{"schema":"https://policywatcher.online/schemas/evidence-packet/v1","schemaVersion":"1.0.0","mappingVersion":"2026-07-29.1","changeId":"725582fb-d698-4d30-aeb3-810d221ad7c9","screeningDate":"2026-07-06T22:08:45.291Z","publicationGate":"published","company":{"id":"51f8db0f-3aef-472e-91d7-da30b3ceec4d","name":"Plaid","slug":"plaid","industry":"FinTech"},"policy":{"id":"ef869aae-4fbc-4941-a2c4-ffe1edfe0524","name":"End User Services Agreement","type":"terms","jurisdiction":"EU","sourceUrl":"https://plaid.com/legal"},"sourceConfidence":{"state":"review-required","lastCheckedAt":"2026-07-06T09:39:08.879Z","retrievalChannel":"other","dataStatus":"Available","publicSnapshotEvidence":true,"limitation":"Source confidence describes recorded retrieval and publication state. It does not rate the provider policy or certify source authenticity."},"snapshots":{"old":null,"current":{"version":1,"sha256":"e109c8a4674ca7b407c8e08764e28825d033b7c96b0ecc4575bb674078c4264d","capturedAt":"2026-07-06T22:08:45.286Z"}},"assessment":{"summary":"Plaid accesses your financial account data with explicit consent, sharing it with third-party apps you use, and you can withdraw consent anytime.","overallRisk":"High","overallScore":7,"previousPublicChange":null,"scoreDelta":null,"direction":"baseline","reasons":[{"icon":"warning","textEn":"Extensive financial data collection.","textIt":"Ampia raccolta di dati finanziari.","deltaScore":2,"evidenceQuote":null,"evidenceSide":null,"relatedKpi":null,"anchorStatus":"not-recorded"},{"icon":"alert","textEn":"Broad data sharing with third-party apps.","textIt":"Ampia condivisione dati con app di terze parti.","deltaScore":3,"evidenceQuote":null,"evidenceSide":null,"relatedKpi":null,"anchorStatus":"not-recorded"},{"icon":"warning","textEn":"Limited liability for third-party actions.","textIt":"Responsabilità limitata per azioni di terze parti.","deltaScore":2,"evidenceQuote":null,"evidenceSide":null,"relatedKpi":null,"anchorStatus":"not-recorded"}],"keyPoints":[{"textEn":"Accesses financial data (transactions, balances, personal info) from your EEA bank accounts.","textIt":"Accede a dati finanziari (transazioni, saldi, info personali) dai tuoi conti bancari SEE.","sentiment":"negative"},{"textEn":"Requires explicit consent to access and share your data with third-party applications.","textIt":"Richiede consenso esplicito per accedere e condividere i tuoi dati con app di terze parti.","sentiment":"positive"},{"textEn":"Plaid disclaims liability for third-party app actions or data accuracy from banks.","textIt":"Plaid declina responsabilità per azioni di app terze o accuratezza dati bancari.","sentiment":"negative"},{"textEn":"You can withdraw consent for data access and sharing at any time.","textIt":"Puoi revocare il consenso per l'accesso e la condivisione dei dati in qualsiasi momento.","sentiment":"positive"},{"textEn":"Agreement can be changed with 2 months' notice; you can terminate if you disagree.","textIt":"L'accordo può cambiare con 2 mesi di preavviso; puoi recedere se non sei d'accordo.","sentiment":"neutral"}],"regionImpacts":[{"region":"EU","perspective":"Enterprise","riskLevel":"Medium","impactAnalysisEn":"Businesses using Plaid must ensure their own data processing aligns with GDPR and PSD2, especially regarding consent and data sharing.","complianceNoteEn":"GDPR Art. 28, PSD2"},{"region":"EU","perspective":"Individual","riskLevel":"Medium","impactAnalysisEn":"Your financial data is processed under PSD2 and GDPR. Explicit consent is key, but data sharing with third-party apps requires careful review.","complianceNoteEn":"GDPR Art. 6, PSD2"},{"region":"Global","perspective":"Enterprise","riskLevel":"Medium","impactAnalysisEn":"Companies operating globally must manage complex compliance requirements when handling financial data across jurisdictions.","complianceNoteEn":"International data transfer laws"},{"region":"Global","perspective":"Individual","riskLevel":"Medium","impactAnalysisEn":"Your financial data is highly sensitive. Understand how it's shared and your rights to withdraw consent globally.","complianceNoteEn":"Global data privacy principles"},{"region":"US","perspective":"Enterprise","riskLevel":"Low","impactAnalysisEn":"US companies using Plaid for EEA users must ensure compliance with EEA regulations, even if their primary operations are in the US.","complianceNoteEn":"Cross-border data transfer"},{"region":"US","perspective":"Individual","riskLevel":"Low","impactAnalysisEn":"This policy is EEA-specific. If your data is transferred to the US, it would be subject to US privacy laws like CCPA/CPRA.","complianceNoteEn":"CCPA/CPRA (if applicable)"}],"explanationBoundary":"Score reasons and deltaScore values are stored AI-assisted screening outputs. Verified anchors confirm only that the quoted passage occurs in the named snapshot; they do not prove the interpretation."},"governance":{"boundary":"Mappings identify review relevance between recorded PolicyWatcher KPI fields and framework topics. They are not legal interpretations, conformity assessments, certifications or compliance verdicts.","mappings":[{"framework":{"id":"eu-ai-act","name":"Regulation (EU) 2024/1689 (EU AI Act)","shortName":"EU AI Act","referenceUrl":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","referenceVersion":"Official Journal text, 2024","reviewQuestion":"Which recorded policy statements may be relevant to transparency, automated decisions, data use and human oversight review?","kpiFields":["kpiAiTrainingOptOut","kpiAlgoTransparency","kpiAutomatedDecision","kpiAiBiasFairness"]},"status":"not-assessed","assessedCount":0,"mappedFieldCount":4,"evidence":[]},{"framework":{"id":"iso-42001","name":"ISO/IEC 42001:2023","shortName":"ISO/IEC 42001","referenceUrl":"https://www.iso.org/standard/42001","referenceVersion":"ISO/IEC 42001:2023 overview","reviewQuestion":"Which recorded policy statements may inform an AI management-system review of transparency, risk oversight and independent assurance?","kpiFields":["kpiAlgoTransparency","kpiAiBiasFairness","kpiIndependentAudit","kpiRegulatoryCompliance"]},"status":"not-assessed","assessedCount":0,"mappedFieldCount":4,"evidence":[]},{"framework":{"id":"nist-ai-rmf","name":"NIST AI Risk Management Framework 1.0","shortName":"NIST AI RMF","referenceUrl":"https://www.nist.gov/itl/ai-risk-management-framework","referenceVersion":"AI RMF 1.0; NIST revision in progress, checked 2026-07-29","reviewQuestion":"Which recorded policy statements may support Govern, Map, Measure or Manage review questions?","kpiFields":["kpiAlgoTransparency","kpiAutomatedDecision","kpiAiBiasFairness","kpiContentModeration"]},"status":"not-assessed","assessedCount":0,"mappedFieldCount":4,"evidence":[]},{"framework":{"id":"oecd-ai-principles","name":"OECD AI Principles","shortName":"OECD AI Principles","referenceUrl":"https://oecd.ai/en/ai-principles","referenceVersion":"OECD AI Principles, updated 2024","reviewQuestion":"Which recorded policy statements may be relevant to transparency, fairness, accountability and user agency review?","kpiFields":["kpiConsentMechanism","kpiAlgoTransparency","kpiAiBiasFairness","kpiIndependentAudit"]},"status":"not-assessed","assessedCount":0,"mappedFieldCount":4,"evidence":[]}]},"humanReviewQuestions":["Does the original End User Services Agreement source still match the recorded public snapshot version 1?","Do the cited source passages support each displayed reason, KPI value and regional note?","Which advisory framework topics require specialist legal, risk or governance review for this use case?","Has a later public change superseded this packet before it is reused in a decision or publication?"],"methodologyUrl":"https://policywatcher.online/methodology/confidence","changeUrl":"https://policywatcher.online/change/725582fb-d698-4d30-aeb3-810d221ad7c9","boundary":"This packet records PolicyWatcher evidence and AI-assisted screening for one public change. It is not legal advice, a compliance verdict, a certification, or proof that the external source remains unchanged.","contentDigest":"13d8057e744b928d6e2b930839ffc8e4107eeb21a833dc9ae038ac75cada29e1"}