Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The notice establishes that Checkout acts as a data controller for its own processing activities but may act as a data processor for Merchant Customer data when processing on a Merchant's behalf, directing affected individuals to the Merchant's own privacy notice in processor contexts.
This analysis describes what Checkout.com's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that the accountability and transparency obligations for Merchant Customer data may rest with the Merchant rather than Checkout in certain processing contexts, which has direct implications for where affected individuals must direct data rights requests and complaints.
The updated policy establishes formal complaint procedures for UK and Australia users, requiring Checkout to acknowledge complaints within 30 days and respond without undue delay. For UK users specifically, the policy clarifies that complaints must first be raised with Checkout before escalating to the Information Commissioner's Office. The policy also discloses that transaction information collection now includes country data alongside currency and amount. For Australia users, the policy clarifies that identity verification is a legal requirement and cannot be provided anonymously or pseudonymously. Users in these jurisdictions can submit data protection complaints through Checkout's designated process and escalate to their respective regulatory authorities if dissatisfied with Checkout's response.
View change record →Under these terms, when Checkout processes consumer data on behalf of a Merchant, the Merchant is the data controller and Checkout is the data processor, meaning that data rights requests and privacy complaints in those contexts should be directed to the Merchant rather than to Checkout. The notice directs consumers to consult the Merchant's privacy notice to understand how that data is processed.
Cross-platform context
See how other platforms handle Dual Controller and Processor Role Distinction and similar clauses.
Compare across platforms →Monitoring
Checkout.com has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"This notice applies where Checkout act as a data controller, but we may sometimes operate as a data processor for Merchant Customer data where we carry out instructions and process data on a Merchant's behalf. In these instances, you should refer to the privacy notice of the Merchant for details regarding how they process your information.Excerpt from Checkout.com's Privacy
1. REGULATORY LANDSCAPE: This provision engages the GDPR controller and processor distinction under Articles 4, 24, and 28, and the UK GDPR equivalent. Under these frameworks, the data controller bears primary accountability for lawfulness of processing and data subject rights fulfillment, while the data processor must act only on documented controller instructions. The notice does not specify which processing activities are conducted in a controller capacity versus a processor capacity for Merchant Customer data. 2. GOVERNANCE EXPOSURE: Medium. The controller and processor distinction directly affects where data subject rights obligations are allocated. If a consumer submits a GDPR access or erasure request to Checkout for data Checkout processes as a processor, Checkout's obligations are different from when it acts as a controller, and the routing of that request to the Merchant may delay resolution. 3. JURISDICTION FLAGS: EEA and UK data subjects have GDPR and UK GDPR rights that must be fulfilled by the data controller within defined timelines. The allocation of controller status to Merchants for some Merchant Customer data means that those Merchants bear compliance obligations they may not be aware of or operationally prepared for. 4. CONTRACT AND VENDOR IMPLICATIONS: This provision is a direct contract review trigger for Merchants using Checkout's services. GDPR Article 28 requires a written data processing agreement between the controller (Merchant) and processor (Checkout) covering the subject matter, duration, nature, and purpose of processing, as well as the obligations and rights of the controller. Merchants should confirm that their agreement with Checkout includes GDPR-compliant DPA terms. 5. COMPLIANCE CONSIDERATIONS: Compliance teams at Merchant organizations should review their Checkout service agreements to confirm the existence and adequacy of a GDPR Article 28 data processing agreement. They should also assess whether their own privacy notices adequately disclose Checkout's role as a sub-processor and the categories of Merchant Customer data processed by Checkout on their behalf.
This provision establishes that the accountability and transparency obligations for Merchant Customer data may rest with the Merchant rather than Checkout in certain processing contexts, which has direct implications for where affected individuals must direct data rights requests and complaints.
Under these terms, when Checkout processes consumer data on behalf of a Merchant, the Merchant is the data controller and Checkout is the data processor, meaning that data rights requests and privacy complaints in those contexts should be directed to the Merchant rather than to Checkout. The notice directs consumers to consult the Merchant's privacy notice to understand how that …
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Checkout.com.