Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The notice states that personal data may be transferred internationally to Checkout group companies or third-party service providers, with EU SCC and UK Addendum mechanisms and transfer impact assessments used for transfers from the UK or EEA to countries without an adequacy decision.
This analysis describes what Checkout.com's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes the legal transfer mechanisms Checkout relies on for cross-border data flows from the UK and EEA, and discloses that transfer impact assessments are conducted, which are operationally significant for GDPR and UK GDPR compliance purposes.
The updated policy establishes formal complaint procedures for UK and Australia users, requiring Checkout to acknowledge complaints within 30 days and respond without undue delay. For UK users specifically, the policy clarifies that complaints must first be raised with Checkout before escalating to the Information Commissioner's Office. The policy also discloses that transaction information collection now includes country data alongside currency and amount. For Australia users, the policy clarifies that identity verification is a legal requirement and cannot be provided anonymously or pseudonymously. Users in these jurisdictions can submit data protection complaints through Checkout's designated process and escalate to their respective regulatory authorities if dissatisfied with Checkout's response.
View change record →Under these terms, personal data may be transferred to countries outside a user's home country without equivalent data protection laws, with EU SCCs, UK Addendum clauses, and transfer impact assessments cited as the protective measures applied to UK and EEA data subject transfers.
Cross-platform context
See how other platforms handle International Data Transfers and SCCs and similar clauses.
Compare across platforms →Monitoring
Checkout.com has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Checkout is a global business and in the provision of our services personal data may be transferred to Checkout group companies or third-party service providers located in a different country than your home country. We will implement appropriate measures to ensure that your personal data remains protected and secure when it is transferred, and we will only transfer your personal data in accordance with applicable laws and regulations. Where data is transferred from the UK or EEA to a third country that is not deemed by the EU Commission or UK Secretary of State to have adequate protections in place, we rely on the EU Standard Contractual Clauses (SCCs) or contractual clauses approved by the ICO (such as the UK Addendum to the EU SCCs) respectively, to transfer your data to that third country and ensure it remains secure. We also carry out transfer impact assessments before transferring your personal data, to assess the level of risk to you and your rights and protections in that third country.Excerpt from Checkout.com's Privacy
1. REGULATORY LANDSCAPE: This provision engages GDPR Chapter V (international data transfers), UK GDPR, and the ICO's international transfer framework. The notice references both EU SCCs in their current form (adopted by the European Commission in 2021) and the ICO's UK Addendum, and states that transfer impact assessments are conducted. The adequacy of these mechanisms is subject to ongoing regulatory scrutiny, including the Schrems II judgment framework applied by EEA supervisory authorities. 2. GOVERNANCE EXPOSURE: Medium. The provision discloses the transfer mechanisms used but does not name the third countries to which data is transferred or specify the categories of data involved in each transfer. This limits the ability to assess whether the transfer impact assessments are appropriately calibrated to the risk profile of each destination jurisdiction. 3. JURISDICTION FLAGS: EEA and UK data subjects have the greatest exposure to this provision, as GDPR Chapter V and UK GDPR impose the most stringent requirements on international transfers. Canada's PIPEDA and Brazil's LGPD also impose transfer adequacy requirements for data processed by those entities; the notice's Canada supplement acknowledges that data may be processed outside Canada under potentially lower protections. 4. CONTRACT AND VENDOR IMPLICATIONS: Organizations relying on Checkout as a payment processor should confirm that Checkout's SCC and UK Addendum documentation is available upon request and that the executed agreements align with current regulatory requirements. The statement that transfer impact assessments are conducted creates a documentation obligation; procurement teams may wish to request evidence of those assessments for high-risk transfer destinations. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should verify that Checkout's SCCs reflect the 2021 European Commission SCC module applicable to the controller-processor relationship and that the UK Addendum has been executed in the current ICO-approved form. They should also assess whether transfer impact assessments are documented for each third-country transfer destination and updated in response to changes in the legal landscape of those destinations.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes the legal transfer mechanisms Checkout relies on for cross-border data flows from the UK and EEA, and discloses that transfer impact assessments are conducted, which are operationally significant for GDPR and UK GDPR compliance purposes.
Under these terms, personal data may be transferred to countries outside a user's home country without equivalent data protection laws, with EU SCCs, UK Addendum clauses, and transfer impact assessments cited as the protective measures applied to UK and EEA data subject transfers.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Checkout.com.