Contract trap · Privacy policy

Sensitive data collection

The policy allows collecting or inferring special-category data — health conditions, reproductive data, sexual orientation, religion, ethnicity, genetic results, HIV status — and using or sharing it for advertising, analytics or 'partners'; and permits creating face templates, voiceprints or fingerprints from your photos, selfies, calls or voice messages, often by default 'for safety, security and identification'.

Severity
Severe
How often it turns up
Regular
Holds up?
Often void
Clause phrases
24

What it looks like in a contract

Redline matches these phrases against your document verbatim. Drafters rarely invent new wording — they copy it, which is why the same sentences turn up across unrelated contracts.

In English-language contracts

  • health information
  • reproductive or sexual health
  • sexual orientation
  • religious or philosophical beliefs
  • racial or ethnic origin
  • genetic information
  • we may infer your interests, including
  • sensitive personal information
  • biometric information
  • facial geometry
  • voiceprint
  • we may collect and use your biometric information for safety, security and identification purposes

In Russian-language contracts

  • специальные категории персональных данных
  • сведения о состоянии здоровья
  • о расовой, национальной принадлежности
  • политических взглядах, религиозных или философских убеждениях
  • интимной жизни
  • генетические данные
  • медицинские данные и диагнозы
  • информация о репродуктивном здоровье
  • биометрические персональные данные
  • изображение лица
  • распознавание лиц
  • согласие на обработку биометрических персональных данных

Check your own contract

Paste a clause, a page or the whole document. Nothing leaves your browser: the matching runs here, on this page, against the phrases above.

Run the full scan on this document

Why it bites

This is the data that gets people fired, denied insurance, outed or targeted; once it reaches ad platforms or brokers it is effectively permanent (BetterHelp, Grindr, Flo); genetic data outlives you and implicates relatives (1Health, 23andMe); biometrics cannot be changed after a leak and have produced the largest privacy settlements in history (Meta $650M BIPA, $1.4B Texas).

Is it enforceable where you are

The same clause can be routine in one country and void in another. What follows is what the law says where you are — not advice on your particular contract.

In the EU and the UK, the GDPR governs the legal basis, the retention period and your right to erasure; in the US, state privacy laws (CCPA/CPRA and its successors) give an opt-out of sale and sharing.

United States

No general ban; FTC Act §5 and the Health Breach Notification Rule used against health-data sharing (GoodRx, BetterHelp, Premom); Washington My Health My Data Act (2024) and CCPA 'sensitive personal information' limits; Illinois BIPA (written consent, retention policy, $1,000-$5,000 per violation — Facebook $650M, Google $100M, Clearview); Texas CUBI (Meta $1.4B, 2024); FTC bans and algorithm disgorgement (Rite Aid 2023, Everalbum 2021); state genetic privacy laws.

  • Cited
  • BIPA
  • CCPA
  • FTC Act §5
  • Washington My Health My Data Act

European Union

GDPR Art 9: processing prohibited absent explicit consent or listed exceptions, inferences count, biometrics for identification are a special category; Grindr fined for sharing HIV/PrEP-related and GPS data; Clearview AI fined €20M each by CNIL and Garante and €30.5M by the Dutch AP (2024); Meta €1.2B and Amazon €746M show the scale of ad-related penalties.

  • Cited
  • GDPR Art 9

United Kingdom

UK GDPR Art 9; ICO treats health-data leaks as most serious; ICO fined Clearview AI £7.5M (2022; jurisdiction upheld by the Upper Tribunal 2025).

  • Cited
  • GDPR Art 9
  • ICO

Russia

Ст. 10 152-ФЗ: обработка специальных категорий запрещена без письменного согласия (кроме исключений); ст. 11: биометрия только с письменного согласия; 572-ФЗ (2022): коммерческий сбор биометрии для идентификации через ЕБС/аккредитованные системы, запрет отказывать в услуге за отказ от биометрии; ст. 13.11 ч. 2-2.1 КоАП; с 30 мая 2025 (420-ФЗ) утечка спецкатегорий/биометрии — до 20 млн ₽, повторно 1-3% выручки (биометрия — до 500 млн ₽).

  • Cited
  • 152-ФЗ
  • 420-ФЗ
  • 572-ФЗ
  • ст. 11
  • ст. 13.11 ч. 2

Where this has actually happened

Regulator actions, court rulings and the contracts they were fought over.

  • FTC v. BetterHelp (2023) — $7.8M and a ban on sharing health data for advertising; FTC v. Flo Health (2021) and Premom/Easy Healthcare (2023)
  • Datatilsynet v. Grindr (2021) — HIV status/PrEP fields and GPS shared with ad partners
  • FTC v. 1Health.io/Vitagene (2023) — genetic data exposed, deletion promises broken; 23andMe Chapter 11 (23 Mar 2025) — state AGs urged users to delete genetic data
  • In re Facebook Biometric Information Privacy Litigation — $650M BIPA settlement (2021); Texas v. Meta — $1.4B under CUBI/DTPA (30 Jul 2024)
  • X (Twitter) privacy policy effective 29 Sept 2023 — 'may collect and use your biometric information for safety, security and identification purposes'
  • Clearview AI fines: ICO £7.5M (2022), CNIL €20M, Garante €20M, Dutch AP €30.5M (2024)

What to do

In order, from the thing that takes a minute to the thing that takes a letter.

  1. Do not use services whose policy permits sharing sensitive data for marketing
  2. Check for a 'special categories' clause with explicit opt-in
  3. Refuse selfie/ID verification unless legally required and decline face-tagging and voice features
  4. Exercise deletion and revoke consent in writing
  5. RU: sensitive and biometric data require written consent (ст. 10, 11 152-ФЗ) and a business cannot refuse service for declining biometrics (572-ФЗ)
  6. US Illinois/Texas/Washington: demand written consent and a retention schedule
  7. Report health data sent to advertisers to the DPA/FTC.

Check your own document

Traps that travel with it

Drafters who use one of these usually use several.

79 traps · 1789 verbatim clause phrases