Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The document states that Marqeta participates in the EU-U.S., UK Extension, and Swiss-U.S. Data Privacy Frameworks as certified by the U.S. Department of Commerce, and that the Data Privacy Framework Notice takes precedence over this Website Privacy Notice in the event of a conflict regarding transatlantic transfers.
This analysis describes what Marqeta's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
Marqeta's DPF certification establishes a recognized adequacy mechanism for transfers of personal data from the EEA, UK, and Switzerland to the U.S., and makes the FTC the relevant enforcement authority for DPF compliance under U.S. law. The document's statement that the DPF Notice governs in the event of a conflict means that the full scope of data subject rights for international transfers requires review of both this notice and the separately published DPF Notice.
Under this provision, personal data transferred from the EEA, UK, and Switzerland to the United States is covered by Marqeta's DPF certification, which provides data subjects with DPF recourse mechanisms including the right to invoke binding arbitration through the DPF Arbitration Panel for unresolved complaints. The document directs individuals to a separate Data Privacy Framework Notice for the full terms of DPF compliance.
Cross-platform context
See how other platforms handle International Data Transfers and Data Privacy Framework Participation and similar clauses.
Compare across platforms →Monitoring
Marqeta has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Marqeta, Inc. and its subsidiaries and affiliates (collectively, 'Marqeta', 'we', 'our', or 'us') are committed to protecting your personal data and privacy rights. [...] For the purposes of transfers to the United States, Marqeta participates in and complies with the EU-U.S. Data Privacy Framework, the UK Extension of the EU-U.S. Data Privacy Framework and the Swiss-U.S. Data Privacy Framework (referred to generally as the 'DPFs') as set forth by the U.S. Department of Commerce in relation to the processing of personal data sent from the EEA, the UK and Switzerland to the U.S. Pursuant to its certification, Marqeta has committed to adhere to the respective DPF Principles for the EU, the UK and Switzerland in line with the corresponding frameworks. For more information, please see our Data Privacy Framework Notice. In the event of any conflict between this Notice and the Data Privacy Framework Notice, the Data Privacy Framework Notice shall govern.Excerpt from Marqeta's Privacy Policy
1. REGULATORY LANDSCAPE: This provision implicates the EU-U.S. Data Privacy Framework as administered by the U.S. Department of Commerce and enforced by the FTC. The European Commission's adequacy decision for the EU-U.S. DPF, the UK's adequacy regulations for the UK Extension, and the Swiss Federal Data Protection and Information Commissioner's recognition of the Swiss-U.S. DPF are the relevant international legal bases. GDPR Chapter V governs the lawfulness of transfers from EEA to third countries. 2. GOVERNANCE EXPOSURE: Medium. DPF certification requires annual recertification with the U.S. Department of Commerce and ongoing adherence to DPF Principles including notice, choice, accountability for onward transfer, security, data integrity and purpose limitation, access, and recourse. The document's statement that the DPF Notice governs over this notice in the event of conflict requires that compliance teams maintain current versions of both documents and assess them together. 3. JURISDICTION FLAGS: This provision applies specifically to transfers of personal data from the EEA, UK, and Switzerland to the United States. Transfers between Marqeta entities in other jurisdictions, such as transfers to or from Canada, are addressed separately under the Canadian supplemental notice and are not covered by DPF certification. Transfers between the EEA and UK are noted as occurring as part of business operations and may be covered by adequacy mechanisms or standard contractual clauses as described in the notice. 4. CONTRACT AND VENDOR IMPLICATIONS: Organizations transferring personal data to Marqeta in the context of EEA or UK services should confirm Marqeta's current DPF certification status via the U.S. Department of Commerce DPF list. Data processing agreements referencing the DPF as the transfer mechanism should be updated if Marqeta's certification lapses or is modified. The document's reference to standard contractual clauses as an additional transfer mechanism means that backup transfer arrangements may exist. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should obtain and review the separate Data Privacy Framework Notice to confirm alignment with DPF Principles and to identify any provisions that may conflict with this Website Privacy Notice. Annual DPF recertification status should be monitored. Records of processing activities for EEA and UK data subjects should document the DPF as the applicable transfer mechanism for U.S. transfers and note the subordination of this notice to the DPF Notice in cases of conflict.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
Marqeta's DPF certification establishes a recognized adequacy mechanism for transfers of personal data from the EEA, UK, and Switzerland to the U.S., and makes the FTC the relevant enforcement authority for DPF compliance under U.S. law. The document's statement that the DPF Notice governs in the event of a conflict means that the full scope of data subject rights for …
Under this provision, personal data transferred from the EEA, UK, and Switzerland to the United States is covered by Marqeta's DPF certification, which provides data subjects with DPF recourse mechanisms including the right to invoke binding arbitration through the DPF Arbitration Panel for unresolved complaints. The document directs individuals to a separate Data Privacy Framework Notice for the full terms …
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Marqeta.