Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This page describes what the document states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability may vary by jurisdiction. Methodology
This document establishes Revolut's data collection, processing, and use practices for UK customers. The policy authorizes collection of identity documents, bank account details, card numbers, location data, device activity, transaction history, and data obtained through Open Banking access to other financial accounts. The policy establishes that Revolut employs automated profiling and decision-making systems to determine eligibility for products including credit facilities, and specifies that users may request human review of automated decisions, access collected data, and submit objections through the Revolut app or dpo@revolut.com.
This is the Revolut Ltd Customer Privacy Notice (effective 17 March 2026), governing personal data processing for UK customers across all Revolut products and services, with the stated legal controller being either Revolut Bank UK Ltd or Revolut Ltd depending on the product used. The notice states that Revolut collects identity documents, financial details, device and location data, transaction history, biometric data for identity verification, credit reference agency data, Open Banking data, and behaviorally inferred data; the terms authorize use of this data for service delivery, fraud prevention, credit decisioning, automated profiling, product improvement, and marketing where permitted. A notable provision is the explicit commitment that Revolut will never sell personal data, alongside a broad automated decision-making disclosure including credit scoring and fraud detection that relies on profiling with potentially significant legal effects, which the document states is subject to rights of human review under applicable law. The notice engages UK GDPR and the UK Data Protection Act 2018 as primary frameworks, with the ICO as the lead supervisory authority, and separately references compliance obligations under AML, PSD2/Open Banking, and financial services regulation; international data transfers to third countries are disclosed and stated to be covered by Standard Contractual Clauses or other appropriate safeguards. For customers using investment, crypto, or credit products, additional standalone notices and just-in-time disclosures apply, creating a layered privacy framework where this document serves as the master notice but does not contain the full picture for all product lines.
The policy establishes that Revolut collects and processes a comprehensive range of personal financial and behavioral data, including information from external bank accounts via Open Banking. The policy authorizes use of this data in automated decision-making systems that determine product eligibility and financial terms. The policy specifies procedural rights including the ability to request human review of automated decisions, access personal data held by Revolut, submit data deletion requests, and object to specific processing activities or marketing communications.
Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.
Revolut has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.
Cross-platform context
See how other platforms handle Automated Decision-Making and Credit Eligibility and similar clauses.
Compare across platforms →Governance Monitoring
Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.