Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
SoFi maintains a separate U.S. Consumer Privacy Notice governed by GLBA that describes collection, use, and disclosure of financial personal information, affiliate and non-affiliate sharing practices, and available opt-out rights for certain categories of sharing.
This analysis describes what SoFi's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The GLBA Consumer Privacy Notice is a legally required instrument for financial institutions that governs the most sensitive category of personal financial data SoFi collects, including account, credit, and transaction information. The opt-out rights described in this notice are distinct from and operate independently of the cookie consent opt-outs on SoFi's website.
Interpretive note: The specific categories of sharing, opt-out mechanisms, and affiliate/non-affiliate relationships governed by the GLBA notice are not enumerated in this document text and require review of the full Consumer Privacy Notice.
The updated terms restructure how SoFi discloses and collects consent for tracking technologies. Previously, SoFi stated that non-selection of preferences constituted acceptance of tracking. The updated version creates distinct cookie categories (Functional, Performance, Targeting, Strictly Necessary) and establishes a Privacy Preference Center allowing you to individually toggle Performance and Targeting cookies on or off. Strictly Necessary Cookies remain non-optional and cannot be disabled, as the updated terms state these are necessary for website functionality. You can manage individual cookie category preferences through the Privacy Preference Center interface before or after initial site visit.
View change record →The updated Privacy Notice explicitly discloses that SoFi collects user information through cookies, pixels, and other tracking technologies and shares this data with social media, advertising, and analytics partners. Previously, the policy described these practices in more general language. Under the revised terms, continued use of SoFi's website constitutes acceptance of these tracking and data-sharing practices unless the user actively makes selections in the Privacy Preference Center. You can use the preference center to opt out of optional tracking technologies, though strictly necessary cookies cannot be disabled.
View change record →The updated privacy notice explicitly discloses that SoFi uses pixels and tracking technologies to collect information about your actions and preferences, and shares this data with social media, advertising, and analytics partners. The revised consent interface distinguishes between strictly necessary cookies (which cannot be disabled) and optional cookies for performance and targeting purposes (which require affirmative consent). The terms state that if you do not make a selection, you agree to use of these technologies; you can opt out by toggling the button that appears to the right of each optional cookie category.
View change record →The agreement establishes that GLBA-covered financial personal information is governed by a separate notice with its own opt-out framework for affiliate and non-affiliate data sharing. Under these terms, consumers may have the right to opt out of certain categories of information sharing as described in that notice, though the specific opt-out options and their scope are defined in the full GLBA notice rather than this landing page.
Cross-platform context
See how other platforms handle GLBA U.S. Consumer Privacy Notice and similar clauses.
Compare across platforms →Monitoring
SoFi has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"This U.S. Consumer Privacy Notice applies to SoFi's customers and consumers and explains how SoFi collects, uses, and discloses personal information covered by the Gramm-Leach-Bliley Act ("GLBA"). Further, it describes how SoFi collects and shares information with affiliates and non-affiliates and what types of information sharing customers and consumers may opt-out of.Excerpt from SoFi's Privacy Notice
1) REGULATORY LANDSCAPE: This provision directly engages the Gramm-Leach-Bliley Act and its Privacy Rule (Regulation P), which requires financial institutions to deliver annual privacy notices and provide opt-out rights for sharing nonpublic personal information with non-affiliated third parties. The CFPB holds primary federal enforcement authority over GLBA Privacy Rule compliance for most covered financial institutions. The FTC retains jurisdiction over entities not covered by other regulators. Federal banking regulators may also hold jurisdiction depending on SoFi's charter structure. 2) GOVERNANCE EXPOSURE: High. GLBA compliance is a core regulatory obligation for SoFi as a financial services provider. The notice describes affiliate and non-affiliate sharing, which are the two primary categories of sharing subject to GLBA disclosure and opt-out requirements. Any gaps between the notice's described practices and actual data sharing workflows create material regulatory exposure. Annual notice delivery and opt-out mechanism maintenance are affirmative compliance obligations. 3) JURISDICTION FLAGS: GLBA applies at the federal level to all U.S. customers of covered financial institutions. California customers are additionally protected by CCPA/CPRA, which may provide broader opt-out rights than GLBA. State financial privacy laws in other jurisdictions may impose additional obligations. The interaction between GLBA and state privacy frameworks requires jurisdiction-specific assessment. 4) CONTRACT AND VENDOR IMPLICATIONS: Non-affiliate sharing under GLBA requires that third parties receiving nonpublic personal information are bound by contractual restrictions on secondary use consistent with the institution's GLBA obligations. Vendor contracts with data recipients should be reviewed to confirm these restrictions are in place and operationally enforced. 5) COMPLIANCE CONSIDERATIONS: Legal teams should confirm that the full GLBA Consumer Privacy Notice accurately describes all current data sharing practices with affiliates and non-affiliates, that annual notice delivery obligations are being met, that opt-out mechanisms described in the notice are technically operational, and that the notice is updated to reflect any changes in sharing practices. The interaction between GLBA opt-outs and CCPA/CPRA opt-outs should be mapped to avoid creating conflicting or incomplete user-facing disclosures.
The GLBA Consumer Privacy Notice is a legally required instrument for financial institutions that governs the most sensitive category of personal financial data SoFi collects, including account, credit, and transaction information. The opt-out rights described in this notice are distinct from and operate independently of the cookie consent opt-outs on SoFi's website.
The agreement establishes that GLBA-covered financial personal information is governed by a separate notice with its own opt-out framework for affiliate and non-affiliate data sharing. Under these terms, consumers may have the right to opt out of certain categories of information sharing as described in that notice, though the specific opt-out options and their scope are defined in the full …
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by SoFi.