The document designates Marqeta Inc. (U.S.), Marqeta UK Ltd., and Marqeta sp. z.o.o. (Poland) as joint data controllers for EEA and UK processing under this notice, with Marqeta U.S. identified as the primary controller responsible for compliance and rights request management.
This analysis describes what Marqeta's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes a joint controller arrangement across three legal entities under GDPR, which requires a documented joint controller agreement under GDPR and requires that the essence of that arrangement be made available to data subjects. Compliance teams should confirm that a written joint controller agreement exists and that it accurately reflects the responsibilities described in this notice.
Interpretive note: The document identifies the three joint controllers and assigns primary responsibility to Marqeta U.S. but does not reproduce or confirm the existence of a written joint controller agreement as required by GDPR Article 26; compliance implications depend on whether such an agreement exists and its specific terms.
Under this clause, EEA and UK residents interacting with Marqeta's website and developer services are subject to a joint controller arrangement involving three Marqeta entities; individual rights requests are handled by Marqeta U.S., which the document designates as the primary controller responsible for GDPR and UK data protection compliance.
Cross-platform context
See how other platforms handle Joint Data Controller Arrangement (EEA and UK) and similar clauses.
Compare across platforms →"For the purposes of the Services and this supplemental notice, joint data controllers include: Marqeta UK Ltd (Marqeta UK) Marqeta, Inc. (Marqeta US) Marqeta sp. z.o.o.(Marqeta Poland) In most instances, for the Services within the Notice, Marqeta US will be the primary controller although your personal data may also be processed by Marqeta UK and Marqeta Poland for the purposes of the Services (e.g., for lead generation purposes in the UK and the EEA respectively). Marqeta Poland and Marqeta UK each act as a controller under the respective EEA and UK laws. Marqeta US is primarily responsible for ensuring that Marqeta is compliant with applicable legislation and our internal policies in the EEA and UK. Marqeta US is also entrusted with managing individual rights requests.Excerpt from Marqeta's Privacy Policy
1.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes a joint controller arrangement across three legal entities under GDPR, which requires a documented joint controller agreement under GDPR and requires that the essence of that arrangement be made available to data subjects. Compliance teams should confirm that a written joint controller agreement exists and that it accurately reflects the responsibilities described in this notice.
Under this clause, EEA and UK residents interacting with Marqeta's website and developer services are subject to a joint controller arrangement involving three Marqeta entities; individual rights requests are handled by Marqeta U.S., which the document designates as the primary controller responsible for GDPR and UK data protection compliance.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Marqeta.