Provision record
Checkout.com · Checkout.com Privacy · View original document ↗

Dual Controller and Processor Status

Medium severity High confidence Explicit document language Common · 290 of 352 platforms
Stay ahead of the changes
Track Checkout.com and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF
Document Record

What it is

Checkout.com acts as the responsible party for data it collects about merchants directly, but when processing payment data on behalf of merchants, it acts under the merchant's instructions, meaning the merchant bears primary responsibility for cardholder data rights.

This analysis describes what Checkout.com's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This distinction determines who is legally accountable for cardholder data rights requests: if a cardholder wants to exercise GDPR rights over their payment data, they may need to contact the merchant rather than Checkout.com directly for certain processing activities.

Recent Activity

This document changed recently

Medium Jun 19, 2026

The updated policy establishes formal complaint procedures for UK and Australia users, requiring Checkout to acknowledge complaints within 30 days and respond without undue delay. For UK users specifically, the policy clarifies that complaints must first be raised with Checkout before escalating to the Information Commissioner's Office. The policy also discloses that transaction information collection now includes country data alongside currency and amount. For Australia users, the policy clarifies that identity verification is a legal requirement and cannot be provided anonymously or pseudonymously. Users in these jurisdictions can submit data protection complaints through Checkout's designated process and escalate to their respective regulatory authorities if dissatisfied with Checkout's response.

View change record →

Clause Stability Stable

0
Changes
3
Months Monitored
May 11, 2026
First Seen
May 22, 2026
Last Seen
This clause type exists across 5149 other provisions on other platforms.

Consumer impact (what this means for users)

Cardholders whose payment data is processed through Checkout.com may find that their data rights requests need to be directed to the merchant, not Checkout.com, because Checkout.com is acting as a processor in those contexts and the merchant is the data controller.

How other platforms handle this

ZipRecruiter Medium

Where ZipRecruiter processes your Personal Data in the capacity of a service provider (data processor), and you seek access, or want to correct, amend, or delete your Personal Data...we will provide you with the data controller's contact information, so you can contact them directly.

Tinder Medium

If you choose to reveal any personal information about yourself to other users, you do so at your own risk. We strongly encourage you to use caution in disclosing any personal information online.

Skillshare Medium

When you are asked to provide information, you may decline to do so; but if you choose not to provide information that is necessary to provide some of our Services, you may not be able to use those Services.

See all platforms with this clause type →
▸ View Original Clause Language DOCUMENT RECORD
"
Checkout.com acts as a data controller in respect of personal data that we collect about merchants and their representatives, and as a data processor when we process personal data on behalf of our merchant clients in connection with the payment services we provide to them.

Excerpt from Checkout.com's Privacy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1.

Insight

Unlock the full institutional analysis

Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.

Applicable regulations

CCPA/CPRA
California, USA
Connecticut Data Privacy Act Amendments
US-CT
FCRA
United States Federal
FTC Act Section 5
United States Federal
GDPR
European Union
GLBA
United States Federal
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
Checkout.com Privacy
Entity
Checkout.com
Document last updated
May 5, 2026
Tracking information
First tracked
May 8, 2026
Last verified
May 11, 2026
Record ID
CA-P-010384
Document ID
CA-D-00663
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
a644fb34e781c2f85b7f4158747e8b392097069bd33d31e2fe9cda04abdf18be
Analysis generated
May 8, 2026 15:31 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Checkout.com
Document: Checkout.com Privacy
Record ID: CA-P-010384
Captured: 2026-05-08 15:31:40 UTC
SHA-256: a644fb34e781c2f8…
URL: https://conductatlas.com/platform/checkoutcom/checkoutcom-privacy/provision/CA-P-010384/dual-controller-and-processor-status/
Accessed: Aug. 12, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Related Analysis

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does Checkout.com's Dual Controller and Processor Status clause do?

This distinction determines who is legally accountable for cardholder data rights requests: if a cardholder wants to exercise GDPR rights over their payment data, they may need to contact the merchant rather than Checkout.com directly for certain processing activities.

How does this clause affect you?

Cardholders whose payment data is processed through Checkout.com may find that their data rights requests need to be directed to the merchant, not Checkout.com, because Checkout.com is acting as a processor in those contexts and the merchant is the data controller.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.

Is ConductAtlas affiliated with Checkout.com?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Checkout.com.