PlanetScale · PlanetScale Terms of Service · View original document ↗

Prohibited Data Categories: HIPAA, GDPR Special Categories, and PCI-DSS

High severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time PlanetScale changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for PlanetScale Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The agreement prohibits customers from transmitting, storing, or processing HIPAA-covered health information without an executed BAA, PCI-DSS-covered payment card information, and GDPR special category personal data on the PlanetScale platform.

This analysis describes what PlanetScale's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes three distinct data category prohibitions with materially different practical implications: HIPAA data is conditionally permitted via BAA execution; PCI-DSS data is categorically prohibited without a stated exception pathway; and GDPR special category data is categorically prohibited without a stated exception pathway. Organizations processing any of these data categories must verify their compliance posture before deploying workloads on PlanetScale.

Consumer impact (what this means for users)

Under this clause, customers agree not to use PlanetScale to process HIPAA health data without a signed BAA, any PCI-DSS payment card data, or GDPR special category personal data. Violation of these restrictions may constitute a breach of the agreement and could trigger suspension or termination rights.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Close Your Account
    If your workloads involve HIPAA, GDPR special category, or PCI-DSS data and you cannot obtain a BAA or achieve required workload segregation, contact PlanetScale support to discuss account options or initiate export and migration of Customer Content before closing the account.

Cross-platform context

See how other platforms handle Prohibited Data Categories: HIPAA, GDPR Special Categories, and PCI-DSS and similar clauses.

Compare across platforms →

Monitoring

PlanetScale has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Customer will not, and will not allow End Users to... (g) to transmit, store, or process health information subject to United States HIPAA regulations except as permitted by an executed HIPAA BAA; (h) to transmit, store or process payment information subject to the payment card industry data security standards; (i) to transmit, store or process 'special categories of personal data' (as defined in the General Data Protection Regulation 2016/679)

Excerpt from PlanetScale's Terms of Service

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

(1) REGULATORY LANDSCAPE: This provision directly engages HIPAA (administered by HHS OCR), PCI-DSS (enforced through payment card brand rules and acquiring banks), and GDPR (enforced by EU/EEA supervisory authorities). The categorical prohibition on GDPR special category data (which includes health, biometric, racial, religious, and political data under GDPR Article 9) is notable because it provides no compliant pathway, unlike the HIPAA carve-out. The absence of a PCI-DSS exception pathway means customers who process payment card data must ensure complete workload segregation from PlanetScale. (2) GOVERNANCE EXPOSURE: High for organizations in healthcare, financial services, or those processing EU personal data. The prohibition on GDPR special category data without any permitted exception pathway means that inadvertent processing of such data constitutes an agreement breach, independent of whether GDPR compliance is otherwise maintained. Healthcare organizations must confirm BAA execution before any production deployment. (3) JURISDICTION FLAGS: EU/EEA customers face categorical prohibition on special category data processing on this platform as stated in the agreement. HIPAA-covered entities and business associates in the U.S. must execute a BAA before processing any PHI. PCI-DSS restrictions apply globally to any customer processing payment card data. California customers processing health data that may not meet the HIPAA threshold should also evaluate California Confidentiality of Medical Information Act (CMIA) applicability. (4) CONTRACT AND VENDOR IMPLICATIONS: Procurement teams conducting vendor assessments for workloads involving any of the three prohibited data categories must verify the applicable exception pathway (BAA for HIPAA) or confirm workload segregation (PCI-DSS, GDPR special categories). The DPA at the referenced URL should be reviewed to confirm whether it addresses GDPR Article 28 obligations and whether it modifies the categorical special category data prohibition. (5) COMPLIANCE CONSIDERATIONS: Legal and compliance teams should conduct a data mapping exercise to identify whether any existing or planned PlanetScale workloads involve prohibited data categories. Healthcare organizations should obtain and execute the HIPAA BAA before processing any PHI. Organizations handling EU personal data should confirm with data protection officers whether any processed data may constitute GDPR special category data and establish workload boundaries accordingly. The PCI-DSS prohibition should be operationalized through technical controls ensuring payment card data is not routed to PlanetScale systems.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Get same-day alerts when this changes → Get Analyst

Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.

Applicable agencies

  • Hhs Ocr
    HHS OCR enforces HIPAA requirements relevant to the BAA prerequisite for health data processing on the platform
    File a complaint →

Provision details

Document information
Document
PlanetScale Terms of Service
Entity
PlanetScale
Document last updated
May 5, 2026
Tracking information
First tracked
July 12, 2026
Last verified
July 12, 2026
Record ID
CA-P-074342
Document ID
CA-D-00683
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
66f4acad5ba0274c92946f618cbb71bc8537e8d2abef828139e0c429c54ca79d
Analysis generated
July 12, 2026 15:44 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: PlanetScale
Document: PlanetScale Terms of Service
Record ID: CA-P-074342
Captured: 2026-07-12 15:44:57 UTC
SHA-256: 66f4acad5ba0274c…
URL: https://conductatlas.com/platform/planetscale/planetscale-terms-of-service/provision/CA-P-074342/prohibited-data-categories-hipaa-gdpr-special-categories-and-pci-dss/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Get Compliance

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does PlanetScale's Prohibited Data Categories: HIPAA, GDPR Special Categories, and PCI-DSS clause do?

This provision establishes three distinct data category prohibitions with materially different practical implications: HIPAA data is conditionally permitted via BAA execution; PCI-DSS data is categorically prohibited without a stated exception pathway; and GDPR special category data is categorically prohibited without a stated exception pathway. Organizations processing any of these data categories must verify their compliance posture before deploying workloads on …

How does this clause affect you?

Under this clause, customers agree not to use PlanetScale to process HIPAA health data without a signed BAA, any PCI-DSS payment card data, or GDPR special category personal data. Violation of these restrictions may constitute a breach of the agreement and could trigger suspension or termination rights.

Is ConductAtlas affiliated with PlanetScale?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by PlanetScale.