The GDPR covers card data
Payment card data is personal data, so any processing of it falls under the GDPR (Regulation (EU) 2016/679, in force since May 25, 2018). A payment flow must therefore meet both the security requirements of PCI DSS and the requirements of data protection law. Data protection covers lawfulness, minimization, retention and individuals’ rights. The two frameworks govern the same data for different ends. PCI DSS protects the security of card data; the GDPR governs whether processing it is legitimate.
Every processing activity needs a legal basis. In payments, three bases dominate: performance of a contract (collecting payment for the order), legal obligation (keeping invoices, meeting AML/CFT rules), and legitimate interest (fraud prevention). Consent comes into play only for uses the transaction does not require, typically storing the card for one-click checkout.
Controllers and processors
The controller is the entity that determines the purposes and means of processing. The processor acts on the controller’s behalf and on its instructions. This classification determines who carries which obligations and who is liable for a violation. In payments, the merchant is generally the controller for its sales, while the PSP often acts as a processor. The PSP’s role changes, however, when it processes the same data for its own purposes.
Retention periods: each type of data has its own rule
The GDPR bars keeping data longer than the purpose requires, but it sets no specific period. The period therefore varies by purpose, and other laws, on accounting or anti-money laundering, impose their own. A single database is thus subject to several retention rules at once, which is why mistakes on this point are so common.
| Data | Term | Legal basis |
|---|---|---|
| Card number (PAN) | For the duration of the transaction; beyond that, only with consent (one-click checkout) or to bill a subscription | Performance of contract / consent |
| Card security code (CVV) | Never stored after the transaction | GDPR + PCI DSS |
| Order and invoice data | 10 years | French legal requirement (Commercial Code, art. L123-22) |
| KYC / AML/CFT data | 5 years after the business relationship ends or the transaction is completed | French legal requirement (Monetary and Financial Code, art. L561-12) |
| Proof of consent | As long as needed to prove consent | Accountability principle |
| Fraud data (lists) | A proportionate, justified period (often rolling) | Legitimate interest, with conditions |
Individuals’ rights versus AML/CFT
The GDPR gives data subjects a set of rights: access, rectification, erasure (the “right to be forgotten”), portability, and objection. These rights are not absolute. They give way when a legal obligation requires the data to be kept. The tension between the right to erasure and AML/CFT rules is the clearest example.
A customer can ask for their data to be erased, yet an institution subject to anti-money laundering and counter-terrorist financing rules must keep their identification (KYC) data. In France, the period is 5 years after the relationship ends; each member state sets its own period within the common baseline of the EU AML/CFT directives. Here the legal obligation overrides the right to erasure. The data is locked in an archive, out of reach of any commercial use, and kept until the regulatory period expires.
- Erasure: granted, unless the law requires retention (AML/CFT, accounting) or a dispute is pending.
- Access: customers can get a copy of their payment data, except for items covered by confidentiality or concerning third parties.
- Objection: valid against marketing; harder to exercise against fraud-prevention processing based on a compelling legitimate interest.
- Portability: limited to data the individual provided and that is processed on the basis of consent or a contract.
CNIL guidance and penalties
In France, the CNIL is the supervisory authority. Its key guidance on card data in remote sales is Deliberation No. 2018-303 of September 6, 2018, which replaced its previous recommendation of July 20, 2017. The text restates that the card security code must never be stored and sets conditions for storing a card for future purchases (consent, notice, security).
The violations most often penalized in payments are excessive retention (data kept with no legal basis), a stored security code, inadequate notice to customers, and weak security. Fines can reach €20 million or 4% of worldwide annual revenue. Regulators can also issue compliance orders and publish the penalty.
Elsewhere in the world. The same mechanism, elsewhere.
Maximum fines for data protection violations
In Brazil, the LGPD caps a simple fine at 2% of the revenue the company, group or conglomerate earned in Brazil in its last fiscal year, net of taxes, up to R$50 million per violation. The ANPD, Brazil’s data protection authority, can also block or delete the data concerned and suspend the processing activity for six months, renewable.
Lei nº 13.709/2018 (LGPD), art. 52, https://www.planalto.gov.br/ccivil_03/_ato2015-2018/2018/lei/l13709.htm
In China, the Personal Information Protection Law (PIPL) sets a fine of up to 1 million yuan when a company refuses to correct a violation, rising to 50 million yuan or 5% of the prior year’s revenue for serious violations. Regulators can also suspend the business, potentially revoke its license, fine the directly responsible executives 100,000 to 1 million yuan, and temporarily bar them from serving as directors, senior managers or data protection officers (art. 66).
中华人民共和国个人信息保护法 (PIPL), art. 66, http://www.npc.gov.cn/npc/c2/c30834/202108/t20210820_313088.html
In India, the Digital Personal Data Protection Act 2023 sets fixed amounts rather than a percentage of revenue: up to ₹250 crore for failing to take reasonable security safeguards that led to a breach, ₹200 crore for failing to notify that breach to the regulator or the individuals affected, and ₹50 crore for any other violation of the Act.
The Digital Personal Data Protection Act, 2023, “The Schedule,” https://egazette.gov.in/WriteReadData/2023/248045.pdf
Statutory retention period for accounting records and invoices
In Germany, § 147(3) of the Fiscal Code (Abgabenordnung) sets three periods instead of one: 10 years for books, inventories and annual financial statements, eight years for accounting vouchers (Buchungsbelege, including invoices), and six years for business correspondence sent or received. The clock starts only at the end of the calendar year in which the entry was made or the letter sent.
Abgabenordnung (AO), § 147(3) and (4), https://www.gesetze-im-internet.de/ao_1977/__147.html
In the UK, the Companies Act 2006 requires accounting records to be kept for three years from the date they are made for a private company and six years for a public company. For a small or midsize business, that is less than a third of France’s 10 years.
Companies Act 2006, section 388(4), https://www.legislation.gov.uk/ukpga/2006/46/section/388
In Brazil, the National Tax Code sets no period in years. Mandatory commercial and tax books, and the vouchers supporting their entries, must be kept until the tax claims arising from those transactions are time-barred (art. 195), which is five years under Articles 173 and 174.
Código Tributário Nacional (Lei nº 5.172/1966), arts. 173, 174 and 195, https://www.planalto.gov.br/ccivil_03/leis/l5172compilado.htm
Deadline for reporting a data breach to the supervisory authority
In Brazil, ANPD Resolution CD/ANPD nº 15 of April 24, 2024 cuts the deadline to three business days for reporting a security incident to the ANPD and to the individuals affected. A controller that does not yet have all the facts can file a preliminary report and complete it within the following 20 business days.
ANPD, Resolução CD/ANPD nº 15 of April 24, 2024, https://www.gov.br/anpd/pt-br/assuntos/incidente-de-seguranca
In the US, the FTC Safeguards Rule requires non-bank financial institutions, which covers most payment companies, to report an incident to the FTC as soon as possible and no later than 30 days after discovery when it involves unencrypted data on at least 500 consumers. A law enforcement agency can request a 30-day delay, which it can extend by 60 days with a written request.
16 CFR § 314.4(j), https://www.govinfo.gov/content/pkg/CFR-2024-title16-vol1/pdf/CFR-2024-title16-vol1-sec314-4.pdf
In China, the PIPL grants no grace period. When personal information is leaked, altered or lost, or may have been, the handler must take remedial measures immediately and notify both the competent authority and the individuals affected. It can skip notifying individuals only if it shows that it has prevented any harm, and even then the authority can order it to notify them (art. 57).
中华人民共和国个人信息保护法 (PIPL), art. 57, http://www.npc.gov.cn/npc/c2/c30834/202108/t20210820_313088.html