The policy authorizes sharing user data with app developers and as directed by developers, financial institutions, service providers, partners, agents, contractors, professional advisors, fraud prevention services, identity verification services, cloud storage providers, Plaid affiliates, and governmental authorities when legally required. For US users, the policy states that sharing with non-affiliated third parties is limited to what is permitted under GLBA's Regulation P (12 C.F.R. §§ 1016.13, 1016.14, and 1016.15).
This analysis describes what Plaid's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision authorizes a broad range of data sharing recipients, including that developers may direct sharing of user data, which means the scope of third-party access to user financial data depends in part on the practices of individual app developers; compliance teams should assess whether developer-directed sharing is subject to adequate contractual controls and whether disclosures to users are sufficient to satisfy applicable law.
End consumers may see their financial data accessed by a broader range of people under developer accounts, but Plaid now requires developers to formally designate and manage these 'Authorized Users' and take responsibility for their conduct. The introduction of session replay and activity monitoring means developer interactions with your financial data may be recorded for audit or security purposes. The policy does not specify what data is covered by monitoring or how long recordings are retained, which creates operational uncertainty for developers handling sensitive consumer financial information.
View change record →Plaid's updated terms establish a new direct relationship with you through the Plaid Account and introduce a monitoring service that operates through a web app. The terms now authorize Plaid to share financial information needed for third-party apps to initiate payments to or from you, which is a broader statement of data-sharing scope than the previous language. This means Plaid's role shifts from primarily facilitating connections to third-party apps toward directly providing account services, including monitoring. The effective date is April 14, 2026, though the change was detected on April 19, 2026. Review your Plaid Account settings to understand what data Plaid holds and how the monitoring service works.
View change record →The updated terms clarify that Plaid may request and collect phone numbers, email addresses, and other contact information when you connect financial accounts or verify your identity through a Plaid-connected application. The terms no longer describe a separate Plaid Monitoring Service or Plaid Web-App. The Plaid Account is now framed primarily as a tool to accelerate onboarding and use of third-party applications rather than as a standalone service for monitoring and alerts. The updated language authorizes Plaid to store identity verification data within your Plaid Account if you choose to do so.
View change record →Under these terms, financial data, identifiers, transaction histories, and other personal data may be shared with app developers and as directed by those developers, as well as with financial institutions, service providers, fraud prevention services, identity verification services, and Plaid affiliates. The policy states that for US users, sharing with non-affiliated third parties is limited to what Regulation P permits.
Cross-platform context
See how other platforms handle Data Sharing with Developers and Third Parties and similar clauses.
Compare across platforms →"As permitted by law, we may share your data as follows: With the developer of the app you are using and as directed by that developer; With the financial institutions you connect to Plaid or to an app using Plaid; To enforce any contract with you; With our data processors and other service providers, partners, agents, or contractors in connection with the services they perform for us or developers; If we believe in good faith that disclosure is appropriate or required to comply with applicable law, regulation, or legal process (like a court order or subpoena); In connection with a change in ownership or control of all or a part of our business (like a merger, acquisition, reorganization, or bankruptcy)... (For US users) We do not share your data with non-affiliated third parties except as permitted by law (as authorized by 12 C.F.R. § 1016.13, 1016.14, and 1016.15).Excerpt from Plaid's End User Privacy Policy
1.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision authorizes a broad range of data sharing recipients, including that developers may direct sharing of user data, which means the scope of third-party access to user financial data depends in part on the practices of individual app developers; compliance teams should assess whether developer-directed sharing is subject to adequate contractual controls and whether disclosures to users are sufficient …
Under these terms, financial data, identifiers, transaction histories, and other personal data may be shared with app developers and as directed by those developers, as well as with financial institutions, service providers, fraud prevention services, identity verification services, and Plaid affiliates. The policy states that for US users, sharing with non-affiliated third parties is limited to what Regulation P permits.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Plaid.