Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The notice discloses that personal data may be shared with Checkout group affiliates, third-party service providers covering a range of functions including advertising networks and background screening, and payment ecosystem partners including banks, card schemes, alternative payment method providers, and issuers.
This analysis describes what Checkout.com's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision identifies the categories of third-party recipients of personal data and notably includes advertising networks and background screening companies among the service provider categories, which are operationally distinct from the core payment processing function and may engage additional regulatory considerations.
The updated policy establishes formal complaint procedures for UK and Australia users, requiring Checkout to acknowledge complaints within 30 days and respond without undue delay. For UK users specifically, the policy clarifies that complaints must first be raised with Checkout before escalating to the Information Commissioner's Office. The policy also discloses that transaction information collection now includes country data alongside currency and amount. For Australia users, the policy clarifies that identity verification is a legal requirement and cannot be provided anonymously or pseudonymously. Users in these jurisdictions can submit data protection complaints through Checkout's designated process and escalate to their respective regulatory authorities if dissatisfied with Checkout's response.
View change record →Under these terms, personal data may be shared with a broad set of third parties including Checkout group affiliates, advertising networks, background screening companies, data and cloud services providers, and payment ecosystem partners such as banks and card schemes. The notice does not identify the specific third parties in each category beyond the named biometric processors.
Cross-platform context
See how other platforms handle Third-Party Data Sharing with Payment Partners and Service Providers and similar clauses.
Compare across platforms →Monitoring
Checkout.com has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"In order to provide our services to you we may share your personal data with the following parties: Members of the Checkout Group: Your information may be shared with our affiliates within the Checkout.com group, to provide you with our services. Third party service providers: We may also use third-party service providers acting on our behalf. These service providers help us with data and cloud services, website hosting, data analysis, background screening, fraud detection and prevention, application services, advertising networks, information technology and related infrastructure, customer service, communications, and auditing. Payment partners: We may share your personal data with third parties across the payments ecosystem as necessary to securely and effectively process payments. This includes banks, card schemes, alternative payment method providers and issuers.Excerpt from Checkout.com's Privacy
1. REGULATORY LANDSCAPE: This provision engages GDPR Articles 13 and 14 (disclosure of recipients or categories of recipients), UK GDPR, CCPA and CPRA (which require disclosure of categories of third parties with whom personal information is shared), and applicable payment industry regulations including PCI DSS for cardholder data sharing with payment partners. The inclusion of advertising networks as a service provider category may engage CPRA's cross-context behavioral advertising restrictions for California residents. 2. GOVERNANCE EXPOSURE: Medium. The provision uses category-level disclosure rather than naming specific third parties, with the exception of Snowflake and AWS in the biometric section. GDPR and CPRA permit category-level disclosure but require sufficient specificity to be meaningful. The inclusion of background screening companies as recipients of personal data is operationally significant for Merchant Representatives who submit identity and financial information during onboarding. 3. JURISDICTION FLAGS: California residents are entitled under CPRA to a list of specific categories of personal information shared with each category of third party. EEA and UK data subjects may request information about specific recipients under GDPR Articles 15 and 13. The breadth of the service provider list, particularly the inclusion of advertising networks, is relevant to any jurisdiction with opt-out rights for targeted advertising. 4. CONTRACT AND VENDOR IMPLICATIONS: The disclosure that payment partners include banks, card schemes, alternative payment method providers, and issuers means that Merchant Customer transaction data flows through a multi-party payment chain. Organizations assessing Checkout as a vendor should map this data flow against their own data protection impact assessments and supply chain due diligence requirements. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should confirm that data sharing agreements with advertising network partners include appropriate data processing terms, particularly given that advertising networks typically engage in cross-context profiling. They should also verify that background screening service providers are operating under appropriate data processing agreements and that the personal data categories shared with them are limited to what is necessary for the stated KYC and KYB purposes.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision identifies the categories of third-party recipients of personal data and notably includes advertising networks and background screening companies among the service provider categories, which are operationally distinct from the core payment processing function and may engage additional regulatory considerations.
Under these terms, personal data may be shared with a broad set of third parties including Checkout group affiliates, advertising networks, background screening companies, data and cloud services providers, and payment ecosystem partners such as banks and card schemes. The notice does not identify the specific third parties in each category beyond the named biometric processors.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Checkout.com.