data report card

Data Report Card · American Express

American Express Data Report Card

Card issuer · American Express Company
Data
Practices
1Access1Portability1Friction1Deletion1Sells1Trains AI
=
C
6/12
Agent
Readiness
1Access 1Portability 2API access
=
C
4/6

Agent Readiness is a derived signal — a synthesis of two existing cells (Access, Portability) plus one sourced factor (API access), not an independently measured grade. API access scale: Best (2) consumer-grantable API · Moderate (1) partial / encumbered · Restrictive (0) manual export only. What is Agent Readiness?

Help me make a request →
Reviewed Jun 2026 · policies are checked weekly for changes  ·  stated — every cell is read from American Express's published policy; none has been tested (run by us) yet.
1Accessstated
Amex grants a CCPA right to access your personal information in a portable format, but to exercise it you must visit the Privacy Center, call 1 (800) 528-4800, or the number on your card — a request-mediated path, not a self-serve in-product data dashboard.
Amex — California Privacy Notice (eff. Feb 19, 2026) · accessed Jun 2026 ↗
1Portabilitystated
Amex offers self-serve download of transaction data in structured machine-readable formats (CSV, OFX, QFX, plus Quicken/QuickBooks/Excel year-end summaries) from the online Statements & Activity page, but this covers transactions only — the whole-account CCPA export format is unspecified. Scored on data scope, not format count: with no documented structured whole-account export, portability is at the partial level.
Amex — Download Transactions & Statements FAQ (page CSS-only; formats corroborated via secondary sources) · accessed Jun 2026 ↗
1Frictionstated
A CCPA access/deletion/correction request is request-mediated (Privacy Center web form or phone), not a one-click in-product action, and Amex's notice publishes no specific day-count SLA (the 45-day figure is the statutory CCPA baseline, not stated by Amex).
Amex — California Privacy Notice §6 (eff. Feb 19, 2026) · accessed Jun 2026 ↗
1Deletionstated
Amex offers CCPA deletion but notes the right is "subject to limitations, such as when we are retaining personal information to comply with our own legal obligations," and GLBA-protected financial data is carved out of the CCPA notice entirely — the transaction/account core is legally retained under financial-recordkeeping law, not withheld arbitrarily.
Amex — California Privacy Notice §5/§4 + U.S. Consumer GLBA Notice (Rev. 3/2024) · accessed Jun 2026 ↗
1Sells / sharesstated
Amex states "We do not sell personal information" but expressly shares data for cross-context behavioral advertising with a "Do Not Sell or Share" opt-out link and Global Privacy Control support; its GLBA notice separately confirms it shares with affiliates and for joint marketing by default (only creditworthiness/affiliate-marketing sharing is opt-out-able), so sharing is scored at the shares-with-opt-out level.
Amex — California Privacy Notice §3/§6 + U.S. Consumer GLBA Notice (Rev. 3/2024) · accessed Jun 2026 ↗
1Trains AIstated
Amex discloses it uses AI, automated decision-making systems and machine-learning models for security, fraud, risk and certain automated decisions, but its consumer privacy statements are silent on whether customer personal data is used to train general AI models and offer no training-specific opt-out, so model-training use is scored at the unclear level.
Amex — Online Privacy Statement (page CSS-only; AI/ML language corroborated via indexed excerpts) · accessed Jun 2026 ↗
2API access — feeds Agent Readiness, not the /12stated
Amex operates a real customer-permissioned Open Banking / Account Financials API using OAuth2, OpenID Connect and Financial-grade API (FAPI) standards, letting you grant and revoke third-party app connections (via Plaid, MX, Akoya) without sharing your Amex password; access is aggregator-mediated rather than a first-party consumer developer key, but is genuinely consumer-directed, tokenized and manageable. (Context: the CFPB Section 1033 open-banking rule is currently enjoined and under reconsideration, so this access is voluntary/contractual, not mandated.)
Amex — Developer Open Banking portal (page CSS-only; OAuth/FAPI + Plaid details corroborated via secondary sources) · accessed Jun 2026 ↗
Reviewed Jun 2026 from American Express's own California Privacy Notice (effective Feb 19, 2026) and U.S. Consumer GLBA Privacy Notice (Rev. 3/2024), which were read in full, plus corroborating secondary sources where amex.com pages returned CSS/JS-only to automated fetch (transaction-export formats, AI/ML language, and the Open Banking OAuth/FAPI details). All cells "stated", not tested. Amex is a regulated financial institution, so its transaction core is legally retained under financial-recordkeeping law and its deletion score reflects that floor.

How to request your data from American Express

  1. Go to https://www.americanexpress.com/us/privacy-center/ — American Express's data-request entry point.
  2. Privacy Center CCPA request form or 1 (800) 528-4800 for right-to-know/delete/correct; self-serve transaction export (CSV/OFX/QFX) via Statements & Activity.
  3. Expected wait: request-mediated CCPA access/deletion (Privacy Center web form or phone), statutory 45-day baseline; self-serve transaction export in CSV/OFX/QFX; transaction core legally retained under financial-recordkeeping law; consumer-permissioned Open Banking OAuth/FAPI access via aggregators — American Express's stated turnaround (we haven't independently timed a request yet).
  4. No self-serve option, or want a formal request? Contact Amex Privacy Center: https://www.americanexpress.com/content/dam/amex/us/company/Privacy/California_Privacy_Notice.pdf.

These steps reflect American Express's documented process as of Jun 2026. The wait time is the company's stated figure, not yet independently measured by us.