Glossary
GDPR (General Data Protection Regulation)

GDPR (General Data Protection Regulation)

A data protection regulation governing how personal data is collected, processed, stored and transferred within the UK and EU. It imposes strict requirements on organisations handling customer information, including payment data.

GLOSSARY
What is a
GDPR (General Data Protection Regulation)

GDPR, the General Data Protection Regulation, is the EU framework governing how personal data must be collected, used, stored and protected, and its UK equivalent continues to shape how payment businesses handle customer information after Brexit. For anyone working in payments, GDPR isn't an abstract legal topic sitting in a compliance folder; it directly affects how checkout forms are designed, how long transaction data can be kept, and what happens if that data is ever exposed.

The Seven Principles That Sit Behind Everything Else

Article 5 sets out seven core principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. The ICO's guide to the data protection principles breaks each one down in detail, and it's worth reading directly rather than relying on a secondhand summary, since these principles are what every specific GDPR obligation ultimately traces back to.

Why Payment Data Specifically Draws Extra Scrutiny

Payment information sits at the intersection of financial and personal data, which tends to attract closer attention from regulators than most other categories of personal information. Practices like tokenisation are intended to help reduce how much raw personal and card data a business needs to store directly, which can meaningfully lower both GDPR exposure and the broader risk surface a business is responsible for protecting.

Consent, Legitimate Interest And The Difference That Matters

Not every use of personal data requires explicit consent under GDPR; processing that's necessary to fulfil a contract, such as completing a payment a customer has requested, often relies on a different lawful basis entirely. Confusing consent with legitimate interest is a common mistake, and getting it wrong can mean either asking customers for permissions that aren't actually required or, worse, processing data without a valid basis at all.

Data Subject Rights In A Payments Context

Customers have the right to access, correct, or in many cases request erasure of their personal data, though payment records often carry separate retention obligations under financial regulation that can limit how quickly erasure requests can actually be honoured. Balancing these two sets of rules is genuinely one of the trickier parts of running compliant payment operations, and it's an area where getting specific legal advice tends to matter more than relying on general guidance.

The 72-Hour Breach Notification Rule

Where a personal data breach is likely to result in risk to individuals, organisations are generally required to notify their relevant supervisory authority within 72 hours of becoming aware of it. For a payment business, that clock can start the moment unusual activity is detected, which is part of why having a tested incident response process in place matters far more than most businesses appreciate until they actually need one.

Cross-Border Transfers And Why They Get Complicated

Moving personal data outside the UK or EU triggers additional requirements, and the rules here have shifted more than once in recent years as adequacy decisions and transfer mechanisms have been reviewed and challenged. A payment platform operating across multiple regions, supported by tools like open banking connections that move account data between institutions, needs to keep a close eye on which transfer mechanisms currently apply to each corridor it operates in.

Where GDPR And AML Obligations Can Pull In Different Directions

GDPR's data minimisation principle can sit in tension with AML (Anti-Money Laundering) requirements that expect businesses to retain detailed customer records for extended periods. Neither obligation cancels the other out; in practice, businesses need to document why specific data is retained for AML purposes so that decision holds up if a GDPR-related question is ever raised about the same records.

Penalties Are Real, But Rarely The Main Point

Fines for the most serious infringements can reach up to £17.5 million or 4% of global annual turnover, whichever is higher, though most GDPR enforcement in practice looks more like corrective orders and mandated changes than headline-grabbing penalties. Treating GDPR purely as a fine to avoid, rather than a framework for handling customer data responsibly, tends to produce weaker compliance outcomes than businesses expect.

Building GDPR Into Payment Operations From The Start

Retrofitting GDPR compliance onto an existing payment flow is possible but noticeably harder than designing it in from the outset, particularly around data retention schedules and what gets logged by default. Businesses that treat data protection as part of initial product design, rather than a review step added at the end, generally find the ongoing compliance burden far more manageable.

Table of contents

Frequently Asked Questions

Does UK GDPR differ from EU GDPR?

They started from the same text, but UK GDPR and EU GDPR have diverged in some details since Brexit, and businesses operating in both regions need to track each framework separately rather than assuming they remain identical.

Do payment businesses always need customer consent to process card data?

Not necessarily. Processing that's needed to fulfil a contract, such as completing a purchase a customer has initiated, often relies on a lawful basis other than consent, though the specific basis should be documented clearly.

How long can a business keep payment transaction data?

It depends on the purpose. Financial regulations often set minimum retention periods, while GDPR's storage limitation principle discourages keeping data longer than necessary, so the retention period is usually set by whichever obligation requires the longer window.

What counts as a reportable data breach under GDPR?

Broadly, any breach likely to result in a risk to individuals' rights and freedoms, which in a payments context often includes exposure of card numbers, personal identifiers or account details.

Can tokenisation reduce a business's GDPR obligations?

It can help by limiting how much raw personal and card data needs to be stored, which reduces overall exposure, though it doesn't remove the need for a proper legal basis and appropriate safeguards elsewhere in the data lifecycle.

Still Have Questions?

Let’s Find the Right Solution for You

Share this article
Glossary

Stay Connected with Us!

Follow us on social media to stay up to date with the latest news, updates, and exclusive insights!