Provision record
Revolut · Revolut Privacy Policy · View original document ↗

Biometric and Sensitive Data Collection

High severity Low confidence Inferredfromcontext Common · 295 of 352 platforms
Get alerted the next time Revolut changes these terms. Follow Revolut →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Revolut Monitor emails you the same day this changes. The archive stays free.
Follow Revolut →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

Revolut collects sensitive categories of personal data, which may include biometric information used for identity verification purposes such as facial recognition or fingerprint authentication.

This analysis describes what Revolut's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

Biometric data such as facial scans or fingerprints is highly sensitive because, unlike passwords or account numbers, it cannot be changed if compromised, making its collection and protection particularly significant.

Interpretive note: The specific extent of biometric data collection is inferred from the financial services and identity verification context; the exact policy language on this point was in portions of the document not fully reproduced in the source text.

Clause Stability Stable

0
Changes
3
Months Monitored
May 9, 2026
First Seen
May 22, 2026
Last Seen
This clause type exists across 5260 other provisions on other platforms.

Consumer impact (what this means for users)

If Revolut collects your biometric data for identity verification, that information is subject to specific legal protections in several US states, and its exposure or misuse would carry risks that cannot be remediated by simply resetting a credential.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Contact dpo@revolut.com to request information about what biometric data Revolut holds about you and to request its deletion if you no longer wish for it to be retained.

How other platforms handle this

Baseten Medium

The right to notice. You have the right to be notified which categories of Personal Data are being collected and the purposes for which the Personal Data is being used.

Skillshare Medium

In certain circumstances, the right to data portability, which means that you can request that we provide certain Personal Data we hold about you in a machine-readable format

Discord Medium

If you want to see what information we have collected about you, you can request a copy of your data in the Data & Privacy section of your User Settings. You should receive your data packet within 30 days.

See all platforms with this clause type →

Monitoring

Revolut has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Follow Revolut → Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
We collect your personal data when you use: our website at www.revolut.com/en-US/; any of our Revolut apps; any of the services available to you through our apps or website

Excerpt from Revolut's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

REGULATORY LANDSCAPE: Biometric data collection is regulated at the state level in the US, most significantly under the Illinois Biometric Information Privacy Act (BIPA), which requires written notice and consent before collecting biometric identifiers and imposes strict retention and destruction schedules. Texas and Washington have analogous statutes. The CCPA and CPRA classify biometric data as a sensitive personal information category subject to additional disclosure and opt-out rights. No comprehensive federal biometric privacy statute currently exists, though the FTC has addressed biometric data in enforcement actions. GOVERNANCE EXPOSURE: High. Biometric data collection by a financial services platform creates significant exposure under state biometric statutes, particularly BIPA, which provides a private right of action with statutory damages and has generated substantial class action litigation. Even where a user is not physically located in Illinois, questions about where data is processed may affect exposure. JURISDICTION FLAGS: Illinois BIPA creates the most significant litigation exposure due to its private right of action. Texas CUBI and Washington's statute are enforced by state attorneys general. California CPRA requires that consumers be given the ability to limit use of sensitive personal information, including biometric data, which may require a specific opt-out mechanism. CONTRACT AND VENDOR IMPLICATIONS: If biometric data collection is performed by a third-party identity verification vendor, the vendor agreement must address BIPA compliance, data retention limitations, destruction obligations, and prohibition on onward sharing. Procurement teams should verify vendor consent collection processes and data destruction schedules. COMPLIANCE CONSIDERATIONS: A biometric data inventory should be maintained documenting what biometric data is collected, from which users, for what purpose, by which entity, and with what retention schedule. Consent mechanisms for biometric data should be reviewed to ensure they meet the informed written consent standard required under BIPA and analogous statutes. State-by-state applicability assessments should be conducted and updated as new state biometric laws are enacted.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Applicable agencies

  • FTC
    The FTC has issued guidance and taken enforcement action related to biometric data collection and consumer protection in this area.
    File a complaint →
  • State AG
    State attorneys general enforce biometric privacy statutes in Texas, Washington, and other states with biometric data laws.
    File a complaint →

Applicable regulations

Connecticut Data Privacy Act Amendments
US-CT
CAN-SPAM
United States Federal
FCRA
United States Federal
FTC Act Section 5
United States Federal
GDPR
European Union
GLBA
United States Federal
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
UK GDPR
United Kingdom
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
Revolut Privacy Policy
Entity
Revolut
Document last updated
May 5, 2026
Tracking information
First tracked
May 7, 2026
Last verified
May 9, 2026
Record ID
CA-P-007479
Document ID
CA-D-00268
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
5b1da235e3ef773ab4e412f9de7a6bf3e5b88cf622f80575afcd49e6541d72fb
Analysis generated
May 7, 2026 07:48 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Revolut
Document: Revolut Privacy Policy
Record ID: CA-P-007479
Captured: 2026-05-07 07:48:41 UTC
SHA-256: 5b1da235e3ef773a…
URL: https://conductatlas.com/platform/revolut/revolut-privacy-policy/provision/CA-P-007479/biometric-and-sensitive-data-collection/
Accessed: July 25, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Related Analysis

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention

Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.

Frequently Asked Questions

What does Revolut's Biometric and Sensitive Data Collection clause do?

Biometric data such as facial scans or fingerprints is highly sensitive because, unlike passwords or account numbers, it cannot be changed if compromised, making its collection and protection particularly significant.

How does this clause affect you?

If Revolut collects your biometric data for identity verification, that information is subject to specific legal protections in several US states, and its exposure or misuse would carry risks that cannot be remediated by simply resetting a credential.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 295 platforms. See the full comparison.

Is ConductAtlas affiliated with Revolut?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Revolut.