🎓 CoursesRisk & complianceIntermediate⏱ 60 min

GDPR and payment data. 6 chapters and a final quiz.

IBANs, card numbers, and transaction histories are among the most revealing personal data there is. This course applies the GDPR to the payment chain: legal bases, data minimization, retention periods (13 or 15 months, the CVV), how to classify a PSP (processor or controller?), transfers outside the EU, data breaches, and how the GDPR fits with PCI DSS, drawing on guidance from the CNIL, France's data protection authority.

Chapter 1. Payment data is personal data.

The GDPR (Regulation (EU) 2016/679, in effect since May 25, 2018) protects any information relating to an identified or identifiable natural person. An IBAN, a card number (PAN), a wallet ID, or a transaction history falls squarely within that definition, because each identifies a person. More importantly, they tell the story of a person's life. Who pays for what, where, when, and how much reveals their movements, their habits, and sometimes their health (pharmacy purchases), beliefs (donations), or family situation.

🪪
Identity data
Cardholder name, billing and shipping addresses, email, phone number. The merchant collects them and passes some of them to the PSP.
💳
Card data
The PAN, expiration date, and security code (CVV) are the trio fraudsters want most, and they are central to both CNIL guidance and PCI DSS.
🧾
Transaction data
Amount, currency, timestamp, merchant, authorization status, decline reasons. Put together, they paint a complete picture of someone's life.
📱
Technical data
Device fingerprint, IP address, 3-D Secure data, and fraud scoring data. These are personal data too, and data maps often leave them out.

One common misconception needs clearing up. Financial data is not “sensitive data” under Article 9 of the GDPR, which covers health, political opinions, biometrics, and similar categories. But the European Data Protection Board (EDPB) classifies it as highly personal data, and that label weighs in the risk assessment: stricter security requirements, a data protection impact assessment (DPIA) that is often required, and near-zero tolerance from regulators when things go wrong.

17 772
complaints received by the CNIL in 2024, a record
CNIL 2024 annual report
5 629
data breaches reported to the CNIL in 2024 (up 20% year over year)
CNIL 2024 annual report
4 %
of annual global revenue: the maximum GDPR fine (or €20 million)
GDPR, art. 83
€1.2B
record fine imposed on Meta in May 2023 for unlawful data transfers to the US
Irish DPC / EDPB
🔑
The habit to build
In the payment chain, everything is personal data: a tokenized PAN, a hashed IBAN, a fraud score, a 3-D Secure log. As long as re-identification is possible, and it almost always is, the GDPR applies in full.
🎯 Quick question
Is an IBAN on its own, without the account holder's name, personal data?