Marqeta · Marqeta Privacy Policy · View original document ↗

International Data Transfers and Data Privacy Framework Participation

Low severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Marqeta changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Marqeta Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The document states that Marqeta participates in the EU-U.S., UK Extension, and Swiss-U.S. Data Privacy Frameworks as certified by the U.S. Department of Commerce, and that the Data Privacy Framework Notice takes precedence over this Website Privacy Notice in the event of a conflict regarding transatlantic transfers.

This analysis describes what Marqeta's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

Marqeta's DPF certification establishes a recognized adequacy mechanism for transfers of personal data from the EEA, UK, and Switzerland to the U.S., and makes the FTC the relevant enforcement authority for DPF compliance under U.S. law. The document's statement that the DPF Notice governs in the event of a conflict means that the full scope of data subject rights for international transfers requires review of both this notice and the separately published DPF Notice.

Consumer impact (what this means for users)

Under this provision, personal data transferred from the EEA, UK, and Switzerland to the United States is covered by Marqeta's DPF certification, which provides data subjects with DPF recourse mechanisms including the right to invoke binding arbitration through the DPF Arbitration Panel for unresolved complaints. The document directs individuals to a separate Data Privacy Framework Notice for the full terms of DPF compliance.

Cross-platform context

See how other platforms handle International Data Transfers and Data Privacy Framework Participation and similar clauses.

Compare across platforms →

Monitoring

Marqeta has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Marqeta, Inc. and its subsidiaries and affiliates (collectively, 'Marqeta', 'we', 'our', or 'us') are committed to protecting your personal data and privacy rights. [...] For the purposes of transfers to the United States, Marqeta participates in and complies with the EU-U.S. Data Privacy Framework, the UK Extension of the EU-U.S. Data Privacy Framework and the Swiss-U.S. Data Privacy Framework (referred to generally as the 'DPFs') as set forth by the U.S. Department of Commerce in relation to the processing of personal data sent from the EEA, the UK and Switzerland to the U.S. Pursuant to its certification, Marqeta has committed to adhere to the respective DPF Principles for the EU, the UK and Switzerland in line with the corresponding frameworks. For more information, please see our Data Privacy Framework Notice. In the event of any conflict between this Notice and the Data Privacy Framework Notice, the Data Privacy Framework Notice shall govern.

Excerpt from Marqeta's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: This provision implicates the EU-U.S. Data Privacy Framework as administered by the U.S. Department of Commerce and enforced by the FTC. The European Commission's adequacy decision for the EU-U.S. DPF, the UK's adequacy regulations for the UK Extension, and the Swiss Federal Data Protection and Information Commissioner's recognition of the Swiss-U.S. DPF are the relevant international legal bases. GDPR Chapter V governs the lawfulness of transfers from EEA to third countries. 2. GOVERNANCE EXPOSURE: Medium. DPF certification requires annual recertification with the U.S. Department of Commerce and ongoing adherence to DPF Principles including notice, choice, accountability for onward transfer, security, data integrity and purpose limitation, access, and recourse. The document's statement that the DPF Notice governs over this notice in the event of conflict requires that compliance teams maintain current versions of both documents and assess them together. 3. JURISDICTION FLAGS: This provision applies specifically to transfers of personal data from the EEA, UK, and Switzerland to the United States. Transfers between Marqeta entities in other jurisdictions, such as transfers to or from Canada, are addressed separately under the Canadian supplemental notice and are not covered by DPF certification. Transfers between the EEA and UK are noted as occurring as part of business operations and may be covered by adequacy mechanisms or standard contractual clauses as described in the notice. 4. CONTRACT AND VENDOR IMPLICATIONS: Organizations transferring personal data to Marqeta in the context of EEA or UK services should confirm Marqeta's current DPF certification status via the U.S. Department of Commerce DPF list. Data processing agreements referencing the DPF as the transfer mechanism should be updated if Marqeta's certification lapses or is modified. The document's reference to standard contractual clauses as an additional transfer mechanism means that backup transfer arrangements may exist. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should obtain and review the separate Data Privacy Framework Notice to confirm alignment with DPF Principles and to identify any provisions that may conflict with this Website Privacy Notice. Annual DPF recertification status should be monitored. Records of processing activities for EEA and UK data subjects should document the DPF as the applicable transfer mechanism for U.S. transfers and note the subordination of this notice to the DPF Notice in cases of conflict.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Get same-day alerts when this changes → Get Analyst

Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.

Applicable agencies

  • FTC
    The FTC is the primary U.S. enforcement authority for EU-U.S. Data Privacy Framework compliance, including adherence to DPF Principles and recourse obligations
    File a complaint →

Provision details

Document information
Document
Marqeta Privacy Policy
Entity
Marqeta
Document last updated
May 5, 2026
Tracking information
First tracked
July 12, 2026
Last verified
July 12, 2026
Record ID
CA-P-074559
Document ID
CA-D-00667
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
6553971c090c305c5e2834dd25ed83821a9bbb190a5c70870df2987f69e7c0d8
Analysis generated
July 12, 2026 17:53 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Marqeta
Document: Marqeta Privacy Policy
Record ID: CA-P-074559
Captured: 2026-07-12 17:53:18 UTC
SHA-256: 6553971c090c305c…
URL: https://conductatlas.com/platform/marqeta/marqeta-privacy-policy/provision/CA-P-074559/international-data-transfers-and-data-privacy-framework-participation/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Low
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Get Compliance

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Marqeta's International Data Transfers and Data Privacy Framework Participation clause do?

Marqeta's DPF certification establishes a recognized adequacy mechanism for transfers of personal data from the EEA, UK, and Switzerland to the U.S., and makes the FTC the relevant enforcement authority for DPF compliance under U.S. law. The document's statement that the DPF Notice governs in the event of a conflict means that the full scope of data subject rights for …

How does this clause affect you?

Under this provision, personal data transferred from the EEA, UK, and Switzerland to the United States is covered by Marqeta's DPF certification, which provides data subjects with DPF recourse mechanisms including the right to invoke binding arbitration through the DPF Arbitration Panel for unresolved complaints. The document directs individuals to a separate Data Privacy Framework Notice for the full terms …

Is ConductAtlas affiliated with Marqeta?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Marqeta.