8 Total
5 High severity
3 Medium severity
0 Low severity
Summary

This is Xfinity's Privacy Policy explaining what personal information Comcast collects about you when you use internet, TV, phone, home security, and mobile services, and how they use and share it. The most important thing to know is that Xfinity collects and may use a wide range of sensitive data about you, including your precise location, cable viewing history, internet browsing activity, voice commands, and home security footage, for purposes that include targeted advertising and sharing with affiliated companies like NBCUniversal and Sky. You can visit xfinity.com/privacy/your-privacy-choices to review and adjust your marketing, advertising, and data-sharing preferences, and residents of states like California, Colorado, and Virginia have additional rights to access, delete, or opt out of certain data uses.

Technical / Legal Breakdown

This document is Xfinity's (Comcast) consumer-facing Privacy Policy, effective November 17, 2025, governing the collection, use, retention, and disclosure of personal information across Xfinity-branded, Comcast-branded, and Xumo-branded services, websites, mobile apps, devices, and third-party data sources. The policy states that Xfinity collects a broad range of personal information including name, address, Social Security number, financial information, precise geolocation, biometric identifiers, internet usage and network activity, cable viewing history, call detail records, voice commands, and information derived from home security sensors and cameras; the terms authorize use of this information for service delivery, marketing, advertising (including interest-based advertising using third-party data), analytics, and sharing with affiliates, business partners, vendors, and in some cases law enforcement. Notably, as a cable operator, Xfinity is subject to the Cable Communications Policy Act (CPPA), which imposes specific consent and disclosure requirements for cable subscriber data that the policy acknowledges; however, the policy also asserts broad use of viewing history and network activity data for advertising purposes, and the scope of consent mechanisms described may warrant evaluation under applicable federal and state law. The policy engages the California Consumer Privacy Act (CCPA/CPRA), the Maine Broadband Customer Privacy Law, the Washington My Health MY Data Act, state-level privacy laws in over fifteen jurisdictions including Colorado, Connecticut, Virginia, and Texas, as well as the Electronic Communications Privacy Act (ECPA) and FTC Act; compliance exposure is heightened by the breadth of sensitive data categories collected (biometrics, precise geolocation, health-adjacent data from home monitoring), the use of that data for advertising, and the policy's acknowledgment of sharing with a wide Comcast family of companies including NBCU and Sky.

Institutional Analysis

Institutional analysis available with Professional

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.

Start Professional free trial
High — 5 provisions
Medium — 3 provisions

Monitoring

Xfinity has updated this document before.

Watcher includes same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →

Professional Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Professional includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Professional free trial

Cross-platform context

See how other platforms handle Affiliate Data Sharing (NBCU, Sky, Comcast Family) and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured March 19, 2026 15:14 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000344
Version ID CA-V-000213
SHA-256 c8033c1eea1555714524e778145559b53d96f6342cba9e61f88a30badab5b915
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans