Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The notice discloses that automated systems may process Merchant Customer data to make fraud detection decisions (potentially declining transactions) and identity verification decisions (potentially delaying or denying product or service access), with affected individuals in certain jurisdictions having the right to request human review of those decisions.
This analysis describes what Checkout.com's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that automated processing may directly affect a consumer's ability to complete a transaction or access a service, and the right to request human review is stated to be jurisdiction-dependent, meaning not all affected individuals have the same recourse.
Interpretive note: The right to request human review is stated as jurisdiction-dependent and the notice does not specify which jurisdictions trigger that right, creating ambiguity for users outside the EU, UK, California, and Colorado.
The updated policy establishes formal complaint procedures for UK and Australia users, requiring Checkout to acknowledge complaints within 30 days and respond without undue delay. For UK users specifically, the policy clarifies that complaints must first be raised with Checkout before escalating to the Information Commissioner's Office. The policy also discloses that transaction information collection now includes country data alongside currency and amount. For Australia users, the policy clarifies that identity verification is a legal requirement and cannot be provided anonymously or pseudonymously. Users in these jurisdictions can submit data protection complaints through Checkout's designated process and escalate to their respective regulatory authorities if dissatisfied with Checkout's response.
View change record →Under these terms, transactions initiated through Merchants using Checkout's fraud detection services may be declined by automated systems without prior human review, and identity verification outcomes may delay or deny access to products or services. The agreement states that individuals in certain jurisdictions may request human intervention in automated decisions by contacting dpo@checkout.com.
Cross-platform context
See how other platforms handle Automated Decision-Making for Fraud and Identity Verification and similar clauses.
Compare across platforms →Monitoring
Checkout.com has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"In the course of providing our services, we may make decisions using your personal data which are partially or wholly automated to help make our decisions and services secure and efficient. We use automated decision-making in the following circumstances: -Fraud detection: Where you are a Merchant Customer and you initiate a transaction with a Merchant that uses our fraud detection services, your information may be processed by Checkout for the purposes of fraud detection and prevention. In some cases, this may lead to an automated decision for a transaction to be declined or for further information to be requested from you in order to proceed. -Identity verification: Where you are a Merchant Representative or Merchant Customer and we ask you to provide identity information to sign up to one of our services, or you use our identity verification product, the information you provide may be subject to partially or wholly automated decisions as to whether we are able to verify your identity. In the event we are unable to effectively verify your identity, this could have the impact of delaying or denying you access to a product or service operated by Checkout or one of our Merchants.Excerpt from Checkout.com's Privacy
1. REGULATORY LANDSCAPE: This provision directly engages GDPR Article 22, which establishes the right not to be subject to solely automated decisions producing legal or similarly significant effects, subject to specified exceptions. UK GDPR contains equivalent provisions. The notice acknowledges a right to object to automated decisions and request human review, but qualifies this right as jurisdiction-dependent rather than universal. CPRA and the Colorado Privacy Act also establish rights regarding automated decision-making and profiling that may apply to California and Colorado residents respectively. 2. GOVERNANCE EXPOSURE: High. The provision discloses that automated decisions may result in transaction declines and service denials, which are outcomes with significant operational consequences for affected individuals. The notice does not provide detail on the logic, significance, or envisaged consequences of the automated processing as required by GDPR Article 13 and 14, which may be a transparency gap. 3. JURISDICTION FLAGS: EEA and UK data subjects have a qualified right under GDPR and UK GDPR Article 22 to not be subject to solely automated decisions with significant effects, unless exceptions apply (contract necessity, legal authorization, or explicit consent). California residents have CPRA rights regarding automated decision-making. The notice's statement that human review rights are jurisdiction-dependent means that consumers in jurisdictions without explicit statutory rights may have no contractual remedy for automated service denials. 4. CONTRACT AND VENDOR IMPLICATIONS: Merchants integrating Checkout's fraud detection and identity verification services should assess whether their own customer-facing disclosures adequately address the automated decision-making that may affect their customers' transactions, as the notice states that Checkout may act as a data processor for Merchant Customer data in some instances, placing disclosure obligations on the Merchant. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should evaluate whether the automated decision-making disclosures satisfy GDPR Articles 13, 14, and 22 transparency requirements, including meaningful information about the logic involved and the significance of outcomes. They should also confirm that the human review mechanism described in the notice is operationally implemented and accessible to users who exercise the right, and that the 96-hour image-hash block described elsewhere in the notice is appropriately disclosed as an automated process.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes that automated processing may directly affect a consumer's ability to complete a transaction or access a service, and the right to request human review is stated to be jurisdiction-dependent, meaning not all affected individuals have the same recourse.
Under these terms, transactions initiated through Merchants using Checkout's fraud detection services may be declined by automated systems without prior human review, and identity verification outcomes may delay or deny access to products or services. The agreement states that individuals in certain jurisdictions may request human intervention in automated decisions by contacting dpo@checkout.com.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Checkout.com.