Baseten · Baseten Terms of Service · View original document ↗

Restricted Data Category Prohibition

High severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Baseten changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Baseten Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The DPA prohibits Customer from submitting to Baseten any personal data constituting Restricted Data, defined to include government identifiers, HIPAA-protected health information, biometric data, financial account credentials, payment card data, children's personal data under age thirteen, GDPR special category data, and criminal conviction data, unless a separate written agreement with Baseten expressly permits such submission.

This analysis describes what Baseten's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision creates a contractual data intake restriction that Customer organizations must operationalize through data classification and platform intake controls, and allocates to Customer full contractual responsibility for any breach of this prohibition.

Consumer impact (what this means for users)

Under this clause, Customer is contractually prohibited from submitting sensitive personal data categories to the Baseten platform without a separate written agreement, and bears responsibility for ensuring that Customer Content and model inputs are screened against this restriction prior to submission.

Cross-platform context

See how other platforms handle Restricted Data Category Prohibition and similar clauses.

Compare across platforms →

Monitoring

Baseten has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Unless otherwise agreed upon with Baseten in writing, Customer shall not provide or otherwise make available to Baseten any Customer Personal Data that contains any (a) Social Security numbers or other government-issued identification numbers; (b) protected health information subject to the Health Insurance Portability and Accountability Act (HIPAA) or other information regarding an individual's medical history, mental or physical condition, or medical treatment or diagnosis by a health care professional; (c) health insurance information; (d) biometric information; (e) passwords to any online accounts; (f) credentials to any financial accounts; (g) tax return data; (h) any payment card information subject to the Payment Card Industry Data Security Standard; (i) Personal Data of children under 13 years of age; or (j) any other information that falls within any special categories of personal data (as defined in GDPR) and/or data relating to criminal convictions and offenses or related security measures (together, "Restricted Data").

Excerpt from Baseten's Terms of Service

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

(1) REGULATORY LANDSCAPE: This provision directly engages HIPAA (for PHI), COPPA (for children's data under 13), GDPR Article 9 (special categories of personal data) and Article 10 (criminal conviction data), CCPA and CPRA (for sensitive personal information categories), and PCI DSS (for payment card data). Relevant enforcement authorities include HHS OCR for HIPAA, the FTC for COPPA, national DPAs for GDPR, the California Privacy Protection Agency for CCPA, and PCI Security Standards Council for PCI DSS. The DPA's prohibition functions as a contractual risk allocation mechanism rather than a regulatory compliance guarantee. (2) GOVERNANCE EXPOSURE: High, for Customer organizations operating in healthcare, financial services, education, or consumer-facing contexts where sensitive personal data may be present in model training data, inference inputs, or Customer Content. The prohibition places compliance responsibility on Customer to implement data classification controls that prevent inadvertent submission of Restricted Data categories. (3) JURISDICTION FLAGS: EU and UK customers face heightened exposure under GDPR Article 9 for special category data, which includes health, biometric, and criminal conviction data. California customers should evaluate CPRA sensitive personal information categories, which may not be fully coextensive with the Restricted Data definition in this clause. Illinois customers with biometric data obligations under BIPA should note that biometric information is explicitly included in the Restricted Data prohibition. (4) CONTRACT AND VENDOR IMPLICATIONS: Enterprise procurement and compliance teams should incorporate this Restricted Data prohibition into Customer data governance policies, model intake procedures, and Authorized User training to prevent inadvertent submission. Where Customers intend to deploy ML models that process any Restricted Data category, a separate written agreement with Baseten is required before such use, which creates a separate procurement and legal review trigger. (5) COMPLIANCE CONSIDERATIONS: Compliance teams may want to conduct a data mapping exercise to identify whether existing or planned use cases involve any Restricted Data categories, and establish contractual and technical controls to enforce the prohibition. Organizations in regulated industries (healthcare, financial services) should treat this clause as a hard compliance boundary requiring affirmative sign-off before any sensitive data is submitted to the platform.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Get same-day alerts when this changes → Get Analyst

Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.

Applicable agencies

  • Hhs Ocr
    HHS OCR enforces HIPAA, which is directly referenced in the Restricted Data definition as a category of data prohibited from submission to the Baseten platform.
    File a complaint →
  • FTC
    The FTC enforces COPPA with respect to personal data of children under 13, a category explicitly included in the Restricted Data prohibition.
    File a complaint →

Provision details

Document information
Document
Baseten Terms of Service
Entity
Baseten
Document last updated
May 12, 2026
Tracking information
First tracked
July 12, 2026
Last verified
July 12, 2026
Record ID
CA-P-074199
Document ID
CA-D-00813
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
e9d44a36c9ed500a74656ec3e22a7892bc5e72790392b3c71bde1cc0e32cc19a
Analysis generated
July 12, 2026 14:23 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Baseten
Document: Baseten Terms of Service
Record ID: CA-P-074199
Captured: 2026-07-12 14:23:23 UTC
SHA-256: e9d44a36c9ed500a…
URL: https://conductatlas.com/platform/baseten/baseten-terms-of-service/provision/CA-P-074199/restricted-data-category-prohibition/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Get Compliance

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Baseten's Restricted Data Category Prohibition clause do?

This provision creates a contractual data intake restriction that Customer organizations must operationalize through data classification and platform intake controls, and allocates to Customer full contractual responsibility for any breach of this prohibition.

How does this clause affect you?

Under this clause, Customer is contractually prohibited from submitting sensitive personal data categories to the Baseten platform without a separate written agreement, and bears responsibility for ensuring that Customer Content and model inputs are screened against this restriction prior to submission.

Is ConductAtlas affiliated with Baseten?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Baseten.