Thomson Reuters · Thomson Reuters Privacy · View original document ↗

Sensitive Personal Information Collection

High severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Thomson Reuters changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Thomson Reuters recorded 8 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for Thomson Reuters Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy discloses collection of sensitive personal information categories including political and religious beliefs, sexual orientation, racial or ethnic origin, union membership, medical records, disability information, government identifiers such as social security numbers, and passport or driver's license numbers.

This analysis describes what Thomson Reuters's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes that Thomson Reuters collects multiple categories of special category data under GDPR Article 9, sensitive personal information under CCPA/CPRA, and analogously protected categories under other data protection frameworks, each of which imposes heightened lawful basis, consent, and data subject rights requirements beyond those applicable to ordinary personal data.

Consumer impact (what this means for users)

Under this clause, Thomson Reuters collects political and religious beliefs, sexual orientation, racial and ethnic origin, union membership, health and medical records, disability status, and government identification numbers. California residents may limit the use of sensitive personal information through the opt-out mechanism described in the statement.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Call 866-633-7656 or email privacy.issues@thomsonreuters.com to submit a request to limit processing of sensitive personal information, or use the 'Do not sell or share my personal information/limit the use of my sensitive personal information' link on Thomson Reuters websites.

Cross-platform context

See how other platforms handle Sensitive Personal Information Collection and similar clauses.

Compare across platforms →

Monitoring

Thomson Reuters has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Demographic information Age; date of birth; marriage status; gender; physical characteristics; military status; political, religious, or philosophical beliefs; sexual orientation; racial or ethnic origin; and union membership... Health, benefits, and insurance information Enrollment and participation in insurance or benefits programs; personal information of beneficiaries, family members, emergency contacts, or dependents; medical records; and disability information... Identity information Government identification and governmental identifiers, such as tax identifiers, social security or national insurance numbers, and passport or driver's license numbers

Excerpt from Thomson Reuters's Privacy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1) REGULATORY LANDSCAPE: GDPR Article 9 prohibits processing of special category data including political opinions, religious beliefs, sexual orientation, racial or ethnic origin, trade union membership, and health data except under enumerated lawful bases, most commonly explicit consent or employment necessity. CCPA/CPRA designates government identifiers, health data, racial or ethnic origin, religious beliefs, sexual orientation, and union membership as sensitive personal information subject to opt-out rights and use limitation. Illinois, Texas, and other states impose additional restrictions on specific sensitive categories. 2) GOVERNANCE EXPOSURE: High. The breadth of sensitive categories collected, spanning both employment-context data (medical, disability, union, government ID) and behavioral or demographic profiling categories (political, religious beliefs, sexual orientation), creates a complex multi-framework compliance obligation. GDPR enforcement actions related to special category data processing have resulted in significant regulatory penalties across EU member states. 3) JURISDICTION FLAGS: EU and UK operations face the highest exposure for special category processing under GDPR Article 9 and UK GDPR. California CPRA's sensitive personal information regime imposes use limitation rights. Illinois BIPA intersects with biometric data that may accompany some sensitive category processing. South Africa's POPIA and Brazil's LGPD impose analogous special category protections. 4) CONTRACT AND VENDOR IMPLICATIONS: Employer customers whose employee data is processed through Thomson Reuters HR or benefits-related services should confirm that Thomson Reuters' processing of health, disability, and government identifier data is covered by appropriate data processing agreements specifying the lawful basis, retention periods, and access controls applicable to sensitive categories. 5) COMPLIANCE CONSIDERATIONS: Legal teams should confirm that explicit consent or another GDPR Article 9 lawful basis is documented for each sensitive category processed in EU and UK jurisdictions. CCPA/CPRA compliance teams should verify that the sensitive personal information opt-out mechanism covers all listed sensitive categories and that internal data maps accurately reflect the flow and use of sensitive data across Thomson Reuters products.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Get same-day alerts when this changes → Get Analyst

Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.

Applicable agencies

  • FTC
    The FTC has authority over unfair or deceptive practices related to the collection and use of sensitive personal information categories.
    File a complaint →
  • State AG
    California CPRA, Illinois BIPA, and analogous state sensitive data frameworks create state attorney general enforcement exposure for sensitive personal information processing.
    File a complaint →

Provision details

Document information
Document
Thomson Reuters Privacy
Entity
Thomson Reuters
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-016234
Document ID
CA-D-00720
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
a83ee18dfe057088713d3b01069b111c1d70ed7020e69dee5af3cc20ec960afb
Analysis generated
July 9, 2026 09:54 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Thomson Reuters
Document: Thomson Reuters Privacy
Record ID: CA-P-016234
Captured: 2026-07-09 09:54:14 UTC
SHA-256: a83ee18dfe057088…
URL: https://conductatlas.com/platform/thomson-reuters/thomson-reuters-privacy/provision/CA-P-016234/sensitive-personal-information-collection/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Get Compliance

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Thomson Reuters's Sensitive Personal Information Collection clause do?

This provision establishes that Thomson Reuters collects multiple categories of special category data under GDPR Article 9, sensitive personal information under CCPA/CPRA, and analogously protected categories under other data protection frameworks, each of which imposes heightened lawful basis, consent, and data subject rights requirements beyond those applicable to ordinary personal data.

How does this clause affect you?

Under this clause, Thomson Reuters collects political and religious beliefs, sexual orientation, racial and ethnic origin, union membership, health and medical records, disability status, and government identification numbers. California residents may limit the use of sensitive personal information through the opt-out mechanism described in the statement.

Is ConductAtlas affiliated with Thomson Reuters?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Thomson Reuters.