The notice establishes that Checkout acts as a data controller for its own processing activities but may act as a data processor for Merchant Customer data when processing on a Merchant's behalf, directing affected individuals to the Merchant's own privacy notice in processor contexts.
This analysis describes what Checkout.com's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that the accountability and transparency obligations for Merchant Customer data may rest with the Merchant rather than Checkout in certain processing contexts, which has direct implications for where affected individuals must direct data rights requests and complaints.
The updated policy establishes formal complaint procedures for UK and Australia users, requiring Checkout to acknowledge complaints within 30 days and respond without undue delay. For UK users specifically, the policy clarifies that complaints must first be raised with Checkout before escalating to the Information Commissioner's Office. The policy also discloses that transaction information collection now includes country data alongside currency and amount. For Australia users, the policy clarifies that identity verification is a legal requirement and cannot be provided anonymously or pseudonymously. Users in these jurisdictions can submit data protection complaints through Checkout's designated process and escalate to their respective regulatory authorities if dissatisfied with Checkout's response.
View change record →Under these terms, when Checkout processes consumer data on behalf of a Merchant, the Merchant is the data controller and Checkout is the data processor, meaning that data rights requests and privacy complaints in those contexts should be directed to the Merchant rather than to Checkout. The notice directs consumers to consult the Merchant's privacy notice to understand how that data is processed.
Cross-platform context
See how other platforms handle Dual Controller and Processor Role Distinction and similar clauses.
Compare across platforms →"This notice applies where Checkout act as a data controller, but we may sometimes operate as a data processor for Merchant Customer data where we carry out instructions and process data on a Merchant's behalf. In these instances, you should refer to the privacy notice of the Merchant for details regarding how they process your information.Excerpt from Checkout.com's Privacy
1.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes that the accountability and transparency obligations for Merchant Customer data may rest with the Merchant rather than Checkout in certain processing contexts, which has direct implications for where affected individuals must direct data rights requests and complaints.
Under these terms, when Checkout processes consumer data on behalf of a Merchant, the Merchant is the data controller and Checkout is the data processor, meaning that data rights requests and privacy complaints in those contexts should be directed to the Merchant rather than to Checkout. The notice directs consumers to consult the Merchant's privacy notice to understand how that …
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Checkout.com.