Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The notice authorizes collection of facial images and voice recordings from which biometric identifiers (faceprints, voiceprints, minutiae templates) are extracted for identity verification, with that biometric data shared with Snowflake Computing and Amazon Web Services and retained for up to 365 days before deletion.
This analysis describes what Checkout.com's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision names the specific biometric data categories collected, the two third-party cloud processors receiving that data, and establishes a 365-day outer retention limit, each of which are operationally significant parameters for compliance with GDPR, UK GDPR, and US state-level biometric privacy statutes that impose consent, disclosure, and retention requirements.
Interpretive note: The phrase 'or if our collection of biometric information is otherwise permitted by law' reserves a non-consent legal basis that is not further specified, and the adequacy of the stated consent mechanism under US state biometric laws (BIPA, Texas CUBI) requires jurisdiction-specific legal evaluation.
The updated policy establishes formal complaint procedures for UK and Australia users, requiring Checkout to acknowledge complaints within 30 days and respond without undue delay. For UK users specifically, the policy clarifies that complaints must first be raised with Checkout before escalating to the Information Commissioner's Office. The policy also discloses that transaction information collection now includes country data alongside currency and amount. For Australia users, the policy clarifies that identity verification is a legal requirement and cannot be provided anonymously or pseudonymously. Users in these jurisdictions can submit data protection complaints through Checkout's designated process and escalate to their respective regulatory authorities if dissatisfied with Checkout's response.
View change record →This provision establishes that Merchant Customers who use Checkout's identity verification services may have facial images, voiceprints, and derived biometric templates collected, shared with Snowflake Computing and Amazon Web Services, and retained for up to 365 days, with processing stated to require explicit consent. The agreement also states that biometric collection may proceed where otherwise permitted by law, independent of consent.
Cross-platform context
See how other platforms handle Biometric Data Collection and Retention and similar clauses.
Compare across platforms →Monitoring
Checkout.com has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"If you consent to our collection of biometric information or if our collection of biometric information is otherwise permitted by law, you agree that we may collect your imagery of the face, and voice recordings, from which an identifier template such as a faceprint, a minutiae template, or a voiceprint, can be extracted in order to verify your identity using Checkout's verification services. Your biometric information may be shared with our third-party cloud providers Snowflake Computing and Amazon Web Services. We will delete your biometric information no later than 365 days after the date you provide it.Excerpt from Checkout.com's Privacy
1. REGULATORY LANDSCAPE: This provision implicates GDPR Article 9 (special category data) and UK GDPR Article 9, which require explicit consent or another Article 9(2) basis for processing biometric data. In the US, Illinois BIPA, Texas CUBI, and Washington My Health MY Data Act impose specific written consent, disclosure, prohibition on sale, and retention/destruction requirements for biometric identifiers and templates; the notice does not explicitly address these frameworks by name. The FTC may also examine biometric data practices under Section 5 of the FTC Act. The named processors (Snowflake Computing and Amazon Web Services) as recipients of biometric data must be evaluated under GDPR Article 28 processor agreement requirements. 2. GOVERNANCE EXPOSURE: High. The provision authorizes sharing of biometric identifiers with two named third-party cloud providers and retains data for up to 365 days. The clause also contains the phrase "or if our collection of biometric information is otherwise permitted by law," which reserves a non-consent legal basis that is not further specified in the document, creating ambiguity about the conditions under which biometric processing may proceed without explicit consent. 3. JURISDICTION FLAGS: Illinois BIPA creates heightened exposure as it provides a private right of action for violations of its biometric data consent and retention requirements, and the 365-day retention period would need to be evaluated against BIPA's requirement to destroy biometric data when the initial purpose is fulfilled or within three years, whichever is earlier. Texas and Washington state laws impose similar obligations. EU and UK data subjects benefit from GDPR Article 9 explicit consent requirements and the right to withdraw consent. California CPRA classifies biometric data as sensitive personal information subject to additional restrictions. 4. CONTRACT AND VENDOR IMPLICATIONS: The naming of Snowflake Computing and Amazon Web Services as biometric data recipients creates a procurement due diligence trigger: data processing agreements with these vendors should be confirmed to include the required GDPR Article 28 terms, biometric-specific handling obligations, and deletion obligations aligned with the 365-day commitment in this notice. Organizations using Checkout as a payment processor should also assess whether their own privacy notices adequately disclose downstream biometric processing by Checkout. 5. COMPLIANCE CONSIDERATIONS: Legal and compliance teams should verify: (a) whether the consent mechanism for biometric collection satisfies the written informed consent requirements of applicable state biometric laws; (b) whether data processing agreements with Snowflake and AWS are current and include biometric-specific handling terms; (c) whether the 365-day retention period is documented with operational justification supporting data minimization compliance; and (d) whether the non-consent legal basis reserved by the phrase "otherwise permitted by law" is documented with a specific legal basis for each jurisdiction in which it may be invoked.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision names the specific biometric data categories collected, the two third-party cloud processors receiving that data, and establishes a 365-day outer retention limit, each of which are operationally significant parameters for compliance with GDPR, UK GDPR, and US state-level biometric privacy statutes that impose consent, disclosure, and retention requirements.
This provision establishes that Merchant Customers who use Checkout's identity verification services may have facial images, voiceprints, and derived biometric templates collected, shared with Snowflake Computing and Amazon Web Services, and retained for up to 365 days, with processing stated to require explicit consent. The agreement also states that biometric collection may proceed where otherwise permitted by law, independent of …
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Checkout.com.