Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The document designates Marqeta Inc. (U.S.), Marqeta UK Ltd., and Marqeta sp. z.o.o. (Poland) as joint data controllers for EEA and UK processing under this notice, with Marqeta U.S. identified as the primary controller responsible for compliance and rights request management.
This analysis describes what Marqeta's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes a joint controller arrangement across three legal entities under GDPR, which requires a documented joint controller agreement under GDPR and requires that the essence of that arrangement be made available to data subjects. Compliance teams should confirm that a written joint controller agreement exists and that it accurately reflects the responsibilities described in this notice.
Interpretive note: The document identifies the three joint controllers and assigns primary responsibility to Marqeta U.S. but does not reproduce or confirm the existence of a written joint controller agreement as required by GDPR Article 26; compliance implications depend on whether such an agreement exists and its specific terms.
Under this clause, EEA and UK residents interacting with Marqeta's website and developer services are subject to a joint controller arrangement involving three Marqeta entities; individual rights requests are handled by Marqeta U.S., which the document designates as the primary controller responsible for GDPR and UK data protection compliance.
Cross-platform context
See how other platforms handle Joint Data Controller Arrangement (EEA and UK) and similar clauses.
Compare across platforms →Monitoring
Marqeta has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"For the purposes of the Services and this supplemental notice, joint data controllers include: Marqeta UK Ltd (Marqeta UK) Marqeta, Inc. (Marqeta US) Marqeta sp. z.o.o.(Marqeta Poland) In most instances, for the Services within the Notice, Marqeta US will be the primary controller although your personal data may also be processed by Marqeta UK and Marqeta Poland for the purposes of the Services (e.g., for lead generation purposes in the UK and the EEA respectively). Marqeta Poland and Marqeta UK each act as a controller under the respective EEA and UK laws. Marqeta US is primarily responsible for ensuring that Marqeta is compliant with applicable legislation and our internal policies in the EEA and UK. Marqeta US is also entrusted with managing individual rights requests.Excerpt from Marqeta's Privacy Policy
1. REGULATORY LANDSCAPE: This provision directly implicates GDPR Article 26, which requires joint controllers to determine their respective responsibilities via a transparent arrangement and to make the essence of that arrangement available to data subjects. The relevant supervisory authorities are the European Data Protection Authorities in the EEA (coordinated through the EDPB) and the UK Information Commissioner's Office for UK processing. Marqeta Poland's designation as a controller for EEA lead generation purposes means that the Polish Data Protection Authority (UODO) may also be a relevant supervisory authority. 2. GOVERNANCE EXPOSURE: Medium. The document identifies three joint controllers and assigns primary compliance responsibility to Marqeta U.S., but does not reproduce the terms of the joint controller agreement or confirm its existence as a standalone document. GDPR Article 26 requires that the arrangement reflect the joint controllers' respective roles in relation to data subjects, and the absence of published arrangement details in this notice is a gap to assess. 3. JURISDICTION FLAGS: This provision applies to EEA and UK residents under GDPR and UK GDPR respectively. Marqeta Poland's role as a controller under EEA law creates a specific Polish jurisdiction exposure. Where Marqeta U.S. acts as a controller for EEA data subjects, international transfer mechanisms including standard contractual clauses or Data Privacy Framework certification are required, as referenced elsewhere in the notice. 4. CONTRACT AND VENDOR IMPLICATIONS: Organizations entering into data processing relationships with any of the three Marqeta entities in an EEA or UK context should confirm which entity is the counterparty to their data processing agreement and how the joint controller arrangement affects contractual obligations. The document's statement that Marqeta U.S. manages individual rights requests implies that rights request workflows should be directed to Marqeta U.S. regardless of which entity initially collected the data. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should request confirmation that a GDPR-compliant joint controller agreement exists among the three entities and that its essence is accessible to data subjects as required by GDPR Article 26. The designation of Marqeta U.S. as primary controller for compliance purposes should be reflected in data protection impact assessments, records of processing activities, and any notifications to relevant supervisory authorities. The Polish entity's role in EEA lead generation should be assessed for compliance with applicable local implementing legislation.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes a joint controller arrangement across three legal entities under GDPR, which requires a documented joint controller agreement under GDPR and requires that the essence of that arrangement be made available to data subjects. Compliance teams should confirm that a written joint controller agreement exists and that it accurately reflects the responsibilities described in this notice.
Under this clause, EEA and UK residents interacting with Marqeta's website and developer services are subject to a joint controller arrangement involving three Marqeta entities; individual rights requests are handled by Marqeta U.S., which the document designates as the primary controller responsible for GDPR and UK data protection compliance.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Marqeta.