Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy discloses that Peloton processes sensitive personal information categories including health information, biometric data, precise geolocation, race, sexuality, and religion data for service provision and legal compliance purposes, and states that users acknowledge they will not volunteer such information unless Peloton explicitly requests it.
This analysis describes what Peloton's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision acknowledges processing of sensitive personal information categories that trigger heightened regulatory obligations under GDPR, CCPA, and multiple U.S. state privacy frameworks. The clause's statement that users acknowledge they will not disclose sensitive information unless explicitly requested does not function as a complete limitation on such processing, as other provisions in the policy describe collection of health-adjacent and biometric data through automated service features.
Interpretive note: The specific lawful basis asserted for each sensitive personal information category is not fully specified in this provision, and the interaction between the user acknowledgment statement and the automated collection of sensitive data through platform features requires further analysis for a complete compliance assessment.
The agreement establishes that Peloton processes sensitive personal information categories, including health information, biometric data, precise geolocation, and information related to race, sexuality, and religion, for purposes of service provision and legal compliance. The policy states that users acknowledge they will not volunteer sensitive information beyond what Peloton explicitly requests, though other provisions describe automated collection of biometric-adjacent and health-related data through platform features.
Cross-platform context
See how other platforms handle Sensitive Personal Information Processing and similar clauses.
Compare across platforms →Monitoring
Peloton has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"Sensitive Personal Information. We process Sensitive Personal Information for the purposes of providing Services, carrying out our legal obligations or exercising specific rights as permitted by law. The definition of Sensitive Personal Information depends on jurisdiction and where you are located, but health information, biometric data, precise geolocation data, information relating to race, sexuality, and religion are examples of what may be considered sensitive in some locations. Please also review the YOUR PRIVACY RIGHTS AND PREFERENCES section below. By choosing to use our Services, you acknowledge that you will not disclose Sensitive Personal Information to us through, or in connection, with our Services unless we have explicitly requested such disclosure from you.Excerpt from Peloton's Privacy Policy
REGULATORY LANDSCAPE: GDPR Article 9 prohibits processing of special category data without explicit consent or another enumerated exception, covering health data, biometric data, racial or ethnic origin, and sexual orientation. CCPA and CPRA establish a category of sensitive personal information with restricted processing requirements and an opt-out right. Multiple U.S. state privacy laws (Virginia, Colorado, Texas, Connecticut, and others) impose heightened consent or opt-out requirements for sensitive data categories. The FTC has enforcement authority over deceptive practices related to sensitive data processing. GOVERNANCE EXPOSURE: High. The breadth of sensitive data categories acknowledged in this provision, combined with the automated collection of biometric-adjacent and health-related data through platform features described elsewhere in the policy, creates compound compliance exposure across GDPR, CCPA, and state privacy frameworks. The policy's attempt to limit user-volunteered sensitive disclosures does not address the regulatory obligations triggered by automated sensitive data collection. JURISDICTION FLAGS: EU/EEA exposure is highest given GDPR Article 9's explicit consent requirements for special category data processing. California CPRA's sensitive personal information provisions impose specific use limitations and opt-out rights. Illinois BIPA applies to biometric data specifically. State health data statutes may apply to health information processed through the platform. CONTRACT AND VENDOR IMPLICATIONS: Organizations deploying Peloton as a workplace wellness benefit should assess whether employee processing of sensitive personal information through Peloton services creates obligations under their own GDPR data protection agreements or CCPA service provider contracts. The policy's legal basis assertions for sensitive data processing should be reviewed against applicable regulatory requirements. COMPLIANCE CONSIDERATIONS: Legal teams should map each sensitive data category identified in this provision against the specific legal basis and consent mechanism used for its processing, and assess whether those mechanisms satisfy applicable requirements in each relevant jurisdiction. The interaction between this provision's acknowledgment language and the automated collection of sensitive data through platform features should be reviewed for consistency and adequacy of disclosure.
Regulatory citations, enforcement risk, and due diligence action items.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
This provision acknowledges processing of sensitive personal information categories that trigger heightened regulatory obligations under GDPR, CCPA, and multiple U.S. state privacy frameworks. The clause's statement that users acknowledge they will not disclose sensitive information unless explicitly requested does not function as a complete limitation on such processing, as other provisions in the policy describe collection of health-adjacent and biometric …
The agreement establishes that Peloton processes sensitive personal information categories, including health information, biometric data, precise geolocation, and information related to race, sexuality, and religion, for purposes of service provision and legal compliance. The policy states that users acknowledge they will not volunteer sensitive information beyond what Peloton explicitly requests, though other provisions describe automated collection of biometric-adjacent and health-related …
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Peloton.