{"schema":"https://policywatcher.online/schemas/evidence-packet/v1","schemaVersion":"1.0.0","mappingVersion":"2026-07-29.1","changeId":"c9aadce8-c90e-46d9-9ad2-372ed55b339d","screeningDate":"2026-07-06T22:09:35.927Z","publicationGate":"published","company":{"id":"51f8db0f-3aef-472e-91d7-da30b3ceec4d","name":"Plaid","slug":"plaid","industry":"FinTech"},"policy":{"id":"912ef5e4-3fe5-45ec-bb2b-74b97970fce1","name":"Privacy Policy","type":"privacy","jurisdiction":"EU","sourceUrl":"https://plaid.com/legal"},"sourceConfidence":{"state":"review-required","lastCheckedAt":"2026-07-06T09:39:08.878Z","retrievalChannel":"other","dataStatus":"Available","publicSnapshotEvidence":true,"limitation":"Source confidence describes recorded retrieval and publication state. It does not rate the provider policy or certify source authenticity."},"snapshots":{"old":null,"current":{"version":1,"sha256":"8cd752cc9c499f6a0c444e9588f418b1fd12628c521190313a626bf51b3baa28","capturedAt":"2026-07-06T22:09:35.920Z"}},"assessment":{"summary":"Plaid collects extensive financial data, uses it for AI training, and shares it broadly, but offers a portal for user control and data deletion.","overallRisk":"High","overallScore":7,"previousPublicChange":null,"scoreDelta":null,"direction":"baseline","reasons":[{"icon":"alert","textEn":"Extensive collection of sensitive financial and personal data.","textIt":"Ampia raccolta di dati finanziari e personali sensibili.","deltaScore":2,"evidenceQuote":null,"evidenceSide":null,"relatedKpi":null,"anchorStatus":"not-recorded"},{"icon":"warning","textEn":"Data explicitly used for AI system development and training.","textIt":"Dati esplicitamente usati per lo sviluppo e l'addestramento di sistemi AI.","deltaScore":2,"evidenceQuote":null,"evidenceSide":null,"relatedKpi":null,"anchorStatus":"not-recorded"},{"icon":"warning","textEn":"Broad sharing of data with third-party app developers.","textIt":"Ampia condivisione di dati con sviluppatori di app di terze parti.","deltaScore":1,"evidenceQuote":null,"evidenceSide":null,"relatedKpi":null,"anchorStatus":"not-recorded"}],"keyPoints":[{"textEn":"Extensive financial and personal data, including potential biometrics, is collected from various sources.","textIt":"Vengono raccolti dati finanziari e personali estesi, inclusi potenziali dati biometrici, da varie fonti.","sentiment":"negative"},{"textEn":"Your data may be used to develop, train, test, and deploy artificial intelligence (AI) systems.","textIt":"I tuoi dati potrebbero essere utilizzati per sviluppare, addestrare, testare e implementare sistemi di intelligenza artificiale (AI).","sentiment":"negative"},{"textEn":"Data is shared broadly with app developers, financial institutions, and service providers.","textIt":"I dati sono ampiamente condivisi con sviluppatori di app, istituzioni finanziarie e fornitori di servizi.","sentiment":"negative"},{"textEn":"Plaid Portal provides tools to view, manage, and delete your data connections and associated data.","textIt":"Plaid Portal offre strumenti per visualizzare, gestire ed eliminare le tue connessioni dati e i dati associati.","sentiment":"positive"},{"textEn":"International data transfers occur, primarily to the US, with safeguards like SCCs and TIAs.","textIt":"Si verificano trasferimenti internazionali di dati, principalmente negli Stati Uniti, con garanzie come SCC e TIA.","sentiment":"neutral"}],"regionImpacts":[{"region":"EU","perspective":"Enterprise","riskLevel":"High","impactAnalysisEn":"Enterprises using Plaid must ensure their data processing aligns with GDPR, DORA (for financial entities), and the AI Act. Managing vendor risk, international data transfers, and data subject rights is critical for compliance.","complianceNoteEn":"GDPR Art. 28, DORA"},{"region":"EU","perspective":"Individual","riskLevel":"High","impactAnalysisEn":"Extensive financial data collection and AI training raise GDPR concerns, especially regarding consent and legitimate interests. International transfers to the US are managed with SCCs and TIAs, but still require careful consideration under GDPR and the upcoming AI Act.","complianceNoteEn":"GDPR Art. 6, 9, 44"},{"region":"Global","perspective":"Enterprise","riskLevel":"High","impactAnalysisEn":"Global enterprises using Plaid must navigate diverse international data protection laws and cross-border data transfer requirements. Robust vendor management and data governance strategies are essential to mitigate compliance risks.","complianceNoteEn":"Cross-border Data Flows"},{"region":"Global","perspective":"Individual","riskLevel":"High","impactAnalysisEn":"Individuals globally face risks due to extensive data collection, AI training, and broad sharing, despite Plaid's user controls. Understanding local data protection rights and exercising them is crucial for privacy.","complianceNoteEn":"Data Protection Principles"},{"region":"US","perspective":"Enterprise","riskLevel":"Medium","impactAnalysisEn":"Businesses integrating Plaid must ensure their use of collected data complies with state-specific privacy laws like CCPA/CPRA and financial regulations. Managing data flows and consumer requests is key for legal adherence.","complianceNoteEn":"CCPA/CPRA, GLBA"},{"region":"US","perspective":"Individual","riskLevel":"Medium","impactAnalysisEn":"The collection of sensitive financial data and potential biometric data (Illinois/Texas) triggers strong privacy rights under CCPA/CPRA. Users have rights to access, delete, and opt-out of sales/sharing, which Plaid Portal supports.","complianceNoteEn":"CCPA/CPRA, BIPA"}],"explanationBoundary":"Score reasons and deltaScore values are stored AI-assisted screening outputs. Verified anchors confirm only that the quoted passage occurs in the named snapshot; they do not prove the interpretation."},"governance":{"boundary":"Mappings identify review relevance between recorded PolicyWatcher KPI fields and framework topics. They are not legal interpretations, conformity assessments, certifications or compliance verdicts.","mappings":[{"framework":{"id":"eu-ai-act","name":"Regulation (EU) 2024/1689 (EU AI Act)","shortName":"EU AI Act","referenceUrl":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","referenceVersion":"Official Journal text, 2024","reviewQuestion":"Which recorded policy statements may be relevant to transparency, automated decisions, data use and human oversight review?","kpiFields":["kpiAiTrainingOptOut","kpiAlgoTransparency","kpiAutomatedDecision","kpiAiBiasFairness"]},"status":"not-assessed","assessedCount":0,"mappedFieldCount":4,"evidence":[]},{"framework":{"id":"iso-42001","name":"ISO/IEC 42001:2023","shortName":"ISO/IEC 42001","referenceUrl":"https://www.iso.org/standard/42001","referenceVersion":"ISO/IEC 42001:2023 overview","reviewQuestion":"Which recorded policy statements may inform an AI management-system review of transparency, risk oversight and independent assurance?","kpiFields":["kpiAlgoTransparency","kpiAiBiasFairness","kpiIndependentAudit","kpiRegulatoryCompliance"]},"status":"not-assessed","assessedCount":0,"mappedFieldCount":4,"evidence":[]},{"framework":{"id":"nist-ai-rmf","name":"NIST AI Risk Management Framework 1.0","shortName":"NIST AI RMF","referenceUrl":"https://www.nist.gov/itl/ai-risk-management-framework","referenceVersion":"AI RMF 1.0; NIST revision in progress, checked 2026-07-29","reviewQuestion":"Which recorded policy statements may support Govern, Map, Measure or Manage review questions?","kpiFields":["kpiAlgoTransparency","kpiAutomatedDecision","kpiAiBiasFairness","kpiContentModeration"]},"status":"not-assessed","assessedCount":0,"mappedFieldCount":4,"evidence":[]},{"framework":{"id":"oecd-ai-principles","name":"OECD AI Principles","shortName":"OECD AI Principles","referenceUrl":"https://oecd.ai/en/ai-principles","referenceVersion":"OECD AI Principles, updated 2024","reviewQuestion":"Which recorded policy statements may be relevant to transparency, fairness, accountability and user agency review?","kpiFields":["kpiConsentMechanism","kpiAlgoTransparency","kpiAiBiasFairness","kpiIndependentAudit"]},"status":"not-assessed","assessedCount":0,"mappedFieldCount":4,"evidence":[]}]},"humanReviewQuestions":["Does the original Privacy Policy source still match the recorded public snapshot version 1?","Do the cited source passages support each displayed reason, KPI value and regional note?","Which advisory framework topics require specialist legal, risk or governance review for this use case?","Has a later public change superseded this packet before it is reused in a decision or publication?"],"methodologyUrl":"https://policywatcher.online/methodology/confidence","changeUrl":"https://policywatcher.online/change/c9aadce8-c90e-46d9-9ad2-372ed55b339d","boundary":"This packet records PolicyWatcher evidence and AI-assisted screening for one public change. It is not legal advice, a compliance verdict, a certification, or proof that the external source remains unchanged.","contentDigest":"f68d2109b73affe2846bfc3b2aea549b4d9e2aa943a24876ae689fd5667f5ab1"}