Marqeta · Marqeta Terms of Use · View original document ↗

KYC Services Usage Restrictions

High severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Marqeta changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Marqeta Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

Customer's use of KYC identity verification services is restricted to GLBA-permitted purposes and explicitly prohibited from FCRA permissible purpose use cases, adverse action decisions, and DPPA-restricted data uses. Customer is also prohibited from using KYC service outputs in violation of any applicable law governing PII use.

This analysis describes what Marqeta's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes that KYC service outputs cannot be used as a basis for FCRA adverse action decisions, which means Customer cannot use identity verification results to deny credit, employment, housing, or other FCRA-covered determinations. Violations of these restrictions would constitute Customer indemnification triggers under Section B(7)(b) and could expose Customer to direct regulatory liability under the FCRA, GLBA, and DPPA.

Consumer impact (what this means for users)

The agreement restricts Customer's use of KYC verification outputs to identity and age verification for card program purposes only, and prohibits using the outputs to take adverse action as defined under the FCRA. Customer's failure to observe these restrictions is treated as a material breach and triggers the Customer's indemnification obligations under the agreement.

Cross-platform context

See how other platforms handle KYC Services Usage Restrictions and similar clauses.

Compare across platforms →

Monitoring

Marqeta has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Customer will use the KYC Services only to the extent permitted under an exception to the Gramm-Leach-Bliley Act and its implementing regulations. Customer will not use the KYC Services for any "permissible purpose" as defined under the Federal Credit Reporting Act ("FCRA") and its implementing regulations or use any of the information it receives through the KYC Services to take any "adverse action," as defined in the FCRA. Customer will not use the KYC Services in violation of the Driver's Privacy Protection Act and its implementing regulations. Customer will not use the KYC Services in violation of any other Applicable Law, whether now or hereafter in effect, that limits the use of the KYC Services or PII.

Excerpt from Marqeta's Terms of Use

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: This provision directly engages the Gramm-Leach-Bliley Act (GLBA), the Fair Credit Reporting Act (FCRA), and the Driver's Privacy Protection Act (DPPA). The FTC enforces the FCRA and GLBA with respect to non-bank financial institutions. The CFPB enforces the FCRA with respect to consumer financial products. The adverse action prohibition under FCRA has specific procedural requirements (adverse action notices, disclosure of consumer reporting agency) that Customer must satisfy independently if it uses any other data sources for covered determinations. 2. GOVERNANCE EXPOSURE: High. The prohibition on FCRA adverse action use of KYC outputs creates a clear compliance boundary that Customer must operationalize through system controls and staff training. If Customer's internal workflows could inadvertently route KYC verification outputs into credit decisioning, employment screening, or similar FCRA-covered processes, the restriction creates direct regulatory exposure for Customer under the FCRA, which provides for actual damages, statutory damages, and attorneys' fees in private actions, in addition to regulatory penalties. 3. JURISDICTION FLAGS: The FCRA, GLBA, and DPPA are federal statutes with national applicability. State analogues, including California's Consumer Credit Reporting Agencies Act and the California Privacy Rights Act (CPRA), may impose additional restrictions on identity verification data use. Illinois, New York, and other states with biometric or identity data laws may create heightened compliance requirements for KYC data handling. 4. CONTRACT AND VENDOR IMPLICATIONS: The limitation of KYC Service Provider liability to 12 months of fees paid, combined with the explicit statement that the KYC Service Provider is not a party to the agreement, means Customer has no direct contractual recourse against the KYC Service Provider for data errors or system failures. Customer's operational compliance with FCRA adverse action restrictions must be managed entirely through internal controls rather than relying on KYC service outputs as a definitive compliance mechanism. 5. COMPLIANCE CONSIDERATIONS: Legal and compliance teams should implement technical controls to prevent KYC verification outputs from being used in any FCRA-covered decisioning workflow. Written compliance policies should document the permissible use scope as defined in the agreement. Data mapping exercises should confirm that KYC outputs are segregated from credit, employment, or housing decisioning systems. Staff training on FCRA adverse action requirements is a priority given the direct regulatory exposure created by this provision.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Get same-day alerts when this changes → Get Analyst

Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.

Applicable agencies

  • CFPB
    CFPB enforces the FCRA with respect to consumer financial products and has authority over adverse action practices in connection with card programs and identity verification
    File a complaint →
  • FTC
    FTC enforces the FCRA and GLBA with respect to non-bank financial institutions and may have jurisdiction over KYC data misuse by Customer
    File a complaint →

Provision details

Document information
Document
Marqeta Terms of Use
Entity
Marqeta
Document last updated
May 5, 2026
Tracking information
First tracked
July 12, 2026
Last verified
July 12, 2026
Record ID
CA-P-074322
Document ID
CA-D-00666
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
bbb9885e232304ba5f7143efb49a715cb875cef5b9d5f8893d363771bc6eac76
Analysis generated
July 12, 2026 15:34 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Marqeta
Document: Marqeta Terms of Use
Record ID: CA-P-074322
Captured: 2026-07-12 15:34:24 UTC
SHA-256: bbb9885e232304ba…
URL: https://conductatlas.com/platform/marqeta/marqeta-terms-of-use/provision/CA-P-074322/kyc-services-usage-restrictions/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Get Compliance

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Marqeta's KYC Services Usage Restrictions clause do?

This provision establishes that KYC service outputs cannot be used as a basis for FCRA adverse action decisions, which means Customer cannot use identity verification results to deny credit, employment, housing, or other FCRA-covered determinations. Violations of these restrictions would constitute Customer indemnification triggers under Section B(7)(b) and could expose Customer to direct regulatory liability under the FCRA, GLBA, and …

How does this clause affect you?

The agreement restricts Customer's use of KYC verification outputs to identity and age verification for card program purposes only, and prohibits using the outputs to take adverse action as defined under the FCRA. Customer's failure to observe these restrictions is treated as a material breach and triggers the Customer's indemnification obligations under the agreement.

Is ConductAtlas affiliated with Marqeta?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Marqeta.