Klaviyo no longer promises to pass privacy requests on to you

Stani Mihov
Founder & CEO
·

TL;DR
What changed:
Klaviyo no longer promises to forward privacy requests it receives, and may tell people to contact you directly.
Cross-brand data linking, which can match the same shoppers across linked brand accounts and, if enabled, market to them across brands, is now part of the DPA itself.
Customers who use it must have a lawful basis, updated privacy notices, and multi-brand consent where the law requires it.
Anthropic, OpenAI, Glean, and Zendesk are now also used for customer success, and Slack and ClickHouse were added as subprocessors.
The new DPA took effect on September 11 and, like earlier versions, applies to existing customers without a signature.
What to do: Make sure your privacy notice gives people a direct way to reach you with requests, and check consent before anyone turns on cross-brand features.
The change
On September 11, 2026, Klaviyo published a new version of its Data Processing Agreement, the contract that governs how Klaviyo handles the customer data its users collect: email lists, purchase history, browsing behavior, and more. The same day, it updated its subprocessor list.
As with earlier versions, the DPA applies to existing customers from its "Updated" date and "shall replace any previously agreed data processing and security terms," so no signature is needed for the new terms to apply. Venpo flagged both changes on September 12, and the redlines are public for the DPA and the subprocessor list.
What changed
Privacy requests. The old promise to forward requests from individuals to the customer is gone. Klaviyo now "may advise the individual to submit their request directly to Customer."
Cross-brand data linking. A new Schedule 7 brings the Organizations Feature into the DPA itself. The feature lets linked Klaviyo accounts match the same person across brands, run combined analytics, and, if separately enabled, market to people across brands.
Consent sits with you. Customers who enable it must have a lawful basis, updated privacy notices, and "valid multi-brand consent" where the law requires it, and are "solely responsible" for any resulting regulatory obligations.
A wider description of processing. The DPA now lists website visitors, app users, and social media creators as people whose data may be processed, and adds purposes such as predictive analytics, product recommendations, and "aggregated and de-identified insights."
AI and support vendors. Anthropic, OpenAI, Glean, and Zendesk are now listed for customer success as well as support. Slack and ClickHouse were added as subprocessors, and two others were removed.
Privacy requests may now come straight to you
When someone asks to see or delete the data a company holds about them, the request sometimes reaches the vendor instead. Klaviyo's old DPA promised to pass those requests on. The new one says the customer has "sole responsibility" for responding, and Klaviyo may simply tell the person to contact the customer.
In practice, that means the path for privacy requests needs to be clear on your side. If your privacy notice does not tell people how to reach you, a request that starts at Klaviyo may not reach you at all.
One shopper, many brands
Many companies run several brands as separate Klaviyo accounts. Klaviyo's help page on cross-brand data linking describes the goal: showing when the same person shops more than one brand, for unified reporting and cross-brand strategy.
These terms were first published as a separate Organizations Feature addendum, dated July 29, 2026. The September DPA moves them into the DPA itself as Schedule 7. With the feature on, Klaviyo can match profiles across linked accounts, analyze overlap and lifetime value across brands, and, if the customer turns it on, run cross-brand marketing, segmentation, and activation. Before switching it on, the customer promises it has updated its privacy policies, has a lawful basis for the processing, has authority over every linked account, has a joint controller agreement where separate companies share data, and has multi-brand consent where needed. If a security incident touches this data, Klaviyo notifies one Organization-level administrator, and the customer handles notice to every other brand and to the people affected.
What got better
Several changes favor customers. Audits needed to verify compliance are now provided "at no additional charge," with charges only for audits that go beyond that and only if agreed in advance. Extra help with privacy requests is no longer automatically billable and now requires mutual agreement on fees. The U.S. addendum now expressly bars Klaviyo from using customer data for targeted advertising where the law requires it. Subprocessor changes still come with at least 15 days' notice, now by email, and the list is described as covering every subprocessor.
Why this matters
Klaviyo holds some of the most detailed customer data a company has: who bought what, what they browsed, and whether they agreed to marketing. The DPA decides who does what with that data, and new versions apply to existing customers without a signature. After this update, every company on Klaviyo carries the full job of handling privacy requests, and multi-brand companies that turn on cross-brand features take on a large share of the consent work as well.
Vendors have been moving AI and support providers into more roles in the same way, as we saw when SurveyMonkey changed its AI providers, and marketing platforms keep adding responsibilities for their customers, as when HubSpot made customers answer for its AI agents. Keeping track of which vendors changed their data terms, and when, is what monitoring AI subprocessors and DPAs is for.
Potential impact
For a company that uses Klaviyo, the update raises four practical questions:
Does your privacy notice give people a direct way to send you access and deletion requests?
If you run several brands in Klaviyo, has anyone enabled the Organizations Feature, and do you have the consent and agreements it requires?
Does your own vendor record reflect that Anthropic, OpenAI, Glean, and Zendesk may now be used for customer success?
Is the email address on your Klaviyo account the one that should receive subprocessor notices?
DPAs that update themselves for existing customers are one of the hidden risks of vendor legal changes.
How Venpo detected it
Venpo monitors Klaviyo's legal pages as part of continuous vendor risk monitoring. On September 12, it flagged the new DPA and the subprocessor update, and separated the privacy request, cross-brand, and subprocessor changes from a long list of wording and numbering edits. The redlines are on the DPA change page and the subprocessor change page, and every monitored Klaviyo document is listed on the Klaviyo vendor profile.
Business outcome
Teams that track Klaviyo got a plain-English summary the day after the new DPA took effect. That leaves time to check the privacy request path, review consent before anyone enables cross-brand features, and update the vendor record. The alternative is learning about the new terms from a privacy request that never reached you.
Key takeaway
Klaviyo's September DPA drops the promise to forward privacy requests and brings cross-brand data linking into the DPA with the consent on customers, while making audits cheaper and ad use stricter. Because new DPA versions apply without a signature, the only way to know what changed is to track every version as it happens.
The change
On September 11, 2026, Klaviyo published a new version of its Data Processing Agreement, the contract that governs how Klaviyo handles the customer data its users collect: email lists, purchase history, browsing behavior, and more. The same day, it updated its subprocessor list.
As with earlier versions, the DPA applies to existing customers from its "Updated" date and "shall replace any previously agreed data processing and security terms," so no signature is needed for the new terms to apply. Venpo flagged both changes on September 12, and the redlines are public for the DPA and the subprocessor list.
What changed
Privacy requests. The old promise to forward requests from individuals to the customer is gone. Klaviyo now "may advise the individual to submit their request directly to Customer."
Cross-brand data linking. A new Schedule 7 brings the Organizations Feature into the DPA itself. The feature lets linked Klaviyo accounts match the same person across brands, run combined analytics, and, if separately enabled, market to people across brands.
Consent sits with you. Customers who enable it must have a lawful basis, updated privacy notices, and "valid multi-brand consent" where the law requires it, and are "solely responsible" for any resulting regulatory obligations.
A wider description of processing. The DPA now lists website visitors, app users, and social media creators as people whose data may be processed, and adds purposes such as predictive analytics, product recommendations, and "aggregated and de-identified insights."
AI and support vendors. Anthropic, OpenAI, Glean, and Zendesk are now listed for customer success as well as support. Slack and ClickHouse were added as subprocessors, and two others were removed.
Privacy requests may now come straight to you
When someone asks to see or delete the data a company holds about them, the request sometimes reaches the vendor instead. Klaviyo's old DPA promised to pass those requests on. The new one says the customer has "sole responsibility" for responding, and Klaviyo may simply tell the person to contact the customer.
In practice, that means the path for privacy requests needs to be clear on your side. If your privacy notice does not tell people how to reach you, a request that starts at Klaviyo may not reach you at all.
One shopper, many brands
Many companies run several brands as separate Klaviyo accounts. Klaviyo's help page on cross-brand data linking describes the goal: showing when the same person shops more than one brand, for unified reporting and cross-brand strategy.
These terms were first published as a separate Organizations Feature addendum, dated July 29, 2026. The September DPA moves them into the DPA itself as Schedule 7. With the feature on, Klaviyo can match profiles across linked accounts, analyze overlap and lifetime value across brands, and, if the customer turns it on, run cross-brand marketing, segmentation, and activation. Before switching it on, the customer promises it has updated its privacy policies, has a lawful basis for the processing, has authority over every linked account, has a joint controller agreement where separate companies share data, and has multi-brand consent where needed. If a security incident touches this data, Klaviyo notifies one Organization-level administrator, and the customer handles notice to every other brand and to the people affected.
What got better
Several changes favor customers. Audits needed to verify compliance are now provided "at no additional charge," with charges only for audits that go beyond that and only if agreed in advance. Extra help with privacy requests is no longer automatically billable and now requires mutual agreement on fees. The U.S. addendum now expressly bars Klaviyo from using customer data for targeted advertising where the law requires it. Subprocessor changes still come with at least 15 days' notice, now by email, and the list is described as covering every subprocessor.
Why this matters
Klaviyo holds some of the most detailed customer data a company has: who bought what, what they browsed, and whether they agreed to marketing. The DPA decides who does what with that data, and new versions apply to existing customers without a signature. After this update, every company on Klaviyo carries the full job of handling privacy requests, and multi-brand companies that turn on cross-brand features take on a large share of the consent work as well.
Vendors have been moving AI and support providers into more roles in the same way, as we saw when SurveyMonkey changed its AI providers, and marketing platforms keep adding responsibilities for their customers, as when HubSpot made customers answer for its AI agents. Keeping track of which vendors changed their data terms, and when, is what monitoring AI subprocessors and DPAs is for.
Potential impact
For a company that uses Klaviyo, the update raises four practical questions:
Does your privacy notice give people a direct way to send you access and deletion requests?
If you run several brands in Klaviyo, has anyone enabled the Organizations Feature, and do you have the consent and agreements it requires?
Does your own vendor record reflect that Anthropic, OpenAI, Glean, and Zendesk may now be used for customer success?
Is the email address on your Klaviyo account the one that should receive subprocessor notices?
DPAs that update themselves for existing customers are one of the hidden risks of vendor legal changes.
How Venpo detected it
Venpo monitors Klaviyo's legal pages as part of continuous vendor risk monitoring. On September 12, it flagged the new DPA and the subprocessor update, and separated the privacy request, cross-brand, and subprocessor changes from a long list of wording and numbering edits. The redlines are on the DPA change page and the subprocessor change page, and every monitored Klaviyo document is listed on the Klaviyo vendor profile.
Business outcome
Teams that track Klaviyo got a plain-English summary the day after the new DPA took effect. That leaves time to check the privacy request path, review consent before anyone enables cross-brand features, and update the vendor record. The alternative is learning about the new terms from a privacy request that never reached you.
Key takeaway
Klaviyo's September DPA drops the promise to forward privacy requests and brings cross-brand data linking into the DPA with the consent on customers, while making audits cheaper and ad use stricter. Because new DPA versions apply without a signature, the only way to know what changed is to track every version as it happens.
Real-time change notifications
Stay ahead of every legal change
Get updates, product news and expert tips on navigating legal changes
Dispute resolution clause now requires mandatory arbitration in all regions
Data retention period extended from 2 years to 5 years for all services
New restrictions on AI-generated content in product descriptions
Third-party data sharing expanded to include analytics partners
Real-time change notifications
Stay ahead of every legal change
Get updates, product news and expert tips on navigating legal changes
Dispute resolution clause now requires mandatory arbitration in all regions
Data retention period extended from 2 years to 5 years for all services
New restrictions on AI-generated content in product descriptions
Third-party data sharing expanded to include analytics partners
