Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The document adds five entities to the affiliate list for crypto and stablecoin-related personal data processing: Horkos, Inc. (d/b/a Privy), Bridge Ventures, LLC, Bridge Building Sp. Z.o.o., Bridge Building S.A., and Stripe Global Technology, LLC. These entities are located in the United States, Poland, and Luxembourg and process personal data in connection with stablecoin financial account products and crypto services.
This analysis describes what Stripe's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The addition of crypto and stablecoin-related processing entities introduces new categories of data processing activity and geographic sub-processor locations that Business Users must evaluate against their own DPA schedules, data transfer mechanisms, and sector-specific regulatory obligations. The cross-border processing involving Polish and Luxembourg entities may require updated transfer impact assessments for EU Business Users.
Under the updated affiliate list, personal data associated with Stripe's stablecoin financial account product and related crypto services may be processed by five newly added affiliate entities across the United States, Poland, and Luxembourg. Business Users whose DPAs or privacy documentation do not currently reflect these entities or processing purposes should review whether updates are required.
Cross-platform context
See how other platforms handle Stablecoin and Crypto Affiliate Additions and similar clauses.
Compare across platforms →Monitoring
Stripe has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"Horkos, Inc. (d/b/a Privy), a recently-acquired company in the stablecoin space; and Bridge Ventures, LLC, Bridge Building Sp. Z.o.o., and Bridge Building S.A., another recently-acquired company also in the stablecoin space. Stripe Global Technology, LLC, a new Stripe Affiliate Sub-processor; ... Stripe Global Technology, LLC AMER United States UX and related services in connection with the stablecoin financial account product. Horkos, Inc. (d/b/a Privy) AMER United States Crypto and stablecoin related services. Bridge Ventures, LLC AMER United States Crypto and stablecoin related services. Bridge Building Sp. Z.o.o. EMEA Poland Crypto and stablecoin related services. Bridge Building S.A. EMEA Luxembourg Crypto and stablecoin related services.Excerpt from Stripe's Service Providers (Sub-Processors)
1. REGULATORY LANDSCAPE: Stablecoin and crypto-related personal data processing may engage EU Markets in Crypto-Assets Regulation (MiCA), applicable virtual asset service provider (VASP) registration and AML requirements under the EU's AMLD frameworks, and equivalent UK regulations. Data processing by these entities is also subject to GDPR for EU and EEA-based data subjects. The Polish and Luxembourg entities are subject to their respective national data protection authorities as well as the Irish DPC under GDPR's one-stop-shop where applicable. US-based entities are subject to applicable federal and state financial and privacy regulations. 2. GOVERNANCE EXPOSURE: Medium. The addition of newly acquired entities to the sub-processor list means Business Users may not have previously documented these processing relationships. For Business Users whose End Customers engage with stablecoin or crypto products, the addition of these affiliates expands the scope of personal data processing covered by the DPA and may require notification to End Customers under applicable privacy law. 3. JURISDICTION FLAGS: EU and EEA Business Users face heightened exposure due to GDPR sub-processor consent requirements and potential MiCA compliance obligations. UK Business Users should assess compliance with UK GDPR and FCA crypto-asset regulations. US Business Users in states with comprehensive privacy laws (California, Virginia, Colorado) should review whether stablecoin-related processing triggers additional disclosure or consent obligations. 4. CONTRACT AND VENDOR IMPLICATIONS: Business Users should confirm that their DPA schedules are updated to include the five newly listed entities and assess whether transfers of personal data to these entities require new or updated Standard Contractual Clauses, Binding Corporate Rules, or equivalent mechanisms. Procurement teams should note that Bridge Building Sp. Z.o.o. (Poland) and Bridge Building S.A. (Luxembourg) are EU-based entities, while the US-based entities require separate transfer mechanism assessment. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should update sub-processor registers, data transfer impact assessments, and Article 30 records to reflect the five new entities. Teams operating in regulated financial services environments should assess whether stablecoin-related data processing by these newly acquired affiliates triggers additional AML, KYC, or financial services regulatory notification obligations.
Regulatory citations, enforcement risk, and due diligence action items.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
The addition of crypto and stablecoin-related processing entities introduces new categories of data processing activity and geographic sub-processor locations that Business Users must evaluate against their own DPA schedules, data transfer mechanisms, and sector-specific regulatory obligations. The cross-border processing involving Polish and Luxembourg entities may require updated transfer impact assessments for EU Business Users.
Under the updated affiliate list, personal data associated with Stripe's stablecoin financial account product and related crypto services may be processed by five newly added affiliate entities across the United States, Poland, and Luxembourg. Business Users whose DPAs or privacy documentation do not currently reflect these entities or processing purposes should review whether updates are required.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Stripe.