Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that Samsung collects payment card numbers, expiration dates, and security codes for order processing, and that users may optionally save payment information for future transactions. The policy also discloses that social security numbers are collected when users apply for credit or financing through Samsung.
This analysis describes what Samsung's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The collection of payment card data including security codes and social security numbers for credit applications represents categories of highly sensitive financial data. The optional storage of payment information for future transactions creates a persistent data retention relationship that users should be aware of when evaluating account data management.
The updated policy expands Samsung's data collection authority to include device registration, verification for repairs, and configuration of device settings. The terms now explicitly state that Samsung may collect card and transaction information if you apply for a Samsung-branded payment card. Samsung clarified that it will only send personalized marketing when you have provided consent, where required by law. The policy removed its previous statement that defective devices are wiped of personal information before analysis; the updated terms now state Samsung will analyze returned defective devices without that explicit pre-analysis data deletion commitment. For US residents, the policy now discloses rights to opt out of sale of personal information, sharing for cross-context behavioral advertising, targeted advertising processing, sensitive data collection or processing, and to request lists of third parties receiving your information.
View change record →The agreement authorizes collection of payment card numbers, expiration dates, and security codes for order processing, with an option to save payment information for future use. Social security numbers are collected from users who apply for credit or financing through Samsung services.
Cross-platform context
See how other platforms handle Payment and Financial Information Collection and similar clauses.
Compare across platforms →Monitoring
Samsung has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"If you order a product or paid service from us, we also ask for your name, address, contact information, and shipping and payment information such as card number, expiration date, and security code to process your order. You can also choose to save your payment information with us so you can check out more easily next time. Information you provide when you apply for credit or financing, such as your social security number.Excerpt from Samsung's Privacy Policy
1. REGULATORY LANDSCAPE: Collection and storage of payment card data engages Payment Card Industry Data Security Standards (PCI DSS), which are contractual requirements enforced through card network agreements rather than a regulatory statute. Social security number collection for credit applications engages the Fair Credit Reporting Act and applicable state laws governing SSN privacy and credit application processing. The CFPB exercises authority over credit-related disclosures and consumer financial protection. The FTC exercises authority over unfair or deceptive practices in financial data collection. 2. GOVERNANCE EXPOSURE: Medium. The storage of payment card data including security codes (CVV) raises PCI DSS compliance considerations, as card network rules generally prohibit post-authorization storage of CVV data. The policy does not specify whether CVV data is retained post-authorization or only used for transaction processing. Social security number collection for credit applications requires specific privacy notice obligations under applicable state and federal law. 3. JURISDICTION FLAGS: California's SB 1386 and similar state breach notification laws impose obligations if financial data is compromised. State laws in New York and other jurisdictions impose specific requirements for social security number protection. The CCPA and CPRA classify financial information as a category of sensitive personal information subject to opt-out rights. 4. CONTRACT AND VENDOR IMPLICATIONS: Financing partners named as business partners in the policy who receive credit application data including social security numbers should be assessed under applicable vendor management frameworks. Enterprise procurement teams should evaluate whether Samsung's payment data storage practices align with PCI DSS requirements applicable to their own payment card environments. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should verify that Samsung's payment card data storage practices, particularly regarding security codes, comply with PCI DSS requirements. The disclosure of social security number collection for credit applications should be evaluated against applicable federal and state credit application privacy notice requirements. Data retention policies for stored payment information and credit application data should be audited for alignment with the policy's stated retention principles.
The collection of payment card data including security codes and social security numbers for credit applications represents categories of highly sensitive financial data. The optional storage of payment information for future transactions creates a persistent data retention relationship that users should be aware of when evaluating account data management.
The agreement authorizes collection of payment card numbers, expiration dates, and security codes for order processing, with an option to save payment information for future use. Social security numbers are collected from users who apply for credit or financing through Samsung services.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Samsung.