TransUnion · TransUnion Privacy Policy · View original document ↗

Sensitive Personal Information Collection

High severity High confidence Explicitdocumentlanguage Rare · 8 of 343 platforms
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for TransUnion Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

TransUnion may collect highly sensitive categories of personal information including your Social Security number, precise location, biometric identifiers, racial or ethnic origin, health information, and financial account credentials.

This analysis describes what TransUnion's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

These categories of data carry the highest privacy risk; their exposure in a data breach or unauthorized sharing can cause significant harm including identity theft, discrimination, and financial loss.

Consumer impact (what this means for users)

Collection of biometric data, precise geolocation, racial or ethnic origin, and health information alongside financial identifiers means a security incident at TransUnion could expose you to a wide range of personal harms beyond credit fraud.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Export Your Data
    Submit a data access request through TransUnion's privacy portal to receive a copy of the sensitive personal information TransUnion holds about you. Review the categories returned and assess whether you want to exercise deletion or limiting rights.

How other platforms handle this

Ledger Medium

At Ledger, earning and maintaining our users' trust is a top priority. That's why we are deeply committed not only to protecting your privacy and securing your personal data, but also to being fully transparent about how we handle it.

Strava Medium

We may display advertisements on our Services and those advertisements may be targeted to your interests based on your personal information. We may share your personal information with advertising partners for interest-based advertising purposes. You may opt out of interest-based advertising by visi...

eBay Medium

We collect your personal data when you use our Services, create a new eBay account, provide us with information via a web form, add or update information in your eBay account, participate in online community discussions or otherwise interact with us.

See all platforms with this clause type →

Monitoring

TransUnion has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
We may collect the following categories of sensitive personal information: Social Security, driver's license, state identification card, or passport number; Account log-in, financial account, debit card, or credit card number in combination with any required security or access code, password, or credentials allowing access to an account; Precise geolocation; Racial or ethnic origin, religious or philosophical beliefs, or union membership; The contents of mail, email, or text messages unless we are the intended recipient of the communication; Genetic data; Biometric information processed for the purpose of uniquely identifying a consumer; Personal information collected and analyzed concerning a consumer's health; Personal information collected and analyzed concerning a consumer's sex life or sexual orientation.

— Excerpt from TransUnion's TransUnion Privacy Policy

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

REGULATORY LANDSCAPE: Under the CPRA, sensitive personal information receives heightened protection, including the right to limit its use and disclosure beyond what is necessary to perform the disclosed services. The CPRA's implementing regulations, enforced by the California Privacy Protection Agency, require that sensitive data use be limited unless the consumer consents to broader use. Biometric data collection implicates BIPA in Illinois, which requires informed written consent and prohibits profit from biometric identifiers. Health information, depending on its source and use, may engage HIPAA, though TransUnion is not a covered entity in the traditional sense. Precise geolocation data raises additional concerns under state wiretapping and location privacy statutes. GOVERNANCE EXPOSURE: High. The collection of biometric information and health-related data in a commercial credit and data services context is operationally unusual and creates elevated regulatory scrutiny risk, particularly in states with specific biometric and health data statutes. The notice does not clearly articulate the purpose or frequency of biometric data collection, which creates ambiguity about whether BIPA consent requirements are being met. JURISDICTION FLAGS: Illinois BIPA creates a private right of action for biometric data collection without consent, with statutory damages per violation. Washington's My Health MY Data Act may apply to health data collection. California residents have the right to limit use of sensitive personal information. States without specific biometric laws may still regulate collection under general consumer protection authority. CONTRACT AND VENDOR IMPLICATIONS: Organizations receiving TransUnion data that includes sensitive categories should confirm contractually that they are authorized to receive and use such data and that the collection was lawfully conducted. Use of sensitive data in automated decision-making, including credit scoring or employment screening, may trigger additional legal requirements. COMPLIANCE CONSIDERATIONS: Legal teams should verify that each sensitive data category listed is actually collected in TransUnion's current operations and that notice and consent mechanisms match the collection. The right to limit use of sensitive personal information under CPRA should be operationalized and tested. Biometric data collection should be reviewed against BIPA requirements for written consent and a publicly available retention and destruction policy.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Monitor free for 14 days

Free: track 1 platform + weekly digest. Monitor: 25 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    The FTC has authority to investigate unfair or deceptive collection and use of sensitive personal information by data brokers and consumer reporting agencies.
    File a complaint →
  • State AG
    State attorneys general in California, Illinois, and Washington have specific authority over biometric data, health data, and sensitive personal information under state-specific statutes.
    File a complaint →

Applicable regulations

CCPA/CPRA
California, USA
Connecticut Data Privacy Act Amendments
US-CT
FCRA
United States Federal
FTC Act Section 5
United States Federal
GDPR
European Union
GLBA
United States Federal
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
TransUnion Privacy Policy
Entity
TransUnion
Document last updated
May 5, 2026
Tracking information
First tracked
May 8, 2026
Last verified
May 10, 2026
Record ID
CA-P-009411
Document ID
CA-D-00593
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
70807c662f0b1c52c6343a59056ff3ccc90198c94cf07f3874e8fe7d6f563a7f
Analysis generated
May 8, 2026 07:44 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: TransUnion
Document: TransUnion Privacy Policy
Record ID: CA-P-009411
Captured: 2026-05-08 07:44:52 UTC
SHA-256: 70807c662f0b1c52…
URL: https://conductatlas.com/platform/transunion/transunion-privacy-policy/sensitive-personal-information-collection/
Accessed: June 27, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Related Analysis

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Compliance free trial

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does TransUnion's Sensitive Personal Information Collection clause do?

These categories of data carry the highest privacy risk; their exposure in a data breach or unauthorized sharing can cause significant harm including identity theft, discrimination, and financial loss.

How does this clause affect you?

Collection of biometric data, precise geolocation, racial or ethnic origin, and health information alongside financial identifiers means a security incident at TransUnion could expose you to a wide range of personal harms beyond credit fraud.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 8 platforms. See the full comparison.

Is ConductAtlas affiliated with TransUnion?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by TransUnion.