Contract trap · Privacy policy
Sensitive data collection
The policy allows collecting or inferring special-category data — health conditions, reproductive data, sexual orientation, religion, ethnicity, genetic results, HIV status — and using or sharing it for advertising, analytics or 'partners'; and permits creating face templates, voiceprints or fingerprints from your photos, selfies, calls or voice messages, often by default 'for safety, security and identification'.
- Severity
- Severe
- How often it turns up
- Regular
- Holds up?
- Often void
- Clause phrases
- 24
What it looks like in a contract
Redline matches these phrases against your document verbatim. Drafters rarely invent new wording — they copy it, which is why the same sentences turn up across unrelated contracts.
In English-language contracts
- health information
- reproductive or sexual health
- sexual orientation
- religious or philosophical beliefs
- racial or ethnic origin
- genetic information
- we may infer your interests, including
- sensitive personal information
- biometric information
- facial geometry
- voiceprint
- we may collect and use your biometric information for safety, security and identification purposes
In Russian-language contracts
- специальные категории персональных данных
- сведения о состоянии здоровья
- о расовой, национальной принадлежности
- политических взглядах, религиозных или философских убеждениях
- интимной жизни
- генетические данные
- медицинские данные и диагнозы
- информация о репродуктивном здоровье
- биометрические персональные данные
- изображение лица
- распознавание лиц
- согласие на обработку биометрических персональных данных
Check your own contract
Paste a clause, a page or the whole document. Nothing leaves your browser: the matching runs here, on this page, against the phrases above.
Why it bites
This is the data that gets people fired, denied insurance, outed or targeted; once it reaches ad platforms or brokers it is effectively permanent (BetterHelp, Grindr, Flo); genetic data outlives you and implicates relatives (1Health, 23andMe); biometrics cannot be changed after a leak and have produced the largest privacy settlements in history (Meta $650M BIPA, $1.4B Texas).
Is it enforceable where you are
The same clause can be routine in one country and void in another. What follows is what the law says where you are — not advice on your particular contract.
In the EU and the UK, the GDPR governs the legal basis, the retention period and your right to erasure; in the US, state privacy laws (CCPA/CPRA and its successors) give an opt-out of sale and sharing.
United States
No general ban; FTC Act §5 and the Health Breach Notification Rule used against health-data sharing (GoodRx, BetterHelp, Premom); Washington My Health My Data Act (2024) and CCPA 'sensitive personal information' limits; Illinois BIPA (written consent, retention policy, $1,000-$5,000 per violation — Facebook $650M, Google $100M, Clearview); Texas CUBI (Meta $1.4B, 2024); FTC bans and algorithm disgorgement (Rite Aid 2023, Everalbum 2021); state genetic privacy laws.
- Cited
- BIPA
- CCPA
- FTC Act §5
- Washington My Health My Data Act
European Union
GDPR Art 9: processing prohibited absent explicit consent or listed exceptions, inferences count, biometrics for identification are a special category; Grindr fined for sharing HIV/PrEP-related and GPS data; Clearview AI fined €20M each by CNIL and Garante and €30.5M by the Dutch AP (2024); Meta €1.2B and Amazon €746M show the scale of ad-related penalties.
- Cited
- GDPR Art 9
United Kingdom
UK GDPR Art 9; ICO treats health-data leaks as most serious; ICO fined Clearview AI £7.5M (2022; jurisdiction upheld by the Upper Tribunal 2025).
- Cited
- GDPR Art 9
- ICO
Russia
Ст. 10 152-ФЗ: обработка специальных категорий запрещена без письменного согласия (кроме исключений); ст. 11: биометрия только с письменного согласия; 572-ФЗ (2022): коммерческий сбор биометрии для идентификации через ЕБС/аккредитованные системы, запрет отказывать в услуге за отказ от биометрии; ст. 13.11 ч. 2-2.1 КоАП; с 30 мая 2025 (420-ФЗ) утечка спецкатегорий/биометрии — до 20 млн ₽, повторно 1-3% выручки (биометрия — до 500 млн ₽).
- Cited
- 152-ФЗ
- 420-ФЗ
- 572-ФЗ
- ст. 11
- ст. 13.11 ч. 2
Where this has actually happened
Regulator actions, court rulings and the contracts they were fought over.
- FTC v. BetterHelp (2023) — $7.8M and a ban on sharing health data for advertising; FTC v. Flo Health (2021) and Premom/Easy Healthcare (2023)
- Datatilsynet v. Grindr (2021) — HIV status/PrEP fields and GPS shared with ad partners
- FTC v. 1Health.io/Vitagene (2023) — genetic data exposed, deletion promises broken; 23andMe Chapter 11 (23 Mar 2025) — state AGs urged users to delete genetic data
- In re Facebook Biometric Information Privacy Litigation — $650M BIPA settlement (2021); Texas v. Meta — $1.4B under CUBI/DTPA (30 Jul 2024)
- X (Twitter) privacy policy effective 29 Sept 2023 — 'may collect and use your biometric information for safety, security and identification purposes'
- Clearview AI fines: ICO £7.5M (2022), CNIL €20M, Garante €20M, Dutch AP €30.5M (2024)
What to do
In order, from the thing that takes a minute to the thing that takes a letter.
- Do not use services whose policy permits sharing sensitive data for marketing
- Check for a 'special categories' clause with explicit opt-in
- Refuse selfie/ID verification unless legally required and decline face-tagging and voice features
- Exercise deletion and revoke consent in writing
- RU: sensitive and biometric data require written consent (ст. 10, 11 152-ФЗ) and a business cannot refuse service for declining biometrics (572-ФЗ)
- US Illinois/Texas/Washington: demand written consent and a retention schedule
- Report health data sent to advertisers to the DPA/FTC.
Traps that travel with it
Drafters who use one of these usually use several.