Live feed · updated daily
Recent policy changes
3052 policy changes
detected across 352 platforms. Most platforms don't announce policy changes — these updates were detected automatically.
March 8, 2026
Clarified COPPA compliance language for child accounts; removed detailed data collection purpose categories.
Why it matters: The updated policy establishes a narrower definition of personal information collected from children under COPPA (email only) and removes detailed disclosure of how persistent identifiers are used for internal operations. This affects how parents understand child data handling and may influence how organizations process or represent Roblox's child account practices in their own compliance frameworks.
Restructured Terms of Use with embedded AI policies, advertising updates, and regional compliance appendices; removed standalone change summary.
Why it matters: The restructured terms incorporate AI tool disclosures and advertising policies directly into binding user and creator agreements, rather than treating them as supplemental guidance. The addition of six region-specific appendices establishes different contractual terms based on user location, particularly in regulated jurisdictions like the EU and UK. The removal of the standalone change summary eliminates the previous transparency mechanism, requiring users to navigate a 1242-sentence document to understand what changed.
Updated language support from Vietnamese to Thai in Terms of Service.
Why it matters: This change expands accessibility of YouTube Ads' Terms of Service to Thai-speaking users, though no substantive policy modifications occur. Language localization of legal terms ensures users can review binding agreements in their preferred language.
Removes explicit fraud-prevention data disclosures and narrows privacy appeal submission methods to email only.
Why it matters: The removal of explicit fraud-prevention data-sharing disclosure reduces the stated transparency of how customer information flows to government agencies and financial institutions, a practice that typically requires clear disclosure under state consumer privacy laws. The consolidation of privacy appeal submission to email only narrows the procedural accessibility of privacy rights requests and may affect response timelines for users who previously relied on webform submission.
Updated privacy policy page navigation. No substantive terms changed.
Why it matters: This change does not affect your privacy rights or data handling. The substantive privacy policy language remains unchanged; only the page navigation or formatting was updated.
Stay ahead of the changes
You're seeing a fraction of what's changing
ConductAtlas monitors every tracked platform and captures every policy update.
March 6, 2026
Restructured privacy policy separates financial data disclosures by service entity and removes social media product from scope.
Why it matters: The updated policy reorganizes how Robinhood discloses its financial data practices by service entity and separates non-financial data handling to a distinct privacy statement. This change affects how users and compliance teams locate privacy information for specific Robinhood services and makes clear which policy statement governs different types of data collection. The removal of Robinhood Social from this policy's scope creates a practical question about where social media privacy practices are now documented.
Removed chat support navigation from fee schedule
Why it matters: This change removes customer support navigation from the fee schedule but does not modify fees, fee disclosure obligations, or substantive terms. Users will no longer see the chat support prompt within this specific document, but fee information and the advisory that fees are subject to change remain in place.
Removed explicit language describing advertiser data use and direct marketing practices from privacy policy; added Korea-specific addendum reference.
Why it matters: The updated policy removes explicit disclosures about how advertiser data is collected and used to measure ad performance, and eliminates transparency about direct marketing practices. Under privacy laws requiring transparent description of data sources and processing purposes (GDPR, CCPA, PIPA), the absence of these disclosures may create compliance gaps if the practices continue undisclosed, or may clarify that these practices have discontinued. Organizations referencing OpenAI's privacy policy in their own vendor documentation or privacy notices will need to update their compliance materials to reflect the removal of these disclosures.
Updated section references and formatting in privacy policy; no material changes to data practices or user rights.
Why it matters: While operationally insignificant, these corrections ensure that internal cross-references within Coinbase's Privacy Policy are accurate and that users accessing archived versions can locate historical policy language. The changes do not alter data practices or user rights.
Removed Direct Deposit feature documentation, including enrollment and virtual account procedures
Why it matters: The removal of Direct Deposit documentation from Coinbase's principal User Agreement eliminates contractual disclosure of a potentially significant financial feature. If the service remains operational, users no longer have access to official terms explaining enrollment, virtual account mechanics, or service scope. If the service has been discontinued, the removal without explicit notification creates ambiguity about the transition timeline and available alternatives.
Stay ahead of the changes
You're seeing a fraction of what's changing
ConductAtlas monitors every tracked platform and captures every policy update.
Removed navigation menu and footer references from Purchase Protection Program policy; core protections unchanged.
Why it matters: This change does not materially affect the operational terms under which consumers can access purchase protection. The removal of navigation menu items and footer references is a structural adjustment without substantive impact on eligibility, claims procedures, or protection scope.
Updates privacy contact information for South Korea domestic agent and Nevada attorney general email.
Why it matters: The updated contact information ensures that users in South Korea and Nevada can accurately reach the correct contact points for privacy inquiries and complaints as required by applicable data protection regulations in those jurisdictions. Accurate contact details are foundational to compliance with transparency and access rights obligations.
Removed US state privacy disclosures from main statement; simplified data collection language around advertising inferences and voice inputs
Why it matters: The updated statement removes explicit references to key data practices and reorganizes how state privacy rights disclosures are accessed, which affects transparency regarding advertising inferences and voice input collection. The removal of household inference language and voice input mentions narrows what Netflix explicitly discloses about data practices, even if underlying practices continue. For state privacy law compliance, the removal of the direct 'Notice at Collection' reference from the main body may affect whether disclosures meet accessibility and prominence requirements under CCPA and similar laws.
Restructured and condensed membership terms with clearer definitions; removed prior arbitration and dispute resolution language.
Why it matters: The removal of mandatory arbitration language from Netflix's Terms of Use represents a material change to the dispute resolution framework documented in the consumer contract. The prior terms explicitly required users to resolve disputes through arbitration rather than in court, and this language is no longer present in the updated excerpt. If this removal is complete and not offset by replacement language elsewhere in the full document, Netflix consumers would regain access to class action and court-based dispute resolution, which could affect the company's litigation posture and consumer complaint handling procedures. The change also affects how customers understand their contractual rights and remedies available to them.
Reorganized Community Guidelines into categorized structure with expanded explanatory sections and examples
Why it matters: The restructured Community Guidelines establish a more organized, categorized policy document that consolidates guidance previously distributed across multiple pages. This change improves discoverability and clarity of policy rules, making it easier for users and reviewers to locate specific policy categories and understand the reasoning behind restrictions, but does not alter the substantive rules themselves or expand TikTok's enforcement authority.
Updated Conditions of Use with regional delivery location changes and reorganized service navigation.
Why it matters: The updated terms reflect operational changes to customer service navigation and regional delivery information, but do not substantively modify consumer rights, obligations, data processing practices, or dispute resolution procedures. Consumers should review the updated document if they are in the Thailand region or rely on specific service links, but the change does not alter the fundamental terms governing Amazon transactions or service use.
Minor rewordings and formatting adjustments to Microsoft Responsible AI Principles messaging and resource links.
Why it matters: The updated language maintains Microsoft's stated security and compliance commitments while refining how those commitments are presented to business customers. The change does not alter what security requirements are enforced, how data is protected, or what compliance obligations apply to Copilot deployments; it adjusts the marketing framing and resource delivery format.
Clarified data retention criteria including customer expectations, automated deletion controls, and data sensitivity; disclosed 30-day post-deletion retention window.
Why it matters: The updated policy clarifies that deletion is not instantaneous; your data persists for up to 30 days after you take deletion action. This matters because it affects how quickly your data is truly removed from Microsoft's systems and may impact your understanding of data breach risk, data residency, and compliance with privacy regulations that require timely erasure.
Updated country version designation from Vietnam to Thailand; no substantive terms changes.
Why it matters: This change updates the geographic country version associated with Google's Terms of Service but does not modify the substantive rights, obligations, or protections the terms establish. Users are governed by the identical terms and conditions; the change is administrative rather than operational.
March 5, 2026
Added notice of updated data retention policy and additional rights for EU/EEA users effective March 2026.
Why it matters: The updated language establishes that Microsoft has modified its data retention practices in response to regulatory requirements effective March 2026 and has granted additional rights to EEA users. This signals that the underlying data handling framework has changed, but the disclosure itself does not specify what those changes entail, leaving organizations and users without clear operational guidance on how their data will now be retained, processed, or deleted.
Removed disclosure of AI-generated voice marketing call practices from privacy statement.
Why it matters: The removal of explicit disclosure language about a specific marketing contact practice (AI-generated voice auto-dialer calls) creates an absence where the policy previously acknowledged the possibility. For users accustomed to seeing this disclosure in Microsoft's terms, the removal signals a change in how the company describes its marketing practices. For compliance teams, the removal may trigger review of whether TCPA and FTC Act transparency obligations are still adequately addressed under the updated language, and whether vendor documentation needs to be refreshed.
Updated daily. New changes added as detected.