Checkout.com uses automated systems to assess fraud risk in payment transactions, and these systems may make decisions about transactions without human review, though individuals can request a human review if the decision significantly affects them.
This analysis describes what Checkout.com's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
Automated fraud decisions can result in transactions being declined or accounts being flagged without any human judgment involved, and individuals may not always know when they have been subject to such a decision or how to challenge it.
Interpretive note: The scope of which automated decisions qualify as having 'significant effects' triggering Article 22 rights is subject to regulatory interpretation and may vary depending on the specific fraud screening context and jurisdiction.
The updated policy establishes formal complaint procedures for UK and Australia users, requiring Checkout to acknowledge complaints within 30 days and respond without undue delay. For UK users specifically, the policy clarifies that complaints must first be raised with Checkout before escalating to the Information Commissioner's Office. The policy also discloses that transaction information collection now includes country data alongside currency and amount. For Australia users, the policy clarifies that identity verification is a legal requirement and cannot be provided anonymously or pseudonymously. Users in these jurisdictions can submit data protection complaints through Checkout's designated process and escalate to their respective regulatory authorities if dissatisfied with Checkout's response.
View change record →Cardholders whose transactions are declined or flagged through Checkout.com's automated fraud systems may have the right to request a human review of that decision, particularly under GDPR Article 22, but exercising this right requires knowing it exists and contacting the relevant party.
How other platforms handle this
If you choose to reveal any personal information about yourself to other users, you do so at your own risk. We strongly encourage you to use caution in disclosing any personal information online.
When you are asked to provide information, you may decline to do so; but if you choose not to provide information that is necessary to provide some of our Services, you may not be able to use those Services.
to object to profiling activities based on our own legitimate interests
"We may use automated decision-making, including profiling, in connection with fraud detection and prevention. You have the right to request human review of any automated decision that significantly affects you.Excerpt from Checkout.com's Privacy
1.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
Automated fraud decisions can result in transactions being declined or accounts being flagged without any human judgment involved, and individuals may not always know when they have been subject to such a decision or how to challenge it.
Cardholders whose transactions are declined or flagged through Checkout.com's automated fraud systems may have the right to request a human review of that decision, particularly under GDPR Article 22, but exercising this right requires knowing it exists and contacting the relevant party.
ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Checkout.com.