GDPR – Data Protection Gets Serious
GDPR and Payment Data: What Online Merchants Need to Know
GDPR has fundamentally changed how businesses collect, process, store and share personal data. For online merchants, this includes much of the information handled during a payment transaction.
The impact of GDPR on payments goes beyond the privacy policy. Merchants need to consider what information they collect at checkout, which payment providers and other suppliers process that information, how long data is retained, how stored payment credentials are handled, and how payment-related data is used for purposes beyond completing a transaction.
For merchants operating across multiple markets, these considerations become particularly important as payment methods, data-protection requirements and local rules can differ between countries.
What is GDPR?
The General Data Protection Regulation (GDPR) is the European Union’s framework for protecting personal data and regulating how organisations process information relating to individuals. It has applied since 25 May 2018.
GDPR establishes principles governing the collection and processing of personal data and gives individuals a range of rights concerning information held about them.
For online merchants, GDPR can apply to data collected throughout the customer journey, including information collected during account creation, checkout, payment, fraud screening, customer service and post-transaction processes.
Why GDPR matters for payment operations
A payment transaction can involve several different organisations.
Depending on the merchant’s setup, personal data may pass between the merchant, payment service provider, acquirer, payment method provider, fraud-prevention provider, tokenisation service, subscription platform and other technology providers.
The payment page may contain several categories of personal information, including:
Name and other identifying information
Billing and delivery addresses
Payment instrument information
Account or customer identifiers
Transaction information
Information used for fraud and risk assessment
The merchant therefore needs to understand not only what data it collects, but also who processes that data and for what purpose.
Data minimisation on the payment page
One of the practical GDPR principles particularly relevant to online payments is data minimisation.
Merchants should collect only the personal information that is necessary for the relevant purpose.
For example, a merchant should consider whether a particular piece of information is genuinely required to:
Complete and authorise the transaction
Deliver the goods or service
Meet a legal or accounting requirement
Prevent fraud or manage payment risk
Provide a service specifically requested by the customer
Collecting additional information simply because it might be useful in the future creates additional privacy and security responsibilities.
This is also relevant to checkout conversion. Reducing unnecessary fields can make the payment experience simpler while simultaneously reducing the amount of personal data that the merchant needs to manage.
Merchant, payment provider and data-processing responsibilities
Payment transactions frequently involve third-party payment providers.
A merchant may, for example, redirect a customer to a hosted payment page, embed a payment form supplied by a PSP, or use tokenisation so that sensitive payment credentials are handled by a payment provider rather than stored directly by the merchant.
This can reduce the merchant’s direct exposure to payment data, but it does not automatically remove the merchant’s GDPR responsibilities.
The merchant should understand:
What personal data the provider receives
Why the provider processes that data
Where the data is processed
How long the provider retains it
Whether the provider uses additional processors
What security measures are applied
How data-subject requests and deletion requests are handled
What happens when the merchant terminates the relationship
Where a third party processes personal data on the merchant’s behalf, the contractual and data-protection arrangements between the parties should be properly documented.
Lawful basis for processing payment data
GDPR requires organisations to have a lawful basis for processing personal data.
Consent is only one possible lawful basis. Depending on the circumstances, payment-related processing may instead be necessary for the performance of a contract, required by law, or justified under another applicable lawful basis.
This distinction is important because processing necessary to complete a customer’s purchase should not automatically be treated as marketing consent.
A merchant may need to process personal data to fulfil an order and complete a payment while separately needing a different lawful basis for sending marketing communications or using customer information for other purposes.
The purpose of the processing therefore matters.
Payment data and consent
A merchant should distinguish between information required to complete a transaction and information collected for optional purposes.
For example, information required to process a purchase is fundamentally different from information collected to build a marketing profile or send promotional communications.
Similarly, storing payment credentials for future purchases, subscriptions or one-click checkout needs to be considered separately from the processing required to complete the current transaction.
The exact legal requirements can depend on the processing activity, the payment arrangement and applicable national rules. Merchants should therefore avoid treating all payment-data processing as if it had the same GDPR basis.
Stored cards and recurring payments
Stored payment credentials can improve the customer experience and support recurring payments, subscriptions and one-click checkout.
However, storing or reusing payment information creates an additional data-processing consideration.
Merchants should understand:
What information is actually stored
Whether the merchant or PSP stores the information
Whether payment credentials are tokenised
What the token can be used for
How customers can manage or remove stored payment credentials
How long the information is retained
What happens when the customer relationship ends
Where payment credentials are stored by a PSP rather than the merchant, the merchant should still understand the provider’s data-processing and retention practices.
Data retention
GDPR requires organisations to consider how long personal data needs to be retained.
For payment operations, there may be several competing requirements.
A merchant may need transaction information for accounting, tax, fraud management, chargeback handling, customer-service purposes or legal obligations. Other information may no longer be necessary once its original purpose has ended.
There is therefore no universal rule that all payment-related personal data should be deleted immediately after a transaction.
Instead, merchants should identify the purposes for which different categories of data are retained and establish appropriate retention periods.
Data security
Payment-related personal data needs appropriate technical and organisational protection.
Using a reputable payment provider, tokenisation and secure payment infrastructure can reduce the amount of sensitive information handled directly by the merchant, but merchants remain responsible for understanding how their payment environment works.
Security considerations should include:
Encryption and secure transmission
Access controls
Authentication
Tokenisation where appropriate
Secure storage
Supplier security
Monitoring and incident management
Procedures for responding to data breaches
The payment environment should be considered as part of the merchant’s broader data-protection framework rather than as a completely separate system.
Data breaches
A personal-data breach can occur when information is accidentally or unlawfully destroyed, lost, altered, disclosed or accessed without authorisation.
Merchants should have procedures for identifying and responding to potential breaches involving payment-related personal data.
This includes understanding which payment providers and other suppliers need to be notified, how incidents are escalated and what information needs to be documented.
Where a supplier processes data on behalf of the merchant, contractual arrangements should clearly address responsibilities for security incidents and breach notifications.
Data Processing Agreements with payment suppliers
Merchants commonly rely on multiple third parties to operate their payment infrastructure.
These can include:
Payment service providers
Acquirers
Fraud-prevention providers
Subscription platforms
Analytics providers
Customer-service platforms
Tokenisation providers
Where these suppliers process personal data on the merchant’s behalf, the merchant should ensure that appropriate contractual arrangements are in place.
Due diligence should also extend beyond simply signing a data-processing agreement. Merchants should understand what services the supplier actually provides, which other parties may process the data, where processing takes place and how the supplier handles security, retention and data-subject requests.
Privacy by design
Privacy should be considered when payment processes are designed rather than added afterwards.
For example, a merchant launching a new payment method should consider from the beginning:
What personal data the payment method requires
Which parties will receive the data
Whether all collected information is necessary
Whether payment credentials can be tokenised
How long the information needs to be retained
How customers can exercise their data rights
What happens if the payment provider is replaced
This approach can make future changes to payment infrastructure easier because data-processing requirements are considered as part of the architecture.
GDPR and international payment expansion
GDPR becomes particularly relevant when merchants expand into new markets.
A merchant may introduce new payment methods, acquire customers in additional countries, use local payment providers or transfer personal data across borders.
Before entering a new market, merchants should therefore understand:
Local payment requirements
Data-processing requirements
Payment-provider responsibilities
International data transfers
Local retention requirements
Customer-data rights
Local marketing and consent requirements
Payment expansion is not simply a matter of adding another payment method. The associated data flows and responsibilities should also be mapped.
GDPR and payment optimisation
Privacy and payment optimisation are sometimes treated as separate subjects, but they can overlap.
Reducing unnecessary checkout fields can improve the customer experience while reducing unnecessary data collection.
Using tokenisation can support stored-card and recurring-payment functionality while reducing the amount of payment information held directly by the merchant.
Selecting payment providers with appropriate security, data-processing and reporting capabilities can also simplify the merchant’s operational responsibilities.
The objective is not simply to collect less data. It is to design payment processes in which the data collected is appropriate for the purpose for which it is being processed.
What should online merchants review?
A practical review of payment-related GDPR compliance should include:
1. Map the data flows
Identify what personal data is collected during checkout and which organisations receive it.
2. Review the payment page
Check whether every requested field is genuinely necessary for the stated purpose.
3. Review payment providers
Understand what each PSP and payment supplier processes, where the data is processed and how long it is retained.
4. Review contractual arrangements
Ensure appropriate data-processing arrangements are in place with relevant suppliers.
5. Review stored payment information
Understand where payment credentials or tokens are stored and how they are used for future transactions.
6. Review retention
Establish why different categories of payment-related information are retained and for how long.
7. Separate transaction processing from marketing
Make sure information required to complete a payment is not automatically treated as permission for unrelated marketing activities.
8. Review international operations
When expanding into new markets, assess the additional payment and data-protection requirements associated with the new market.
GDPR and payment providers
The payment provider is an important part of the merchant’s overall data-protection environment.
When selecting or reviewing a PSP, merchants should consider more than pricing and payment acceptance rates.
Relevant questions include:
What data does the provider process?
Where is that data processed?
Does the provider use sub-processors?
How long is information retained?
How is payment information protected?
How are data-subject requests handled?
What happens to data when the relationship ends?
How does the provider support the merchant’s regulatory and operational requirements?
These questions become increasingly important as merchants operate across multiple markets and payment methods.
Gropay and GDPR-related payment services
Gropay helps online merchants evaluate and optimise their payment infrastructure, including payment providers, payment methods, transaction flows and international payment operations.
GDPR should be considered alongside payment architecture rather than as an isolated legal requirement. Understanding how personal data moves through the payment ecosystem can help merchants make better decisions when selecting payment providers and designing payment processes.
Frequently asked questions
Does GDPR apply to payment data?
Yes. Payment operations can involve personal data and therefore fall within the scope of GDPR where the relevant conditions for GDPR applicability are met.
Do merchants need consent to process a payment?
Not necessarily. Consent is only one possible lawful basis under GDPR. Processing necessary to fulfil a contract or comply with a legal obligation may rely on another lawful basis, depending on the circumstances.
Does using a PSP remove the merchant’s GDPR responsibilities?
No. Using a third-party payment provider may change which organisation processes particular data, but the merchant still needs to understand its own responsibilities and the contractual and operational relationship with the provider.
Can merchants store customer payment information?
Payment credentials and related information can be stored or tokenised for appropriate purposes, but merchants need to understand the relevant data-protection, payment-security and applicable national requirements.
How long should payment data be retained?
There is no single retention period that applies to every category of payment-related information. Merchants should establish retention periods based on the purposes for which information is processed and applicable legal obligations.
Does GDPR apply when a merchant expands outside the EU?
Potentially. The application of GDPR depends on factors including the merchant’s activities and the circumstances of the processing. International expansion should therefore include a review of the relevant data-protection requirements and cross-border data flows.
Conclusion
GDPR has important implications for online payment operations.
Merchants should understand what information they collect, why they collect it, which payment providers and other suppliers process it, where it is stored, how long it is retained and how it is used.
A well-designed payment operation can reduce unnecessary data collection while providing customers with a secure and efficient checkout experience.
For merchants expanding internationally or reviewing their payment infrastructure, GDPR should therefore be considered as part of the wider payment strategy rather than as a separate compliance exercise.
YOU MIGHT ALSO LIKE
Credential-on-File Payments: How Recurring and Stored-Card Transactions Work
Credential-on-file payments enable merchants to securely process recurring and stored-card transactions. Learn how COF, merchant-initiated transactions and SCA affect recurring payment performance
Payment Authorisation Rates: What They Mean and How Merchants Can Improve Them
For online merchants, every payment that fails at checkout represents a potential lost sale. Yet many businesses monitor overall conversion without looking closely enough at what happens inside the payment process. A customer can reach the checkout, enter valid payment details and still fail to complete the purchase because the transaction is declined, challenged, routed incorrectly or affected by a payment provider issue.
UK Cross-Border Interchange Fees: What Merchants Need to Know in 2025
If your business sells between the UK and the European Economic Area (EEA), there’s a regulatory change in motion that could directly impact your UK cross-border interchange fees in 2025.
How to address human bias when building out automated AML programs
How to address human bias when building out automated AML programs In a previous post we wrote about the value of automating UBO identification as part of regulated entities managing their AML and KYC / DD processes. Compliance departments at regulated entities...
Ultimate Beneficial Owner (UBO) identification important, increasingly complex, requires integrated data solutions and automation
Ultimate Beneficial Owner (UBO) identification important, increasingly complex, requires integrated data solutions and automation Identifying UBOs is important but costly for Regulated Entities Identifying and verifying UBOs is essential for regulated entities...
India’s online shopping sector is currently worth 44 billion, expected to grow by 26.5 % annually
India’s online shopping sector is currently worth 44 billion, expected to grow by 26.5 % annually India’s e-commerce market is rapidly growing and there is considerable room for development. From access to the internet to innovation in its online payment methods....
Improving online conversion on the payments page can save billions
Improving payment page conversion can save billions Online conversion rates range between 1% and 4% according to Industry Insights from Salesforce. With around $400 billion being spent on digital advertising globally it’s clear that even small improvements to online...
Chinese e-commerce market expected to reach US$3 trillion in 2024
China e-commerce market expected to grow to US$ 3 trillion by 2024 China is the largest e-commerce market in the world, it is estimated to reach US $3 trillion in 2024 with a compounded annual growth rate of over 12.4%. According to China’s General...
ASSAULT AGAINST DATA BROKERS LAUNCHED BY PRIVACY INTERNATIONAL COMPLAINTS ALLEGING GDPR NON-COMPLIANCE
ASSAULT AGAINST DATA BROKERS LAUNCHED BY PRIVACY INTERNATIONAL COMPLAINTS ALLEGING GDPR NON-COMPLIANCE Privacy International, a UK-based activist group, complained in early November 2018 that a number of data brokers, ad-tech companies and credit-reference agencies...
GDPR for Payments
GDPR for Payments GDPR is an important EU wide regulatory mandate. It provides increased protection of individual privacy and gives individuals more control over the information they share. In our view GDPR is an important element of building a scalable data centric...
US Supreme Court repeal of PASPA
US Supreme Court repeal of PASPA On Monday, May 14, 2018, the Supreme Court of the United States held in the Murphy v. National Collegiate Athletic Association case that the federal Professional and Amateur Sports Protection Act (“PASPA”) violated the Tenth Amendment...
Gropay’s 5 Tips For The Holiday Season!
GROPAY'S 5 TIPS FOR THE HOLIDAY SEASON With all the preparations for the holiday, last week deadlines, the multitude of drinks, parties, last minute shopping as well as high expectations from family and friends, it is easy to get lost in this busy time before the...
The Payment Challenges of Online Travel Agencies (OTAs)
THE PAYMENT CHALLENGES OF OTAs Who hasn’t used an online travel agency (OTA) in the last 12 months? They are an integral part of our lives and are part of a colossal $600 billion + a year online travel market. The OTA industry is at a juncture where it faces some...
Strong Customer Authentication (SCA) – Impact on Online Merchants
Strong Customer Authentication (SCA) - Impact on Online Merchants The details around the European Banking Authority (EBA’s) proposal for Strong Customer Authentication (SCA) are final and the requirements for SCA are expected to come into force by February 2019. What...
Did Star Trek predict bitcoins and what does it mean for the future?
Did Star Trek predict bitcoins and what does it mean for the future? If you are like me, a Star Trek fan then it’s interesting to note that many of the futuristic technologies and gadgets used on the show have come true or are close to coming true. This is likely more...
Is the future of payments happening in India now?
India Makes Important Advances in Biometric Payments In India it’s already possible for a consumer to authorise and authenticate a payment with their fingerprint or iris scan. As a largely cash based economy India has leapfrogged the use of Cards and Smart Phones for...
How Do Bitcoins Impact Online Merchants?
How do bitcoins impact online merchants? There’s a lot that has been said and written about bitcoins. They are the talk of the town these days. Undoubtedly bitcoins and related distributed ledger technologies will have a lasting impact on payments and financial...
PSD2 What Will Really Change?
PSD2 What Will Really Change? There has been a lot written about the PSD2 and rightly so, it is important regulation soon to be enacted into legislation that will bring significant innovation and change to electronic payments. But what will actually change in the day...
SafeCharge Three Years After IPO
SafeCharge 3 Years After IPO In this post we look at SafeCharge, a medium sized payment processor and recently formed acquirer. We look at the following items; history, the IPO, recent performance, drivers of growth so far, recent strategic moves and execution...
The Stamina Of Clinton Or Trump?
The Stamina of Clinton Or Trump There have been lot of comments made by presidential candidate Donald Trump triggering a lot of media attention and public debates recently. Not the most notorious comment, but still one that made me pause in the work I was doing....
Authentication – Payer! Reveal Thyself
Authentication - Payer! Reveal Thyself EPC releases results of latest consultations for e-mandate today: what does this mean for authentication and your online business? Earlier today, 5 April 2016, the European Payments Council (EPC) announced the launch of the...
Fantasy Sports – It’s All A Fantasy
Fantasy Sports - It's All A Fantasy Fantasy Sports continue to gain popularity California recently introduced a bill to allow online sports betting. The motivation of this bill is believed to be the increasing popularity of fantasy sports. Although, the bill has yet...
Cash – Kicking The Habit
Cash - Kicking The Habit There was an interesting article in The Economist recently about strikes on the London Underground (Tube). Such strikes are commonly believed to have a short term net cost to the economy. However the article quoted a study by Oxford and...
Data Protection – To Russia With Love
Data Protection - To Russia With Love Data Protection Russia Russia’s new data protection law came into effect on the 1st of September 2015. It’s now required by law to store personal details of Russian citizens on servers physically located in Russia. Copies of the...
Dressing For Work – Looking The Part
I had a manager once who was a real mover and shaker in HR, brilliant in strategy and amazing to work with. Although visionary in his business outlook, there were some basic things that could really set him off when meeting new people: things like scruffy shoes. You...
Tattoos – Ink At Work
Are Tattoos ever OK at work? I was HR Director at a large organization when I suddenly completely got caught by a curb ball thrown by one of my main stakeholders. “What is our HR policy on tattoos?” I had to take a two second pause before responding with a gigantic...
Wirecard’s $9 Billion Bid For Worldpay
Wirecard with a market value of $ 5.2 billion made a $9 billion bid for Worldpay. Is this a serious bid? What will Wirecard do with Worldpay? Wirecard has extensive experience with M&A and also in acquiring companies larger than itself and making it a success; as...
Changing Jobs – Stay Or Go?
Changing jobs - How long should you stay in your current job? In this day and age, most employees are not even aware that organisations used to have tenure incentives like a fancy watch, a toaster or at least a bunch of flowers when you reached your 20 or 25 years of...
Distracted Living – A Simple Life
Distracted Living Psychology Today published an interesting blog on distracted living. Distracted living is where you miss out on much of your life because you generally aren’t paying attention, or your attention is so torn in many directions that your really do not...
Is Visa Worried About Paypal?
Is Visa worried about Paypal? Visa recently published a report on Visa Checkout in which they stated that Visa Checkout delivers 17% better conversion than Paypal. One of the interesting points about this report is that Visa considers Paypal as enough of a threat to...
Mergers And Acquisitions
How do I deal with my company going through a merger or acquisition? Working in the payments sector? There is a big chance that your company is engaged in a merger, is taking over another company or is about to become an acquisition. 2014 was a big year for payments...
0 Comments