Live feed · updated daily
Recent policy changes
3052 policy changes
detected across 352 platforms. Most platforms don't announce policy changes — these updates were detected automatically.
March 19, 2026
Minor interface and navigation updates applied to Target privacy policy; no substantive data practice or rights changes detected.
Why it matters: This change does not materially affect Target's privacy practices or consumer rights under the policy. The updates are formatting and interface modifications that do not alter what data Target collects, how it uses personal information, or what protections or controls the policy establishes.
Added comprehensive Target Circle loyalty program terms including automatic updates without notice and continued-use consent provisions.
Why it matters: The updated terms establish an explicit unilateral modification framework for a major consumer loyalty program, enabling Target to change program features, rewards, data handling, and terms without advance notice. The provision that continued participation constitutes acceptance means members remain bound to updated terms simply by using the program, without affirmative reaffirmation. This operational structure concentrates authority to modify loyalty program governance in Target's hands and depends on members actively opting out if they object to changes rather than proactively consenting to each modification.
Updates Canadian office addresses for data processing responsibility in privacy notice.
Why it matters: The updated addresses ensure Canadian users can identify and contact the correct eBay legal entity responsible for their personal data processing and can direct privacy requests to the appropriate location.
Reorganized Privacy Notice with expanded disclosure of data collection, processing relationships, and data controller accountability.
Why it matters: The updated Privacy Notice operationally establishes Twilio's explicit role as a data controller and maps the scope of data relationships it processes, which clarifies accountability for GDPR, CCPA, and equivalent compliance frameworks. Organizations using Twilio as a vendor must verify that their Data Protection Addenda and customer privacy disclosures remain aligned with Twilio's now-detailed controller role and multi-tier data subject framework.
Removes Brazil from entity-specific contracting structure; adds Japan as separate Twilio jurisdiction; commits to not materially decrease service functionality.
Why it matters: The removal of Brazil from the entity-specific contracting structure creates uncertainty about dispute jurisdiction, applicable law, and data handling for Brazilian customers. The addition of Japan as a separate jurisdiction establishes clearer contractual clarity for Japanese customers. The commitment to preserve functionality protects customers against unilateral removal of core service capabilities, though the definition of 'materially decrease' remains subject to dispute interpretation.
Stay ahead of the changes
You're seeing a fraction of what's changing
ConductAtlas monitors every tracked platform and captures every policy update.
Added UK to server location disclosures in data processing notice
Why it matters: The updated policy clarifies that user data processing occurs in UK data centers in addition to the US and EU. This affects how data location and international transfer disclosures are presented to users and impacts compliance obligations under UK and EU data protection law, particularly regarding the adequacy of transfer mechanisms between jurisdictions.
Restructured privacy policy navigation with new links to Consumer Health Data Privacy and HIPAA notices; removed numbered table of contents.
Why it matters: The updated privacy policy structure changes how users navigate privacy disclosures and obligations. Rather than consulting a single numbered policy, users seeking information about data collection, retention, security, children's privacy, or their own rights must now reference multiple linked documents. This change is operationally significant for compliance teams monitoring Headspace as a vendor, as privacy obligations are now distributed across at least three separate documents (main privacy policy, Consumer Health Data Privacy Policy, HIPAA Notice), requiring verification that all linked disclosures are accessible and complete.
Updated privacy contact channels and added subprocessor disclosure and Data Processing Addendum links.
Why it matters: The contact routing changes ensure that privacy inquiries and data subject requests reach the appropriate functional area (support for general questions, external DPO for rights requests). The explicit linking of subprocessor and DPA documentation improves discoverability of data processing terms that organizations relying on Figma need to evaluate for compliance. Operationally, UK and EEA users now have a dedicated Data Protection Officer contact, reinforcing GDPR-required DPO accessibility.
Added links to Candidate Privacy Notice, Data Processing Addendum, and Figma Subprocessors page in Terms of Service footer.
Why it matters: The updated terms establish more accessible data processing documentation, which is operationally significant for organizations subject to data protection regulations. Availability of a Data Processing Addendum and Subprocessors list allows regulated organizations to evaluate Figma's vendor terms against their own data governance and contracting frameworks, particularly under GDPR and CCPA.
Shifted child privacy certification from CARU to ESRB and simplified data retention language in privacy policy update.
Why it matters: The updated policy removes explicit transparency about what persistent identifiers Nintendo collects from child users and why, which may affect how the policy complies with COPPA's requirement for clear disclosure of information collection practices. The shift from CARU to ESRB changes which independent body audits and enforces Nintendo's compliance with its stated practices. Simplified retention language removes prior detail about how Nintendo handles data based on sensitivity levels, though the practical retention practices may remain unchanged.
Removed account monitoring service descriptions and restructured Plaid Account language to emphasize third-party app onboarding rather than standalone features.
Why it matters: The restructured terms shift how Plaid describes its Plaid Account service, moving away from emphasizing independent account management features and toward positioning the account primarily as a facilitator for third-party app integration. This change does not establish new data authorities or restrictions, but it does refocus the service narrative away from standalone consumer-facing features. Organizations relying on Plaid should confirm the intended effective date, as the document lists December 2023 despite changes being made in March 2026.
Removed collapsible sections and reorganized data collection descriptions in privacy policy; formatting change only.
Why it matters: The updated policy maintains the same privacy practices and disclosures; this change affects how information is presented visually and structurally, not what data Klarna collects or how it is used. The operational practices described in the policy remain unchanged.
Reorganized Terms of Service table of contents with new service category headers and additional agreement cross-references.
Why it matters: The reorganization clarifies the navigation and structure of Klarna's legal agreements by adding explicit service categories and cross-references. This presentational change may improve user ability to locate specific agreements governing payment plans, credit card services, and other products, but does not alter the substantive terms that govern those services.
Removes data correction rights, third-party opt-out protections, and use-limitation requests; adds binding arbitration for disputes.
Why it matters: The removal of documented data correction, deletion, and opt-out rights narrows the contractual protections users have in the published privacy policy and may create compliance gaps under GDPR, FADP, and CCPA, which grant users statutory rights to access, correct, and delete personal data and to object to processing. The addition of binding arbitration establishes a mandatory dispute mechanism that limits judicial recourse. For organizations using Glassdoor as a data processor, these changes may require amendment of existing vendor data processing agreements to ensure user data subject rights are preserved through contract rather than relying on Glassdoor's published policy.
March 15, 2026
Updated document header navigation; no change to substantive terms of service language or user obligations.
Why it matters: This change has no operational significance to the terms that govern user conduct, data handling, or service obligations. The navigation header update does not alter any substantive terms of service language.
Reorganized section structure: moved Generative AI Terms to section XXII, updated all cross-references accordingly.
Why it matters: This change has no material operational significance. It is a structural reorganization that updates the document's internal numbering scheme. The substance of each section, including all protections, obligations, and rights, remains unchanged. Users operating under the updated terms face the same rights and obligations as before the reorganization.
Prohibited children under 13 from using service; removed parental authorization option and child-specific privacy guidance.
Why it matters: The updated terms establish a blanket prohibition on service access for children under 13, eliminating a previously documented pathway for parental authorization. This change operationally narrows Cash App's scope and may reduce COPPA compliance complexity, but it also creates ambiguity around detection procedures and data deletion timelines if child-attributed data is collected prior to age verification.
Updated privacy policy reference numbers and page titles; no substantive privacy practice changes.
Why it matters: This change is administrative rebranding of policy page titles and reference numbers. No substantive privacy terms, data practices, or consumer rights were modified, so the operational impact on how data is collected, used, or protected remains unchanged.
March 13, 2026
Expanded privacy policy scope to include Robinhood Social social media product with state privacy law protections.
Why it matters: The updated privacy statement now explicitly governs Robinhood Social alongside financial services, establishing that different regulatory frameworks apply to different products. This clarifies user expectations about which privacy rules protect each service and consolidates disclosures into a single comprehensive statement rather than requiring users to reference multiple separate notices.
Updated marketing language and resource links in Microsoft Responsible AI Principles; no policy changes.
Why it matters: These are editorial updates to promotional messaging and resource links within a governance principles document. They do not alter substantive policy commitments, security frameworks, or compliance obligations, and therefore have no operational impact on how the principles apply to users or organizations.
Adds disclosure that marketing calls via phone may use auto-dialers and AI-generated voices if you consent.
Why it matters: This disclosure sets clear expectations about how Microsoft may contact users who opt in to phone-based marketing. It informs consumers that automated and AI-generated technology may be used in marketing calls, allowing them to make informed decisions about whether to provide a phone number and consent to marketing contact.
Updated resource links and descriptive language in Responsible AI hub; no substantive policy or commitment changes detected.
Why it matters: While these changes are minor, they reflect how Microsoft presents its Responsible AI governance and commitments to users and partners. The shift from 'e-book' to 'webinar' reflects a change in recommended educational format for learning about responsible AI practices, but substantive commitments and governance frameworks remain unchanged.
Removes EEA user rights language and adds consent-based auto-dialer marketing contact authorization using AI-generated voice.
Why it matters: The updated policy establishes explicit authorization for Microsoft to initiate automated marketing calls using AI-generated voice technology where user consent to phone marketing has been given. This creates operational implications for users who provide phone numbers and have opted into marketing contact: they may now receive calls from automated systems. Simultaneously, the removal of language describing EEA user rights narrows the explicit protections stated in the policy for that region, which may have regulatory implications if those rights represented statutory disclosures rather than contractual commitments.
Stay ahead of the changes
You're seeing a fraction of what's changing
ConductAtlas monitors every tracked platform and captures every policy update.
March 10, 2026
Adds Direct Deposit feature allowing users to receive paychecks and government benefits into Coinbase Accounts using virtual routing numbers
Why it matters: The updated terms formally establish the operational and contractual framework for a new Direct Deposit feature, clarifying how virtual account numbers function and what representations Coinbase does and does not make about user employment status or account ownership. This language creates contractual certainty about the feature's scope and limits, which affects how users, employers, and payroll processors interact with the service.
Removed dedicated sections on data retention, user rights, security, and children protections; reorganized policy with jurisdiction-specific routing.
Why it matters: The removal of seven dedicated policy sections, including those addressing data retention, consumer rights, security, and child protections, reduces the transparency and accessibility of core privacy disclosures previously consolidated in standalone form. The reorganization and jurisdiction-specific fragmentation may create compliance documentation challenges and may obscure consumer remedies and protections that were previously clearly delineated.
Formatting and structural revisions to Terms of Use; no material operational changes to consumer rights or obligations.
Why it matters: This is an administrative update with minimal operational significance. The removal of formatting artifacts and reference markers does not alter the substantive rights, restrictions, or protections that govern your use of OpenAI's services. The core terms remain in effect as stated in the January 1, 2026 effective date.
Updated daily. New changes added as detected.