{"schema":"https://policywatcher.online/schemas/evidence-packet/v1","schemaVersion":"1.0.0","mappingVersion":"2026-07-29.1","changeId":"21006935-a215-47d4-bd6d-dd03b775323d","screeningDate":"2026-07-10T01:49:34.563Z","publicationGate":"published","company":{"id":"fc0a9a77-eb4b-432a-8229-00185c53d30e","name":"Klarna","slug":"klarna","industry":"FinTech"},"policy":{"id":"6b03f215-97db-4a24-b92a-22ef3e11fea5","name":"Privacy Notice","type":"privacy","jurisdiction":"US","sourceUrl":"https://www.klarna.com/us/privacy/"},"sourceConfidence":{"state":"verified-retrieval","lastCheckedAt":"2026-08-21T19:01:54.621Z","retrievalChannel":"direct","dataStatus":"Available","publicSnapshotEvidence":true,"limitation":"Source confidence describes recorded retrieval and publication state. It does not rate the provider policy or certify source authenticity."},"snapshots":{"old":{"version":2,"sha256":"81a509728ad2a446629990c6802f8965950701a259f8df28669d5febf11a11c7","capturedAt":"2026-07-06T09:44:43.356Z"},"current":{"version":3,"sha256":"3d0f293b2dd577ed3eedd7740a96b8e5824a669eb84689702f81f81cbb3992ad","capturedAt":"2026-07-10T01:49:34.561Z"}},"assessment":{"summary":"Klarna collects extensive personal and financial data for services, fraud prevention, and marketing, offering some privacy controls and data deletion rights with legal retention limits.","overallRisk":"Medium","overallScore":6,"previousPublicChange":{"id":"1ee4e96e-0be3-46bf-8c66-10c4e8f3718a","overallRisk":"High","overallScore":8,"screeningDate":"2026-07-06T09:44:43.365Z"},"scoreDelta":-2,"direction":"lower","reasons":[{"icon":"warning","textEn":"Extensive data collection for credit, fraud, and marketing.","textIt":"Ampia raccolta dati per credito, frode e marketing.","deltaScore":0,"evidenceQuote":null,"evidenceSide":null,"relatedKpi":null,"anchorStatus":"not-recorded"},{"icon":"warning","textEn":"Broad data sharing with third parties, including for advertising.","textIt":"Ampia condivisione dati con terze parti, anche per pubblicità.","deltaScore":0,"evidenceQuote":null,"evidenceSide":null,"relatedKpi":null,"anchorStatus":"not-recorded"},{"icon":"info","textEn":"Legal obligations allow data retention despite deletion requests.","textIt":"Obblighi legali consentono la conservazione dati nonostante richieste di cancellazione.","deltaScore":0,"evidenceQuote":null,"evidenceSide":null,"relatedKpi":null,"anchorStatus":"not-recorded"}],"keyPoints":[{"textEn":"Extensive data collection for credit checks, app personalization, and fraud prevention.","textIt":"Ampia raccolta dati per controlli credito, personalizzazione app e prevenzione frodi.","sentiment":"negative"},{"textEn":"Data is shared broadly with third parties for various purposes, including marketing and advertising.","textIt":"I dati sono ampiamente condivisi con terze parti per vari scopi, inclusi marketing e pubblicità.","sentiment":"negative"},{"textEn":"Users can access, correct, and request deletion of their data via the Klarna app or account portal.","textIt":"Gli utenti possono accedere, correggere e richiedere la cancellazione dei dati tramite l'app o il portale Klarna.","sentiment":"positive"},{"textEn":"Legal obligations require Klarna to retain some personal data even after deletion requests.","textIt":"Obblighi legali impongono a Klarna di conservare alcuni dati personali anche dopo richieste di cancellazione.","sentiment":"neutral"},{"textEn":"An opt-out option is available for certain data sharing under the GLBA for US residents.","textIt":"Un'opzione di opt-out è disponibile per alcune condivisioni dati sotto GLBA per residenti USA.","sentiment":"positive"}],"regionImpacts":[{"region":"EU","perspective":"Enterprise","riskLevel":"Medium","impactAnalysisEn":"As a financial institution, Klarna faces strict GDPR and DORA compliance for data processing and security. Third-party data sharing needs robust Data Processing Agreements.","complianceNoteEn":"GDPR, DORA"},{"region":"EU","perspective":"Individual","riskLevel":"Medium","impactAnalysisEn":"GDPR grants strong data rights, but Klarna's legal retention clauses may limit full deletion. Data sharing for marketing requires careful consent management.","complianceNoteEn":"GDPR Articles 17, 21"},{"region":"Global","perspective":"Enterprise","riskLevel":"Medium","impactAnalysisEn":"Operating globally requires Klarna to adapt its privacy practices to diverse legal frameworks, ensuring cross-border data transfer mechanisms are compliant.","complianceNoteEn":"Cross-Border Data Transfer"},{"region":"Global","perspective":"Individual","riskLevel":"Medium","impactAnalysisEn":"While general privacy principles are stated, specific rights vary globally. Users should check local laws for additional protections beyond Klarna's policy.","complianceNoteEn":"Global Privacy Standards"},{"region":"US","perspective":"Enterprise","riskLevel":"Medium","impactAnalysisEn":"Klarna must navigate a complex patchwork of state privacy laws (e.g., CCPA, VCDPA) and federal financial regulations like GLBA. Ensuring consistent compliance is challenging.","complianceNoteEn":"GLBA, State Privacy Laws"},{"region":"US","perspective":"Individual","riskLevel":"Medium","impactAnalysisEn":"Users have GLBA opt-out options for data sharing. California residents benefit from CCPA/CPRA rights for access and deletion, though legal retention applies.","complianceNoteEn":"GLBA, CCPA/CPRA"}],"explanationBoundary":"Score reasons and deltaScore values are stored AI-assisted screening outputs. Verified anchors confirm only that the quoted passage occurs in the named snapshot; they do not prove the interpretation."},"governance":{"boundary":"Mappings identify review relevance between recorded PolicyWatcher KPI fields and framework topics. They are not legal interpretations, conformity assessments, certifications or compliance verdicts.","mappings":[{"framework":{"id":"eu-ai-act","name":"Regulation (EU) 2024/1689 (EU AI Act)","shortName":"EU AI Act","referenceUrl":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","referenceVersion":"Official Journal text, 2024","reviewQuestion":"Which recorded policy statements may be relevant to transparency, automated decisions, data use and human oversight review?","kpiFields":["kpiAiTrainingOptOut","kpiAlgoTransparency","kpiAutomatedDecision","kpiAiBiasFairness"]},"status":"mapped","assessedCount":4,"mappedFieldCount":4,"evidence":[{"field":"kpiAiTrainingOptOut","label":"AI training opt-out","value":"Not Available"},{"field":"kpiAlgoTransparency","label":"Algorithmic transparency","value":"Opaque"},{"field":"kpiAutomatedDecision","label":"Automated decisions","value":"Partial"},{"field":"kpiAiBiasFairness","label":"AI bias and fairness","value":"Absent"}]},{"framework":{"id":"iso-42001","name":"ISO/IEC 42001:2023","shortName":"ISO/IEC 42001","referenceUrl":"https://www.iso.org/standard/42001","referenceVersion":"ISO/IEC 42001:2023 overview","reviewQuestion":"Which recorded policy statements may inform an AI management-system review of transparency, risk oversight and independent assurance?","kpiFields":["kpiAlgoTransparency","kpiAiBiasFairness","kpiIndependentAudit","kpiRegulatoryCompliance"]},"status":"mapped","assessedCount":4,"mappedFieldCount":4,"evidence":[{"field":"kpiAlgoTransparency","label":"Algorithmic transparency","value":"Opaque"},{"field":"kpiAiBiasFairness","label":"AI bias and fairness","value":"Absent"},{"field":"kpiIndependentAudit","label":"Independent audit","value":"Mentioned"},{"field":"kpiRegulatoryCompliance","label":"Regulatory compliance","value":"Comprehensive"}]},{"framework":{"id":"nist-ai-rmf","name":"NIST AI Risk Management Framework 1.0","shortName":"NIST AI RMF","referenceUrl":"https://www.nist.gov/itl/ai-risk-management-framework","referenceVersion":"AI RMF 1.0; NIST revision in progress, checked 2026-07-29","reviewQuestion":"Which recorded policy statements may support Govern, Map, Measure or Manage review questions?","kpiFields":["kpiAlgoTransparency","kpiAutomatedDecision","kpiAiBiasFairness","kpiContentModeration"]},"status":"mapped","assessedCount":3,"mappedFieldCount":4,"evidence":[{"field":"kpiAlgoTransparency","label":"Algorithmic transparency","value":"Opaque"},{"field":"kpiAutomatedDecision","label":"Automated decisions","value":"Partial"},{"field":"kpiAiBiasFairness","label":"AI bias and fairness","value":"Absent"}]},{"framework":{"id":"oecd-ai-principles","name":"OECD AI Principles","shortName":"OECD AI Principles","referenceUrl":"https://oecd.ai/en/ai-principles","referenceVersion":"OECD AI Principles, updated 2024","reviewQuestion":"Which recorded policy statements may be relevant to transparency, fairness, accountability and user agency review?","kpiFields":["kpiConsentMechanism","kpiAlgoTransparency","kpiAiBiasFairness","kpiIndependentAudit"]},"status":"mapped","assessedCount":4,"mappedFieldCount":4,"evidence":[{"field":"kpiConsentMechanism","label":"Consent mechanism","value":"Implicit"},{"field":"kpiAlgoTransparency","label":"Algorithmic transparency","value":"Opaque"},{"field":"kpiAiBiasFairness","label":"AI bias and fairness","value":"Absent"},{"field":"kpiIndependentAudit","label":"Independent audit","value":"Mentioned"}]}]},"humanReviewQuestions":["Does the original Privacy Notice source still match the recorded public snapshot version 3?","Do the cited source passages support each displayed reason, KPI value and regional note?","Which advisory framework topics require specialist legal, risk or governance review for this use case?","Has a later public change superseded this packet before it is reused in a decision or publication?"],"methodologyUrl":"https://policywatcher.online/methodology/confidence","changeUrl":"https://policywatcher.online/change/21006935-a215-47d4-bd6d-dd03b775323d","boundary":"This packet records PolicyWatcher evidence and AI-assisted screening for one public change. It is not legal advice, a compliance verdict, a certification, or proof that the external source remains unchanged.","contentDigest":"436ac8da49ab9fe28e4db709488109e61c84e8af136d317f74011743bd1deb22"}