Old version
August 16, 2026 00:24 UTC
0b2a44256be68eee205b71b8e88be8d804634b66114940c8da6f92ce512f41b9
CA-V-005835
New version
August 23, 2026 00:22 UTC
2951de1b4eb7d583aecfe487a3c3f6daf474904d2c7468132f9c842e53ad21cc
CA-V-006019
Share 𝕏 Share in Share
Change Summary
Perplexity AI restructured its Data Processing Addendum in an update detected on August 23, 2026, adding section numbering (1-12) to organizational headings and clarifying language around data subject rights and subprocessor liability. The substantive obligations—customer compliance with privacy laws, Perplexity's processing restrictions, breach notification, data deletion timelines, and data protection assistance—remain materially unchanged. This appears to be an organizational and clarification update with no material expansion or contraction of either party's data protection obligations.
low severity
1 Sentences added
0 Sentences removed
14 Sentences modified
70 Sentences before
71 Sentences after
Added
Removed
Modified
BeforeAfter
11In the event of any conflicts between this DPA and the Agreement, the DPA shall control.11In the event of any conflicts between this DPA and the Agreement, the DPA shall control. 1.
16The terms “ Business ,” “ Controller ,” “ Data Subject ,” “ Processor ,” “ Process ,” “ Sell ,” “ Service Provider ,” and “ Share ” shall have the meaning given to them under applicable Privacy Laws.16The terms “ Business ,” “ Controller ,” “ Data Subject ,” “ Processor ,” “ Process ,” “ Sell ,” “ Service Provider ,” and “ Share ” shall have the meaning given to them under applicable Privacy Laws. 2.
18The Parties acknowledge that in relation to any Personal Data received from Customer in providing the Services, for purposes of Privacy Laws, Customer is the Controller or Processor or Business and Perplexity is the Service Provider or Processor.18The Parties acknowledge that in relation to any Personal Data received from Customer in providing the Services, for purposes of Privacy Laws, Customer is the Controller or Processor or Business and Perplexity is the Service Provider or Processor. 3.
19Customer Obligations: Customer shall comply with all applicable Privacy Laws in providing Personal Data to Perplexity in connection with its use of the Services, including the use of any integrations with the Services.19Customer Obligations.
20Customer shall comply with all applicable Privacy Laws in providing Personal Data to Perplexity in connection with its use of the Services, including the use of any integrations with the Services.
22Customer shall notify Perplexity immediately if Customer makes a determination that the processing of Personal Data under the Agreement does not or will not comply with Privacy Laws, in which case, Perplexity shall not be required to continue processing such Personal Data.23Customer shall notify Perplexity immediately if Customer makes a determination that the processing of Personal Data under the Agreement does not or will not comply with Privacy Laws, in which case, Perplexity shall not be required to continue processing such Personal Data. 4.
25In processing Personal Data under the Agreement, Perplexity shall: a. only process Personal Data on documented instructions from Customer, for the limited and specific purpose described in Annex 1, unless otherwise permitted to process such Personal Data by applicable Privacy Laws, and at all times in compliance with Privacy Laws and the terms of this DPA, providing the same level of privacy protection as is required by Privacy Laws; b. notify Customer promptly if it: (i) makes a determination that it can no longer comply with Customer’s instructions for the processing of Personal Data, its obligations under Privacy Laws or the terms of this DPA or (ii) believes that the instruction of Customer infringes applicable Privacy Laws; c. to the extent required by Privacy Laws, grant Customer the right to take reasonable and appropriate steps to help ensure that Perplexity uses the Personal Data in a manner consistent with Customer’s obligations under this DPA and Privacy Laws, and stop and remediate any unauthorized use of the Personal Data; and d. require that each employee or other person processing Personal Data is subject to an appropriate duty of confidentiality with respect to such Personal Data.26In processing Personal Data under the Agreement, Perplexity shall: a. only process Personal Data on documented instructions from Customer, for the limited and specific purpose described in Annex 1, unless otherwise permitted to process such Personal Data by applicable Privacy Laws, and at all times in compliance with Privacy Laws and the terms of this DPA, providing the same level of privacy protection as is required by Privacy Laws; b. notify Customer promptly if it: (i) makes a determination that it can no longer comply with Customer’s instructions for the processing of Personal Data, its obligations under Privacy Laws or the terms of this DPA or (ii) believes that the instruction of Customer infringes applicable Privacy Laws; c. to the extent required by Privacy Laws, grant Customer the right to take reasonable and appropriate steps to help ensure that Perplexity uses the Personal Data in a manner consistent with Customer’s obligations under this DPA and Privacy Laws, and stop and remediate any unauthorized use of the Personal Data; and d. require that each employee or other person processing Personal Data is subject to an appropriate duty of confidentiality with respect to such Personal Data. 5.
29If Perplexity receives (i) any legally binding request for disclosure of Personal Data by a law enforcement authority; or (ii) any notice, inquiry or investigations with respect to the Personal Data from any supervisory authority/regulator (or similar); or (iii) any complaint or request from a data subject, in each case related to Perplexity’s processing of Personal Data for or on behalf of the Customer under this DPA, then (to the extent permitted by law) Perplexity shall notify the Customer.30If Perplexity receives (i) any legally binding request for disclosure of Personal Data by a law enforcement authority; or (ii) any notice, inquiry or investigations with respect to the Personal Data from any supervisory authority/regulator (or similar); or (iii) any complaint or request from a data subject, in each case related to Perplexity’s processing of Personal Data for or on behalf of the Customer under this DPA, then (to the extent permitted by law) Perplexity shall notify the Customer. 6.
39In the event Perplexity engages a subprocessor to carry out specific processing activities on behalf of Customer pursuant to applicable Privacy Laws, Perplexity shall remain liable to Customer for that subprocessor’s performance of the data-protection obligations flowed down to it, to the same extent and subject to the same limitations as apply to Perplexity’s own performance under this DPA.40In the event Perplexity engages a subprocessor to carry out specific processing activities on behalf of Customer pursuant to applicable Privacy Laws, Perplexity shall remain liable to Customer for that subprocessor’s performance of the data-protection obligations flowed down to it, to the same extent and subject to the same limitations as apply to Perplexity’s own performance under this DPA. 7.
41Perplexity shall, in relation to the processing of Personal Data and to enable Customer to comply with its obligations which arise as a result thereof, provide assistance to Customer by: a. notifying Customer of requests from individuals pursuant to their rights under Privacy Laws, including by providing, deleting or correcting the relevant Personal Data, or by enabling Customer to do the same, insofar as this is possible ; b. to the extent required by Privacy Laws, conducting data protection impact assessments and, if required, prior consultation with relevant competent authorities; and c. notifying Customer of any accidental, unauthorized or illegal access, destruction, use, loss, modification, or disclosure of Personal Data (“ Personal Data Breach ”) without undue delay after Perplexity becomes aware of such Personal Data Breach.42Perplexity shall, in relation to the processing of Personal Data and to enable Customer to comply with its obligations which arise as a result thereof, provide assistance to Customer by: a. notifying Customer of requests from individuals pursuant to their rights under Privacy Laws, including by providing, deleting or correcting the relevant Personal Data, or by enabling Customer to do the same, insofar as this is possible ; b. to the extent required by Privacy Laws, conducting data protection impact assessments and, if required, prior consultation with relevant competent authorities; and c. notifying Customer of any accidental, unauthorized or illegal access, destruction, use, loss, modification, or disclosure of Personal Data (“ Personal Data Breach ”) without undue delay after Perplexity becomes aware of such Personal Data Breach. 8.
44Perplexity shall provide data protection and security training to those employees and other persons authorized to access Personal Data.45Perplexity shall provide data protection and security training to those employees and other persons authorized to access Personal Data. 9.
49Notwithstanding the foregoing, in no event shall Perplexity be required to give Customer access to information, facilities or systems to the extent doing so would cause Perplexity to be in violation of confidentiality obligations owed to other customers or its legal obligations.50Notwithstanding the foregoing, in no event shall Perplexity be required to give Customer access to information, facilities or systems to the extent doing so would cause Perplexity to be in violation of confidentiality obligations owed to other customers or its legal obligations. 10.
50Deletion of Personal Data .51Deletion of Personal Data.
51Perplexity shall delete (or, at Customer’s option, return) all Personal Data within thirty days of the end of the provision of the Services to Customer, unless retention of the Personal Data is required by law, in which case, Perplexity shall notify Customer without undue delay of such legal requirement and shall upon the expiration of such retention obligation delete (or, at Customer’s option, return) the Personal Data.52Perplexity shall delete (or, at Customer’s option, return) all Personal Data within thirty days of the end of the provision of the Services to Customer, unless retention of the Personal Data is required by law, in which case, Perplexity shall notify Customer without undue delay of such legal requirement and shall upon the expiration of such retention obligation delete (or, at Customer’s option, return) the Personal Data. 11.
55At Customer’s request, Perplexity shall enter separately into the Controller to Processor Clauses with Customer and shall take any other alternative or additional steps reasonably requested by Customer in order to ensure that Perplexity’s processing of Personal Data takes place in accordance with the requirements of Privacy Laws.to a party hereunder.56At Customer’s request, Perplexity shall enter separately into the Controller to Processor Clauses with Customer and shall take any other alternative or additional steps reasonably requested by Customer in order to ensure that Perplexity’s processing of Personal Data takes place in accordance with the requirements of Privacy Laws.to a party hereunder. 12.
Stay ahead of the changes

Watch this before it changes again

Follow unlimited companies, monitor the clauses that matter across every platform, and get the full institutional analysis on what each change obligates you to do.