← HomeREP27All categories

Payment gateways and checkout providers

Data protection

In short
Authorised payment institution established in the Union, plus an Article 27 GDPR representative

Who has to appoint one

Payment providers outside the Union serving EU merchants and consumers. Providing payment services requires authorisation of an entity established in a member state; the GDPR representative addresses only the data side.

Thresholds and exemptions

Authorisation thresholds depend on the service. The limited network and commercial agent exclusions are narrow and must be assessed rather than assumed.

What must appear on the label

Not physical. Merchant and consumer disclosures required by PSD2, including the identity of the provider, the charges and the execution times, plus the representative in the privacy notice.

Marketplace fields

Card schemes and acquirers impose PCI DSS compliance as a contractual condition, and merchants require DORA-compatible terms where they are financial entities.

Documentation you must hold

Authorisation file, safeguarding arrangements for user funds, strong customer authentication implementation documentation with the exemptions applied, AML programme, incident reporting procedures, Article 30 records, the Article 27 designation, and DORA register of information for ICT third-party arrangements.

Standards and testing

PCI DSS assessment, strong customer authentication testing, and for DORA-relevant providers participation in resilience testing.

Language requirements

Merchant and consumer information in the language of the markets served.

When it applies

Authorisation before providing services. DORA has applied since 17 January 2025.

How long records are kept

Transaction records per PSD2 and national law, generally at least five years, and AML records for the same period.

What happens if you do not comply

Prohibition of activity and withdrawal of authorisation, GDPR fines up to 4% of turnover, and scheme fines for PCI failures. Operating without authorisation is criminal in several member states.

Who enforces it

National financial supervisors and the EBA, data protection authorities, and card schemes contractually.

Where the boundary lies

Payment data is personal data with a high sensitivity, and the AML retention obligations conflict with minimisation unless documented as a legal obligation. Providers acting as technical service providers rather than payment institutions must be able to demonstrate that they never hold funds or account data in a way that triggers authorisation.

Questions we are asked

Does a GDPR representative allow us to process payments in the EU?
No. Payment services require authorisation of an established entity. The representative satisfies Article 27 only.
Are we in scope of DORA?
Payment institutions are financial entities under DORA, and ICT providers to them face the third-party risk regime including the register of information.
EU representative · from €290 / year

Who signs for you
EU representative Europe Services, SE — Na Čečeličce 425/4, Smíchov, 150 00 Praha 5, Czech Republic
UK representative REP27 LTD — Unit 82a James Carter Road, Mildenhall, Suffolk IP28 7DE, United Kingdom

Talk to usCheck your category