Marqeta · Marqeta Privacy Policy · View original document ↗

Joint Data Controller Arrangement (EEA and UK)

Medium severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Marqeta changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Marqeta Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The document designates Marqeta Inc. (U.S.), Marqeta UK Ltd., and Marqeta sp. z.o.o. (Poland) as joint data controllers for EEA and UK processing under this notice, with Marqeta U.S. identified as the primary controller responsible for compliance and rights request management.

This analysis describes what Marqeta's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes a joint controller arrangement across three legal entities under GDPR, which requires a documented joint controller agreement under GDPR and requires that the essence of that arrangement be made available to data subjects. Compliance teams should confirm that a written joint controller agreement exists and that it accurately reflects the responsibilities described in this notice.

Interpretive note: The document identifies the three joint controllers and assigns primary responsibility to Marqeta U.S. but does not reproduce or confirm the existence of a written joint controller agreement as required by GDPR Article 26; compliance implications depend on whether such an agreement exists and its specific terms.

Consumer impact (what this means for users)

Under this clause, EEA and UK residents interacting with Marqeta's website and developer services are subject to a joint controller arrangement involving three Marqeta entities; individual rights requests are handled by Marqeta U.S., which the document designates as the primary controller responsible for GDPR and UK data protection compliance.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Send a data rights request (access, erasure, correction, portability, restriction, or objection) to privacy@marqeta.com. Include your name and sufficient identifying information to allow Marqeta to verify your identity and locate your personal data. Marqeta U.S. is designated as the primary entity managing individual rights requests for EEA and UK residents.

Cross-platform context

See how other platforms handle Joint Data Controller Arrangement (EEA and UK) and similar clauses.

Compare across platforms →

Monitoring

Marqeta has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
For the purposes of the Services and this supplemental notice, joint data controllers include: Marqeta UK Ltd (Marqeta UK) Marqeta, Inc. (Marqeta US) Marqeta sp. z.o.o.(Marqeta Poland) In most instances, for the Services within the Notice, Marqeta US will be the primary controller although your personal data may also be processed by Marqeta UK and Marqeta Poland for the purposes of the Services (e.g., for lead generation purposes in the UK and the EEA respectively). Marqeta Poland and Marqeta UK each act as a controller under the respective EEA and UK laws. Marqeta US is primarily responsible for ensuring that Marqeta is compliant with applicable legislation and our internal policies in the EEA and UK. Marqeta US is also entrusted with managing individual rights requests.

Excerpt from Marqeta's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: This provision directly implicates GDPR Article 26, which requires joint controllers to determine their respective responsibilities via a transparent arrangement and to make the essence of that arrangement available to data subjects. The relevant supervisory authorities are the European Data Protection Authorities in the EEA (coordinated through the EDPB) and the UK Information Commissioner's Office for UK processing. Marqeta Poland's designation as a controller for EEA lead generation purposes means that the Polish Data Protection Authority (UODO) may also be a relevant supervisory authority. 2. GOVERNANCE EXPOSURE: Medium. The document identifies three joint controllers and assigns primary compliance responsibility to Marqeta U.S., but does not reproduce the terms of the joint controller agreement or confirm its existence as a standalone document. GDPR Article 26 requires that the arrangement reflect the joint controllers' respective roles in relation to data subjects, and the absence of published arrangement details in this notice is a gap to assess. 3. JURISDICTION FLAGS: This provision applies to EEA and UK residents under GDPR and UK GDPR respectively. Marqeta Poland's role as a controller under EEA law creates a specific Polish jurisdiction exposure. Where Marqeta U.S. acts as a controller for EEA data subjects, international transfer mechanisms including standard contractual clauses or Data Privacy Framework certification are required, as referenced elsewhere in the notice. 4. CONTRACT AND VENDOR IMPLICATIONS: Organizations entering into data processing relationships with any of the three Marqeta entities in an EEA or UK context should confirm which entity is the counterparty to their data processing agreement and how the joint controller arrangement affects contractual obligations. The document's statement that Marqeta U.S. manages individual rights requests implies that rights request workflows should be directed to Marqeta U.S. regardless of which entity initially collected the data. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should request confirmation that a GDPR-compliant joint controller agreement exists among the three entities and that its essence is accessible to data subjects as required by GDPR Article 26. The designation of Marqeta U.S. as primary controller for compliance purposes should be reflected in data protection impact assessments, records of processing activities, and any notifications to relevant supervisory authorities. The Polish entity's role in EEA lead generation should be assessed for compliance with applicable local implementing legislation.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Get same-day alerts when this changes → Get Analyst

Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.

Applicable agencies

  • FTC
    The FTC has oversight authority over Marqeta's compliance with the EU-U.S. Data Privacy Framework, which is relevant to transfers from EEA joint controllers to Marqeta U.S. as the primary controller
    File a complaint →

Provision details

Document information
Document
Marqeta Privacy Policy
Entity
Marqeta
Document last updated
May 5, 2026
Tracking information
First tracked
July 12, 2026
Last verified
July 12, 2026
Record ID
CA-P-074558
Document ID
CA-D-00667
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
6553971c090c305c5e2834dd25ed83821a9bbb190a5c70870df2987f69e7c0d8
Analysis generated
July 12, 2026 17:53 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Marqeta
Document: Marqeta Privacy Policy
Record ID: CA-P-074558
Captured: 2026-07-12 17:53:18 UTC
SHA-256: 6553971c090c305c…
URL: https://conductatlas.com/platform/marqeta/marqeta-privacy-policy/provision/CA-P-074558/joint-data-controller-arrangement-eea-and-uk/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Get Compliance

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Marqeta's Joint Data Controller Arrangement (EEA and UK) clause do?

This provision establishes a joint controller arrangement across three legal entities under GDPR, which requires a documented joint controller agreement under GDPR and requires that the essence of that arrangement be made available to data subjects. Compliance teams should confirm that a written joint controller agreement exists and that it accurately reflects the responsibilities described in this notice.

How does this clause affect you?

Under this clause, EEA and UK residents interacting with Marqeta's website and developer services are subject to a joint controller arrangement involving three Marqeta entities; individual rights requests are handled by Marqeta U.S., which the document designates as the primary controller responsible for GDPR and UK data protection compliance.

Is ConductAtlas affiliated with Marqeta?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Marqeta.