The agreement states that a Stripe Connect Platform may designate itself as a data controller and instruct Stripe to process the user's data, subject to the terms of the separately negotiated Platform Provider Agreement. This creates a data processing structure in which the platform controls how Stripe processes the user's data.
This analysis describes what Stripe's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes a data processing relationship in which a third-party platform holds data controller authority over the user's data processed by Stripe, which has direct implications for data subject rights fulfillment, lawful basis documentation, and accountability obligations under GDPR and equivalent frameworks.
Interpretive note: The precise allocation of controller and processor roles between the platform and Stripe depends on the content of the Platform Provider Agreement, which is not included in this document, and may vary by jurisdiction and processing activity.
Under this clause, a Stripe Connect Platform may act as a data controller and direct Stripe to process the user's data, meaning the platform's instructions govern how the user's data is handled within Stripe's infrastructure, subject to the Platform Provider Agreement.
How other platforms handle this
we may share data between our affiliates for the safety and security of our users and may take necessary actions if we believe you have violated these Terms, including banning you from our Services and/or our affiliates' services...
Protect us, our business, our users, and others, for example to enforce our terms of service, prevent spam or other unwanted communications, and investigate or protect against fraud
Each payment processor uses and processes your complete payment information in accordance with its applicable privacy policy (Stripe and PayPal).
"A Stripe Connect Platform may conduct Activity on User's behalf and act as a data controller to instruct Stripe to process User Data (as defined below), as long as it does so according to User's Platform Provider Agreement.Excerpt from Stripe's Connect Platform Agreement
(1) REGULATORY LANDSCAPE: This provision directly implicates GDPR Articles 4(7), 26, and 28 regarding the definition of data controller, joint controllers, and controller-processor contracts.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
ConductAtlas detected a major restructuring of Meta’s privacy policy that removed detailed consumer rights disclosures and relocated them to separate documents.
Your genetic data may be transferred to a new owner as a business asset. Here is what the Terms of Service actually say and what you can do right now.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes a data processing relationship in which a third-party platform holds data controller authority over the user's data processed by Stripe, which has direct implications for data subject rights fulfillment, lawful basis documentation, and accountability obligations under GDPR and equivalent frameworks.
Under this clause, a Stripe Connect Platform may act as a data controller and direct Stripe to process the user's data, meaning the platform's instructions govern how the user's data is handled within Stripe's infrastructure, subject to the Platform Provider Agreement.
ConductAtlas has identified this type of provision across 288 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Stripe.