U.S. Online Privacy Notice
Original documentLAST VERIFIED 2026-10-01
ATTENTION POINTS · 14 TO CHECK · HEURISTIC, NOT LEGAL ADVICE
GDPR / UK-GDPR
4/13 ADDRESSED- Who controls your data (identity & contact of the data controller)GDPR Art. 13(1)(a)
- Data Protection Officer contactGDPR Art. 13(1)(b)
- The legal basis for using your dataGDPR Art. 13(1)(c)
- Legitimate interests relied on (where that is the basis)GDPR Art. 13(1)(d)
- International transfers and their safeguardsGDPR Art. 13(1)(f) / 46
- How long your data is kept (retention)GDPR Art. 13(2)(a)
- Your data-subject rights (access, erasure, portability, object, …)GDPR Arts. 13(2)(b), 15–21
- The right to complain to a supervisory authority (e.g. the ICO)GDPR Art. 13(2)(d)
- Automated decision-making or profilingGDPR Arts. 13(2)(f), 22
CCPA / CPRA
5/10 ADDRESSED- A 'Do Not Sell or Share My Personal Information' option (if it sells/shares)CCPA §1798.135(a)
- A 'Limit the Use of My Sensitive Personal Information' option (CPRA)CPRA §1798.135(a)
- Your CCPA rights (know, delete, correct, opt-out, limit, non-discrimination)CCPA §§1798.100–125
- A non-discrimination promise for exercising your rightsCCPA §1798.125
- At least two ways to submit a request, plus a contactCCPA §1798.130
Last updated June 2025 Your privacy is important to us. We conduct regular assessment reviews and abide by rigorous privacy standards to ensure personal information we collect, use and share is protected. This U.S. Online Privacy Notice ("Notice") describes how Bank of America and our affiliates manage personal information about you when you interact with us online through our websites, event registration sites, mobile applications and social sites ("Sites and Mobile Apps")…
Show full text