The agreement prohibits use of Squarespace services in ways that would subject Squarespace to HIPAA, GLBA, FERPA, or similar industry-specific regulations without prior written agreement from Squarespace. Handling protected health information is specifically prohibited unless the account is designated as HIPAA-enabled and a separate business associate agreement is in place.
This analysis describes what Squarespace's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes a contractual prohibition on processing protected health information or other regulated data through standard Squarespace services, requiring a separate written agreement and account designation. Operators in healthcare, financial services, or education sectors must obtain specific contractual authorization before using the platform for regulated data processing.
This provision establishes that standard Squarespace accounts cannot lawfully be used to collect or process protected health information or other data regulated under HIPAA, GLBA, or FERPA without a separately negotiated written agreement and account designation. End users submitting health or other sensitive regulated data through a non-HIPAA-enabled Squarespace site should be aware that the platform is not contractually authorized to handle such data under standard terms.
Cross-platform context
See how other platforms handle HIPAA and Industry-Specific Compliance Prohibition and similar clauses.
Compare across platforms →"If your use of the Services requires you to comply with industry-specific regulations applicable to such use, such as HIPAA, GLBA or FERPA (each, an "Industry-Specific Regulation"), you will be solely responsible for such compliance, except to the extent Squarespace has agreed with you in writing otherwise. You are not permitted to use the Services in any way that would subject Squarespace to an Industry-Specific Regulation without obtaining Squarespace's prior written agreement. For example, you may not use any Services to collect, use, disclose, protect or otherwise handle "protected health information" (as defined in 45 C.F.R. §160.103) unless your Account for such Services is designated as HIPAA-enabled and you enter into a separate business associate agreement with Squarespace.Excerpt from Squarespace's Terms of Service
(1) REGULATORY LANDSCAPE: This provision directly engages HIPAA (45 C.F.R.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes a contractual prohibition on processing protected health information or other regulated data through standard Squarespace services, requiring a separate written agreement and account designation. Operators in healthcare, financial services, or education sectors must obtain specific contractual authorization before using the platform for regulated data processing.
This provision establishes that standard Squarespace accounts cannot lawfully be used to collect or process protected health information or other data regulated under HIPAA, GLBA, or FERPA without a separately negotiated written agreement and account designation. End users submitting health or other sensitive regulated data through a non-HIPAA-enabled Squarespace site should be aware that the platform is not contractually authorized …
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Squarespace.