Overview
- The analysis by Netzwerk Datenschutzexpertise cites multiple breaches of the GDPR and Germany’s ZAG, focusing on the use of sensitive financial data beyond payment services.
- Investigators say the Offsite Ads program unlawfully repurposes purchase information to target users on external platforms, contravening purpose limitation rules.
- Consent mechanisms are described as preselected and uninformed, with advertising personalization set by default in a way the report says violates privacy by default requirements.
- The report highlights opaque sharing with roughly 600 potential recipients, questions the legality of cross‑border transfers and PayPal’s Binding Corporate Rules, and says users cannot trace where data goes.
- Authors criticize blanket retention of data for up to ten years after contract end and insufficient transparency about profiling and automated decisions; PayPal states it is examining the report.