Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The statement enumerates data subject rights available to individuals in the UK, EEA, and Switzerland, including access, correction, erasure, restriction, objection, portability, consent withdrawal, and the right to lodge a supervisory authority complaint.
This analysis describes what Palantir's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes the specific rights Palantir acknowledges for EEA, UK, and Swiss residents and the mechanism for exercising them, including direct contact with Palantir's Data Protection Officer. The statement notes these rights are not absolute and may be balanced against other considerations.
The updated Privacy Statement now authorizes Palantir to disclose personal data to promotional code partners who may then contact you if you sign up for a Palantir service using their code. This establishes a new third-party contact pathway not previously disclosed in the policy. The terms do not specify how frequently partners may contact you, what data is included in the disclosure, or whether you can opt out of partner contact after signing up.
View change record →Under this provision, individuals in the EEA, UK, and Switzerland may submit rights requests including access, erasure, correction, portability, and processing restriction by contacting privacy@palantir.com or the regional DPO addresses listed in the document. The statement acknowledges that rights are not absolute and that compelling legitimate interests may limit certain objection requests.
Cross-platform context
See how other platforms handle Data Subject Rights (EEA, UK, Switzerland) and similar clauses.
Compare across platforms →Monitoring
Palantir has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Your rights: The right of access to your personal data: You may have the right to receive confirmation about whether we process your personal data and, if we do, to obtain access to your personal data. The right to ask us to correct any personal data we hold on you. The right to request erasure of your personal data. The right to restrict how we process your personal data. The right to object to our processing of your personal data. The right to data portability. Right to withdraw your previously given consent to our use of your personal data. Right to lodge a complaint with the data protection or consumer privacy regulatory or authority.Excerpt from Palantir's Privacy Statement
1. REGULATORY LANDSCAPE: This provision directly implements GDPR and UK GDPR data subject rights obligations. The document references the ICO complaint mechanism for UK residents and EU member state data protection authorities for EEA residents. The statement's qualification that rights are not absolute and may be balanced against other considerations is consistent with GDPR Article 12-22 structure. 2. GOVERNANCE EXPOSURE: Low. The provision reflects standard GDPR-compliant rights disclosure. Governance exposure arises primarily from operational implementation, including response timelines, identity verification procedures, and the process for communicating compelling legitimate interests when objection requests are declined. 3. JURISDICTION FLAGS: EEA, UK, and Switzerland are the primary jurisdictions addressed by this provision. The statement notes that residents of other countries with similar rights may also have access to these mechanisms, creating some ambiguity about the scope of application in non-enumerated jurisdictions. 4. CONTRACT AND VENDOR IMPLICATIONS: Organizations processing personal data as Palantir customers should note that this provision explicitly excludes data processed by Palantir as a processor on behalf of customers. Data subject requests related to customer-processed data must be directed to the customer, not Palantir. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should review the documented response procedures for data subject requests, including identity verification requirements, response timelines consistent with GDPR Article 12, and procedures for documenting declined objection requests based on compelling legitimate interests.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes the specific rights Palantir acknowledges for EEA, UK, and Swiss residents and the mechanism for exercising them, including direct contact with Palantir's Data Protection Officer. The statement notes these rights are not absolute and may be balanced against other considerations.
Under this provision, individuals in the EEA, UK, and Switzerland may submit rights requests including access, erasure, correction, portability, and processing restriction by contacting privacy@palantir.com or the regional DPO addresses listed in the document. The statement acknowledges that rights are not absolute and that compelling legitimate interests may limit certain objection requests.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Palantir.