Stripe · Stripe Connect Platform Agreement · View original document ↗

Platform as Data Controller

High severity Medium confidence Explicitdocumentlanguage Unique · 0 of 343 platforms
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Stripe recorded 2 documented changes in the last 30 days.
Start monitoring updates
Monitor governance changes for Stripe Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

The agreement states that a Stripe Connect Platform may designate itself as a data controller and instruct Stripe to process the user's data, subject to the terms of the separately negotiated Platform Provider Agreement. This creates a data processing structure in which the platform controls how Stripe processes the user's data.

This analysis describes what Stripe's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes a data processing relationship in which a third-party platform holds data controller authority over the user's data processed by Stripe, which has direct implications for data subject rights fulfillment, lawful basis documentation, and accountability obligations under GDPR and equivalent frameworks.

Interpretive note: The precise allocation of controller and processor roles between the platform and Stripe depends on the content of the Platform Provider Agreement, which is not included in this document, and may vary by jurisdiction and processing activity.

Consumer impact (what this means for users)

Under this clause, a Stripe Connect Platform may act as a data controller and direct Stripe to process the user's data, meaning the platform's instructions govern how the user's data is handled within Stripe's infrastructure, subject to the Platform Provider Agreement.

How other platforms handle this

MetaMask Medium

We may share your personal information with our affiliates, meaning entities that control, are controlled by, or are under common control with Consensys. We also share information with service providers who assist in operating our services, subject to confidentiality obligations.

Ledger Medium

At Ledger, earning and maintaining our users' trust is a top priority. That's why we are deeply committed not only to protecting your privacy and securing your personal data, but also to being fully transparent about how we handle it.

Target Medium

RedCard. We share information with our financial partners to operate the Target RedCard program.

See all platforms with this clause type →

Monitoring

Stripe has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Monitor free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
A Stripe Connect Platform may conduct Activity on User's behalf and act as a data controller to instruct Stripe to process User Data (as defined below), as long as it does so according to User's Platform Provider Agreement.

— Excerpt from Stripe's Stripe Connect Platform Agreement

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

(1) REGULATORY LANDSCAPE: This provision directly implicates GDPR Articles 4(7), 26, and 28 regarding the definition of data controller, joint controllers, and controller-processor contracts. Where the platform acts as controller and instructs Stripe as processor, a Data Processing Agreement must be in place. Where the platform and Stripe exercise joint control over processing purposes and means, the requirements of GDPR Article 26 regarding joint controller arrangements may apply. The relevant supervisory authorities are national data protection authorities within the EU/EEA and the UK ICO for UK-based users. CCPA may be implicated for California residents. (2) GOVERNANCE EXPOSURE: High. The provision creates a tripartite data processing structure where the user's data subject rights may need to be fulfilled through or against the platform as controller, rather than directly against Stripe, depending on how processing roles are allocated in the Platform Provider Agreement. This structure requires careful documentation to satisfy GDPR accountability obligations. (3) JURISDICTION FLAGS: EU/EEA and UK users have the most significant exposure given GDPR and UK GDPR requirements for documented controller-processor arrangements, lawful basis for processing, and data subject rights mechanisms. The provision's reference to the Platform Provider Agreement as the governing instrument for the controller designation means that data protection compliance depends on terms not contained in this document. (4) CONTRACT AND VENDOR IMPLICATIONS: Data protection officers should obtain the Data Processing Agreement between the platform and Stripe and assess whether the allocation of controller and processor roles is consistent with the actual decision-making over processing purposes and means. Where the platform and Stripe may both be determining processing purposes, a joint controller arrangement under GDPR Article 26 may be required. (5) COMPLIANCE CONSIDERATIONS: Organizations should update their Records of Processing Activities to reflect the platform's controller role and Stripe's processor role where applicable. Consent mechanisms and privacy notices presented to end users should accurately reflect the tripartite processing structure. Data subject rights request workflows should identify whether requests should be directed to the platform or Stripe.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Monitor free for 14 days

Free: track 1 platform + weekly digest. Monitor: 10 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    The FTC has authority over data privacy and consumer protection practices related to data processing by platforms and payment processors for US users
    File a complaint →

Applicable regulations

CCPA/CPRA
California, USA
Connecticut Data Privacy Act Amendments
US-CT
CAN-SPAM
United States Federal
FCRA
United States Federal
FTC Act Section 5
United States Federal
GDPR
European Union
GLBA
United States Federal
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
UK GDPR
United Kingdom
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
Stripe Connect Platform Agreement
Entity
Stripe
Document last updated
May 20, 2026
Tracking information
First tracked
May 20, 2026
Last verified
May 20, 2026
Record ID
CA-P-012576
Document ID
CA-D-00874
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
285053180e3aa86aa2f31c6f50b34824c52dc7fb11edcaf98f2ef7727b7b48cc
Analysis generated
May 20, 2026 23:03 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Stripe
Document: Stripe Connect Platform Agreement
Record ID: CA-P-012576
Captured: 2026-05-20 23:03:01 UTC
SHA-256: 285053180e3aa86a…
URL: https://conductatlas.com/platform/stripe/stripe-connect-platform-agreement/platform-as-data-controller/
Accessed: May 25, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Related Analysis

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Compliance free trial

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Stripe's Platform as Data Controller clause do?

This provision establishes a data processing relationship in which a third-party platform holds data controller authority over the user's data processed by Stripe, which has direct implications for data subject rights fulfillment, lawful basis documentation, and accountability obligations under GDPR and equivalent frameworks.

How does this clause affect you?

Under this clause, a Stripe Connect Platform may act as a data controller and direct Stripe to process the user's data, meaning the platform's instructions govern how the user's data is handled within Stripe's infrastructure, subject to the Platform Provider Agreement.

Is ConductAtlas affiliated with Stripe?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Stripe.