Added granular cookie controls and Privacy Preference Center; replaced implicit consent model with explicit category-based opt-in/opt-out framework.
Why it matters: The updated terms establish explicit user control over tracking and data collection on SoFi's website, replacing a prior model where non-selection of preferences implied consent. This shift reflects regulatory alignment with GDPR and CCPA requirements for affirmative consent to non-essential tracking. For users, it creates actionable control over what data is collected and shared; for SoFi, it establishes a documented consent mechanism that may reduce privacy liability.
Added explicit consent requirement for Anthropic model abuse detection; clarified 30-day content retention for abuse detection on identified Bedrock models.
Why it matters: The updated terms introduce a material change in data flow governance: abuse detection on Anthropic models now requires explicit user consent and involves third-party data transfer, rather than remaining an implicit AWS-internal function. This operationally requires organizations to implement consent collection, disclose Anthropic's involvement in user agreements, and review third-party processing addenda. For compliance teams, this expands third-party risk governance and may trigger DPA amendment requirements.
Added promotional partner contact authorization to third-party data sharing disclosures.
Why it matters: The updated Privacy Statement establishes a new third-party data-sharing and contact pathway for promotional code partners. This expands the disclosed recipients of customer personal data beyond Palantir's previously disclosed third-party categories, creating a new contact vector that users should understand before signing up via promotional offers.
Clarifies zero data retention with model providers but adds disclosure that abuse detectors may store data for investigation.
Why it matters: The updated policy clarifies Cursor's data handling practices by explicitly disclosing that abuse detection systems may store data for investigation, even under Privacy Mode. This represents a more specific articulation of actual data handling practices compared to the previous blanket statement, but signals that absolute zero retention is qualified by abuse detection exceptions.
Target revises 899 sentences in Terms and Conditions, including dispute resolution, account management, and service policies.
Why it matters: Target's comprehensive revision of 899 sentences in its Terms and Conditions on June 10, 2026 materially affects the legal framework governing website use, account management, service access, and dispute resolution for all users. The scope of changes (442 added, 216 removed, 241 modified) suggests substantive policy revisions beyond routine updates; users should review the complete updated terms to understand how modified provisions affect their rights regarding account termination, service access, arbitration obligations, and other material terms.
Removed explicit 18+ age requirement statement; added Host Recommendations Directory supplemental terms.
Why it matters: The removal of the explicit 18+ age eligibility statement eliminates a clearly stated contractual requirement that served as a foundational eligibility criterion for both booking and hosting. This change creates regulatory uncertainty under child protection frameworks and leaves users without clear contractual notice of age restrictions, which may complicate platform enforcement and expose Airbnb to regulatory challenge.