Walmart · Walmart Privacy Policy · View original document ↗

Sensitive Personal Information Handling

High severity Medium confidence Explicitdocumentlanguage Rare · 2 of 325 platforms
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Walmart Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

Walmart collects sensitive categories of personal information including government ID numbers, health and pharmacy data, precise location, and financial account details, and states it limits the use of this data to purposes disclosed in the notice and permitted by law.

This analysis describes what Walmart's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

The CPRA established specific rights for consumers to limit the use and disclosure of sensitive personal information; the policy's disclosure of sensitive data categories triggers those rights for California residents and creates heightened compliance obligations for Walmart's health and pharmacy data practices.

Interpretive note: Whether Walmart's pharmacy operations qualify as a HIPAA covered entity depends on operational structure and is not explicitly resolved in the privacy notice; the applicability of HIPAA versus state health privacy law requires separate legal analysis.

Consumer impact (what this means for users)

The policy states Walmart collects government ID numbers, precise geolocation, health and medical information from pharmacy interactions, and financial account details as sensitive personal information; California residents have the right under CPRA to direct Walmart to limit the use and disclosure of this sensitive information to what is necessary to perform the requested service.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Opt Out of Arbitration
    Visit https://www.walmart.com/account/privacy and select 'Limit the Use of My Sensitive Personal Information' if you are a California resident. This restricts Walmart's use of sensitive categories including health data, government IDs, and precise location.

Cross-platform context

See how other platforms handle Sensitive Personal Information Handling and similar clauses.

Compare across platforms →

Monitoring

Walmart has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
We collect certain categories of sensitive personal information, including financial account information, government-issued identification numbers, precise geolocation data, health and medical information provided in connection with pharmacy or health services, and information about your race or ethnic origin where voluntarily provided. We use sensitive personal information only for the purposes described in this Notice and do not use or disclose it for purposes other than those permitted under applicable law.

— Excerpt from Walmart's Walmart Privacy Policy

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

1) REGULATORY LANDSCAPE: CPRA Article 1798.121 grants California consumers the right to limit the use and disclosure of sensitive personal information. Health and pharmacy data may separately implicate state health privacy laws and, depending on the context, HIPAA if Walmart's pharmacy operations qualify as a covered entity or business associate. The FTC's health breach notification rule may also apply to non-HIPAA health data. 2) GOVERNANCE EXPOSURE: High. The collection of government-issued identification numbers (driver's license, SSN fragments) in connection with age verification, check cashing, or pharmacy services creates significant data security and identity theft exposure. Health data collected through pharmacy operations may be subject to overlapping state health privacy requirements beyond CPRA. 3) JURISDICTION FLAGS: California CPRA creates the most defined sensitive data framework. Virginia VCDPA, Colorado CPA, Connecticut CTDPA, and Texas TDPSA each contain sensitive data categories and processing restrictions that may differ from CPRA's definitions. Pharmacy health data in states with enacted health privacy legislation (Washington My Health MY Data Act) may require separate consent mechanisms. 4) CONTRACT AND VENDOR IMPLICATIONS: Vendors processing sensitive personal information on Walmart's behalf must be operating under data processing agreements that restrict use to specified service provider purposes. Pharmacy data vendors and health analytics partners require heightened contractual protections. 5) COMPLIANCE CONSIDERATIONS: Compliance teams should verify that the 'Limit the Use of My Sensitive Personal Information' opt-in or opt-out mechanism required by CPRA is clearly presented on Walmart's digital properties. Data mapping should distinguish health-related personal information processed in pharmacy contexts from general customer data to assess HIPAA applicability and state health privacy law obligations.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Watcher free for 14 days

Free: track 1 platform + weekly digest. Watcher: 10 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    The FTC has enforcement authority over the adequacy of sensitive personal information disclosures and health breach notification obligations for non-HIPAA health data.
    File a complaint →
  • Hhs Ocr
    Walmart's pharmacy operations may qualify as a HIPAA-covered entity or interact with covered entities, making health data handling potentially subject to HHS Office for Civil Rights oversight.
    File a complaint →

Provision details

Document information
Document
Walmart Privacy Policy
Entity
Walmart
Document last updated
May 5, 2026
Tracking information
First tracked
May 7, 2026
Last verified
May 12, 2026
Record ID
CA-P-011363
Document ID
CA-D-00617
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
9200be8a92b071fecc372cef5e5d5d41ac0ea9720243d99cf467dc9f3ca2026b
Analysis generated
May 7, 2026 15:27 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Walmart
Document: Walmart Privacy Policy
Record ID: CA-P-011363
Captured: 2026-05-07 15:27:09 UTC
SHA-256: 9200be8a92b071fe…
URL: https://conductatlas.com/platform/walmart/walmart-privacy-policy/sensitive-personal-information-handling/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Professional Governance Intelligence

Need to monitor specific governance provisions?

Professional includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Professional free trial

Or start with Watcher →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Walmart's Sensitive Personal Information Handling clause do?

The CPRA established specific rights for consumers to limit the use and disclosure of sensitive personal information; the policy's disclosure of sensitive data categories triggers those rights for California residents and creates heightened compliance obligations for Walmart's health and pharmacy data practices.

How does this clause affect you?

The policy states Walmart collects government ID numbers, precise geolocation, health and medical information from pharmacy interactions, and financial account details as sensitive personal information; California residents have the right under CPRA to direct Walmart to limit the use and disclosure of this sensitive information to what is necessary to perform the requested service.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 2 platforms. See the full comparison.

Is ConductAtlas affiliated with Walmart?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Walmart.