The agreement prohibits customers from transmitting, storing, or processing HIPAA-covered health information without an executed BAA, PCI-DSS-covered payment card information, and GDPR special category personal data on the PlanetScale platform.
This analysis describes what PlanetScale's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes three distinct data category prohibitions with materially different practical implications: HIPAA data is conditionally permitted via BAA execution; PCI-DSS data is categorically prohibited without a stated exception pathway; and GDPR special category data is categorically prohibited without a stated exception pathway. Organizations processing any of these data categories must verify their compliance posture before deploying workloads on PlanetScale.
Under this clause, customers agree not to use PlanetScale to process HIPAA health data without a signed BAA, any PCI-DSS payment card data, or GDPR special category personal data. Violation of these restrictions may constitute a breach of the agreement and could trigger suspension or termination rights.
Cross-platform context
See how other platforms handle Prohibited Data Categories: HIPAA, GDPR Special Categories, and PCI-DSS and similar clauses.
Compare across platforms →"Customer will not, and will not allow End Users to... (g) to transmit, store, or process health information subject to United States HIPAA regulations except as permitted by an executed HIPAA BAA; (h) to transmit, store or process payment information subject to the payment card industry data security standards; (i) to transmit, store or process 'special categories of personal data' (as defined in the General Data Protection Regulation 2016/679)Excerpt from PlanetScale's Terms of Service
(1) REGULATORY LANDSCAPE: This provision directly engages HIPAA (administered by HHS OCR), PCI-DSS (enforced through payment card brand rules and acquiring banks), and GDPR (enforced by EU/EEA supervisory authorities).
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes three distinct data category prohibitions with materially different practical implications: HIPAA data is conditionally permitted via BAA execution; PCI-DSS data is categorically prohibited without a stated exception pathway; and GDPR special category data is categorically prohibited without a stated exception pathway. Organizations processing any of these data categories must verify their compliance posture before deploying workloads on …
Under this clause, customers agree not to use PlanetScale to process HIPAA health data without a signed BAA, any PCI-DSS payment card data, or GDPR special category personal data. Violation of these restrictions may constitute a breach of the agreement and could trigger suspension or termination rights.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by PlanetScale.