Checkout.com · Checkout.com Privacy · View original document ↗

Dual Controller and Processor Role Distinction

Medium severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Checkout.com changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Checkout.com recorded 2 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for Checkout.com Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The notice establishes that Checkout acts as a data controller for its own processing activities but may act as a data processor for Merchant Customer data when processing on a Merchant's behalf, directing affected individuals to the Merchant's own privacy notice in processor contexts.

This analysis describes what Checkout.com's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes that the accountability and transparency obligations for Merchant Customer data may rest with the Merchant rather than Checkout in certain processing contexts, which has direct implications for where affected individuals must direct data rights requests and complaints.

Recent Activity

This document changed recently

Medium Jun 19, 2026

The updated policy establishes formal complaint procedures for UK and Australia users, requiring Checkout to acknowledge complaints within 30 days and respond without undue delay. For UK users specifically, the policy clarifies that complaints must first be raised with Checkout before escalating to the Information Commissioner's Office. The policy also discloses that transaction information collection now includes country data alongside currency and amount. For Australia users, the policy clarifies that identity verification is a legal requirement and cannot be provided anonymously or pseudonymously. Users in these jurisdictions can submit data protection complaints through Checkout's designated process and escalate to their respective regulatory authorities if dissatisfied with Checkout's response.

View change record →

Consumer impact (what this means for users)

Under these terms, when Checkout processes consumer data on behalf of a Merchant, the Merchant is the data controller and Checkout is the data processor, meaning that data rights requests and privacy complaints in those contexts should be directed to the Merchant rather than to Checkout. The notice directs consumers to consult the Merchant's privacy notice to understand how that data is processed.

Cross-platform context

See how other platforms handle Dual Controller and Processor Role Distinction and similar clauses.

Compare across platforms →

Monitoring

Checkout.com has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
This notice applies where Checkout act as a data controller, but we may sometimes operate as a data processor for Merchant Customer data where we carry out instructions and process data on a Merchant's behalf. In these instances, you should refer to the privacy notice of the Merchant for details regarding how they process your information.

Excerpt from Checkout.com's Privacy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: This provision engages the GDPR controller and processor distinction under Articles 4, 24, and 28, and the UK GDPR equivalent. Under these frameworks, the data controller bears primary accountability for lawfulness of processing and data subject rights fulfillment, while the data processor must act only on documented controller instructions. The notice does not specify which processing activities are conducted in a controller capacity versus a processor capacity for Merchant Customer data. 2. GOVERNANCE EXPOSURE: Medium. The controller and processor distinction directly affects where data subject rights obligations are allocated. If a consumer submits a GDPR access or erasure request to Checkout for data Checkout processes as a processor, Checkout's obligations are different from when it acts as a controller, and the routing of that request to the Merchant may delay resolution. 3. JURISDICTION FLAGS: EEA and UK data subjects have GDPR and UK GDPR rights that must be fulfilled by the data controller within defined timelines. The allocation of controller status to Merchants for some Merchant Customer data means that those Merchants bear compliance obligations they may not be aware of or operationally prepared for. 4. CONTRACT AND VENDOR IMPLICATIONS: This provision is a direct contract review trigger for Merchants using Checkout's services. GDPR Article 28 requires a written data processing agreement between the controller (Merchant) and processor (Checkout) covering the subject matter, duration, nature, and purpose of processing, as well as the obligations and rights of the controller. Merchants should confirm that their agreement with Checkout includes GDPR-compliant DPA terms. 5. COMPLIANCE CONSIDERATIONS: Compliance teams at Merchant organizations should review their Checkout service agreements to confirm the existence and adequacy of a GDPR Article 28 data processing agreement. They should also assess whether their own privacy notices adequately disclose Checkout's role as a sub-processor and the categories of Merchant Customer data processed by Checkout on their behalf.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Professional · $99/mo Start with Monitor · $29/mo

Applicable agencies

  • FTC
    The FTC has enforcement authority over consumer privacy practices and transparency obligations that may arise from ambiguous controller and processor role allocations.
    File a complaint →

Provision details

Document information
Document
Checkout.com Privacy
Entity
Checkout.com
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-016117
Document ID
CA-D-00663
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
aabf92a3ffd7ad34135ff9f030ee34d8f733b33feed3b830c2380fe5554a223b
Analysis generated
July 9, 2026 09:37 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Checkout.com
Document: Checkout.com Privacy
Record ID: CA-P-016117
Captured: 2026-07-09 09:37:20 UTC
SHA-256: aabf92a3ffd7ad34…
URL: https://conductatlas.com/platform/checkoutcom/checkoutcom-privacy/provision/CA-P-016117/dual-controller-and-processor-role-distinction/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Professional · $99/mo Start with Monitor · $29/mo

Frequently Asked Questions

What does Checkout.com's Dual Controller and Processor Role Distinction clause do?

This provision establishes that the accountability and transparency obligations for Merchant Customer data may rest with the Merchant rather than Checkout in certain processing contexts, which has direct implications for where affected individuals must direct data rights requests and complaints.

How does this clause affect you?

Under these terms, when Checkout processes consumer data on behalf of a Merchant, the Merchant is the data controller and Checkout is the data processor, meaning that data rights requests and privacy complaints in those contexts should be directed to the Merchant rather than to Checkout. The notice directs consumers to consult the Merchant's privacy notice to understand how that …

Is ConductAtlas affiliated with Checkout.com?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Checkout.com.