PayPal collects an unusually broad set of financial, behavioural, and biometric data — then retains it for ten years after you close your account. Automated systems can freeze or terminate your account with limited recourse, your purchase history is shared with merchants for personalised shopping by default, and your data trains PayPal's AI models. Some of this is legally required for a financial institution, but much is not.
No known public data breaches
PayPal does not appear in the Have I Been Pwned database of publicly disclosed data breaches.