Provision record
Peloton · Peloton Privacy Policy · View original document ↗

Sensitive Personal Information Processing

Medium severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Peloton changes these terms. Follow Peloton →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Peloton Monitor emails you the same day this changes. The archive stays free.
Follow Peloton →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy discloses that Peloton processes sensitive personal information categories including health information, biometric data, precise geolocation, race, sexuality, and religion data for service provision and legal compliance purposes, and states that users acknowledge they will not volunteer such information unless Peloton explicitly requests it.

This analysis describes what Peloton's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision acknowledges processing of sensitive personal information categories that trigger heightened regulatory obligations under GDPR, CCPA, and multiple U.S. state privacy frameworks. The clause's statement that users acknowledge they will not disclose sensitive information unless explicitly requested does not function as a complete limitation on such processing, as other provisions in the policy describe collection of health-adjacent and biometric data through automated service features.

Interpretive note: The specific lawful basis asserted for each sensitive personal information category is not fully specified in this provision, and the interaction between the user acknowledgment statement and the automated collection of sensitive data through platform features requires further analysis for a complete compliance assessment.

Clause Stability Stable

0
Changes
4
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Consumer impact (what this means for users)

The agreement establishes that Peloton processes sensitive personal information categories, including health information, biometric data, precise geolocation, and information related to race, sexuality, and religion, for purposes of service provision and legal compliance. The policy states that users acknowledge they will not volunteer sensitive information beyond what Peloton explicitly requests, though other provisions describe automated collection of biometric-adjacent and health-related data through platform features.

Cross-platform context

See how other platforms handle Sensitive Personal Information Processing and similar clauses.

Compare across platforms →

Monitoring

Peloton has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Follow Peloton → Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Sensitive Personal Information. We process Sensitive Personal Information for the purposes of providing Services, carrying out our legal obligations or exercising specific rights as permitted by law. The definition of Sensitive Personal Information depends on jurisdiction and where you are located, but health information, biometric data, precise geolocation data, information relating to race, sexuality, and religion are examples of what may be considered sensitive in some locations. Please also review the YOUR PRIVACY RIGHTS AND PREFERENCES section below. By choosing to use our Services, you acknowledge that you will not disclose Sensitive Personal Information to us through, or in connection, with our Services unless we have explicitly requested such disclosure from you.

Excerpt from Peloton's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

REGULATORY LANDSCAPE: GDPR Article 9 prohibits processing of special category data without explicit consent or another enumerated exception, covering health data, biometric data, racial or ethnic origin, and sexual orientation. CCPA and CPRA establish a category of sensitive personal information with restricted processing requirements and an opt-out right. Multiple U.S. state privacy laws (Virginia, Colorado, Texas, Connecticut, and others) impose heightened consent or opt-out requirements for sensitive data categories. The FTC has enforcement authority over deceptive practices related to sensitive data processing. GOVERNANCE EXPOSURE: High. The breadth of sensitive data categories acknowledged in this provision, combined with the automated collection of biometric-adjacent and health-related data through platform features described elsewhere in the policy, creates compound compliance exposure across GDPR, CCPA, and state privacy frameworks. The policy's attempt to limit user-volunteered sensitive disclosures does not address the regulatory obligations triggered by automated sensitive data collection. JURISDICTION FLAGS: EU/EEA exposure is highest given GDPR Article 9's explicit consent requirements for special category data processing. California CPRA's sensitive personal information provisions impose specific use limitations and opt-out rights. Illinois BIPA applies to biometric data specifically. State health data statutes may apply to health information processed through the platform. CONTRACT AND VENDOR IMPLICATIONS: Organizations deploying Peloton as a workplace wellness benefit should assess whether employee processing of sensitive personal information through Peloton services creates obligations under their own GDPR data protection agreements or CCPA service provider contracts. The policy's legal basis assertions for sensitive data processing should be reviewed against applicable regulatory requirements. COMPLIANCE CONSIDERATIONS: Legal teams should map each sensitive data category identified in this provision against the specific legal basis and consent mechanism used for its processing, and assess whether those mechanisms satisfy applicable requirements in each relevant jurisdiction. The interaction between this provision's acknowledgment language and the automated collection of sensitive data through platform features should be reviewed for consistency and adequacy of disclosure.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Applicable agencies

  • FTC
    The FTC has enforcement authority over unfair or deceptive practices related to sensitive personal information processing, including health and biometric data.
    File a complaint →
  • State AG
    State Attorneys General in California, Illinois, and other states with sensitive data provisions in their privacy statutes have enforcement authority over sensitive personal information processing practices.
    File a complaint →

Provision details

Document information
Document
Peloton Privacy Policy
Entity
Peloton
Document last updated
May 5, 2026
Tracking information
First tracked
April 27, 2026
Last verified
July 9, 2026
Record ID
CA-P-015951
Document ID
CA-D-00220
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
dc94d4de5c0a32807ebe04a1fad05e9914d9dffe0165262b81083c5a41020389
Analysis generated
April 27, 2026 14:37 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Peloton
Document: Peloton Privacy Policy
Record ID: CA-P-015951
Captured: 2026-04-27 14:37:01 UTC
SHA-256: dc94d4de5c0a3280…
URL: https://conductatlas.com/platform/peloton/peloton-privacy-policy/provision/CA-P-015951/sensitive-personal-information-processing/
Accessed: July 25, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention

Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.

Frequently Asked Questions

What does Peloton's Sensitive Personal Information Processing clause do?

This provision acknowledges processing of sensitive personal information categories that trigger heightened regulatory obligations under GDPR, CCPA, and multiple U.S. state privacy frameworks. The clause's statement that users acknowledge they will not disclose sensitive information unless explicitly requested does not function as a complete limitation on such processing, as other provisions in the policy describe collection of health-adjacent and biometric …

How does this clause affect you?

The agreement establishes that Peloton processes sensitive personal information categories, including health information, biometric data, precise geolocation, and information related to race, sexuality, and religion, for purposes of service provision and legal compliance. The policy states that users acknowledge they will not volunteer sensitive information beyond what Peloton explicitly requests, though other provisions describe automated collection of biometric-adjacent and health-related …

Is ConductAtlas affiliated with Peloton?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Peloton.