Provision record
Groq · Groq Privacy Policy · View original document ↗

Third-Party Identity Verification Under Separate Privacy Notices

High severity Medium confidence Explicit document language Common · 289 of 352 platforms
Stay ahead of the changes
Track Groq and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF
Document Record

What it is

If Groq asks you to verify your identity, you will submit your government-issued ID and a selfie directly to a third-party verification company, which handles that sensitive data under its own privacy policy, not Groq's.

This analysis describes what Groq's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

Your most sensitive personal data, including government ID documents and facial images, is handled by a company whose privacy practices are separate from Groq's policy commitments, creating a gap in the protections you might expect to apply.

Interpretive note: The policy characterizes the identity verification services as 'processors' but states that users' data is processed under the services' own privacy notices, which may indicate a controller relationship rather than a processor relationship under GDPR; the legal distinction affects accountability and user rights.

Consumer impact (what this means for users)

This provision means that biometric-adjacent data (facial images, government IDs) you submit during identity verification is governed by a third party's privacy notice, which Groq does not reproduce or link in this policy, leaving consumers without clear visibility into how that data is retained, shared, or deleted.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Email privacy@groq.com to request information about which third-party identity verification service holds your data and how to exercise deletion rights against that vendor. Groq states it does not store government IDs or selfies itself, so the deletion request may need to be directed to the third-party processor.

How other platforms handle this

Notion Medium

To protect your privacy, we will take steps to verify your identity before fulfilling your request, such as by requiring you to submit your request via your account.

Google Cloud Medium

When you use them, we'll validate your request by verifying your identity (for example, by confirming that you're signed in to your Google Account).

ZipRecruiter Medium

we may need to request specific information from you to help us confirm your identity and ensure your right to access your Personal Data (or to exercise any of your other rights). This is a security measure to ensure that Personal Data is not disclosed to any person who has no right to receive it.

See all platforms with this clause type →
▸ View Original Clause Language DOCUMENT RECORD
"
We may use third-party identity verification services to verify your identity, secure our Services, and protect against fraud or abuse. When you engage in this process, you provide information, such as a photo ID or selfie, directly to that service. We receive confirmation of verification results but do not store your government identification documents or selfies ourselves. These services act as our processors and process your information in accordance with their own privacy notices.

Excerpt from Groq's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1) REGULATORY LANDSCAPE: This provision may engage Illinois BIPA (if facial geometry is derived from selfies), Texas CUBI, Washington My Health MY Data Act, and GDPR Article 9 (biometric data as a special category).

Insight

Unlock the full institutional analysis

Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.

Applicable agencies

  • Federal Trade Commission (ftc)
    Oversees unfair or deceptive business practices and can investigate companies that mislead consumers about data collection, sharing, or use.
    Who can file: Anyone affected by the company's practices (US or international)
    What you need: Your account details, a timeline of relevant events, and a description of the specific issue
    What to expect: Complaints inform FTC enforcement priorities and investigations but do not result in individual resolution or compensation
    File a complaint →
  • State Attorney General
    State AGs in California, New York, Texas, and other states can investigate violations of state consumer protection and privacy laws, including CCPA (California), SHIELD Act (New York), and equivalents.
    Who can file: Residents of states with comprehensive privacy laws — primarily California, Virginia, Colorado, Connecticut, and Utah
    What you need: Evidence of the violation, explanation of how your state rights were affected, and your account or contact information with the company
    What to expect: Outcomes vary by state. May result in investigation, enforcement action, or requirement for the company to change practices. No direct individual compensation in most cases.

    Search "[your state] attorney general consumer complaint" to find your state's direct complaint form

Applicable regulations

EU AI Act
European Union
CCPA/CPRA
California, USA
Colorado AI Act
US-CO
Connecticut Data Privacy Act Amendments
US-CT
EU AI Act - High Risk Provisions
EU
FTC Act Section 5
United States Federal
GDPR
European Union
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
Groq Privacy Policy
Entity
Groq
Document last updated
May 5, 2026
Tracking information
First tracked
April 30, 2026
Last verified
May 10, 2026
Record ID
CA-P-004213
Document ID
CA-D-00492
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
bbe9975e5b75738e082446f8b589a8f36a567aa7306af5902ace86d990c56c34
Analysis generated
April 30, 2026 07:09 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Groq
Document: Groq Privacy Policy
Record ID: CA-P-004213
Captured: 2026-04-30 07:09:55 UTC
SHA-256: bbe9975e5b75738e…
URL: https://conductatlas.com/platform/groq/groq-privacy-policy/provision/CA-P-004213/third-party-identity-verification-under-separate-privacy-notices/
Accessed: Sept. 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Related Analysis

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does Groq's Third-Party Identity Verification Under Separate Privacy Notices clause do?

Your most sensitive personal data, including government ID documents and facial images, is handled by a company whose privacy practices are separate from Groq's policy commitments, creating a gap in the protections you might expect to apply.

How does this clause affect you?

This provision means that biometric-adjacent data (facial images, government IDs) you submit during identity verification is governed by a third party's privacy notice, which Groq does not reproduce or link in this policy, leaving consumers without clear visibility into how that data is retained, shared, or deleted.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 289 platforms. See the full comparison.

Is ConductAtlas affiliated with Groq?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Groq.