1. What the document is: Perplexity's Data Processing Addendum (DPA) for business customers (Pro for Enterprise, API). It governs Perplexity's role as Processor/Service Provider for Customer-submitted Personal Data.
What this wiki found — complete, every page
Presence facts, not verdicts — each flagged term links to its definition and the exact clause on this page. Absence of a badge means the term isn't currently flagged here, not that the page is risk-free.
Perplexity – Data Processor Agreement
Dataset: GenGA (Generative AI Governance Archive) — 11 AI services, 2025–present
GenGA (Generative AI Governance Archive) is this wiki’s Generative-AI dataset: raw policy snapshots captured by the Open Terms Archive
genai-euproject across 11 GenAI providers (ChatGPT, Claude.ai, DeepSeek, Google Generative AI Services, Le Chat, Llama API, Meta AI, Microsoft Copilot, Perplexity, Qwen Chat, xAI). Unlike PGAv2, GenGA has no pre-tagged risk scores — all risk scoring and keyword tagging on these pages is LLM-assigned by direct reading, spanning 2025–present.
Note: This page contains documented policy clauses. Risk assessment is qualitative and context-dependent. For analysis of patterns across platforms, see:
Source: sources/GenGA/Perplexity/Data Processor Agreement/ (raw Markdown captures, Open Terms Archive genai-eu dataset — no pre-tagged JSONL exists for this source)
Last updated: 2025-11-11 (only capture in this dataset; document’s own “Last updated: July 8th, 2025”)
Note on methodology: No pre-computed
risk_score/keywordfields exist for this source. Keyword tags and clause analysis on this page are LLM-assigned, using the same rubric/vocabulary as the PGAv2 pages plus new GenAI-specific tags (gdpr,train AI/models). Treat as first-pass analysis, not externally verified ground truth. This wiki’s risk-scoring system was retired project-wide on 2026-06-21 (seemethodology.md§4) — no page, GenGA included, computes or displays a numeric risk score.
Overview
1. What the document is: Perplexity’s Data Processing Addendum (DPA) for business customers (Pro for Enterprise, API). It governs Perplexity’s role as Processor/Service Provider for Customer-submitted Personal Data.
2. Input rights: An explicit no-training commitment, but scoped to Personal Data specifically: “For the avoidance of doubt, Personal Data will not be used for training of Perplexity’s large language models.” This is narrower than Llama API’s or Claude.ai’s unconditional commitments — it only covers Personal Data within Input, not Input/Output generally.
3. Output restrictions: Not addressed in this document.
4. Non-explicit predatory clauses: A distinctive subcontractor-objection asymmetry. For ordinary subcontractors, the Customer may object and, if unresolved, terminate the Agreement for a refund. But for “Model Provider” subcontractors (LLM/generative-AI providers), the Customer’s “sole recourse” if it objects is to “cease all use of the relevant Third-Party Model via the Services” — a narrower, feature-level remedy rather than a right to terminate the contract.
5. Regulatory references: A comprehensive, standard GDPR/UK GDPR DPA. It defines “Controller to Processor Clauses” (EU SCCs Module 2) and “Processor to Processor Clauses” (Module 3), citing Commission Decision 2021/914, and designates the Irish regulator as the competent supervisory authority with Irish law/courts governing — consistent with other providers’ in-house-EU-entity pattern (OpenAI, Anthropic, Mistral).
6. Regional variation: Distinguishes EU/UK Privacy Laws from US Privacy Laws (CCPA, Colorado, Connecticut, Utah, Virginia) within the same defined-terms section — one of the more US-state-law-detailed DPAs in this dataset.
7. Key risk to users: Low — this is a standard, well-structured Processor agreement. The only point worth flagging is that the no-training carve-out covers Personal Data specifically, not Input generally, leaving open whether non-personal Input data could still be used for training.
Flagged Keywords & Risks (LLM-assigned)
gdpr— The full EU/UK SCC Module 2/Module 3 framework, with Irish supervisory authority and governing law. Why it matters: this is a complete, well-cited GDPR compliance structure, consistent with this dataset’s in-house-EU-entity providers.train AI/models— “Personal Data will not be used for training of Perplexity’s large language models.” Why it matters: this only covers Personal Data, not a blanket Input/Output no-training commitment — narrower than Llama API’s or Claude.ai’s equivalents.
Regulatory & Research Context
Perplexity falls outside the provider sets directly studied by Davidson et al. (2026) and Pandit et al. (2026), so their findings apply here only by analogy. The Model Provider subcontractor asymmetry flagged above — where Customer’s “sole recourse” against an objectionable LLM subcontractor is to “cease all use of the relevant Third-Party Model,” rather than terminate the Agreement for a refund as with ordinary subcontractors — illustrates the kind of one-sided remedy structure Pandit et al. describe when they note that GenAI terms leave customers with “responsibilities they cannot materially fulfil without violating the terms.” Edwards et al. (2025) would likewise read this asymmetry as consistent with the “platformisation paradigm,” in which contractual remedies are narrowed precisely where the provider’s own AI-model supply chain is implicated.
Changes Summary
| Date | What changed |
|---|---|
| 2025-11-11 | Baseline and only version captured in this dataset. |
Version History
2025-11-11
- Explicit AI clause: YES
- Non-explicit predatory: NO
- Flagged keywords:
gdpr,train AI/models
Clause: gdpr
“Controller to Processor Clauses” means (i) in respect of transfers of Personal Data subject to the GDPR, the standard contractual clauses for the transfer of Personal Data to third countries set out in Commission Decision 2021/914 of 4 June 2021, specifically including Module 2 (Controller to Processor) (“EU SCCs”); and (ii) in respect of transfers of Personal Data subject to the UK GDPR, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (version B.1.0) issued by the UK Information Commissioner (“UK Addendum”).
Clause: train AI/models
For the avoidance of doubt, Personal Data will not be used for training of Perplexity’s large language models.
Clause: Model Provider subcontractor asymmetry (not separately concept-tagged)
If Perplexity appoints a new subcontractor or intends to make any changes concerning the addition or replacement of any subcontractor that provides large language models or other generative artificial intelligence models (a “Model Provider”), Perplexity will notify Customer (email sufficient) and will update the list of “Third-Party Providers”… If Customer objects to the appointment or replacement, Customer’s sole recourse is to (and Customer must) cease all use of the relevant Third-Party Model via the Services.