Brex · Brex Privacy Policy · View original document ↗

GDPR and UK GDPR Rights for EU and UK Users

Medium severity Medium confidence Explicitdocumentlanguage Rare · 2 of 343 platforms
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Brex Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

The policy grants EU and UK users data subject rights under GDPR and UK GDPR, including access, rectification, erasure, restriction, portability, objection, and consent withdrawal, with a designated contact for exercising these rights.

This analysis describes what Brex's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes Brex's GDPR and UK GDPR compliance framework for EU and UK users, requiring the company to maintain lawful bases for all processing activities, respond to data subject requests within statutory timeframes, and support cross-border transfer mechanisms for data flows outside the EEA and UK.

Interpretive note: The source document was truncated; the verbatim excerpt reflects available policy language. The specific lawful bases relied upon for each processing activity are not fully visible in the truncated document.

Consumer impact (what this means for users)

EU and UK users may submit requests to access, correct, delete, restrict, or port their personal data, and may object to processing or withdraw consent, by contacting privacy@brex.com as stated in the policy.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Email privacy@brex.com stating the specific GDPR right you wish to exercise (access, erasure, restriction, portability, or objection). Include sufficient information to verify your identity. Brex is required to respond within one month under GDPR.

How other platforms handle this

Garmin Medium

If you are located in the European Economic Area, Switzerland, or the United Kingdom, you have the right to access, correct, or erase your personal data; the right to restrict or object to our processing of your personal data; the right to data portability; and, where our processing is based on your...

Grindr Medium

Depending on where you are located, you may have certain rights regarding your personal information, including the right to access, correct, delete, or restrict processing of your personal information, the right to data portability, and the right to object to or withdraw consent for certain processi...

Strava Medium

For individuals in the United States, please also refer to our Notice For Individuals Residing In Certain US States below and the Consumer Health Data Policy.

See all platforms with this clause type →

Monitoring

Brex has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
If you are located in the European Economic Area or the United Kingdom, you have certain rights under applicable data protection law, including the right to access, rectify, erase, restrict processing of, and port your personal information. You also have the right to object to processing and to withdraw consent where processing is based on consent. To exercise these rights, please contact us at privacy@brex.com.

— Excerpt from Brex's Brex Privacy Policy

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

(1) REGULATORY LANDSCAPE: This provision implements obligations under GDPR (enforced by EU supervisory authorities including lead DPA for cross-border processing) and UK GDPR (enforced by the UK Information Commissioner's Office). GDPR Articles 15-22 establish the data subject rights listed; Article 77 provides the right to lodge complaints with supervisory authorities. Response to requests is required within one month, extendable by two additional months for complex requests. (2) GOVERNANCE EXPOSURE: High for organizations with EU or UK employees using Brex business accounts, as employee personal data processed through corporate expense tools may be subject to GDPR obligations beyond standard customer privacy disclosures. Brex's role as controller versus processor for employee data in B2B contexts requires clear contractual definition. (3) JURISDICTION FLAGS: EEA and UK create heightened obligations. Cross-border data transfers from EU to US require Standard Contractual Clauses or other approved transfer mechanisms under GDPR Chapter V. Brexit has created a separate UK adequacy and transfer framework that requires parallel assessment. (4) VENDOR AND CONTRACT IMPLICATIONS: B2B customers using Brex for employee expense management should assess whether a Data Processing Agreement with Brex is in place, clearly defining controller and processor roles for employee personal data. (5) COMPLIANCE CONSIDERATIONS: Confirm that Standard Contractual Clauses or alternative transfer mechanisms are documented for EU-US data flows; verify that a GDPR-compliant Data Processing Agreement is available for business customers; confirm response SLAs for data subject requests meet GDPR timelines; and assess whether consent-based processing activities include functioning consent withdrawal mechanisms.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Monitor free for 14 days

Free: track 1 platform + weekly digest. Monitor: 25 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    The FTC may have jurisdiction over US-based entities' representations about compliance with international privacy frameworks including GDPR-related commitments
    File a complaint →

Applicable regulations

CCPA/CPRA
California, USA
Connecticut Data Privacy Act Amendments
US-CT
FCRA
United States Federal
FTC Act Section 5
United States Federal
GDPR
European Union
GLBA
United States Federal
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
Brex Privacy Policy
Entity
Brex
Document last updated
May 5, 2026
Tracking information
First tracked
May 21, 2026
Last verified
May 21, 2026
Record ID
CA-P-012920
Document ID
CA-D-00534
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
826d5eb46f1bad67ce7d64b85841aaebd7164af055cf24e7b3cd4220d63965c8
Analysis generated
May 21, 2026 02:58 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Brex
Document: Brex Privacy Policy
Record ID: CA-P-012920
Captured: 2026-05-21 02:58:06 UTC
SHA-256: 826d5eb46f1bad67…
URL: https://conductatlas.com/platform/brex/brex-privacy-policy/gdpr-and-uk-gdpr-rights-for-eu-and-uk-users/
Accessed: June 8, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Compliance free trial

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Brex's GDPR and UK GDPR Rights for EU and UK Users clause do?

This provision establishes Brex's GDPR and UK GDPR compliance framework for EU and UK users, requiring the company to maintain lawful bases for all processing activities, respond to data subject requests within statutory timeframes, and support cross-border transfer mechanisms for data flows outside the EEA and UK.

How does this clause affect you?

EU and UK users may submit requests to access, correct, delete, restrict, or port their personal data, and may object to processing or withdraw consent, by contacting privacy@brex.com as stated in the policy.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 2 platforms. See the full comparison.

Is ConductAtlas affiliated with Brex?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Brex.