102 Total
21 High severity
63 Medium severity
18 Low severity

Key Facts

Will Palantir process Sensitive Personal Information without obtaining consent for consumers in Virginia, New Hampshire, Colorado, Connecticut, Delaware, Nebraska, Utah, Texas, and Oregon?
Palantir will not process Sensitive Personal Information without obtaining consent for consumers in Virginia, New Hampshire, Colorado, Connecticut, Delaware, Nebraska, Utah, Texas, and Oregon.
What does Palantir generate by combining data it has collected with information obtained from third parties?
Palantir generates Inferred Data profiles reflecting preferences and likelihood of interest in its products or services by combining data it has collected with information obtained from third parties.
What do Palantir's Inferred Data profiles reflect?
Palantir generates Inferred Data profiles reflecting preferences and likelihood of interest in its products or services by combining data it has collected with information obtained from third parties.
Who controls what personal data is processed using Palantir's products or services?
Palantir acts as a data processor when providing products and services to its customers, meaning customers — not Palantir — control what personal data is processed using those products or services.
Does Palantir process personal information in connection with proposed or actual mergers, purchases, sales, acquisitions, financing due diligence, service transitions, divestitures, bankruptcies, and restructurings?
Palantir processes personal information in connection with proposed or actual mergers, purchases, sales, acquisitions, financing due diligence, service transitions, divestitures, bankruptcies, and restructurings.
What uses or disclosures of Sensitive Personal Information does Palantir restrict?
Palantir restricts use or disclosure of Sensitive Personal Information to performing services or providing goods reasonably expected by an average consumer, preventing or detecting security incidents, and resisting malicious, deceptive, fraudulent, harmful, or illegal actions.
What data transfer agreements does Palantir use?
Palantir uses data transfer agreements based on Standard Contractual Clauses approved by the European Commission, the UK Secretary of State, or the UK Information Commissioner's Office to ensure adequate protection for personal data transferred to recipients in the EEA or UK.
What agreements does Palantir use to ensure adequate protection for personal data transferred to recipients in the EEA or UK?
Palantir uses data transfer agreements based on Standard Contractual Clauses approved by the European Commission, the UK Secretary of State, or the UK Information Commissioner's Office to ensure adequate protection for personal data transferred to recipients in the EEA or UK.
Does Palantir's Privacy Statement apply to its customers' processing of personal data using Palantir products or services?
Palantir's Privacy Statement does not apply to its customers' processing of personal data using Palantir products or services.
Is Stripe an independent controller of information provided in the course of using Stripe's payment processing service on Palantir platforms?
Stripe is an independent controller of information provided in the course of using Stripe's payment processing service on Palantir platforms.
Stay ahead of the changes
Track Palantir and get the diff the day its terms change.
Summary

This document explains what personal information Palantir collects about you, how it uses that information (including to build profiles and target advertising), and what rights you have over your data. If you are in certain U.S. states, Palantir must get your consent before processing sensitive personal information, and you may opt out of the sale or sharing of your personal information for targeted advertising. Importantly, if a Palantir customer processes your data using Palantir's products, this Statement does not cover that — the customer is responsible.

Analysis

Palantir's Privacy Statement establishes how Palantir collects, uses, and shares personal data in its capacity as a data controller — distinct from its role as a data processor when providing products and services to customers, in which case customers control what personal data is processed and this Statement does not apply. Palantir automatically collects a broad range of technical data from website visitors, combines collected data with third-party information to generate Inferred Data profiles, and uses multiple categories of personal data to target advertisements through third-party platforms. Use and disclosure of Sensitive Personal Information is restricted to enumerated purposes, and processing of Sensitive Personal Information for consumers in specified U.S. states requires affirmative consent. International transfers from the EEA and UK are conducted under Standard Contractual Clauses approved by the European Commission, the UK Secretary of State, or the UK Information Commissioner's Office.

What this means for you

Palantir automatically collects identifying and behavioral data when you visit its websites, and it combines that data with third-party information to build profiles reflecting your preferences and likely interest in its products. Palantir uses these profiles — along with Contact, Professional, Communication, Technical, Transaction, Training and Educational, and Inferred Data — to target advertisements through third-party platforms. If you are a consumer in Virginia, New Hampshire, Colorado, Connecticut, Delaware, Nebraska, Utah, Texas, or Oregon, Palantir must obtain your consent before processing Sensitive Personal Information. Where applicable, you may opt out of the sale of your Personal Information or its sharing for targeted advertising purposes.

Institutional Analysis
Stay ahead of the changes

Institutional analysis available with Insight

Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.

4 important changes detected

8 versions captured · Last updated: August 2026

What changed Palantir's navigation menu was updated in an update detected on August 12, 2026 to add a 'Sovereign AI' offering link at the top level of the product navigation. This is a navigation and marketing change with no material impact on the privacy statement's terms, conditions, or obligations.
Why this matters This change does not materially affect consumer privacy rights or data processing obligations. The update adds a navigation link to Palantir's 'Sovereign AI' product offering. No changes to the privacy statement's substantive terms, data collection practices, or consumer rights were detected.
View full change record →
What changed Palantir's Privacy Statement was updated in an update detected on August 5, 2026, with three sentences modified. The document's last-updated date changed from June 2026 to July 2026. Most substantively, the UK complaint procedure was revised: the statement previously directed UK residents to complain to the Information Commissioner's Office; the updated language now offers UK residents the option to lodge complaints directly with Palantir at privacy@palantir.com before or instead of contacting the ICO.
Why this matters The updated terms now offer UK users two pathways to lodge data protection complaints: directly with Palantir at privacy@palantir.com, or with the Information Commissioner's Office. Previously, only the ICO option was explicitly stated. This change does not alter the underlying right to complain; it clarifies an additional procedural option.
View full change record →

June 18, 2026 low

Palantir updated its Privacy Statement on June 18, 2026, involving substantial structural and content changes across 197 added sentences, 87 removed sentences, and 137 modified sentences. The diff shows primarily …

View change record →
June 10, 2026 medium

Palantir updated its Privacy Statement on June 10, 2026, adding a new disclosure category and updating the last-modified date. The updated terms now explicitly state that Palantir discloses personal data …

View change record →
Featured, High severity
Featured, Medium severity

Complete Provision Index

Every distinct legal provision identified in this document. Featured provisions appear above with analysis.

102 provisions
12 featured
9 clause types
21 high severity
Privacy Rights 29 4 high
Show all 29 privacy rights provisions
Stay ahead of the changes

Monitoring

Palantir has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Stay ahead of the changes

Governance Intelligence

Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.

Cross-platform context

See how other platforms handle California right to limit Sensitive Personal Information use and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
ePrivacy Directive
European Union
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured September 11, 2026 01:00 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000496
Version ID CA-V-006792
SHA-256 2525aecdaee201f502416a210989283c1ded96808a6302c7a17616355c2076ee
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.

Start monitoring → Compare plans