8 Total
1 High severity
4 Medium severity
3 Low severity
Summary

This document establishes Checkout.com's data handling procedures for personal data collected from merchants, cardholders, and website visitors in connection with payment processing services. The policy authorizes Checkout.com to share financial and identity data, including payment card details, transaction history, and identity verification information, with fraud prevention agencies and credit reference agencies. Individuals in the EU and UK may submit requests for data access, correction, or deletion by contacting the Data Protection Officer at dpo@checkout.com.

Technical / Legal Breakdown

This document is Checkout.com's Privacy Policy governing the collection, use, storage, and sharing of personal data by Checkout.com Ltd and its group entities, with legal bases including contract performance, legitimate interests, legal obligations, and consent under GDPR and equivalent frameworks. The policy states that Checkout.com collects identity data, contact data, financial data, transaction data, technical data, usage data, and communications data from merchants, their end customers (cardholders), job applicants, and website visitors, and the terms authorize sharing this data with payment networks, issuing banks, fraud prevention agencies, credit reference agencies, regulators, and third-party service providers. A notable operational distinction is that Checkout.com processes data both as a data controller (for its own merchant and website visitor relationships) and as a data processor (on behalf of merchants for cardholder data), which creates layered accountability structures where merchants bear primary responsibility for their end customers' data rights. The policy engages GDPR and UK GDPR as primary frameworks, with additional references to CCPA-adjacent rights for California residents and sector-specific financial regulation; international data transfers are addressed via Standard Contractual Clauses and adequacy decisions, creating compliance dependencies that vary by jurisdiction and transfer destination. Material considerations include the breadth of data sharing with fraud and credit reference agencies, which may interact with consumer credit reporting obligations, and the policy's acknowledgment of automated decision-making in fraud screening contexts, which may require evaluation under GDPR Article 22.

Institutional Analysis

Institutional analysis available with Compliance

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Compliance.

Start Compliance free trial

1 important change detected

2 versions captured · Last updated: June 2026

June 19, 2026

unknown
What changed Checkout.com updated their Checkout.com Privacy on June 19, 2026. Change detected: 10 sentence(s) added, 2 sentence(s) removed, 8 sentence(s) modified. Document contained 132 sentences after update.
View full change record →

Recent Provision Changes Jun 19, 2026

8 provisions unchanged.

View full change record →
High — 1 provision
Medium — 4 provisions
Low — 3 provisions

Monitoring

Checkout.com has updated this document before.

Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →

Compliance Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Compliance includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Compliance free trial

Cross-platform context

See how other platforms handle Controller vs Processor Dual Role and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
FCRA
United States Federal
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
GLBA
United States Federal
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured June 19, 2026 01:17 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000663
Version ID CA-V-004033
SHA-256 3e2ae395c573c95b22be1cb7b8fc2f3e90aa6d244b42a3b0506ae1b8c5133710
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans