CompanyScope
by Janus Compliance

AI search / RAG-first answer engine

Perplexity compliance: GDPR, AI Act, DPA, training, transfers

Independent compliance research from Janus Compliance. Reviewed by Michael K. Onyekwere, CIPP/E. Last reviewed 2026-05-01. Not legal advice.

Share this Perplexity profile:Share on XBluesky

TL;DR. Four distinct products: Enterprise Pro / Enterprise Max (no training, ZDR available, contractual); Sonar API (same enterprise posture); consumer free / Pro (training enabled by default unless opted out); Comet (agentic browser — much larger data-collection surface). Perplexity routes some workloads to underlying LLMs (OpenAI, Anthropic, plus first-party Sonar models) — terms apply transitively. Search query strings themselves are often Article 9 data in regulated sectors and most DPIAs miss this. HIPAA scope tightened February 2026.

DPO action: distinguish surfaces in your AI inventory; address transitive dependencies on OpenAI / Anthropic; treat Comet as a separate vendor evaluation.

What the tool does

Perplexity is an AI-powered answer engine. Instead of returning a list of links like a search engine, it crawls the web and synthesises a sourced answer. Buyers commonly evaluate one of four products:

  1. Perplexity (free / Pro consumer) — at perplexity.ai, individual or team subscriptions
  2. Perplexity Enterprise Pro / Enterprise Max — business-tier with admin controls and stronger compliance defaults
  3. Sonar API — Perplexity's developer API for embedding answer-engine functionality into other products
  4. Comet — Perplexity's agentic browser (separate product, separate compliance posture)

The compliance answer is meaningfully different across these surfaces. Most enterprise buyers should be looking at Enterprise Pro or Sonar API, not the consumer tier.

Data processed

Special-category likelihood: Medium-high. Search queries are unusually revealing — a query string like "side effects of [drug] when pregnant" is itself special-category data. Free-form team usage will leak Article 9 categories regularly.

Default geographic processing: US-centric. Perplexity has been adding EU options for Enterprise tiers through 2026 — confirm current regional configuration with Perplexity sales before procurement decisions.

DPA availability

Perplexity publishes a Data Processing Addendum.

Consumer tier (free / Pro individual) does NOT auto-incorporate the DPA in the same way. Consumer use sits under the standard consumer Terms with weaker processor commitments.

Subprocessor list

Perplexity publishes its subprocessor list at https://trust.perplexity.ai/subprocessors (also rendered inline on the trust portal landing page). First two listed: Amazon Web Services (cloud provider, US) and Microsoft Azure (cloud provider, US).

Notable architecture (which determines transitive subprocessing):

The multi-LLM Agent API is a genuine compliance complication: a buyer using it is in practice also accepting OpenAI's, Anthropic's, Google's, and xAI's terms transitively. Sonar-only deployments avoid this — confirm which API your integration uses.

Training-on-customer-data position

Enterprise Pro and Enterprise Max: Customer data is not used to train AI models. Zero Data Retention (ZDR) is offered. This is contractual.

Sonar API: Same posture — no training, ZDR available. Configurable file retention.

Free / Pro individual consumer tier: Default may include data being used for AI training, with opt-out available in user settings. This is the same trap as ChatGPT consumer and consumer Gemini — staff using personal Pro accounts are in a training-eligible flow unless they've actively opted out.

API log retention: Configurable on Enterprise / Sonar. Default retention period changes periodically; confirm at review time.

Enterprise / Sonar defaults are strong and on par with Anthropic / OpenAI enterprise tiers. Consumer-tier shadow use is the dominant unmanaged risk for any organisation with knowledge workers. — My read

EU / UK transfer position

Perplexity relies on Standard Contractual Clauses Module 2 (controller-to-processor) and Module 3 (processor-to-processor) for EU transfers via the DPA. The DPA explicitly names the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (version B.0) issued by the UK Information Commissioner for transfers subject to UK GDPR. Perplexity is certified under the EU-US Data Privacy Framework including the UK Extension to the EU-US DPF — verified self-certification with the U.S. Department of Commerce as of 2026-05 (same DPF reauthorisation caveat as OpenAI and Anthropic).

EU data residency: confirm current options for Enterprise tiers. Default processing is US-resident.

Security documentation

Per the trust portal at https://trust.perplexity.ai/ (verified 2026-05-02):

Perplexity's security disclosures have been less comprehensive than Google's or Microsoft's. Audit-grade documentation is available through the trust portal but typically behind a registration gate.

AI Act role + risk classification

Perplexity has not, as of 2026-05-01, published a comprehensive AI Act mapping for its products.

DPIA prompts (for your use case)

  1. Which Perplexity surface are staff using? Free, Pro individual, Pro for Enterprise, Sonar API, or Comet — each has a different compliance posture. Don't accept "we use Perplexity" as a sufficient inventory entry.
  2. Are search queries themselves a privacy concern for your sector? Legal, healthcare, HR, compliance teams — query strings often expose case-level detail that the buyer didn't realise was being transmitted.
  3. Is the underlying LLM stack acceptable to you? Perplexity routes through multiple model providers depending on plan and feature. Your DPA chain runs through Perplexity to those vendors transitively.
  4. Comet browser specifically: if any staff use Comet, you have a much larger data-collection surface (full browsing history, page content) than the answer-engine product. Treat Comet as a separate vendor evaluation.
  5. AI Act Annex III applicability: is the answer engine being used as decision-support in any Annex III process? If yes, deployer high-risk obligations engage.

Unresolved questions / red flags

Related profiles

Sources checked

<!-- All Phase C residual items resolved (browser agent run 2026-05-02). trust.perplexity.ai publicly displays SOC 2 Type 2, HIPAA, GDPR, PCI DSS SAQ A, FedRAMP 20x Low. Confirmed: ISO 27001 NOT displayed, ISO 42001 NOT displayed (gap flagged in red flags section). Subprocessor list canonical URL: https://trust.perplexity.ai/subprocessors. DPA explicitly names UK ICO IDTA version B.0 (not the "2 Feb 2022" framing — that's how Anthropic phrases it). DPF + UK Extension active. -->
Share this Perplexity profile:Share on XBluesky

Need a reviewed note for your specific use case?

For when the public profile isn't enough — your sector is regulated, your procurement gate is real, your use case is unusual. Tell us the situation and we'll come back with a CIPP/E-reviewed Vendor Risk Note (typically £149, depending on scope).

Your context goes only to Michael. We don't share with the vendor or anyone else. Privacy notice.

AI vendor compliance updates

New profiles, regulatory deadline reminders, and the occasional AI vendor red flag. Written by Michael K. Onyekwere, CIPP/E. Free.

We don't share your address. Unsubscribe any time. Privacy notice.

For ongoing AI compliance support, work with Janus DPO-as-a-Service. For other vendors, browse the full index.