10 Total
0 High severity
5 Medium severity
5 Low severity
Summary

This document establishes Databricks' privacy practices for personal data collected from website visitors, event attendees, job applicants, and service users. The notice authorizes the sharing of personal information including name, email, company, job title, device identifiers, and behavioral data with advertising partners and analytics providers for targeted marketing purposes. Individuals may submit requests to limit the sale or sharing of personal data for cross-context behavioral advertising through the designated OneTrust portal or website mechanism.

Technical / Legal Breakdown

This document is Databricks' Privacy Notice governing the collection, use, disclosure, and retention of personal information by Databricks, Inc. and its affiliates across its websites, products, services, and marketing activities, with a stated legal basis rooted in legitimate interests, contractual necessity, consent, and compliance with applicable law depending on jurisdiction. The notice states that Databricks collects categories of personal data including identifiers, professional and employment information, usage and technical data, inference data, and sensitive personal information such as Social Security numbers in limited employment contexts; the terms authorize sharing this data with service providers, business partners, affiliates, and third parties for advertising and analytics purposes, and permit cross-context behavioral advertising subject to opt-out rights. A notable operational distinction is the explicit carve-out establishing that customer data processed through Databricks' platform products is governed separately by the applicable customer agreement and Data Processing Addendum rather than this notice, which meaningfully limits the notice's scope for enterprise platform users. The notice explicitly engages GDPR and the UK GDPR by identifying Databricks as a data controller for certain processing, referencing lawful bases and data subject rights including access, rectification, erasure, portability, and objection; it also engages the California Consumer Privacy Act as amended by CPRA, the Colorado Privacy Act, Connecticut Data Privacy Act, Texas Data Privacy and Security Act, Oregon Consumer Privacy Act, and several other US state privacy laws, with jurisdiction-specific rights sections and a do-not-sell or share opt-out mechanism. Material compliance considerations include the adequacy of Databricks' cross-border data transfer mechanisms from the EEA and UK, the sufficiency of consent for cookie-based advertising tracking, the handling of inference data as a distinct data category under CPRA, and the operationalization of state-specific universal opt-out signal recognition.

Institutional Analysis

Institutional analysis available with Compliance

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Compliance.

Start Compliance free trial

2 important changes detected

3 versions captured · Last updated: June 2026

June 10, 2026

unknown
What changed Databricks updated their Databricks Privacy Notice on June 10, 2026. Change detected: 1 sentence(s) modified. Document contained 110 sentences after update.
View full change record →
What changed Databricks added a new document link labeled 'Additional Billing and Commitment Terms' to its privacy notice navigation menu on May 5, 2026. This appears to be a navigation or organizational change rather than a substantive policy modification. The core privacy notice text itself did not change.
Why this matters This change appears to be a navigation or organizational update to Databricks' documentation structure rather than a substantive modification to privacy practices or consumer rights. The actual privacy notice text remains unchanged. Consumers should not expect any immediate impact on how their data is collected, used, or protected.
View full change record →

Recent Provision Changes Jun 10, 2026

Added (3)
Inference Data Collection Medium

Explicitly discloses the collection and use of sophisticated profiling inferences derived from personal data, which was previously only obliquely referenced in behavioral advertising disclosures.

Third-Party Service Provider Sharing Low

Provides transparency about routine sharing with service providers performing standard business functions, distinguishing this from advertising/analytics partner sharing.

Notice Changes and Updates Low

New provision establishing notification procedures for material privacy policy changes, providing users with awareness mechanisms when updates occur.

Removed (2)
Legitimate Interests as Legal Basis (GDPR)

Removal of explicit GDPR legal basis disclosure (legitimate interests) weakens transparency about the lawful grounds for processing under GDPR, potentially limiting user understanding of their protections.

Business Transaction Data Sharing

Removal of the M&A data transfer provision eliminates disclosure about how personal data may be handled in business transactions, potentially leaving users unaware of data sharing in acquisition scenarios.

Modified (7)
Platform Customer Data Carve-Out

Simplified and streamlined the explanation of processor/controller distinction, removing the guidance to contact customers and focusing on the governing agreements (DPA added explicitly).

Cross-Context Behavioral Advertising and Data Sharing

Replaced explicit mention of CCPA/CPRA compliance language and opt-out rights with more specific categorization of data types shared for behavioral advertising, removing state-specific legal framework references.

Data Subject Rights and Opt-Out Mechanisms

Expanded rights enumeration to include opt-out of sale/sharing, targeted advertising, and automated decision-making/profiling, while removing the specific instruction to contact privacy@databricks.com and use the privacy portal.

Cookie and Tracking Technologies

Added specific examples of collected data (IP address, browser type, OS, referral URL, email interaction data) while removing language about cookie preference center and user control mechanisms.

Cross-Border Data Transfers

Restructured for clarity by separating general transfer statement from specific EEA/UK/Switzerland protections; simplified language and removed incomplete sentence about 'approved by the'.

1 provision unchanged.

View full change record →
Medium — 5 provisions
Low — 5 provisions

Monitoring

Databricks has updated this document before.

Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →

Compliance Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Compliance includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Compliance free trial

Cross-platform context

See how other platforms handle AI and ML Model Training Use of Personal Data and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured June 10, 2026 00:58 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000458
Version ID CA-V-003613
SHA-256 5387f15fdadede4656755ee75e465ad4d71b39bee2e0cbc974c03562e7b908e6
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans