PolicyWatcherPublic evidence laboratory

Public Evidence Packet

Klarna - Privacy Notice

Privacy Notice

3da8fec6-fc2d-4e26-8901-ca7e27ab6572
Screening date
23 Sept 2026, 17:22 UTC
Jurisdiction
EU
Risk screening
Medium · 6/10
Score trace
+1 points from previous public change

This packet records PolicyWatcher evidence and AI-assisted screening for one public change. It is not legal advice, a compliance verdict, a certification, or proof that the external source remains unchanged.

  1. 01Source evidence
  2. 02Explainability
  3. 03Governance Relevance
  4. 04Report Output
01

Dataset QA · sanitized public view

Source evidence

Publication gate
Published
Retrieval state
Recorded retrieval available
Latest retrieval
23 Sept 2026, 17:22 UTC
Sanitized channel
direct
Data status
Available
Public snapshot evidence
Available

Public snapshot fingerprints

Previous · version 3d8dab3dd70c2134d9b617c931456343b470d2e05b7d10a888147002e178be387Captured 18 Aug 2026, 02:27 UTC
Current · version 410b150f31d6e4e60502364e866a4f9e7750df8d0d7baf1c91d047b6e1b63b241Captured 23 Sept 2026, 17:22 UTC

Source confidence describes recorded retrieval and publication state. It does not rate the provider policy or certify source authenticity.

02

Source-anchored screening trace

Explainability

Klarna's Privacy Notice update clarifies that it collects data from external bank accounts, improving transparency without adding new data types.

  1. Reason 1-1 score contribution

    Clarified external bank data collection improves transparency.

    Related KPI
    Data collection
    Source side
    new snapshot
    Verified exact source passage

    external bank account number

  2. Reason 20 score contribution

    Extensive collection of financial and service-specific data.

    Related KPI
    Data collection
    Source side
    new snapshot
    Verified exact source passage

    Payment information - Credit and debit card details (card number, expiry date and CVV code), external bank account number, bank name, external bank account holder name, bank login details.

  3. Reason 30 score contribution

    Policy allows processing of sensitive personal data with explicit consent.

    Related KPI
    Consent mechanism
    Source side
    new snapshot
    Verified exact source passage

    If the service processes information that constitutes sensitive personal data (e.g., from materials you choose to upload), our processing takes place based on your explicit consent (Article 9(2)(a) GDPR).

Score reasons and deltaScore values are stored AI-assisted screening outputs. Verified anchors confirm only that the quoted passage occurs in the named snapshot; they do not prove the interpretation.

03

Advisory review map

Governance Relevance

EU AI Act

Official Journal text, 2024

Mapped evidence

Which recorded policy statements may be relevant to transparency, automated decisions, data use and human oversight review?

AI training opt-out
Not Available
Algorithmic transparency
Mentioned
Automated decisions
Partial
AI bias and fairness
Absent
Framework source

ISO/IEC 42001

ISO/IEC 42001:2023 overview

Mapped evidence

Which recorded policy statements may inform an AI management-system review of transparency, risk oversight and independent assurance?

Algorithmic transparency
Mentioned
AI bias and fairness
Absent
Independent audit
Absent
Regulatory compliance
Comprehensive
Framework source

NIST AI RMF

AI RMF 1.0; NIST revision in progress, checked 2026-07-29

Mapped evidence

Which recorded policy statements may support Govern, Map, Measure or Manage review questions?

Algorithmic transparency
Mentioned
Automated decisions
Partial
AI bias and fairness
Absent
Framework source

OECD AI Principles

OECD AI Principles, updated 2024

Mapped evidence

Which recorded policy statements may be relevant to transparency, fairness, accountability and user agency review?

Consent mechanism
Explicit Opt-In
Algorithmic transparency
Mentioned
AI bias and fairness
Absent
Independent audit
Absent
Framework source

Mappings identify review relevance between recorded PolicyWatcher KPI fields and framework topics. They are not legal interpretations, conformity assessments, certifications or compliance verdicts.

04

Exact change-bound files

Report Output

Both files are generated from this exact change ID.

Download exact-change PDF Download exact-change JSON
Packet content digest · SHA-2565e32e75f2c0a95d7d9627c4052f431ad4a694c4a474a7357cdb9fc48bc4043ca

Questions before reuse

  1. Does the original Privacy Notice source still match the recorded public snapshot version 4?
  2. Do the cited source passages support each displayed reason, KPI value and regional note?
  3. Which advisory framework topics require specialist legal, risk or governance review for this use case?
  4. Has a later public change superseded this packet before it is reused in a decision or publication?