Perplexity is required to delete or return all Personal Data within 30 days of service termination, with notification required if legal retention obligations apply.
This analysis describes what Perplexity AI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes a 30-day post-termination deletion or return obligation, a standard data lifecycle management control that enables Customer compliance with data minimization and retention obligations under GDPR and applicable US state privacy laws.
Business customers using Perplexity services are now governed by an updated DPA with two material operational changes. First, subprocessor disclosures have shifted from a static document attachment (Annex 2) to a live online list maintained at https://trust.perplexity.ai/subprocessors, with notifications of changes coming through in-product notification or email rather than through formal amendment. Second, certain Perplexity services (specifically Embeddings API and Perplexity Search) now operate under product-specific data postures and terms that control over the main DPA, meaning the data handling for those services may differ from the baseline agreement. Business customers should review the Trust Center list regularly and check for in-product notifications regarding subprocessor changes, as the updated terms no longer require static amendment cycles.
View change record →Previous version had empty excerpt but same provision name; current version now includes specific 30-day deletion timeline and legal retention exception with explicit notification requirement.
View full change record →The agreement requires Perplexity to delete or return all Customer Personal Data within 30 days of service termination, and to notify Customer if any legal retention obligation extends that period.
Cross-platform context
See how other platforms handle Data Deletion and Return Obligation and similar clauses.
Compare across platforms →"Perplexity shall delete (or, at Customer's option, return) all Personal Data within thirty days of the end of the provision of the Services to Customer, unless retention of the Personal Data is required by law, in which case, Perplexity shall notify Customer without undue delay of such legal requirement and shall upon the expiration of such retention obligation delete (or, at Customer's option, return) the Personal Data.Excerpt from Perplexity AI's Perplexity Data Processing Addendum
REGULATORY LANDSCAPE: This provision engages GDPR Article 28(3)(g), which requires processor agreements to address deletion or return of data upon termination, and equivalent US state law data retention and deletion requirements.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes a 30-day post-termination deletion or return obligation, a standard data lifecycle management control that enables Customer compliance with data minimization and retention obligations under GDPR and applicable US state privacy laws.
The agreement requires Perplexity to delete or return all Customer Personal Data within 30 days of service termination, and to notify Customer if any legal retention obligation extends that period.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Perplexity AI.