Checkout.com · Checkout.com Privacy · View original document ↗

Automated Decision-Making for Fraud and Identity Verification

High severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Checkout.com changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Checkout.com recorded 2 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for Checkout.com Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The notice discloses that automated systems may process Merchant Customer data to make fraud detection decisions (potentially declining transactions) and identity verification decisions (potentially delaying or denying product or service access), with affected individuals in certain jurisdictions having the right to request human review of those decisions.

This analysis describes what Checkout.com's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes that automated processing may directly affect a consumer's ability to complete a transaction or access a service, and the right to request human review is stated to be jurisdiction-dependent, meaning not all affected individuals have the same recourse.

Interpretive note: The right to request human review is stated as jurisdiction-dependent and the notice does not specify which jurisdictions trigger that right, creating ambiguity for users outside the EU, UK, California, and Colorado.

Recent Activity

This document changed recently

Medium Jun 19, 2026

The updated policy establishes formal complaint procedures for UK and Australia users, requiring Checkout to acknowledge complaints within 30 days and respond without undue delay. For UK users specifically, the policy clarifies that complaints must first be raised with Checkout before escalating to the Information Commissioner's Office. The policy also discloses that transaction information collection now includes country data alongside currency and amount. For Australia users, the policy clarifies that identity verification is a legal requirement and cannot be provided anonymously or pseudonymously. Users in these jurisdictions can submit data protection complaints through Checkout's designated process and escalate to their respective regulatory authorities if dissatisfied with Checkout's response.

View change record →

Consumer impact (what this means for users)

Under these terms, transactions initiated through Merchants using Checkout's fraud detection services may be declined by automated systems without prior human review, and identity verification outcomes may delay or deny access to products or services. The agreement states that individuals in certain jurisdictions may request human intervention in automated decisions by contacting dpo@checkout.com.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Email dpo@checkout.com to exercise the right to object to automated decision-making and request human review of a specific automated decision that affected your transaction or service access.

Cross-platform context

See how other platforms handle Automated Decision-Making for Fraud and Identity Verification and similar clauses.

Compare across platforms →

Monitoring

Checkout.com has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
In the course of providing our services, we may make decisions using your personal data which are partially or wholly automated to help make our decisions and services secure and efficient. We use automated decision-making in the following circumstances: -Fraud detection: Where you are a Merchant Customer and you initiate a transaction with a Merchant that uses our fraud detection services, your information may be processed by Checkout for the purposes of fraud detection and prevention. In some cases, this may lead to an automated decision for a transaction to be declined or for further information to be requested from you in order to proceed. -Identity verification: Where you are a Merchant Representative or Merchant Customer and we ask you to provide identity information to sign up to one of our services, or you use our identity verification product, the information you provide may be subject to partially or wholly automated decisions as to whether we are able to verify your identity. In the event we are unable to effectively verify your identity, this could have the impact of delaying or denying you access to a product or service operated by Checkout or one of our Merchants.

Excerpt from Checkout.com's Privacy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: This provision directly engages GDPR Article 22, which establishes the right not to be subject to solely automated decisions producing legal or similarly significant effects, subject to specified exceptions. UK GDPR contains equivalent provisions. The notice acknowledges a right to object to automated decisions and request human review, but qualifies this right as jurisdiction-dependent rather than universal. CPRA and the Colorado Privacy Act also establish rights regarding automated decision-making and profiling that may apply to California and Colorado residents respectively. 2. GOVERNANCE EXPOSURE: High. The provision discloses that automated decisions may result in transaction declines and service denials, which are outcomes with significant operational consequences for affected individuals. The notice does not provide detail on the logic, significance, or envisaged consequences of the automated processing as required by GDPR Article 13 and 14, which may be a transparency gap. 3. JURISDICTION FLAGS: EEA and UK data subjects have a qualified right under GDPR and UK GDPR Article 22 to not be subject to solely automated decisions with significant effects, unless exceptions apply (contract necessity, legal authorization, or explicit consent). California residents have CPRA rights regarding automated decision-making. The notice's statement that human review rights are jurisdiction-dependent means that consumers in jurisdictions without explicit statutory rights may have no contractual remedy for automated service denials. 4. CONTRACT AND VENDOR IMPLICATIONS: Merchants integrating Checkout's fraud detection and identity verification services should assess whether their own customer-facing disclosures adequately address the automated decision-making that may affect their customers' transactions, as the notice states that Checkout may act as a data processor for Merchant Customer data in some instances, placing disclosure obligations on the Merchant. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should evaluate whether the automated decision-making disclosures satisfy GDPR Articles 13, 14, and 22 transparency requirements, including meaningful information about the logic involved and the significance of outcomes. They should also confirm that the human review mechanism described in the notice is operationally implemented and accessible to users who exercise the right, and that the 96-hour image-hash block described elsewhere in the notice is appropriately disclosed as an automated process.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Get same-day alerts when this changes → Get Analyst

Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.

Applicable agencies

  • FTC
    The FTC has enforcement authority over unfair or deceptive practices related to automated consumer decision-making systems under Section 5 of the FTC Act.
    File a complaint →
  • State AG
    State attorneys general in California and Colorado have enforcement authority over automated decision-making rights established under CPRA and the Colorado Privacy Act.
    File a complaint →

Provision details

Document information
Document
Checkout.com Privacy
Entity
Checkout.com
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-016111
Document ID
CA-D-00663
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
aabf92a3ffd7ad34135ff9f030ee34d8f733b33feed3b830c2380fe5554a223b
Analysis generated
July 9, 2026 09:37 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Checkout.com
Document: Checkout.com Privacy
Record ID: CA-P-016111
Captured: 2026-07-09 09:37:20 UTC
SHA-256: aabf92a3ffd7ad34…
URL: https://conductatlas.com/platform/checkoutcom/checkoutcom-privacy/provision/CA-P-016111/automated-decision-making-for-fraud-and-identity-verification/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Get Compliance

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Checkout.com's Automated Decision-Making for Fraud and Identity Verification clause do?

This provision establishes that automated processing may directly affect a consumer's ability to complete a transaction or access a service, and the right to request human review is stated to be jurisdiction-dependent, meaning not all affected individuals have the same recourse.

How does this clause affect you?

Under these terms, transactions initiated through Merchants using Checkout's fraud detection services may be declined by automated systems without prior human review, and identity verification outcomes may delay or deny access to products or services. The agreement states that individuals in certain jurisdictions may request human intervention in automated decisions by contacting dpo@checkout.com.

Is ConductAtlas affiliated with Checkout.com?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Checkout.com.