Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The agreement prohibits customers from transmitting, storing, or processing HIPAA-covered health information without an executed BAA, PCI-DSS-covered payment card information, and GDPR special category personal data on the PlanetScale platform.
This analysis describes what PlanetScale's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes three distinct data category prohibitions with materially different practical implications: HIPAA data is conditionally permitted via BAA execution; PCI-DSS data is categorically prohibited without a stated exception pathway; and GDPR special category data is categorically prohibited without a stated exception pathway. Organizations processing any of these data categories must verify their compliance posture before deploying workloads on PlanetScale.
Under this clause, customers agree not to use PlanetScale to process HIPAA health data without a signed BAA, any PCI-DSS payment card data, or GDPR special category personal data. Violation of these restrictions may constitute a breach of the agreement and could trigger suspension or termination rights.
Cross-platform context
See how other platforms handle Prohibited Data Categories: HIPAA, GDPR Special Categories, and PCI-DSS and similar clauses.
Compare across platforms →Monitoring
PlanetScale has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Customer will not, and will not allow End Users to... (g) to transmit, store, or process health information subject to United States HIPAA regulations except as permitted by an executed HIPAA BAA; (h) to transmit, store or process payment information subject to the payment card industry data security standards; (i) to transmit, store or process 'special categories of personal data' (as defined in the General Data Protection Regulation 2016/679)Excerpt from PlanetScale's Terms of Service
(1) REGULATORY LANDSCAPE: This provision directly engages HIPAA (administered by HHS OCR), PCI-DSS (enforced through payment card brand rules and acquiring banks), and GDPR (enforced by EU/EEA supervisory authorities). The categorical prohibition on GDPR special category data (which includes health, biometric, racial, religious, and political data under GDPR Article 9) is notable because it provides no compliant pathway, unlike the HIPAA carve-out. The absence of a PCI-DSS exception pathway means customers who process payment card data must ensure complete workload segregation from PlanetScale. (2) GOVERNANCE EXPOSURE: High for organizations in healthcare, financial services, or those processing EU personal data. The prohibition on GDPR special category data without any permitted exception pathway means that inadvertent processing of such data constitutes an agreement breach, independent of whether GDPR compliance is otherwise maintained. Healthcare organizations must confirm BAA execution before any production deployment. (3) JURISDICTION FLAGS: EU/EEA customers face categorical prohibition on special category data processing on this platform as stated in the agreement. HIPAA-covered entities and business associates in the U.S. must execute a BAA before processing any PHI. PCI-DSS restrictions apply globally to any customer processing payment card data. California customers processing health data that may not meet the HIPAA threshold should also evaluate California Confidentiality of Medical Information Act (CMIA) applicability. (4) CONTRACT AND VENDOR IMPLICATIONS: Procurement teams conducting vendor assessments for workloads involving any of the three prohibited data categories must verify the applicable exception pathway (BAA for HIPAA) or confirm workload segregation (PCI-DSS, GDPR special categories). The DPA at the referenced URL should be reviewed to confirm whether it addresses GDPR Article 28 obligations and whether it modifies the categorical special category data prohibition. (5) COMPLIANCE CONSIDERATIONS: Legal and compliance teams should conduct a data mapping exercise to identify whether any existing or planned PlanetScale workloads involve prohibited data categories. Healthcare organizations should obtain and execute the HIPAA BAA before processing any PHI. Organizations handling EU personal data should confirm with data protection officers whether any processed data may constitute GDPR special category data and establish workload boundaries accordingly. The PCI-DSS prohibition should be operationalized through technical controls ensuring payment card data is not routed to PlanetScale systems.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes three distinct data category prohibitions with materially different practical implications: HIPAA data is conditionally permitted via BAA execution; PCI-DSS data is categorically prohibited without a stated exception pathway; and GDPR special category data is categorically prohibited without a stated exception pathway. Organizations processing any of these data categories must verify their compliance posture before deploying workloads on …
Under this clause, customers agree not to use PlanetScale to process HIPAA health data without a signed BAA, any PCI-DSS payment card data, or GDPR special category personal data. Violation of these restrictions may constitute a breach of the agreement and could trigger suspension or termination rights.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by PlanetScale.