Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The DPA prohibits Customer from submitting to Baseten any personal data constituting Restricted Data, defined to include government identifiers, HIPAA-protected health information, biometric data, financial account credentials, payment card data, children's personal data under age thirteen, GDPR special category data, and criminal conviction data, unless a separate written agreement with Baseten expressly permits such submission.
This analysis describes what Baseten's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision creates a contractual data intake restriction that Customer organizations must operationalize through data classification and platform intake controls, and allocates to Customer full contractual responsibility for any breach of this prohibition.
Under this clause, Customer is contractually prohibited from submitting sensitive personal data categories to the Baseten platform without a separate written agreement, and bears responsibility for ensuring that Customer Content and model inputs are screened against this restriction prior to submission.
Cross-platform context
See how other platforms handle Restricted Data Category Prohibition and similar clauses.
Compare across platforms →Monitoring
Baseten has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Unless otherwise agreed upon with Baseten in writing, Customer shall not provide or otherwise make available to Baseten any Customer Personal Data that contains any (a) Social Security numbers or other government-issued identification numbers; (b) protected health information subject to the Health Insurance Portability and Accountability Act (HIPAA) or other information regarding an individual's medical history, mental or physical condition, or medical treatment or diagnosis by a health care professional; (c) health insurance information; (d) biometric information; (e) passwords to any online accounts; (f) credentials to any financial accounts; (g) tax return data; (h) any payment card information subject to the Payment Card Industry Data Security Standard; (i) Personal Data of children under 13 years of age; or (j) any other information that falls within any special categories of personal data (as defined in GDPR) and/or data relating to criminal convictions and offenses or related security measures (together, "Restricted Data").Excerpt from Baseten's Terms of Service
(1) REGULATORY LANDSCAPE: This provision directly engages HIPAA (for PHI), COPPA (for children's data under 13), GDPR Article 9 (special categories of personal data) and Article 10 (criminal conviction data), CCPA and CPRA (for sensitive personal information categories), and PCI DSS (for payment card data). Relevant enforcement authorities include HHS OCR for HIPAA, the FTC for COPPA, national DPAs for GDPR, the California Privacy Protection Agency for CCPA, and PCI Security Standards Council for PCI DSS. The DPA's prohibition functions as a contractual risk allocation mechanism rather than a regulatory compliance guarantee. (2) GOVERNANCE EXPOSURE: High, for Customer organizations operating in healthcare, financial services, education, or consumer-facing contexts where sensitive personal data may be present in model training data, inference inputs, or Customer Content. The prohibition places compliance responsibility on Customer to implement data classification controls that prevent inadvertent submission of Restricted Data categories. (3) JURISDICTION FLAGS: EU and UK customers face heightened exposure under GDPR Article 9 for special category data, which includes health, biometric, and criminal conviction data. California customers should evaluate CPRA sensitive personal information categories, which may not be fully coextensive with the Restricted Data definition in this clause. Illinois customers with biometric data obligations under BIPA should note that biometric information is explicitly included in the Restricted Data prohibition. (4) CONTRACT AND VENDOR IMPLICATIONS: Enterprise procurement and compliance teams should incorporate this Restricted Data prohibition into Customer data governance policies, model intake procedures, and Authorized User training to prevent inadvertent submission. Where Customers intend to deploy ML models that process any Restricted Data category, a separate written agreement with Baseten is required before such use, which creates a separate procurement and legal review trigger. (5) COMPLIANCE CONSIDERATIONS: Compliance teams may want to conduct a data mapping exercise to identify whether existing or planned use cases involve any Restricted Data categories, and establish contractual and technical controls to enforce the prohibition. Organizations in regulated industries (healthcare, financial services) should treat this clause as a hard compliance boundary requiring affirmative sign-off before any sensitive data is submitted to the platform.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision creates a contractual data intake restriction that Customer organizations must operationalize through data classification and platform intake controls, and allocates to Customer full contractual responsibility for any breach of this prohibition.
Under this clause, Customer is contractually prohibited from submitting sensitive personal data categories to the Baseten platform without a separate written agreement, and bears responsibility for ensuring that Customer Content and model inputs are screened against this restriction prior to submission.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Baseten.