102 Total
21 High severity
63 Medium severity
18 Low severity

Key Facts

Will Palantir process Sensitive Personal Information without obtaining consent for consumers in Virginia, New Hampshire, Colorado, Connecticut, Delaware, Nebraska, Utah, Texas, and Oregon?
Palantir will not process Sensitive Personal Information without obtaining consent for consumers in Virginia, New Hampshire, Colorado, Connecticut, Delaware, Nebraska, Utah, Texas, and Oregon.
What does Palantir generate by combining data it has collected with information obtained from third parties?
Palantir generates Inferred Data profiles reflecting preferences and likelihood of interest in its products or services by combining data it has collected with information obtained from third parties.
What do Palantir's Inferred Data profiles reflect?
Palantir generates Inferred Data profiles reflecting preferences and likelihood of interest in its products or services by combining data it has collected with information obtained from third parties.
Who controls what personal data is processed using Palantir's products or services?
Palantir acts as a data processor when providing products and services to its customers, meaning customers — not Palantir — control what personal data is processed using those products or services.
Does Palantir process personal information in connection with proposed or actual mergers, purchases, sales, acquisitions, financing due diligence, service transitions, divestitures, bankruptcies, and restructurings?
Palantir processes personal information in connection with proposed or actual mergers, purchases, sales, acquisitions, financing due diligence, service transitions, divestitures, bankruptcies, and restructurings.
What uses or disclosures of Sensitive Personal Information does Palantir restrict?
Palantir restricts use or disclosure of Sensitive Personal Information to performing services or providing goods reasonably expected by an average consumer, preventing or detecting security incidents, and resisting malicious, deceptive, fraudulent, harmful, or illegal actions.
What data transfer agreements does Palantir use?
Palantir uses data transfer agreements based on Standard Contractual Clauses approved by the European Commission, the UK Secretary of State, or the UK Information Commissioner's Office to ensure adequate protection for personal data transferred to recipients in the EEA or UK.
What agreements does Palantir use to ensure adequate protection for personal data transferred to recipients in the EEA or UK?
Palantir uses data transfer agreements based on Standard Contractual Clauses approved by the European Commission, the UK Secretary of State, or the UK Information Commissioner's Office to ensure adequate protection for personal data transferred to recipients in the EEA or UK.
Does Palantir's Privacy Statement apply to its customers' processing of personal data using Palantir products or services?
Palantir's Privacy Statement does not apply to its customers' processing of personal data using Palantir products or services.
Is Stripe an independent controller of information provided in the course of using Stripe's payment processing service on Palantir platforms?
Stripe is an independent controller of information provided in the course of using Stripe's payment processing service on Palantir platforms.
Stay ahead of the changes
Track Palantir and get the diff the day its terms change.
Summary

This document explains what personal information Palantir collects about you, how it uses that information (including to build profiles and target advertising), and what rights you have over your data. If you are in certain U.S. states, Palantir must get your consent before processing sensitive personal information, and you may opt out of the sale or sharing of your personal information for targeted advertising. Importantly, if a Palantir customer processes your data using Palantir's products, this Statement does not cover that — the customer is responsible.

Analysis

Palantir's Privacy Statement establishes how Palantir collects, uses, and shares personal data in its capacity as a data controller — distinct from its role as a data processor when providing products and services to customers, in which case customers control what personal data is processed and this Statement does not apply. Palantir automatically collects a broad range of technical data from website visitors, combines collected data with third-party information to generate Inferred Data profiles, and uses multiple categories of personal data to target advertisements through third-party platforms. Use and disclosure of Sensitive Personal Information is restricted to enumerated purposes, and processing of Sensitive Personal Information for consumers in specified U.S. states requires affirmative consent. International transfers from the EEA and UK are conducted under Standard Contractual Clauses approved by the European Commission, the UK Secretary of State, or the UK Information Commissioner's Office.

What this means for you

Palantir automatically collects identifying and behavioral data when you visit its websites, and it combines that data with third-party information to build profiles reflecting your preferences and likely interest in its products. Palantir uses these profiles — along with Contact, Professional, Communication, Technical, Transaction, Training and Educational, and Inferred Data — to target advertisements through third-party platforms. If you are a consumer in Virginia, New Hampshire, Colorado, Connecticut, Delaware, Nebraska, Utah, Texas, or Oregon, Palantir must obtain your consent before processing Sensitive Personal Information. Where applicable, you may opt out of the sale of your Personal Information or its sharing for targeted advertising purposes.

Institutional Analysis
Stay ahead of the changes

Institutional analysis available with Insight

Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.

2 important changes detected

3 versions captured · Last updated: June 2026

What changed Palantir updated its Privacy Statement on June 18, 2026, involving substantial structural and content changes across 197 added sentences, 87 removed sentences, and 137 modified sentences. The diff shows primarily formatting and structural reorganization of content, converting a plaintext document into an HTML-based structure with internal hyperlinks and improved navigation. The operational substance of data collection, use, and user rights practices appears to be preserved, though the full scope of substantive policy changes cannot be fully assessed from the truncated diff.
Why this matters The updated Privacy Statement incorporates structural reorganization and reformatting improvements on June 18, 2026. The core content regarding how Palantir collects, uses, and protects personal data remains substantively similar based on available change details, though the document now includes HTML formatting, hyperlinked navigation, and improved section organization. The statement continues to apply only to personal data Palantir processes as a data controller on its own behalf, not to data processed on behalf of customers using Palantir products or services.
View full change record →

June 10, 2026

medium
What changed Palantir updated its Privacy Statement on June 10, 2026, adding a new disclosure category and updating the last-modified date. The updated terms now explicitly state that Palantir discloses personal data to partners who provided you with a promotional code, enabling them to contact you if you sign up for a Palantir service using that code. This creates a new pathway for third-party contact based on promotional code registration.
Why this matters The updated Privacy Statement now authorizes Palantir to disclose personal data to promotional code partners who may then contact you if you sign up for a Palantir service using their code. This establishes a new third-party contact pathway not previously disclosed in the policy. The terms do not specify how frequently partners may contact you, what data is included in the disclosure, or whether you can opt out of partner contact after signing up.
View full change record →

Featured, High severity
Featured, Medium severity

Complete Provision Index

Every distinct legal provision identified in this document. Featured provisions appear above with analysis.

102 provisions
12 featured
9 clause types
21 high severity
Privacy Rights 29 4 high
Show all 29 privacy rights provisions
Stay ahead of the changes

Monitoring

Palantir has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Stay ahead of the changes

Governance Intelligence

Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.

Cross-platform context

See how other platforms handle California right to limit Sensitive Personal Information use and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
ePrivacy Directive
European Union
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured June 18, 2026 04:31 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000496
Version ID CA-V-004004
SHA-256 44e19809b96d8a82ce0ac621d25ad0e0848c512e8ae7549a1fc65923639fca6e
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.

Start monitoring → Compare plans