Provision record
Perplexity AI · Perplexity Data Processing Addendum · View original document ↗

Subprocessor Liability under EU/UK Privacy Laws

Low severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Perplexity AI changes these terms. Follow Perplexity AI →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Perplexity AI recorded 11 documented changes in the last 30 days.
Follow Perplexity AI →
Monitor governance changes for Perplexity AI Monitor emails you the same day this changes. The archive stays free.
Follow Perplexity AI →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The DPA requires Perplexity to flow down DPA obligations to subcontractors and states that Perplexity remains fully liable for subcontractor performance failures under EU/UK Privacy Laws.

This analysis describes what Perplexity AI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes Perplexity's full liability for subcontractor failures under EU/UK Privacy Laws, consistent with GDPR Article 28(4), and requires written sub-processor agreements with equivalent obligations.

Change history

added Jul 23, 2026

This addition ensures Perplexity maintains full liability for subcontractor failures under EU/UK Privacy Laws despite contractual pass-through obligations, protecting customers under GDPR/UK GDPR frameworks.

View full change record →

Consumer impact (what this means for users)

Under this clause, Perplexity remains contractually and legally liable for the performance of its subcontractors under EU/UK Privacy Laws, providing Customer with a single point of accountability for sub-processor failures.

Cross-platform context

See how other platforms handle Subprocessor Liability under EU/UK Privacy Laws and similar clauses.

Compare across platforms →

Monitoring

Perplexity AI has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Follow Perplexity AI → Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Perplexity shall engage subcontractors only pursuant to a written agreement that contains obligations on the subcontractor which are no less onerous on the relevant subcontractor than the obligations on Perplexity under this DPA. In the event Perplexity engages a subcontractor to carry out specific processing activities on behalf of Customer pursuant to EU/UK Privacy Laws, where that subcontractor fails to fulfil its obligations, Perplexity shall remain fully liable under applicable EU/UK Privacy Laws to Customer for the performance of that subcontractor's obligations.

Excerpt from Perplexity AI's Perplexity Data Processing Addendum

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

REGULATORY LANDSCAPE: This provision directly implements GDPR Article 28(4) requirements, which establish that where a sub-processor fails to fulfill its data protection obligations, the initial processor (Perplexity) remains fully liable to the controller. The Irish DPC is the designated competent supervisory authority for EU enforcement purposes. UK GDPR imposes equivalent requirements. GOVERNANCE EXPOSURE: Low. The provision is consistent with GDPR Article 28(4) mandatory requirements and is standard in compliant processor agreements. However, the practical scope of Perplexity's liability is limited to EU/UK Privacy Laws contexts, and the DPA does not expressly extend equivalent liability for subcontractor failures under US Privacy Laws. JURISDICTION FLAGS: EU/EEA and UK customers have the clearest contractual protection under this provision. US customers should assess whether equivalent subcontractor liability is available under applicable US state law or must be negotiated separately. CONTRACT AND VENDOR IMPLICATIONS: Procurement teams should request copies of or representations about Perplexity's sub-processor agreements to confirm that equivalent obligations are flowed down, particularly for Model Providers listed in Annex 2. The reference to Amazon Web Services and Microsoft as security measure subcontractors in Annex 3 indicates that these entities process Personal Data in scope. COMPLIANCE CONSIDERATIONS: Legal teams should confirm that the sub-processor list in Annex 2 and the Third-Party Providers list are current and that Perplexity has executed Processor-to-Processor Clauses with each subcontractor processing Personal Data in Third Countries.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Provision details

Document information
Document
Perplexity Data Processing Addendum
Entity
Perplexity AI
Document last updated
May 11, 2026
Tracking information
First tracked
May 20, 2026
Last verified
July 9, 2026
Record ID
CA-P-013631
Document ID
CA-D-00763
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
63330764edf10647a51ca197723ef717b3e1db5fabfb778068184b91e31fc670
Analysis generated
May 20, 2026 22:20 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Perplexity AI
Document: Perplexity Data Processing Addendum
Record ID: CA-P-013631
Captured: 2026-05-20 22:20:53 UTC
SHA-256: 63330764edf10647…
URL: https://conductatlas.com/platform/perplexity-ai/perplexity-data-processing-addendum/provision/CA-P-013631/subprocessor-liability-under-euuk-privacy-laws/
Accessed: July 25, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Low
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention

Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.

Frequently Asked Questions

What does Perplexity AI's Subprocessor Liability under EU/UK Privacy Laws clause do?

This provision establishes Perplexity's full liability for subcontractor failures under EU/UK Privacy Laws, consistent with GDPR Article 28(4), and requires written sub-processor agreements with equivalent obligations.

How does this clause affect you?

Under this clause, Perplexity remains contractually and legally liable for the performance of its subcontractors under EU/UK Privacy Laws, providing Customer with a single point of accountability for sub-processor failures.

Is ConductAtlas affiliated with Perplexity AI?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Perplexity AI.