Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The notice establishes a set of data subject rights including access, correction, erasure, processing restriction, objection, consent withdrawal, and objection to automated decision-making, all exercisable by contacting dpo@checkout.com, with the notice qualifying that availability of these rights depends on jurisdiction and that erasure may be declined where legal retention obligations apply.
This analysis describes what Checkout.com's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes the operative mechanism for individuals to exercise data subject rights and qualifies the scope of those rights by jurisdiction and by Checkout's legal retention obligations, which are relevant parameters for compliance teams assessing the practical scope of data subject access and erasure requests.
The updated policy establishes formal complaint procedures for UK and Australia users, requiring Checkout to acknowledge complaints within 30 days and respond without undue delay. For UK users specifically, the policy clarifies that complaints must first be raised with Checkout before escalating to the Information Commissioner's Office. The policy also discloses that transaction information collection now includes country data alongside currency and amount. For Australia users, the policy clarifies that identity verification is a legal requirement and cannot be provided anonymously or pseudonymously. Users in these jurisdictions can submit data protection complaints through Checkout's designated process and escalate to their respective regulatory authorities if dissatisfied with Checkout's response.
View change record →The agreement establishes that data subject rights including access, erasure, correction, and objection to automated processing are exercisable by contacting dpo@checkout.com, with the notice stating that erasure requests may be declined where Checkout has legal retention obligations. Jurisdiction determines which specific rights are available to a given individual.
Cross-platform context
See how other platforms handle Data Subject Rights and Contact Mechanism and similar clauses.
Compare across platforms →Monitoring
Checkout.com has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Depending on your jurisdiction, you have rights and choices over the way your information is used by us: Right to opt-out of direct marketing communications: This enables you to opt-out of receiving marketing communications from us. You can do this at any time by clicking on the 'unsubscribe' link included in any email marketing material we send to you, or by informing us by emailing dpo@checkout.com. Right to request access to your personal data: This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it. In some cases, you have a right to receive a copy of this information in a reusable format and have it transmitted to another organisation. Right to request erasure of your personal data: This enables you to ask us to delete or remove your personal data. Please note that in some cases, for example if we need to retain your data to comply with legal obligations, we may be unable to comply with such requests.Excerpt from Checkout.com's Privacy
1. REGULATORY LANDSCAPE: This provision engages GDPR Articles 15 through 22 (data subject rights), UK GDPR, CCPA and CPRA for California residents, the Colorado Privacy Act, Australian Privacy Principles, and Brazil's LGPD. Each framework imposes different timelines, response obligations, and scope of rights. GDPR requires responses to access requests within one month, with a possible two-month extension. The ICO enforces UK GDPR data subject rights for UK residents. 2. GOVERNANCE EXPOSURE: Medium. The provision routes all rights requests through a single email address (dpo@checkout.com) without describing the internal triage or response process, which may be a transparency gap under GDPR transparency requirements. The carve-out for erasure requests where legal retention obligations apply is standard but requires documented retention schedules to substantiate. 3. JURISDICTION FLAGS: EU and UK data subjects have the most comprehensive suite of rights under GDPR and UK GDPR, including data portability under Article 20. California residents have CPRA-specific rights including correction and the right to limit use of sensitive personal information. The notice qualifies rights as jurisdiction-dependent, which means consumers in jurisdictions without comprehensive privacy laws may have fewer enforceable rights. 4. CONTRACT AND VENDOR IMPLICATIONS: Merchants using Checkout as a processor should confirm that their data processing agreements with Checkout include obligations for Checkout to assist with data subject rights requests received by the Merchant under GDPR Article 28, as the notice acknowledges that Checkout sometimes acts as a data processor for Merchant Customer data. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should verify that the dpo@checkout.com inbox is operationally staffed to meet applicable response timelines (one month under GDPR, 45 days under CCPA), that identity verification procedures for rights requests are documented and do not create disproportionate barriers, and that the retention schedule used to evaluate erasure request exemptions is current and defensible.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes the operative mechanism for individuals to exercise data subject rights and qualifies the scope of those rights by jurisdiction and by Checkout's legal retention obligations, which are relevant parameters for compliance teams assessing the practical scope of data subject access and erasure requests.
The agreement establishes that data subject rights including access, erasure, correction, and objection to automated processing are exercisable by contacting dpo@checkout.com, with the notice stating that erasure requests may be declined where Checkout has legal retention obligations. Jurisdiction determines which specific rights are available to a given individual.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Checkout.com.