If employees submit personal data to Perplexity while using the service, a separate data processing agreement governs how that data is handled. That separate document is incorporated into this contract by reference.
This analysis describes what Perplexity AI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The DPA is a critical companion document for GDPR and CCPA compliance, but it is incorporated by reference rather than appended to the main agreement. Enterprise customers must review the DPA separately to understand their data protection obligations and Perplexity's commitments as a data processor.
Interpretive note: The exact DPA reference language was not directly extractable from the truncated HTML. The specific URL, scope, and terms of the DPA incorporated by reference are not available from the rendered document and must be reviewed separately from Perplexity's legal page.
The updated terms now apply to multiple Perplexity enterprise products (not just Enterprise Pro and Max), and Perplexity reserves the right to add, remove, or modify which services are covered at its sole discretion, with continued use constituting acceptance. The terms introduce automatic data sharing with third-party marketing partners for advertising purposes, though Perplexity states it does not share Customer Content. New provisions govern usage-based billing and seat count changes, including immediate effectiveness of seat increases with prorated charges and seat decreases taking effect at renewal without refund. You can review product-specific terms for Comet and Agentic services, and you may request cessation of Perplexity Controlled Information use if it conflicts with applicable data privacy laws.
View change record →Removal of explicit DPA reference may indicate relocation of data processing terms or integration into the main agreement, potentially affecting GDPR/privacy compliance documentation.
View full change record →Enterprise customers who deploy Perplexity for employees must review the separately published Data Processing Addendum to understand how personal data submitted during service use is processed, stored, and protected. The DPA governs GDPR and CCPA compliance obligations and sub-processor arrangements, which are not visible in the main agreement.
How other platforms handle this
to request that your data be transferred to a third party (data portability)
Your organization may allow you to access and export your data in order to back it up or transfer it to a service outside of Google.
Further, you may take legal actions in relation to any potential breach of your rights regarding the processing of your Personal Information, as well as to lodge complaints before the competent data prot...
"To the extent Customer Data includes Personal Data (as defined under applicable data protection laws), the processing of such Personal Data by Perplexity shall be governed by the Data Processing Addendum ('DPA') available at [Perplexity's legal page], which is incorporated by reference into this Agreement.Excerpt from Perplexity AI's Perplexity Enterprise Terms
(1) REGULATORY LANDSCAPE: The DPA reference directly engages GDPR Article 28, which requires a written contract between controllers and processors specifying the subject matter, duration, nature, and purpose of processing, as well as sub-processor obligations.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
The DPA is a critical companion document for GDPR and CCPA compliance, but it is incorporated by reference rather than appended to the main agreement. Enterprise customers must review the DPA separately to understand their data protection obligations and Perplexity's commitments as a data processor.
Enterprise customers who deploy Perplexity for employees must review the separately published Data Processing Addendum to understand how personal data submitted during service use is processed, stored, and protected. The DPA governs GDPR and CCPA compliance obligations and sub-processor arrangements, which are not visible in the main agreement.
ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Perplexity AI.