Mixpanel · Mixpanel Privacy Statement · View original document ↗

Controller and Processor Dual-Role Structure

High severity High confidence Explicitdocumentlanguage Unique · 0 of 325 platforms
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Mixpanel Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

When you use a third-party app that runs Mixpanel's analytics tools, Mixpanel handles your data on behalf of that app's owner, not on its own behalf, which means your data rights must generally be directed to that app rather than to Mixpanel.

This analysis describes what Mixpanel's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision determines who is responsible for your personal data and where you must direct rights requests; end users of apps built on Mixpanel's platform may have limited direct recourse against Mixpanel itself.

Consumer impact (what this means for users)

If your data is collected through a third-party product that uses Mixpanel's analytics, the policy states Mixpanel's obligations to you are governed by its contract with that product's operator, not by this privacy policy directly; you must contact that operator to exercise deletion, correction, or access rights.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Email privacy@mixpanel.com with your deletion request, specifying whether you are a Mixpanel website visitor or a customer. If you are an end user of a third-party app that uses Mixpanel, contact that app's operator directly.

How other platforms handle this

Auth0 Medium

When Okta provides its products and services to its customers (e.g., organizations that use Okta to manage their workforce or Auth0 to manage their customer identity), Okta processes personal data on behalf of those customers as a data processor. In those cases, the customer is the data controller a...

Squarespace Medium

When you visit a website built on Squarespace, Squarespace acts as a service provider or data processor, meaning that we process your information on behalf of the website owner. In this case, the website owner is responsible for the information they collect through their website and you should conta...

Egnyte Medium

Egnyte is a data controller with respect to personal data it collects from visitors to its website and through its marketing activities. Egnyte acts as a data processor with respect to the content and data that customers store within the Egnyte platform. In that capacity, Egnyte processes data on be...

See all platforms with this clause type →

Monitoring

Mixpanel has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Mixpanel acts as a 'data controller' when we collect and use personal data for our own purposes, such as information about visitors to our website or customers who use our Service. Mixpanel acts as a 'data processor' when we process personal data on behalf of our customers. In this case, our customers are the data controllers and determine the purposes and means of processing. If you are an end user of one of our customers' products and have questions about how your data is handled, please contact that customer directly.

— Excerpt from Mixpanel's Mixpanel Privacy Statement

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

1) REGULATORY LANDSCAPE: This provision directly engages GDPR Articles 4(7) and 4(8) defining controller and processor roles, and the associated obligations under GDPR Articles 24 through 28 requiring documented data processing agreements. The Irish Data Protection Commission is identified as the lead supervisory authority for EU matters. Under CCPA, the equivalent distinction between business and service provider is similarly operative, with the California Privacy Protection Agency as relevant enforcement authority. 2) GOVERNANCE EXPOSURE: High. The controller/processor distinction has direct compliance consequences for organizations deploying Mixpanel. If a Mixpanel customer transmits personal data to Mixpanel without an executed Data Processing Addendum, that organization may be operating outside GDPR Article 28 requirements, creating regulatory exposure. The policy places the burden on the business customer to handle end-user data rights requests, which requires that those customers have implemented appropriate intake and response processes. 3) JURISDICTION FLAGS: EU and UK deployments face the highest exposure given mandatory DPA requirements under GDPR and UK GDPR. California-resident data processed through Mixpanel by a third-party business triggers CCPA service provider agreement requirements. Deployments involving minors' data may engage COPPA, where the operator/processor chain requires heightened diligence. 4) CONTRACT AND VENDOR IMPLICATIONS: Procurement teams must confirm execution of Mixpanel's Data Processing Addendum prior to deployment. The policy's assertion that Mixpanel acts only on customer instructions as a processor should be verified against the actual DPA terms, including sub-processor lists, audit rights, and breach notification obligations. Organizations should assess whether Mixpanel's standard DPA terms align with their own regulatory obligations. 5) COMPLIANCE CONSIDERATIONS: Compliance teams should confirm DPA execution, review sub-processor disclosure lists, and update their own privacy notices to accurately reflect Mixpanel's involvement in data processing. Data subject rights intake procedures should be mapped to include forwarding obligations where requests concern data processed through Mixpanel's platform.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Watcher free for 14 days

Free: track 1 platform + weekly digest. Watcher: 10 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    The FTC has jurisdiction over unfair or deceptive data practices affecting U.S. consumers, including the adequacy of disclosures about data processor relationships
    File a complaint →

Applicable regulations

CCPA/CPRA
California, USA
Colorado AI Act
US-CO
CAN-SPAM
United States Federal
ePrivacy Directive
European Union
FTC Act Section 5
United States Federal
GDPR
European Union

Provision details

Document information
Document
Mixpanel Privacy Statement
Entity
Mixpanel
Document last updated
May 5, 2026
Tracking information
First tracked
May 8, 2026
Last verified
May 12, 2026
Record ID
CA-P-011463
Document ID
CA-D-00704
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
58ece66c0abafda45174ec4cac6a28f2104769dfb6d084f03237ca0d1e49add5
Analysis generated
May 8, 2026 14:49 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Mixpanel
Document: Mixpanel Privacy Statement
Record ID: CA-P-011463
Captured: 2026-05-08 14:49:11 UTC
SHA-256: 58ece66c0abafda4…
URL: https://conductatlas.com/platform/mixpanel/mixpanel-privacy-statement/controller-and-processor-dual-role-structure/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Related Analysis

Professional Governance Intelligence

Need to monitor specific governance provisions?

Professional includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Professional free trial

Or start with Watcher →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Mixpanel's Controller and Processor Dual-Role Structure clause do?

This provision determines who is responsible for your personal data and where you must direct rights requests; end users of apps built on Mixpanel's platform may have limited direct recourse against Mixpanel itself.

How does this clause affect you?

If your data is collected through a third-party product that uses Mixpanel's analytics, the policy states Mixpanel's obligations to you are governed by its contract with that product's operator, not by this privacy policy directly; you must contact that operator to exercise deletion, correction, or access rights.

Is ConductAtlas affiliated with Mixpanel?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Mixpanel.