Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The notice discloses that when an identity document is flagged for verification or a facial image is used multiple times in a short period, a hashed version of the facial image may be stored for up to 96 hours to detect repeated use of the same image with different documents, with temporary service access blocks possible during that period, all blocks subject to human operator review.
This analysis describes what Checkout.com's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes a secondary automated biometric processing mechanism, distinct from the primary identity verification function, that may impose a temporary service access block on individuals whose facial image triggers the fraud detection heuristic, with human review stated as the backstop for all such blocks.
Interpretive note: Whether a hashed facial image constitutes a biometric identifier under BIPA or analogous state laws is subject to judicial interpretation and is not resolved on the face of the document.
The updated policy establishes formal complaint procedures for UK and Australia users, requiring Checkout to acknowledge complaints within 30 days and respond without undue delay. For UK users specifically, the policy clarifies that complaints must first be raised with Checkout before escalating to the Information Commissioner's Office. The policy also discloses that transaction information collection now includes country data alongside currency and amount. For Australia users, the policy clarifies that identity verification is a legal requirement and cannot be provided anonymously or pseudonymously. Users in these jurisdictions can submit data protection complaints through Checkout's designated process and escalate to their respective regulatory authorities if dissatisfied with Checkout's response.
View change record →Under these terms, a hashed version of a consumer's facial image may be stored for up to 96 hours if flagged during identity verification, and a temporary block on service access may be applied during that period. The agreement states that all such blocks are reviewed by human operators and do not result in permanent classification or denial of service.
Cross-platform context
See how other platforms handle 96-Hour Temporary Image-Hash Block for Fraud Prevention and similar clauses.
Compare across platforms →Monitoring
Checkout.com has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"In addition, in limited cases where your identity document is flagged for further verification, we may process a hashed version of your facial image, for the sole purpose of preventing repeated use of the same facial image with different documents. This data is used for fraud prevention, stored for no more than 96 hours, and does not result in permanent classification, profiling or denial of service. In addition, in the event that a facial image is used multiple times in a short period of time, a temporary block (up to 96 hours) may be applied to a hash of the image. This is to allow us to protect our systems against potential fraud and alert affected Merchants. This does not result in any permanent decision or classification, and all blocks are reviewed and handled by human operators.Excerpt from Checkout.com's Privacy
1. REGULATORY LANDSCAPE: This provision implicates GDPR Article 9 (biometric data as special category) and Article 22 (automated decision-making), as the temporary block constitutes an automated outcome with operational consequences for the affected individual. The notice's statement that all blocks are reviewed by human operators is relevant to the GDPR Article 22 exemption conditions. US state biometric privacy statutes including BIPA would apply to any hashed facial image data retained for Illinois residents. 2. GOVERNANCE EXPOSURE: Medium. The provision states the block is temporary (up to 96 hours), does not result in permanent classification, and is reviewed by human operators, which mitigates the most significant automated decision-making concerns. However, the 96-hour block period during which service access is affected constitutes an operationally significant outcome for affected individuals, particularly in time-sensitive transaction contexts. 3. JURISDICTION FLAGS: Illinois BIPA applies to hashed biometric identifiers derived from facial images; a hashed facial image may constitute a biometric identifier under BIPA depending on judicial interpretation. EEA and UK data subjects affected by a temporary block may have the right to request information about the automated processing under GDPR Articles 13 and 15. 4. CONTRACT AND VENDOR IMPLICATIONS: Merchants integrated with Checkout's identity verification product should be aware that the 96-hour block mechanism may result in their customers being temporarily unable to complete transactions or access services, and should assess whether their customer communications and support workflows account for this scenario. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should confirm that the human review process for 96-hour blocks is operationally documented, that the review timeline is defined and meets any applicable regulatory requirements for automated decision review, and that the hashed image data is verifiably deleted at or before the 96-hour limit.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes a secondary automated biometric processing mechanism, distinct from the primary identity verification function, that may impose a temporary service access block on individuals whose facial image triggers the fraud detection heuristic, with human review stated as the backstop for all such blocks.
Under these terms, a hashed version of a consumer's facial image may be stored for up to 96 hours if flagged during identity verification, and a temporary block on service access may be applied during that period. The agreement states that all such blocks are reviewed by human operators and do not result in permanent classification or denial of service.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Checkout.com.