SoFi · SoFi Privacy Notice · View original document ↗

GLBA U.S. Consumer Privacy Notice

Medium severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time SoFi changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity SoFi recorded 12 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for SoFi Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

SoFi maintains a separate U.S. Consumer Privacy Notice governed by GLBA that describes collection, use, and disclosure of financial personal information, affiliate and non-affiliate sharing practices, and available opt-out rights for certain categories of sharing.

This analysis describes what SoFi's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

The GLBA Consumer Privacy Notice is a legally required instrument for financial institutions that governs the most sensitive category of personal financial data SoFi collects, including account, credit, and transaction information. The opt-out rights described in this notice are distinct from and operate independently of the cookie consent opt-outs on SoFi's website.

Interpretive note: The specific categories of sharing, opt-out mechanisms, and affiliate/non-affiliate relationships governed by the GLBA notice are not enumerated in this document text and require review of the full Consumer Privacy Notice.

Recent Activity

This document changed recently

Medium Jun 15, 2026

The updated terms restructure how SoFi discloses and collects consent for tracking technologies. Previously, SoFi stated that non-selection of preferences constituted acceptance of tracking. The updated version creates distinct cookie categories (Functional, Performance, Targeting, Strictly Necessary) and establishes a Privacy Preference Center allowing you to individually toggle Performance and Targeting cookies on or off. Strictly Necessary Cookies remain non-optional and cannot be disabled, as the updated terms state these are necessary for website functionality. You can manage individual cookie category preferences through the Privacy Preference Center interface before or after initial site visit.

View change record →
Medium Jun 12, 2026

The updated Privacy Notice explicitly discloses that SoFi collects user information through cookies, pixels, and other tracking technologies and shares this data with social media, advertising, and analytics partners. Previously, the policy described these practices in more general language. Under the revised terms, continued use of SoFi's website constitutes acceptance of these tracking and data-sharing practices unless the user actively makes selections in the Privacy Preference Center. You can use the preference center to opt out of optional tracking technologies, though strictly necessary cookies cannot be disabled.

View change record →
Medium Jun 2, 2026

The updated privacy notice explicitly discloses that SoFi uses pixels and tracking technologies to collect information about your actions and preferences, and shares this data with social media, advertising, and analytics partners. The revised consent interface distinguishes between strictly necessary cookies (which cannot be disabled) and optional cookies for performance and targeting purposes (which require affirmative consent). The terms state that if you do not make a selection, you agree to use of these technologies; you can opt out by toggling the button that appears to the right of each optional cookie category.

View change record →

Clause Stability Stable

0
Changes
3
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Consumer impact (what this means for users)

The agreement establishes that GLBA-covered financial personal information is governed by a separate notice with its own opt-out framework for affiliate and non-affiliate data sharing. Under these terms, consumers may have the right to opt out of certain categories of information sharing as described in that notice, though the specific opt-out options and their scope are defined in the full GLBA notice rather than this landing page.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Opt Out of Arbitration
    Contact SoFi customer support at (855) 456-7634 to inquire about and exercise opt-out rights described in SoFi's U.S. Consumer Privacy Notice regarding GLBA-governed information sharing with affiliates and non-affiliates.

Cross-platform context

See how other platforms handle GLBA U.S. Consumer Privacy Notice and similar clauses.

Compare across platforms →

Monitoring

SoFi has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
This U.S. Consumer Privacy Notice applies to SoFi's customers and consumers and explains how SoFi collects, uses, and discloses personal information covered by the Gramm-Leach-Bliley Act ("GLBA"). Further, it describes how SoFi collects and shares information with affiliates and non-affiliates and what types of information sharing customers and consumers may opt-out of.

Excerpt from SoFi's Privacy Notice

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1) REGULATORY LANDSCAPE: This provision directly engages the Gramm-Leach-Bliley Act and its Privacy Rule (Regulation P), which requires financial institutions to deliver annual privacy notices and provide opt-out rights for sharing nonpublic personal information with non-affiliated third parties. The CFPB holds primary federal enforcement authority over GLBA Privacy Rule compliance for most covered financial institutions. The FTC retains jurisdiction over entities not covered by other regulators. Federal banking regulators may also hold jurisdiction depending on SoFi's charter structure. 2) GOVERNANCE EXPOSURE: High. GLBA compliance is a core regulatory obligation for SoFi as a financial services provider. The notice describes affiliate and non-affiliate sharing, which are the two primary categories of sharing subject to GLBA disclosure and opt-out requirements. Any gaps between the notice's described practices and actual data sharing workflows create material regulatory exposure. Annual notice delivery and opt-out mechanism maintenance are affirmative compliance obligations. 3) JURISDICTION FLAGS: GLBA applies at the federal level to all U.S. customers of covered financial institutions. California customers are additionally protected by CCPA/CPRA, which may provide broader opt-out rights than GLBA. State financial privacy laws in other jurisdictions may impose additional obligations. The interaction between GLBA and state privacy frameworks requires jurisdiction-specific assessment. 4) CONTRACT AND VENDOR IMPLICATIONS: Non-affiliate sharing under GLBA requires that third parties receiving nonpublic personal information are bound by contractual restrictions on secondary use consistent with the institution's GLBA obligations. Vendor contracts with data recipients should be reviewed to confirm these restrictions are in place and operationally enforced. 5) COMPLIANCE CONSIDERATIONS: Legal teams should confirm that the full GLBA Consumer Privacy Notice accurately describes all current data sharing practices with affiliates and non-affiliates, that annual notice delivery obligations are being met, that opt-out mechanisms described in the notice are technically operational, and that the notice is updated to reflect any changes in sharing practices. The interaction between GLBA opt-outs and CCPA/CPRA opt-outs should be mapped to avoid creating conflicting or incomplete user-facing disclosures.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Insight · $19.99/mo Start with Monitor · $4.99/mo

Applicable agencies

  • CFPB
    The CFPB holds primary enforcement authority over the GLBA Privacy Rule (Regulation P) compliance for covered financial institutions including SoFi Bank, N.A.
    File a complaint →
  • FTC
    The FTC holds enforcement authority over GLBA Privacy Rule compliance for financial entities within its jurisdiction and over deceptive practices in privacy disclosures
    File a complaint →

Provision details

Document information
Document
SoFi Privacy Notice
Entity
SoFi
Document last updated
March 14, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-013775
Document ID
CA-D-00104
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
7b76847eebe703a2aa3f0e1fafc55926e9cbe3cb44aae8c482b48b4f2e87ebe4
Analysis generated
July 9, 2026 03:58 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: SoFi
Document: SoFi Privacy Notice
Record ID: CA-P-013775
Captured: 2026-07-09 03:58:12 UTC
SHA-256: 7b76847eebe703a2…
URL: https://conductatlas.com/platform/sofi/sofi-privacy-notice/provision/CA-P-013775/glba-us-consumer-privacy-notice/
Accessed: July 24, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Insight · $19.99/mo Start with Monitor · $4.99/mo

Frequently Asked Questions

What does SoFi's GLBA U.S. Consumer Privacy Notice clause do?

The GLBA Consumer Privacy Notice is a legally required instrument for financial institutions that governs the most sensitive category of personal financial data SoFi collects, including account, credit, and transaction information. The opt-out rights described in this notice are distinct from and operate independently of the cookie consent opt-outs on SoFi's website.

How does this clause affect you?

The agreement establishes that GLBA-covered financial personal information is governed by a separate notice with its own opt-out framework for affiliate and non-affiliate data sharing. Under these terms, consumers may have the right to opt out of certain categories of information sharing as described in that notice, though the specific opt-out options and their scope are defined in the full …

Is ConductAtlas affiliated with SoFi?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by SoFi.