Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
Marqeta is authorized to use and disclose aggregated and pseudonymized cardholder and transaction data derived from Customer's card program, combined with data from other customers, for any purpose not prohibited by applicable law. The agreement requires that aggregation be at a national or regional level such that Customer's identity is not individually identifiable from the output.
This analysis describes what Marqeta's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision permits Marqeta to commercially use and disclose pseudonymized transaction and cardholder data derived from Customer's program at a population level. While Customer's identity is protected at the aggregation level, the use of cardholder and transaction data for purposes beyond direct service delivery is authorized under this clause, subject to applicable law constraints.
Interpretive note: The agreement does not define the specific pseudonymization methodology or technical standard applied, and the adequacy of pseudonymization may vary depending on applicable law, particularly GDPR.
Under this clause, pseudonymized cardholder and transaction data from Customer's card program may be aggregated with data from other Marqeta customers and used or disclosed by Marqeta for any lawful purpose. The agreement requires aggregation at a national or regional scale to prevent identification of Customer's specific program data.
Cross-platform context
See how other platforms handle Aggregated Data Use and Disclosure and similar clauses.
Compare across platforms →Monitoring
Marqeta has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Marqeta may use and disclose Aggregated Data to the extent not prohibited by Applicable Law. Marqeta will ensure that Aggregated Data is aggregated on a national or regional basis with data from other customers such that Customer's identity is not discernible from the Aggregated Data. Under the Agreement, "Aggregated Data" means pseudonymized Cardholder Data, Transaction Data, or other information collected by Marqeta in connection with Customer's use of the Services that is combined with pseudonymized data of a similar nature obtained from Marqeta's other customers.Excerpt from Marqeta's Terms of Use
1. REGULATORY LANDSCAPE: The use of pseudonymized and aggregated financial transaction data engages GLBA, which governs the use of customer financial information by financial institutions and their service providers. CCPA and CPRA in California impose requirements on the use of pseudonymized data and may limit commercial use of consumer financial data derived from California cardholders. GDPR applies if any EU cardholder data is processed, and pseudonymization under GDPR does not constitute anonymization, meaning GDPR obligations may persist. 2. GOVERNANCE EXPOSURE: Medium. The authorization to use and disclose aggregated data for any lawful purpose is broad, but the pseudonymization and national or regional aggregation requirements provide structural protections against Customer or cardholder re-identification. Legal teams should assess whether the pseudonymization standard employed by Marqeta meets applicable legal definitions, particularly under GDPR, which requires that data cannot be reasonably attributed to an identified individual. 3. JURISDICTION FLAGS: California CPRA creates specific obligations around the use of sensitive personal information and pseudonymized data in commercial contexts. GDPR's pseudonymization standard is distinct from the agreement's description and compliance teams with EU cardholder exposure should assess whether Marqeta's aggregated data practices constitute processing of personal data under GDPR. Illinois BIPA does not directly apply to payment transaction data but may be relevant if biometric data is incorporated in identity verification workflows. 4. CONTRACT AND VENDOR IMPLICATIONS: Customer should assess whether Marqeta's aggregated data use rights conflict with any representations Customer makes to its own cardholders regarding the use of their transaction data. Cardholder privacy policies and consent disclosures should be reviewed for alignment with this aggregated data use permission. Where Customer operates in regulated industries, sector-specific data use restrictions may limit what cardholder data can be contributed to Marqeta's aggregation pool. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should confirm that Marqeta's pseudonymization and aggregation methodology meets applicable legal standards in all jurisdictions where Customer's cardholders are located. Data mapping exercises should document the flow of cardholder and transaction data from Customer's program into Marqeta's aggregated data pool. Customer's privacy notices to cardholders should accurately describe this data use to maintain compliance with applicable transparency requirements.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision permits Marqeta to commercially use and disclose pseudonymized transaction and cardholder data derived from Customer's program at a population level. While Customer's identity is protected at the aggregation level, the use of cardholder and transaction data for purposes beyond direct service delivery is authorized under this clause, subject to applicable law constraints.
Under this clause, pseudonymized cardholder and transaction data from Customer's card program may be aggregated with data from other Marqeta customers and used or disclosed by Marqeta for any lawful purpose. The agreement requires aggregation at a national or regional scale to prevent identification of Customer's specific program data.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Marqeta.