{"schema":"https://policywatcher.online/schemas/evidence-packet/v1","schemaVersion":"1.0.0","mappingVersion":"2026-07-29.1","changeId":"46e33448-2d8e-4346-86d9-2a11d0c85145","screeningDate":"2026-10-01T19:54:31.822Z","publicationGate":"published","company":{"id":"fc0a9a77-eb4b-432a-8229-00185c53d30e","name":"Klarna","slug":"klarna","industry":"FinTech"},"policy":{"id":"6b03f215-97db-4a24-b92a-22ef3e11fea5","name":"Privacy Notice","type":"privacy","jurisdiction":"US","sourceUrl":"https://www.klarna.com/us/privacy/"},"sourceConfidence":{"state":"verified-retrieval","lastCheckedAt":"2026-10-01T19:54:31.812Z","retrievalChannel":"direct","dataStatus":"Available","publicSnapshotEvidence":true,"limitation":"Source confidence describes recorded retrieval and publication state. It does not rate the provider policy or certify source authenticity."},"snapshots":{"old":{"version":4,"sha256":"f3bc1b1097b6a4d10e619574a62661def001dbf5bae929a7dae4de3f011cde63","capturedAt":"2026-08-18T02:27:24.180Z"},"current":{"version":5,"sha256":"23a8f8ff13afd975658f2fbef695ce533e382807168d79a08e63ce04cc33b737","capturedAt":"2026-10-01T19:54:31.816Z"}},"assessment":{"summary":"Klarna's updated policy expands data sharing and removes a key privacy assurance for Travel eSIM internet browsing data, increasing user risk.","overallRisk":"High","overallScore":8,"previousPublicChange":{"id":"21006935-a215-47d4-bd6d-dd03b775323d","overallRisk":"Medium","overallScore":6,"screeningDate":"2026-07-10T01:49:34.563Z"},"scoreDelta":2,"direction":"higher","reasons":[{"icon":"alert","textEn":"Removed explicit assurance on Travel eSIM internet browsing data access.","textIt":"Rimossa la garanzia esplicita sull'accesso ai dati di navigazione internet Travel eSIM.","deltaScore":3,"evidenceQuote":"Neither Klarna (including all Klarna group companies), nor Gigs Wireless LLC has access to the content of your internet browsing data.","evidenceSide":"old","relatedKpi":"kpiDataCollection","anchorStatus":"verified"},{"icon":"warning","textEn":"New sharing of phone numbers with third-party linking providers for Open Banking.","textIt":"Nuova condivisione di numeri di telefono con fornitori di link di terze parti per Open Banking.","deltaScore":2,"evidenceQuote":"When you connect a bank account, we may share your phone number with our third-party linking provider(s) to check your eligibility for faster linking options and, if eligible, complete the connection.","evidenceSide":"new","relatedKpi":"kpiThirdPartySharing","anchorStatus":"verified"},{"icon":"warning","textEn":"New sharing with digital wallet and payment platform providers.","textIt":"Nuova condivisione con fornitori di portafogli digitali e piattaforme di pagamento.","deltaScore":1,"evidenceQuote":"Digital wallet and payment platform providers, to enable card features (such as displaying your account balance and available credit on your device) when you add your Klarna card to a digital wallet.","evidenceSide":"new","relatedKpi":"kpiThirdPartySharing","anchorStatus":"verified"}],"keyPoints":[{"textEn":"Klarna now shares your phone number with third parties for faster Open Banking connections.","textIt":"Klarna ora condivide il tuo numero di telefono con terze parti per connessioni Open Banking più veloci.","sentiment":"negative"},{"textEn":"Personal information may be shared with digital wallet and payment platform providers.","textIt":"Le informazioni personali possono essere condivise con fornitori di portafogli digitali e piattaforme di pagamento.","sentiment":"negative"},{"textEn":"The explicit assurance against accessing Travel eSIM internet browsing data has been removed.","textIt":"La garanzia esplicita contro l'accesso ai dati di navigazione internet di Travel eSIM è stata rimossa.","sentiment":"negative"},{"textEn":"Automated decision-making processes for credit eligibility and fraud prevention are still in use.","textIt":"I processi decisionali automatizzati per l'idoneità al credito e la prevenzione delle frodi sono ancora in uso.","sentiment":"neutral"}],"regionImpacts":[{"region":"EU","perspective":"Enterprise","riskLevel":"High","impactAnalysisEn":"Klarna's expanded data sharing and reduced transparency, especially regarding eSIM data, could lead to increased scrutiny from EU regulators. Enterprises partnering with Klarna must ensure their own compliance obligations are met, particularly concerning data processing agreements and cross-border transfers. The AI Act may also apply to automated decision-making.","complianceNoteEn":"GDPR Art. 28, AI Act"},{"region":"EU","perspective":"Individual","riskLevel":"High","impactAnalysisEn":"The removal of explicit data access assurance for eSIM browsing data raises significant concerns under GDPR principles of transparency and data minimization. New third-party sharing increases the attack surface for personal data. Individuals should be cautious about using these services.","complianceNoteEn":"GDPR Art. 5, 6, 13"},{"region":"Global","perspective":"Enterprise","riskLevel":"High","impactAnalysisEn":"Enterprises globally using Klarna's services must reassess their data processing agreements and ensure robust due diligence. The policy changes, especially the removed data assurance, could expose businesses to compliance gaps and reputational risks in diverse regulatory environments. Proactive communication with Klarna is advised.","complianceNoteEn":null},{"region":"Global","perspective":"Individual","riskLevel":"High","impactAnalysisEn":"Globally, users face increased data sharing with third parties and a concerning lack of transparency regarding eSIM internet browsing data. This could lead to a higher risk of data misuse or unauthorized access, impacting privacy rights across various jurisdictions. Users should exercise caution and review their settings.","complianceNoteEn":null},{"region":"US","perspective":"Enterprise","riskLevel":"High","impactAnalysisEn":"Klarna's policy changes, particularly the expanded third-party sharing and the ambiguity around eSIM data, increase compliance risks for businesses. Partners must verify Klarna's adherence to US state privacy laws like CCPA/CPRA, especially regarding data sales and consumer rights. The lack of explicit data protection could lead to reputational damage.","complianceNoteEn":"CCPA/CPRA, FTC Act"},{"region":"US","perspective":"Individual","riskLevel":"High","impactAnalysisEn":"New data sharing practices, including phone numbers for Open Banking and digital wallet integration, expand the scope of personal data processing. The removal of the eSIM data access assurance is a significant privacy concern, potentially impacting rights under CCPA/CPRA and other state privacy laws.","complianceNoteEn":"CCPA/CPRA, State Privacy Laws"}],"explanationBoundary":"Score reasons and deltaScore values are stored AI-assisted screening outputs. Verified anchors confirm only that the quoted passage occurs in the named snapshot; they do not prove the interpretation."},"governance":{"boundary":"Mappings identify review relevance between recorded PolicyWatcher KPI fields and framework topics. They are not legal interpretations, conformity assessments, certifications or compliance verdicts.","mappings":[{"framework":{"id":"eu-ai-act","name":"Regulation (EU) 2024/1689 (EU AI Act)","shortName":"EU AI Act","referenceUrl":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","referenceVersion":"Official Journal text, 2024","reviewQuestion":"Which recorded policy statements may be relevant to transparency, automated decisions, data use and human oversight review?","kpiFields":["kpiAiTrainingOptOut","kpiAlgoTransparency","kpiAutomatedDecision","kpiAiBiasFairness"]},"status":"mapped","assessedCount":4,"mappedFieldCount":4,"evidence":[{"field":"kpiAiTrainingOptOut","label":"AI training opt-out","value":"Opt-Out"},{"field":"kpiAlgoTransparency","label":"Algorithmic transparency","value":"Mentioned"},{"field":"kpiAutomatedDecision","label":"Automated decisions","value":"Partial"},{"field":"kpiAiBiasFairness","label":"AI bias and fairness","value":"Absent"}]},{"framework":{"id":"iso-42001","name":"ISO/IEC 42001:2023","shortName":"ISO/IEC 42001","referenceUrl":"https://www.iso.org/standard/42001","referenceVersion":"ISO/IEC 42001:2023 overview","reviewQuestion":"Which recorded policy statements may inform an AI management-system review of transparency, risk oversight and independent assurance?","kpiFields":["kpiAlgoTransparency","kpiAiBiasFairness","kpiIndependentAudit","kpiRegulatoryCompliance"]},"status":"mapped","assessedCount":4,"mappedFieldCount":4,"evidence":[{"field":"kpiAlgoTransparency","label":"Algorithmic transparency","value":"Mentioned"},{"field":"kpiAiBiasFairness","label":"AI bias and fairness","value":"Absent"},{"field":"kpiIndependentAudit","label":"Independent audit","value":"Absent"},{"field":"kpiRegulatoryCompliance","label":"Regulatory compliance","value":"Partial"}]},{"framework":{"id":"nist-ai-rmf","name":"NIST AI Risk Management Framework 1.0","shortName":"NIST AI RMF","referenceUrl":"https://www.nist.gov/itl/ai-risk-management-framework","referenceVersion":"AI RMF 1.0; NIST revision in progress, checked 2026-07-29","reviewQuestion":"Which recorded policy statements may support Govern, Map, Measure or Manage review questions?","kpiFields":["kpiAlgoTransparency","kpiAutomatedDecision","kpiAiBiasFairness","kpiContentModeration"]},"status":"mapped","assessedCount":4,"mappedFieldCount":4,"evidence":[{"field":"kpiAlgoTransparency","label":"Algorithmic transparency","value":"Mentioned"},{"field":"kpiAutomatedDecision","label":"Automated decisions","value":"Partial"},{"field":"kpiAiBiasFairness","label":"AI bias and fairness","value":"Absent"},{"field":"kpiContentModeration","label":"Content moderation","value":"Opaque"}]},{"framework":{"id":"oecd-ai-principles","name":"OECD AI Principles","shortName":"OECD AI Principles","referenceUrl":"https://oecd.ai/en/ai-principles","referenceVersion":"OECD AI Principles, updated 2024","reviewQuestion":"Which recorded policy statements may be relevant to transparency, fairness, accountability and user agency review?","kpiFields":["kpiConsentMechanism","kpiAlgoTransparency","kpiAiBiasFairness","kpiIndependentAudit"]},"status":"mapped","assessedCount":4,"mappedFieldCount":4,"evidence":[{"field":"kpiConsentMechanism","label":"Consent mechanism","value":"Implicit"},{"field":"kpiAlgoTransparency","label":"Algorithmic transparency","value":"Mentioned"},{"field":"kpiAiBiasFairness","label":"AI bias and fairness","value":"Absent"},{"field":"kpiIndependentAudit","label":"Independent audit","value":"Absent"}]}]},"humanReviewQuestions":["Does the original Privacy Notice source still match the recorded public snapshot version 5?","Do the cited source passages support each displayed reason, KPI value and regional note?","Which advisory framework topics require specialist legal, risk or governance review for this use case?","Has a later public change superseded this packet before it is reused in a decision or publication?"],"methodologyUrl":"https://policywatcher.online/methodology/confidence","changeUrl":"https://policywatcher.online/change/46e33448-2d8e-4346-86d9-2a11d0c85145","boundary":"This packet records PolicyWatcher evidence and AI-assisted screening for one public change. It is not legal advice, a compliance verdict, a certification, or proof that the external source remains unchanged.","contentDigest":"375f6feefdfe247920a0bc3a268c7ac77c4d0c27b32faaaa634b3cc69d73dc85"}