Provision Registry

3805 classified provisions across 299 platforms — browse, filter, and compare.

Every clause classified by type, severity, and platform. Updated as policies change.

Start Compliance free trial Track specific clauses across platforms with provision-level alerts.
Filtering: High × Clear all
high Liability limitation
Google Gemini · Google Generative AI Prohibited Use Policy
This provision limits the use of Gemini outputs as a basis for consequential decisions in regulated domains, which directly affects how the service may be deployed in enterprise or consumer-facing applications in these sectors.
CA-P-011355 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
high Content moderation
Zoom · Zoom Privacy Statement
The clause creates a conditional framework where HIPAA-covered entities operate under a separate contractual regime for health data handling. This ensures that entities subject to HIPAA compliance obligations have explicit contractual alignment with Zoom regarding PHI safeguards and use restrictions required by the Health Insurance Portability and Accountability Act.
CA-P-009836 First tracked May 10, 2026 Last seen May 11, 2026 Compare across platforms →
high Content moderation
Box · Box Terms of Service
The clause creates a conditional compliance framework: HIPAA-regulated data processing is permitted only through an executed BAA. Without this requirement, Box could not legally handle PHI under HIPAA regulations, and the BAA mechanism establishes the contractual basis for lawful processing of health information.
CA-P-006131 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
AWS Bedrock · AWS Service Terms
This provision creates a feature-level compliance boundary within a single service offering. Organizations subject to HIPAA must verify feature eligibility before using Bedrock to handle PHI, as non-eligible features lack BAA protections and therefore cannot lawfully process PHI under HIPAA requirements.
CA-P-005321 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →
OpenAI · OpenAI Enterprise Privacy
A BAA is a legal requirement under HIPAA before a covered entity or business associate can share protected health information with a service provider. The document states this is available for qualifying customers but does not specify which services are HIPAA-eligible, requiring separate confirmation.
CA-P-011971 First tracked May 12, 2026 Last seen May 20, 2026 Compare across platforms →
OpenAI · OpenAI Data Processing Addendum
This provision places the compliance burden on the operator to identify when HIPAA applies to their use case and to execute a BAA before submitting any protected health information. Using the API with PHI without a BAA in place would constitute a potential HIPAA violation by the operator.
CA-P-010999 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
OpenAI · OpenAI Enterprise Privacy
This provision establishes that API-based deployments handling protected health information may be eligible for BAA coverage, which is a prerequisite for using a third-party vendor under HIPAA. The provision specifies API deployments; compliance teams should confirm whether ChatGPT Enterprise or other product tiers are also within scope of the BAA.
CA-P-012446 First tracked May 20, 2026 Last seen May 22, 2026 Compare across platforms →
high Content moderation
Headspace · Headspace Privacy Policy
This designation brings Headspace's handling of health information within the regulatory framework established by HIPAA, which imposes specific requirements on business associates regarding the use, disclosure, and safeguarding of protected health information on behalf of covered entities. The provision clarifies the regulatory relationship between Headspace and its Care Provider partners.
CA-P-006415 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
Headspace · Headspace Privacy Policy
This classification subjects Headspace to HIPAA's security, privacy, and breach notification requirements as a business associate, establishing a specific regulatory framework for how protected health information is handled. The provision creates institutional obligations for data protection standards and audit/compliance procedures that differ from standard commercial privacy frameworks.
CA-P-001135 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
Luma AI · Luma AI Terms of Service
This provision explicitly excludes healthcare-related data use cases from the scope of the Services and disclaims all liability for prohibited data or high-risk activity use, which may affect healthcare-adjacent organizations that consider using the platform for clinical, administrative, or research purposes.
CA-P-012708 First tracked May 21, 2026 Last seen May 22, 2026 Compare across platforms →
high Content moderation
Weights & Biases · Weights & Biases Terms of Service
This provision clarifies the regulatory scope of the standard service offering by excluding HIPAA-covered use cases from the default agreement structure. It establishes that HIPAA compliance requires a separate contractual arrangement and explicitly prohibits HIPAA-regulated data flows under the standard terms, creating a binary framework: either use the service without PHI, or negotiate specialized BAA terms.
CA-P-004034 First tracked Apr 30, 2026 Last seen Apr 30, 2026 Compare across platforms →
high Liability limitation
Luma AI · Luma AI Terms of Service
This provision clarifies the operational scope of Luma's compliance obligations by explicitly excluding HIPAA-regulated data from the scope of the service. It establishes liability boundaries by stating that Luma will not accept responsibility for protected health information or high-risk use cases, thereby defining the service's applicable regulatory framework.
CA-P-004098 First tracked Apr 30, 2026 Last seen Apr 30, 2026 Compare across platforms →
high Data sharing
Wealthfront · Wealthfront Privacy Policy
This clause establishes the operational framework for information flow necessary to execute home lending services across multiple vendors and stages of the loan lifecycle. The provision defines the scope of permissible data sharing and the purposes for which third parties may access and use client information.
CA-P-001761 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
Xfinity · Comcast Privacy Policy
Video footage and sensor data from inside a subscriber's home represent some of the most sensitive categories of personal information, and the policy's scope for using and sharing this data deserves careful consumer attention.
CA-P-007697 First tracked May 9, 2026 Last seen May 22, 2026 Compare across platforms →
Zoom · Zoom Privacy Statement
The clause establishes administrative access controls that permit account-level oversight of meeting activity and archived content, which is operationally significant for organizations managing multiple users and meetings under a single account structure.
CA-P-006533 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
high Liability limitation
Airbnb · Airbnb Terms of Service
This provision establishes that Airbnb does not assume responsibility for Hosts' regulatory compliance, placing full compliance obligation on the Host operator. The operational significance is that Hosts must independently identify and satisfy jurisdiction-specific requirements before and during listing operations, including licensing, permitting, lease authorization, and local occupancy restrictions.
CA-P-002760 First tracked Apr 18, 2026 Last seen Apr 18, 2026 Compare across platforms →
high Targeting restrictions
Meta · Meta Special Ad Category Requirements
This provision operationally defines the scope of the Housing Special Ad Category, establishing which product and service types trigger the mandatory designation and associated targeting restrictions. Real estate, mortgage, insurance, and home services advertisers must evaluate whether their campaigns fall within this definition to maintain compliance with both Meta's policy and applicable fair housing law.
CA-P-012285 First tracked May 20, 2026 Last seen May 22, 2026 Compare across platforms →
ADP · ADP Privacy Statement
This provision identifies the specific categories of personal data processed by ADP as a processor, which include payroll, tax, benefits, and HR records, categories that carry heightened sensitivity in some jurisdictions and that trigger specific regulatory obligations regarding accuracy, retention, and security.
CA-P-012834 First tracked May 21, 2026 Last seen May 22, 2026 Compare across platforms →
high Ai automated
Microsoft · Responsible AI
This provision articulates an accountability framework positioning human responsibility as central to the deployment of AI systems. The operational significance depends on how this principle is implemented through specific service terms, policies, or technical controls elsewhere in the documentation.
CA-P-002071 First tracked Apr 4, 2026 Last seen Apr 9, 2026 Compare across platforms →
high Ai automated
Microsoft · Responsible AI Report 2025
Human oversight requirements create governance checkpoints within AI system operations, establishing institutional accountability structures and requiring documented review processes before certain AI outputs or decisions proceed to deployment or user-facing implementation.
CA-P-000030 First tracked Apr 3, 2026 Last seen Apr 10, 2026 Compare across platforms →
Google Gemini · Gemini Apps Privacy Notice
The provision establishes a human review process as an operational mechanism for quality assurance and model improvement, which means certain conversation data flows to human reviewers as part of Google's service delivery and product development practices.
CA-P-001606 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
OpenAI · OpenAI Privacy Policy
The clause establishes a data processing practice where conversation content is accessed for model training purposes, subject to specified privacy protections. This defines the scope of internal access to user-generated content and the technical safeguards applied during that access.
CA-P-002003 First tracked Apr 4, 2026 Last seen Apr 4, 2026 Compare across platforms →
high Privacy rights
Google Gemini · Gemini Apps Privacy Notice
The notice explicitly authorizes human access to conversation content, and the policy advises users not to submit anything they would not want reviewed, signaling that conversation content is not treated as fully private.
CA-P-002310 First tracked Apr 9, 2026 Last seen May 20, 2026 Compare across platforms →
DeepL · DeepL Privacy Policy
This provision establishes a data processing practice that distinguishes free-tier users from paid subscribers, creating operational conditions under which free-tier input data is designated for internal review and model training activities rather than deleted after translation.
CA-P-004493 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →
Uber · Uber Privacy Notice
This provision establishes the operational framework for identity authentication and regulatory compliance in Uber's driver onboarding and management processes. The use of automated verification technology creates an ongoing verification mechanism rather than a one-time authentication event.
CA-P-002305 First tracked Apr 9, 2026 Last seen Apr 9, 2026 Compare across platforms →
FanDuel · FanDuel Privacy Policy
Government-issued identity documents and tax information are among the most sensitive categories of personal data, and making their submission mandatory means you cannot use those features of the service without providing them, with all associated sharing and retention risks described elsewhere in the policy.
CA-P-007235 First tracked May 9, 2026 Last seen May 22, 2026 Compare across platforms →
Ticketmaster · Ticketmaster Privacy Policy
The provision explains the operational basis for identity document collection in the secondary ticket sales process, clarifying that such collection is required by the payment processor's regulatory obligations rather than by Ticketmaster's discretionary choice.
CA-P-001485 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
Square · Square Privacy Notice
Biometric data and government-issued identity documents are among the most sensitive categories of personal information, and their collection triggers specific legal obligations in several US states and under GDPR that go beyond standard privacy protections.
CA-P-010454 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
DocuSign · DocuSign Privacy Statement
This clause establishes the scope of biometric and identity data collection practices DocuSign implements to support identity verification services. The provision specifies the categories of sensitive personal information the entity is authorized to process in connection with verification transactions.
CA-P-005793 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
Coinbase · Coinbase Privacy Policy
Identity verification is a core operational requirement for regulated financial services platforms. The provision establishes the scope of personal data collection necessary for compliance with anti-money laundering and know-your-customer regulatory obligations, and specifies that biometric processing may be delegated to external service providers.
CA-P-002481 First tracked Apr 9, 2026 Last seen Apr 10, 2026 Compare across platforms →

Compliance Governance Intelligence

Monitor specific governance provisions across platforms.

Compliance includes provision-level monitoring, regulatory mapping, and audit-ready analysis.

Start free Start Compliance free trial