Monitored company
Equifax
clause.watch tracks 2 legal documents published by Equifax, re-reading each one every six hours. Below is what each document covers, in plain English.
Privacy Policy
Equifax Privacy Statement: Key Points and Risks
1. Data Collection and Use
Equifax collects extensive personal and sensitive information, including:
- Identity details: name, address, email, phone number, Social Security number, passport and driver’s-license information.
- Financial and credit data: account balances, loan and payment history, bank activity, insurance information, and creditworthiness.
- Employment and education data: job history, compensation, payroll information, education records, and student-loan information.
- Online and device data: browsing and search history, IP address, device identifiers, cookies, geolocation, and interactions with websites, advertisements, and emails.
- Commercial and inferred data: purchases, spending tendencies, profiles, scores, preferences, and other inferences.
- Biometric and support data: photographs, face geometry, identification documents, and recorded or monitored customer-service calls.
Data may come from you, employers, financial institutions, businesses accessing credit reports, government agencies, public records, data brokers, resellers, and devices or browsers.
Equifax uses this information for service delivery, authentication, security, analytics, product development, personalization, marketing, credit and commercial reporting, employment verification, fraud detection, debt recovery, regulatory compliance, and identity management.
Important risk: Equifax’s business model expressly includes collecting and selling data for credit reporting, marketing, fraud prevention, identity services, debt recovery, and other commercial purposes. Some uses are governed by the Fair Credit Reporting Act (FCRA), Gramm-Leach-Bliley Act, or other laws, but not all data uses necessarily have the same protections.
2. User Rights and Choices
Rights depend heavily on your state and the type of data involved.
For California—and similarly covered states—you may generally request to:
- Know or access personal information and its sources and uses.
- Correct inaccurate information, although Equifax says it may delete inaccurate data instead of correcting it.
- Delete information, subject to exceptions.
- Opt out of the sale of personal information, targeted advertising, or certain profiling.
- Limit use or disclosure of sensitive personal information.
- Appeal a denied request in some states.
Requests require identity verification and may require providing additional identifying documents. Deletion rights generally do not apply to information regulated by the FCRA or GLBA, or information retained for fraud prevention. Marketing emails can be unsubscribed from, but operational/account communications will continue.
California residents may also use the state’s centralized DROP data-broker deletion platform.
3. Third-Party Sharing and Selling
Equifax may disclose information to affiliates, service providers, advertising networks, data brokers and resellers, analytics companies, employers, lenders, creditors, collection agencies, insurers, financial institutions, government agencies, social networks, internet providers, identity-verification providers, and operating-system platforms.
It may also disclose information:
- To comply with subpoenas, warrants, court orders, or other legal requirements.
- To investigate fraud, abuse, illegal conduct, security threats, or physical harm.
- During a merger, asset sale, bankruptcy, or corporate restructuring.
Service providers are contractually expected to keep data confidential and use it only for assigned services. However, the policy permits broad commercial sharing and selling, particularly for credit reporting, marketing, fraud detection, workforce services, and debt recovery.
Biometric information is not sold, but may be shared with verification-service providers after consent.
4. AI/ML Training
The policy states that Equifax uses AI and refers to responsible-AI principles. It also specifically states that Equifax does not sell or share consumer personal information with AI or generative-AI developers for model training or development.
However, the policy permits use of data for analytics, modeling, scoring, profiling, product development, and fraud detection. Workforce Solutions may use deidentified employee data for analytics, modeling, and demographic studies where permitted. The policy does not provide a complete technical explanation of whether Equifax trains internal models using personal data, so “no external AI-training sharing” should not be read as a blanket prohibition on all internal machine-learning uses.
5. Key User Obligations and Restrictions
Users should:
- Provide accurate information and complete identity verification where required.
- Obtain appropriate consent when submitting another person’s information.
- Understand that refusing to provide data may prevent Equifax from providing services.
- Review separate FCRA, Workforce Solutions, biometric, cookie, and state-specific notices.
Cookie controls may reduce personalization but generally will not reduce the number of advertisements shown. Strictly necessary cookies cannot be disabled.
6. Liability and Disputes
The statement contains no broad warranty or damages clause governing all disputes. It does state that no transmission or storage is guaranteed to be completely secure and that Equifax cannot warrant the security of information transmitted to it.
For privacy complaints, users may contact Equifax’s Privacy Contact Form or Chief Privacy Officer. EU/UK complaints may proceed through applicable data-protection authorities and, in limited circumstances, binding arbitration under the Data Privacy Framework. FCRA disputes and rights are handled under separate FCRA procedures. The policy does not establish a general lawsuit forum, arbitration requirement, or comprehensive limitation of damages.
7. Policy Changes
Equifax may revise the statement by posting the updated version and its effective date on the website. The policy does not promise individualized notice, email notice, or advance warning. Continued use after posting may expose users to revised practices, so users should periodically check the policy.
Terms of Use
Equifax Terms of Use: Key User Implications
*This summary focuses on the supplied Product Agreement and Site Terms of Use, revised November 11, 2025. The separate Equifax Privacy Policy is incorporated by reference and may contain additional data-use details not included here.*
1. Data Collection and Usage
Equifax may collect, obtain, monitor, and compile:
- Credit information from Equifax and potentially Experian and TransUnion;
- Sensitive personal information, including information covered by the Gramm-Leach-Bliley Act;
- Identity and registration information, such as name, date of birth, Social Security number, addresses, email, telephone number, and other information needed to verify identity;
- Payment and account information for paid products;
- Mobile-carrier information, including subscriber status, payment method, and device details, for identity verification, fraud prevention, and transactions;
- Information from linked financial accounts if you activate Financial Alerts;
- Information about minor children enrolled in Family Plan monitoring;
- Content and feedback submitted to interactive websites or blogs.
By ordering, you provide authorization—or “written instructions” under the FCRA—for Equifax to obtain your credit information to provide the products. You may only order information about yourself, except that a verified parent or legal guardian may enroll eligible minor children.
Equifax may contact you electronically and by telephone, including through automated dialing systems, prerecorded/artificial voice, text, or mobile messages for non-telemarketing purposes. Message and data rates may apply.
2. User Rights
You generally have the right to:
- Obtain free consumer disclosures under federal or state law, including through AnnualCreditReport.com;
- Dispute inaccurate or incomplete information directly with the relevant consumer reporting agency;
- Request fraud alerts and security freezes where legally available;
- Cancel subscription products at any time by telephone or writing;
- Opt out of arbitration within 30 days after first accepting the Agreement;
- Withdraw consent to electronic communications and request paper copies;
- Request access to identity-theft insurance policy summaries where applicable.
The Terms do not provide a detailed privacy-rights framework such as deletion, correction, portability, or opting out of data sales. Those rights, if any, must be assessed under the separate Privacy Policy and applicable state law.
3. Third-Party Sharing
Equifax may share or disclose information to:
- Suppliers, affiliates, service providers, and other companies supporting product delivery, transactions, identity verification, and fraud prevention;
- Consumer reporting agencies and other data providers;
- Mobile carriers for verification-related purposes;
- Third-party financial-account providers when Financial Alerts are enabled;
- Individuals you designate to receive Shared Alerts or a Shared Identity Report;
- Creditors, merchants, banks, bureaus, government entities, and others during identity-theft restoration.
You are responsible for deciding whether to share alerts or identity information. Equifax disclaims responsibility for actions taken by people who receive information you authorize it to share.
4. AI/ML Training
The Terms do not state that user data is used to train artificial-intelligence or machine-learning models. They also do not expressly prohibit such use. The Privacy Policy, product-specific terms, or other disclosures would need to be reviewed for a definitive answer.
The Site Terms state that Equifax may use and distribute submitted “Feedback” without limitation, including to develop and market products. This could potentially include feedback used in analytical or automated systems, although the document does not specifically mention AI training.
5. Key User Obligations and Restrictions
You must:
- Be at least 18 and provide accurate, current information;
- Keep your User ID, password, and PIN confidential;
- Use products only for personal, noncommercial purposes;
- Protect your personal and financial information;
- Cooperate with identity-theft restoration, including providing affidavits, reports, documents, or a limited power of attorney when requested;
- Report qualifying identity theft for restoration assistance within 90 days of discovery;
- Update contact information and notify Equifax if a telephone number changes.
Subscriptions generally renew automatically. Free trials convert to paid memberships unless canceled before the trial ends. Prices may change, and payment information may be automatically updated through card-account updater services.
6. Liability and Disputes
Most disputes must be resolved through individual, binding AAA arbitration, not court. Class actions, class arbitrations, and representative proceedings are waived. Small-claims court remains available for qualifying individual claims. Claims alleging an FCRA violation by EIS are excluded from this arbitration provision.
Equifax disclaims warranties and generally provides products “as is.” It disclaims liability for many direct, indirect, consequential, punitive, emotional-distress, data-loss, and lost-opportunity damages. Where liability is allowed, it is generally capped at amounts paid for the relevant products during the preceding 12 months. Before asserting a claim, you must give written notice and allow Equifax at least 30 days to attempt resolution.
7. Changes and Notice
For the Product Agreement, Equifax says it will:
1. Post amended terms on the Site; and
2. Email an alert about the amendment.
Continued use, payment, or other conduct indicating acceptance binds you to the revised terms. If you reject the changes, you must cancel within 30 days after the email notice.
The Interactive Sites have a broader rule: changes may become effective immediately upon posting, so users should check those terms periodically.
Change history
2026-09-06 · Terms of Use
2026-09-04 · Terms of Use
2026-09-04 · Terms of Use
2026-08-26 · Privacy Policy
2026-08-26 · Privacy Policy
2026-08-22 · Privacy Policy
2026-08-21 · Privacy Policy
2026-08-19 · Terms of Use
2026-08-18 · Privacy Policy
2026-08-18 · Terms of Use
2026-08-18 · Privacy Policy
2025-11-11 · Terms of Use
The publisher records this document as revised on this date (“Last Revised: November 11, 2025”).
Between 2025-04-26 and 2025-09-14 · Privacy Policy
Between 2023-06-01 and 2024-11-16 · Privacy Policy
Between 2022-04-24 and 2023-06-01 · Privacy Policy
Between 2020-06-11 and 2022-04-24 · Privacy Policy
Between 2020-05-29 and 2021-12-02 · Terms of Use
Between 2017-09-17 and 2020-05-29 · Terms of Use
Between 2016-08-30 and 2017-09-17 · Terms of Use