Provision record
PlanetScale · PlanetScale Terms of Service · View original document ↗

Prohibited Data Categories: HIPAA, GDPR Special Categories, and PCI-DSS

High severity High confidence Explicit document language Unique · 0 of 352 platforms
Stay ahead of the changes
Track PlanetScale and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF
Document Record

What it is

The agreement prohibits customers from transmitting, storing, or processing HIPAA-covered health information without an executed BAA, PCI-DSS-covered payment card information, and GDPR special category personal data on the PlanetScale platform.

ⓘ

This analysis describes what PlanetScale's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes three distinct data category prohibitions with materially different practical implications: HIPAA data is conditionally permitted via BAA execution; PCI-DSS data is categorically prohibited without a stated exception pathway; and GDPR special category data is categorically prohibited without a stated exception pathway. Organizations processing any of these data categories must verify their compliance posture before deploying workloads on PlanetScale.

Consumer impact (what this means for users)

Under this clause, customers agree not to use PlanetScale to process HIPAA health data without a signed BAA, any PCI-DSS payment card data, or GDPR special category personal data. Violation of these restrictions may constitute a breach of the agreement and could trigger suspension or termination rights.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Close Your Account
    If your workloads involve HIPAA, GDPR special category, or PCI-DSS data and you cannot obtain a BAA or achieve required workload segregation, contact PlanetScale support to discuss account options or initiate export and migration of Customer Content before closing the account.

Cross-platform context

See how other platforms handle Prohibited Data Categories: HIPAA, GDPR Special Categories, and PCI-DSS and similar clauses.

Compare across platforms →
▸ View Original Clause Language DOCUMENT RECORD
"
Customer will not, and will not allow End Users to... (g) to transmit, store, or process health information subject to United States HIPAA regulations except as permitted by an executed HIPAA BAA; (h) to transmit, store or process payment information subject to the payment card industry data security standards; (i) to transmit, store or process 'special categories of personal data' (as defined in the General Data Protection Regulation 2016/679)

Excerpt from PlanetScale's Terms of Service

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

(1) REGULATORY LANDSCAPE: This provision directly engages HIPAA (administered by HHS OCR), PCI-DSS (enforced through payment card brand rules and acquiring banks), and GDPR (enforced by EU/EEA supervisory authorities).

Insight

Unlock the full institutional analysis

Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.

Applicable agencies

  • Department Of Health & Human Services, Office For Civil Rights (hhs Ocr)
    Enforces HIPAA Privacy and Security Rules, which protect health information held by healthcare providers, health plans, and their business associates.
    Who can file: Anyone whose HIPAA rights may have been violated by a covered entity (healthcare provider, health plan, or healthcare clearinghouse)
    What you need: Name of the entity, description of the violation, date of the incident, and your contact information. Must file within 180 days of the violation.
    What to expect: HHS OCR investigates and may require the entity to take corrective action. Does not provide individual compensation. Serious violations can result in civil monetary penalties.
    File a complaint →

Provision details

Document information
Document
PlanetScale Terms of Service
Entity
PlanetScale
Document last updated
May 5, 2026
Tracking information
First tracked
July 12, 2026
Last verified
July 12, 2026
Record ID
CA-P-074342
Document ID
CA-D-00683
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
66f4acad5ba0274c92946f618cbb71bc8537e8d2abef828139e0c429c54ca79d
Analysis generated
July 12, 2026 15:44 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: PlanetScale
Document: PlanetScale Terms of Service
Record ID: CA-P-074342
Captured: 2026-07-12 15:44:57 UTC
SHA-256: 66f4acad5ba0274c…
URL: https://conductatlas.com/platform/planetscale/planetscale-terms-of-service/provision/CA-P-074342/prohibited-data-categories-hipaa-gdpr-special-categories-and-pci-dss/
Accessed: Sept. 26, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does PlanetScale's Prohibited Data Categories: HIPAA, GDPR Special Categories, and PCI-DSS clause do?

This provision establishes three distinct data category prohibitions with materially different practical implications: HIPAA data is conditionally permitted via BAA execution; PCI-DSS data is categorically prohibited without a stated exception pathway; and GDPR special category data is categorically prohibited without a stated exception pathway. Organizations processing any of these data categories must verify their compliance posture before deploying workloads on …

How does this clause affect you?

Under this clause, customers agree not to use PlanetScale to process HIPAA health data without a signed BAA, any PCI-DSS payment card data, or GDPR special category personal data. Violation of these restrictions may constitute a breach of the agreement and could trigger suspension or termination rights.

Is ConductAtlas affiliated with PlanetScale?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by PlanetScale.