Checkout.com · Checkout.com Privacy · View original document ↗

Data Subject Rights

Low severity High confidence Explicitdocumentlanguage Rare · 3 of 343 platforms
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Checkout.com Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

Depending on where you live, you may have the right to see, correct, delete, or export your personal data held by Checkout.com, and you can exercise these rights by emailing their Data Protection Officer.

This analysis describes what Checkout.com's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

These rights are the primary mechanism by which individuals can control their personal data held by Checkout.com, and knowing the contact point and applicable rights is essential to exercising them effectively.

Consumer impact (what this means for users)

EU and UK users have the broadest data rights under GDPR, including erasure and portability, while California residents have CCPA rights; the single contact point dpo@checkout.com is provided for all rights requests, and the response must be provided within statutory timeframes under applicable law.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Export Your Data
    Email dpo@checkout.com stating your identity and the specific right you wish to exercise (access, deletion, portability, or correction). Include sufficient identifying information for Checkout.com to locate your records.
  • Delete Your Data
    Email dpo@checkout.com requesting erasure of your personal data, specifying the categories of data you want deleted and the basis for your request under applicable law.

How other platforms handle this

Garmin Medium

If you are located in the European Economic Area, Switzerland, or the United Kingdom, you have the right to access, correct, or erase your personal data; the right to restrict or object to our processing of your personal data; the right to data portability; and, where our processing is based on your...

Ledger Medium

At Ledger, earning and maintaining our users' trust is a top priority. That's why we are deeply committed not only to protecting your privacy and securing your personal data, but also to being fully transparent about how we handle it.

Strava Medium

We use information to enhance the quality, reliability, and/or accuracy of our AI Features by creating, developing, training, testing, improving, and maintaining AI and ML models run by Strava or our service providers. We use aggregated, de-identified data for this purpose. We also use personal info...

See all platforms with this clause type →

Monitoring

Checkout.com has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Depending on your location and subject to applicable law, you may have the right to: access your personal data; rectify inaccurate personal data; request erasure of your personal data; restrict or object to processing; data portability; and not be subject to automated decision-making. To exercise any of these rights, please contact our Data Protection Officer at dpo@checkout.com.

— Excerpt from Checkout.com's Checkout.com Privacy

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

1. REGULATORY LANDSCAPE: Data subject rights engage GDPR Articles 15-22 and UK GDPR equivalents for EU/UK users, CCPA/CPRA for California residents, and applicable national or state privacy laws for other jurisdictions. GDPR requires responses to access requests within one month, with a two-month extension available. The ICO and EU national supervisory authorities enforce GDPR rights obligations. The California Privacy Protection Agency (CPPA) enforces CCPA/CPRA. 2. GOVERNANCE EXPOSURE: Medium. The single DPO contact point simplifies consumer-facing rights management but requires robust backend procedures to route, triage, and respond to requests within statutory deadlines across multiple jurisdictions with differing timeframes and scope. Failure to respond within GDPR timeframes can result in supervisory authority complaints and enforcement. 3. JURISDICTION FLAGS: EU and UK users have the most comprehensive rights including erasure, portability, and objection to legitimate interests processing. California residents have CCPA rights to know, delete, correct, and opt out of sale/sharing. Users in other jurisdictions may have more limited rights depending on local law. The policy's qualification 'depending on your location and subject to applicable law' appropriately reflects this variance but may create consumer confusion. 4. CONTRACT AND VENDOR IMPLICATIONS: Merchants acting as data controllers for cardholder data must have procedures to route data subject requests to Checkout.com as processor, and their DPAs should specify Checkout.com's obligations to assist with rights requests under GDPR Article 28(3)(e). Response timelines and cooperation obligations should be contractually specified. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should verify that the DPO function is properly resourced and that intake, triage, and response workflows meet statutory deadlines. Identity verification procedures for rights requests should be proportionate and not create unnecessary barriers. The automated decision-making right (Article 22) should have a specific human review workflow documented separately.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Monitor free for 14 days

Free: track 1 platform + weekly digest. Monitor: 25 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    The FTC has authority over unfair or deceptive practices in consumer data handling, including failure to honor stated privacy rights, relevant to US users.
    File a complaint →
  • State AG
    State Attorneys General enforce state privacy laws including CCPA/CPRA for California residents and equivalent laws in other states with data subject rights provisions.
    File a complaint →

Applicable regulations

CCPA/CPRA
California, USA
Connecticut Data Privacy Act Amendments
US-CT
FCRA
United States Federal
FTC Act Section 5
United States Federal
GDPR
European Union
GLBA
United States Federal
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
Checkout.com Privacy
Entity
Checkout.com
Document last updated
May 5, 2026
Tracking information
First tracked
May 8, 2026
Last verified
May 11, 2026
Record ID
CA-P-010386
Document ID
CA-D-00663
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
a644fb34e781c2f85b7f4158747e8b392097069bd33d31e2fe9cda04abdf18be
Analysis generated
May 8, 2026 15:31 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Checkout.com
Document: Checkout.com Privacy
Record ID: CA-P-010386
Captured: 2026-05-08 15:31:40 UTC
SHA-256: a644fb34e781c2f8…
URL: https://conductatlas.com/platform/checkoutcom/checkoutcom-privacy/data-subject-rights/
Accessed: June 27, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Low
Categories

Other risks in this policy

Related Analysis

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Compliance free trial

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Checkout.com's Data Subject Rights clause do?

These rights are the primary mechanism by which individuals can control their personal data held by Checkout.com, and knowing the contact point and applicable rights is essential to exercising them effectively.

How does this clause affect you?

EU and UK users have the broadest data rights under GDPR, including erasure and portability, while California residents have CCPA rights; the single contact point dpo@checkout.com is provided for all rights requests, and the response must be provided within statutory timeframes under applicable law.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 3 platforms. See the full comparison.

Is ConductAtlas affiliated with Checkout.com?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Checkout.com.