California Privacy Notice

print Privacy Center Page Print

California Privacy Notice


Privacy Notice for California Residents

This California Consumer Privacy Act Disclosure (“Disclosure”) explains how Discover Financial Services and its subsidiaries* (collectively, “Discover”, “our”, “us” or “we”) collect, use, disclose, share, and retain Personal Information subject to the California Consumer Privacy Act, as amended by the California Privacy Rights Act of 2020 (the “CCPA”). 

This Disclosure applies solely to California residents and covers both online and offline practices (e.g., phone and in-person).

* Discover Bank, DFS Services LLC, PULSE Network LLC, Diners Club International, Ltd., the Discover Global Network, Pulse EFT Association, Inc., DFS Corporate Services LLC, DFS International Incorporated, Discover Products Inc., The Student Loan Corporation, and their affiliates and subsidiaries, including companies related by common ownership or control with a Discover or DFS name and financial companies such as GTC Insurance Agency, Inc.

What is Personal Information? 

Under the CCPA, “Personal Information” is information that identifies, relates to, describes, or could reasonably be linked with a particular California resident or household. The CCPA, however, does not apply to certain information, such as information subject to the Gramm-Leach-Bliley Act (“GLBA”). As a result, this Disclosure does not apply, for example, with respect to information that we collect about California residents who apply for or obtain our financial products and services for personal, family, or household purposes (“GLBA Consumers”).

For more information about how we collect, disclose, and secure information relating to our GLBA Consumers, please refer to our Consumer Privacy Statements. If you have an account relationship with us, you are also able to access important account, transaction, and other information by logging in to your secure account at Discover.com.

Our Information Practices Regarding Personal Information

We collect, use, disclose, share, and retain Personal Information relating to California residents in a variety of contexts, as described below. For example, we collect Personal Information relating to California residents for marketing purposes and from individuals who apply for employment with us or are our employees, vendors, contractors, or similar personnel. The specific Personal Information that we collect, use, disclose, share, and retain, relating to a California resident, will depend on our specific relationship or interaction with that individual.

In the past 12 months, we have collected the following categories of Personal Information relating to California residents:

    Begin 12 item list
  1. Personal identifiers, such as name and mailing address;
  2. Personal Information, as defined in the California Customer Records statute, such as contact information and financial information;
  3. Characteristics of protected classifications under California or federal law, such as age, citizenship, and marital status;
  4. Commercial information, such as transaction and account information;
  5. Internet or electronic network activity information, such as browsing history and interactions with our website;
  6. Geolocation data, such as device location and certain device information;
  7. Biometric data, such as faceprint or a voiceprint;
  8. Sensory data, such as call recordings, audio, electronic, visual, and similar information;
  9. Professional or employment-related information, such as current employment information or employment history;
  10. Education information, such as school and date of graduation;
  11. Inferences drawn from any of the Personal Information listed above to create a profile about, for example, an individual’s preferences and characteristics; and
  12. Sensitive Personal Information, such as certain government identifiers (e.g., social security number, driver’s license number, state identification card number, passport number); account access credentials; or biometric information for the purposes of uniquely identifying a California resident.  For employees, former employees, or applicants, examples of Sensitive Personal Information may also include racial or ethnic origin, religious or philosophical beliefs, union membership, health information, or sex life or sexual orientation.

We may keep Personal Information as long as necessary or relevant for the practices described in this Disclosure or as otherwise required by law. Actual retention periods vary depending on product and service. We use the following to determine retention periods: Personal Information that is needed to provide our products and services as described in this Disclosure, for auditing purposes, to troubleshoot problems or assist with investigations, to enforce our policies and to comply with legal requirements. Laws and regulations require all financial institutions to obtain, verify, and record information that identifies each person for whom we open or have established an account. It is the policy of Discover that our records reflect our customer’s name, physical address, date of birth, and identification number. With respect to records such as customer applications, account statements, and payments on the account, Discover generally retains those records for a minimum of seven years.

In the past 12 months, we have collected the categories of Personal Information set forth above from the following categories of sources:

    Begin 9 item list
  1. Directly from you;
  2. Discover affiliates and subsidiaries;
  3. Online and mobile app services, including cookies, pixel tags, beacons, and software development kits;
  4. Consumer reporting agencies;
  5. Data analytics providers;
  6. Government entities, including federal, state, or local government(s), or other public sources;
  7. Third parties such as social networks and advertising networks;
  8. Businesses or Nonbusinesses that you have authorized or directed to disclose your information to us; and
  9. Service providers or contractors, with whom we have a contractual relationship to perform services on our behalf, or that you have authorized or directed to disclose your information with including data brokers as defined under California law.

We may collect Personal Information to operate, manage, and maintain our business, to provide our products and services, for our employment and vendor management purposes, and to accomplish our business purposes and objectives. For example, we use the Personal Information we collect to:

    Begin 13 item list
  1. Personalize, develop, market, advertise, and provide our products and services (including analytic services);
  2. Provide customer service;
  3. Process payments or transactions, provide financing, or fulfill orders;
  4. Help to ensure security and integrity
  5. Conduct research and data analysis;
  6. Perform identity verification;
  7. Maintain our systems, infrastructure, and facilities including debugging to identify and repair errors that impair existing intended functionality;
  8. Maintain or service accounts;
  9. Conduct risk and security control and monitoring;
  10. Perform audit functions, including auditing interactions with consumers;
  11. Maintain and enhance a product or service;
  12. Verify and provide employment benefits and administration (e.g., employment eligibility, payroll, and performance management); and
  13. Conduct other internal functions, such as investigations or research for technology development, comply with legal obligations, maintain business records, and exercise and defend legal claims and rights.

We do not use or disclose Sensitive Personal Information for purposes other than as specified in CCPA.

In the past 12 months, we have disclosed (see how we help keep your information secure) the following categories of Personal Information relating to California residents to the following categories for our business purposes, as indicated: 

    Begin 8 item list
  1. Personal identifiers, such as name and mailing address, Personal Information, as defined in the California Customer Records statute, such as contact information and financial information, and Professional or employment-related information, such as current employment information or employment history, have been disclosed to Discover affiliates and subsidiaries, service providers, regulatory agencies, law enforcement, and other government entities, consumer reporting agencies, social networks/advertising networks, and data analytics providers;
  2. Characteristics of protected classifications under California or federal law, such as age, citizenship, and marital status, and Education information such as school and date of graduation, have been disclosed to Discover affiliates and subsidiaries, service providers, regulatory agencies, law enforcement, and other government entities, consumer reporting agencies, and data analytics providers;
  3. Commercial information, such as transaction and account information, has been disclosed to Discover affiliates and subsidiaries, service providers, and regulatory agencies, law enforcement, and other government entities;
  4. Internet or electronic network activity information, such as browsing history and interactions with our website, has been disclosed to Discover affiliates and subsidiaries, service providers, and consumer reporting agencies, social networks/advertising networks, and data analytics providers;
  5. Geolocation data, such as device location and certain device information, has been disclosed to Discover affiliates and subsidiaries, service providers, and data analytics providers;
  6. Sensory data, such as call recordings, has been disclosed to Discover affiliates and subsidiaries, service providers, regulatory agencies, law enforcement, and other government entities, and social networks;
  7. Inferences drawn from any of the Personal Information listed above has been disclosed to Discover affiliates and subsidiaries; and
  8. Sensitive Personal Information such as certain government identifiers (e.g., social security number, driver’s license, state identification card, passport number); account access credentials; or processing of biometric information for the purposes of uniquely identify a California resident has been disclosed to service providers, regulatory agencies, law enforcement and other government entities, and consumer reporting agencies.  For employees, former employees or applicants, examples of Sensitive Personal Information may also include racial or ethnic origin, religious or philosophical beliefs, union membership, health information, or sex life or sexual orientation has been disclosed to service providers, regulatory agencies, law enforcement and other government entities.

Additionally, we have disclosed Personal Information to Business or Nonbusiness third parties based upon the consent or at the direction of a California resident to disclose the information.

In the past 12 months, we have shared Personal Identifiers and Internet or electronic network activities information with social networks/advertising networks, and data analytics providers to personalize, market, and advertise our products and services. Discover does not share Personal Information of employees, former employees, job applicants, or minors under 16 years of age. For purposes of this Disclosure, “share” means sharing a consumer’s Personal Information with a third party for cross-contextual behavioral advertising for monetary or other valuable consideration or for the benefit of a business in which no money is exchanged.

In the past 12 months, based upon our actual knowledge, we have not “sold” Personal Information or Sensitive Personal Information relating to California residents (including minors under 16 years of age).  For purposes of this Disclosure, “sold” means the disclosure of Personal Information to a business or third party for monetary or other valuable consideration. 

Your Rights Under the CCPA

If you are a California resident, you may have certain rights over the Personal Information we have about you.  You may request the following:

    Begin 6 item list
  • The categories of Personal Information that we collected about you and the categories of sources from which we collected such information;
  • The business or commercial purposes for collecting Personal Information about you; the categories of third parties to whom we disclosed such Personal Information (if applicable); the categories of Personal Information that we disclosed for a business purpose, and for each category identified, the categories of third parties to whom we disclosed that category of Personal Information (if applicable);
  • Access to specific pieces of Personal Information we collected about you;
  • Deletion of Personal Information that we collected from you;
  • Correction of Personal Information that may be inaccurate;
  • Limitations regarding the use of your Sensitive Personal Information; and
  • Opt-out of sharing Personal Information with third parties for targeted advertising purposes. Exercising this right may result in less targeted or personalized advertising on other digital properties that relate to Discover’s products and services. For more information regarding targeted advertising, see About Our Ads section of our Online Privacy Statement.

In some instances, we may decline to honor your request where an exception applies, such as where the disclosure of Personal Information would adversely affect the rights and freedoms of another consumer, where the Personal Information that we maintain about you is not subject to CCPA requirements, or where the Personal Information is a trade secret. We may also decline to honor your request if we cannot verify your identity or confirm that the Personal Information that we maintain relates to you, or if we cannot verify that you have the authority to make a request on behalf of another individual. 

The CCPA also sets forth exceptions for when a business is not required to delete Personal Information, including but not limited to, where it is reasonably necessary to maintain Personal Information to provide a good or service that you requested, comply with a legal obligation, or to help ensure security and integrity.  As you would reasonably expect, the Sensitive Personal Information we collect, use, and disclose is done so to provide goods and services you requested, thus we cannot limit the use of your Sensitive Personal Information.

Furthermore, we may decline the request to correct Personal Information depending on the nature of the Personal Information, the accuracy of the request, how the information was obtained and the business purposes for which the information was collected, maintained, or used.  To maintain integrity, security and accuracy of your pertinent account information, request for changes may be honored by calling 1-800-DISCOVER or through your account log-in on Discover.com.

Nonetheless, you have the right to be free from unlawful discrimination for exercising your rights under the CCPA.

How to Make a Request

If you are a California resident, you may submit a request by:

  • Submit a request to access, delete, or correct your Personal Information:
    • Online or call us at 1-800-347-0316 to speak to an agent. By submitting a request, we will search for your personal Discover Bank information in connection with our products including banking, credit cards, home loans, personal loans, and student loans.
    • Employees, former employees, or job applicants may also submit a request online. By submitting a request via this link, we will search for your Personal Information within our employment or application records.
  • Submit a request to opt-out of “sharing” using this form. We may use a cookie to immediately effectuate your requests; however, clearing your cookies on this browser or using another browser or device may result in your information being shared. Additionally, you may enable a tool at the browser or device level that automatically communicates your opt-out preferences, such as Global Privacy Control (“GPC”). We will process the GPC signal as a request to opt-out for the browser or device you are using at that time; this may require separate opt-out on other browsers or devices that you use to visit our website.

For information related to PULSEDiners Club International, and Discover Global Network, you may click the appropriate link to visit the website and follow the instructions in the Disclosure for California Residents.

You may only exercise your rights to receive specific pieces of Personal Information twice within a 12-month period. The request must:

  • Provide sufficient information that allows us to reasonably verify you are the person about whom we collected Personal Information, or you are an authorized representative; and
  • Describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.

To respond to your request for access, correction, or deletion, we must verify your identity or authority to make the request and confirm the Personal Information in our systems relates to you or the person for whom you are authorized to make the request. We will use Personal Information provided by you, including your name, home address, email address, date of birth, last four digits of your Social Security number, and telephone number, for security purposes and to verify your identity to make the request.  We will provide you with an identification code via a one-time text message or one-time prerecorded voice message at the telephone number you provide. You will need to provide this identification code to us to continue with your request.  We use a third-party identity verification service to assist with ensuring that you are properly authenticated prior to fulfilling your request.

If you intend to submit a request on behalf of someone else, we must have on file or you must provide to us sufficient documentation, such as an appropriate power of attorney, guardian, conservator or trustee or other such verification confirming you have the authority to act on behalf of the individual for whom you are submitting the request. To submit a request on behalf of someone else, you must call us at 1-800-347-0316.

Contact Us 

If you have questions or concerns regarding the above-mentioned rights or our practices under the CCPA, please call us at 1-800-347-0316.

For general questions, or to learn more about Discover’s consumer privacy statements and practices, please follow these Link to Privacy Statement Contact Us pageinstructions to contact us.

Changes to This California Consumer Privacy Act Disclosure
We may change or update this Disclosure from time to time. When we do, we will post the revised Disclosure on this page. This Disclosure was last updated on June 26, 2023.