The policy states that individuals whose personal information was processed by Brex on behalf of an employer business customer must direct data access, correction, or deletion requests to that employer, and that requests submitted directly to Brex will be referred back to the business customer.
This analysis describes what Brex's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that authorized users whose personal information Brex processes in its capacity as a service provider to an employer must route data subject rights requests through that employer, which is a standard processor-controller arrangement under CPRA and GDPR but places the practical burden of rights fulfillment on the business customer rather than Brex.
Under this clause, employees who are authorized users of a company's Brex account and wish to access, correct, or delete their personal information must contact their employer to exercise those rights, rather than submitting requests directly to Brex. Requests submitted directly to Brex will be referred to the employer business customer.
Cross-platform context
See how other platforms handle Authorized User Data Rights Directed to Employer Business Customer and similar clauses.
Compare across platforms →"If personal information about you has been processed by us as a service provider on behalf of a business customer, please inquire with the business customer directly to exercise your rights. If you wish to make your request directly to us, please provide the name of our business customer on whose behalf we processed your personal information. We will refer your request to that business customer, and will support them to the extent required by applicable law in responding to your request.Excerpt from Brex's Privacy Policy
(1) REGULATORY LANDSCAPE: This provision reflects the CPRA service provider model, under which a service provider processing personal information on behalf of a business is not directly obligated to fulfill consumer data subject rights requests …
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Search "[your state] attorney general consumer complaint" to find your state's direct complaint form
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes that authorized users whose personal information Brex processes in its capacity as a service provider to an employer must route data subject rights requests through that employer, which is a standard processor-controller arrangement under CPRA and GDPR but places the practical burden of rights fulfillment on the business customer rather than Brex.
Under this clause, employees who are authorized users of a company's Brex account and wish to access, correct, or delete their personal information must contact their employer to exercise those rights, rather than submitting requests directly to Brex. Requests submitted directly to Brex will be referred to the employer business customer.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Brex.