Provision record
Stripe · Stripe Connect Platform Agreement · View original document ↗

Platform as Data Controller

High severity Medium confidence Explicitdocumentlanguage Common · 294 of 352 platforms
Get alerted the next time Stripe changes these terms. Follow Stripe →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Stripe recorded 2 documented changes in the last 30 days.
Follow Stripe →
Monitor governance changes for Stripe Monitor emails you the same day this changes. The archive stays free.
Follow Stripe →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The agreement states that a Stripe Connect Platform may designate itself as a data controller and instruct Stripe to process the user's data, subject to the terms of the separately negotiated Platform Provider Agreement. This creates a data processing structure in which the platform controls how Stripe processes the user's data.

This analysis describes what Stripe's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes a data processing relationship in which a third-party platform holds data controller authority over the user's data processed by Stripe, which has direct implications for data subject rights fulfillment, lawful basis documentation, and accountability obligations under GDPR and equivalent frameworks.

Interpretive note: The precise allocation of controller and processor roles between the platform and Stripe depends on the content of the Platform Provider Agreement, which is not included in this document, and may vary by jurisdiction and processing activity.

Consumer impact (what this means for users)

Under this clause, a Stripe Connect Platform may act as a data controller and direct Stripe to process the user's data, meaning the platform's instructions govern how the user's data is handled within Stripe's infrastructure, subject to the Platform Provider Agreement.

How other platforms handle this

Squarespace Medium

Each payment processor uses and processes your complete payment information in accordance with its applicable privacy policy (Stripe and PayPal).

Lime Medium

if you are accessing and using Lime Services under a corporate account...you acknowledge and agree that Lime may share certain of your usage information with whomever provided you with access to the Lime Services

Google Gemini Medium

Gemini Apps may share your precise location data with another Google service, like Google Maps, to fulfill your request.

See all platforms with this clause type →

Monitoring

Stripe has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Follow Stripe → Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
A Stripe Connect Platform may conduct Activity on User's behalf and act as a data controller to instruct Stripe to process User Data (as defined below), as long as it does so according to User's Platform Provider Agreement.

Excerpt from Stripe's Connect Platform Agreement

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

(1) REGULATORY LANDSCAPE: This provision directly implicates GDPR Articles 4(7), 26, and 28 regarding the definition of data controller, joint controllers, and controller-processor contracts. Where the platform acts as controller and instructs Stripe as processor, a Data Processing Agreement must be in place. Where the platform and Stripe exercise joint control over processing purposes and means, the requirements of GDPR Article 26 regarding joint controller arrangements may apply. The relevant supervisory authorities are national data protection authorities within the EU/EEA and the UK ICO for UK-based users. CCPA may be implicated for California residents. (2) GOVERNANCE EXPOSURE: High. The provision creates a tripartite data processing structure where the user's data subject rights may need to be fulfilled through or against the platform as controller, rather than directly against Stripe, depending on how processing roles are allocated in the Platform Provider Agreement. This structure requires careful documentation to satisfy GDPR accountability obligations. (3) JURISDICTION FLAGS: EU/EEA and UK users have the most significant exposure given GDPR and UK GDPR requirements for documented controller-processor arrangements, lawful basis for processing, and data subject rights mechanisms. The provision's reference to the Platform Provider Agreement as the governing instrument for the controller designation means that data protection compliance depends on terms not contained in this document. (4) CONTRACT AND VENDOR IMPLICATIONS: Data protection officers should obtain the Data Processing Agreement between the platform and Stripe and assess whether the allocation of controller and processor roles is consistent with the actual decision-making over processing purposes and means. Where the platform and Stripe may both be determining processing purposes, a joint controller arrangement under GDPR Article 26 may be required. (5) COMPLIANCE CONSIDERATIONS: Organizations should update their Records of Processing Activities to reflect the platform's controller role and Stripe's processor role where applicable. Consent mechanisms and privacy notices presented to end users should accurately reflect the tripartite processing structure. Data subject rights request workflows should identify whether requests should be directed to the platform or Stripe.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Applicable agencies

  • FTC
    The FTC has authority over data privacy and consumer protection practices related to data processing by platforms and payment processors for US users
    File a complaint →

Applicable regulations

CCPA/CPRA
California, USA
Connecticut Data Privacy Act Amendments
US-CT
CAN-SPAM
United States Federal
FCRA
United States Federal
FTC Act Section 5
United States Federal
GDPR
European Union
GLBA
United States Federal
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
UK GDPR
United Kingdom
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
Stripe Connect Platform Agreement
Entity
Stripe
Document last updated
May 20, 2026
Tracking information
First tracked
May 20, 2026
Last verified
May 20, 2026
Record ID
CA-P-012576
Document ID
CA-D-00874
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
285053180e3aa86aa2f31c6f50b34824c52dc7fb11edcaf98f2ef7727b7b48cc
Analysis generated
May 20, 2026 23:03 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Stripe
Document: Stripe Connect Platform Agreement
Record ID: CA-P-012576
Captured: 2026-05-20 23:03:01 UTC
SHA-256: 285053180e3aa86a…
URL: https://conductatlas.com/platform/stripe/stripe-connect-platform-agreement/provision/CA-P-012576/platform-as-data-controller/
Accessed: July 25, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Related Analysis

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention

Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.

Frequently Asked Questions

What does Stripe's Platform as Data Controller clause do?

This provision establishes a data processing relationship in which a third-party platform holds data controller authority over the user's data processed by Stripe, which has direct implications for data subject rights fulfillment, lawful basis documentation, and accountability obligations under GDPR and equivalent frameworks.

How does this clause affect you?

Under this clause, a Stripe Connect Platform may act as a data controller and direct Stripe to process the user's data, meaning the platform's instructions govern how the user's data is handled within Stripe's infrastructure, subject to the Platform Provider Agreement.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 294 platforms. See the full comparison.

Is ConductAtlas affiliated with Stripe?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Stripe.