosure that collection may be biometric in some states suggests broader applicability than Illinois and Texas alone. EEA and UK users are covered under GDPR Article 9's special category protections. 4. CONTRACT AND VENDOR IMPLICATIONS: The policy states that service providers collect and process biometric data on Plaid's behalf; organizations deploying Plaid for identity verification should confirm that their vendor agreements with Plaid include appropriate data processing terms for biometric data, including retention and destruction obligations consistent with BIPA and CUBI requirements. Indemnification and liability allocation for BIPA claims should be explicitly addressed in any commercial agreement with Plaid. 5. COMPLIANCE CONSIDERATIONS: Organizations deploying Plaid's identity verification features should assess whether their own user-facing disclosures and consent mechanisms satisfy BIPA's written consent requirement prior to collection of biometric data from Illinois residents. A data mapping exercise should confirm the categories of biometric data collected by Plaid's service providers, the retention schedules applied, and the destruction processes in place, and should document how these align with BIPA's earliest-date destruction standard.
Regulatory citations, enforcement risk, and due diligence action items.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
This provision discloses biometric data collection practices that are subject to specific statutory requirements in Illinois under BIPA and in Texas under the Capture or Use of Biometric Identifier Act; compliance with these statutes requires written consent prior to collection, specified retention schedules, and destruction obligations, and the three-year retention period stated in the policy should be evaluated against each …
Under these terms, Plaid may collect facial photographs or video and derive biometric identifiers (facial geometry scans) for identity verification, and this data may be retained for up to three years for Illinois and Texas residents. The policy refers users to a separate Biometric Policy and Release document for additional details on how this data is treated.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Plaid.