Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The statement authorizes processing and transfer of personal data in connection with a broad range of corporate transactions, including mergers, acquisitions, divestitures, bankruptcy, restructuring, receivership, reorganization, dissolution, and asset sales, where personal data forms part of the assets involved.
This analysis describes what Palantir's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that personal data collected under this statement may be transferred to a buyer or other transaction party across a wide range of corporate restructuring scenarios. The provision applies to proposed transactions as well as completed ones, which means personal data may be disclosed during due diligence processes prior to transaction completion.
Interpretive note: The legal basis for personal data processing during proposed transaction due diligence is not explicitly stated in the regional legal basis section, creating some ambiguity regarding the applicable GDPR basis.
The updated Privacy Statement now authorizes Palantir to disclose personal data to promotional code partners who may then contact you if you sign up for a Palantir service using their code. This establishes a new third-party contact pathway not previously disclosed in the policy. The terms do not specify how frequently partners may contact you, what data is included in the disclosure, or whether you can opt out of partner contact after signing up.
View change record →Under this provision, personal data collected by Palantir may be transferred to acquiring entities or transaction parties in a merger, acquisition, asset sale, bankruptcy, or similar corporate event. The provision applies to both proposed and actual transactions, encompassing due diligence disclosure.
Cross-platform context
See how other platforms handle Business Transfer and Asset Sale Data Processing and similar clauses.
Compare across platforms →Monitoring
Palantir has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"To enable business transfers and transactions: We process your information in connection with transactions if there is a proposed or actual merger, purchase, sale acquisition, financing due diligence, transition of service to another service provider, divestiture, bankruptcy, restructuring, receivership, reorganization, dissolution or other sale or transfer of some or all of Palantir's assets, in which personal information processed by Palantir pursuant to this Statement forms part of the assets transferred or sold.Excerpt from Palantir's Privacy Statement
1. REGULATORY LANDSCAPE: This provision engages GDPR and UK GDPR requirements for lawful transfer of personal data to new controllers in the context of corporate transactions. In the US, applicable state privacy laws may impose notification or consent requirements for certain transfers of personal data in bankruptcy or asset sale contexts. The FTC has previously addressed consumer notification obligations in connection with data asset transfers in commercial transactions. 2. GOVERNANCE EXPOSURE: Medium. The provision's reference to financing due diligence as a trigger for data processing creates exposure to pre-transaction disclosure. The legal basis for this processing in the EEA/UK context is implied as legitimate interests, though the document does not explicitly state the basis for business transfer processing in the regional section. 3. JURISDICTION FLAGS: EEA and UK jurisdictions require that personal data transferred to a new controller in a corporate transaction maintains adequate protections and that individuals are notified of the change in controller where required. California and other US states with comprehensive privacy laws may impose additional disclosure obligations. 4. CONTRACT AND VENDOR IMPLICATIONS: Acquirers and transaction counterparties should confirm that data transfer arrangements in transaction agreements are consistent with applicable data protection law obligations, including any requirement to notify data subjects of the change in data controller following a completed transaction. 5. COMPLIANCE CONSIDERATIONS: Compliance teams involved in Palantir transactions should assess whether adequate data protection measures are included in transaction documents, whether data subject notification obligations are triggered upon transaction completion, and whether the processing basis for due diligence disclosure is documented.
This provision establishes that personal data collected under this statement may be transferred to a buyer or other transaction party across a wide range of corporate restructuring scenarios. The provision applies to proposed transactions as well as completed ones, which means personal data may be disclosed during due diligence processes prior to transaction completion.
Under this provision, personal data collected by Palantir may be transferred to acquiring entities or transaction parties in a merger, acquisition, asset sale, bankruptcy, or similar corporate event. The provision applies to both proposed and actual transactions, encompassing due diligence disclosure.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Palantir.