Reference🔐 Security & dataIntermediate⏱ 11 min read

📋 Personal data and payments

How the GDPR applies to payments: controllers and processors, legal bases, retention periods, the right to erasure versus AML/CFT obligations, and CNIL guidance and penalties

The GDPR covers card data

Payment card data is personal data, so any processing of it falls under the GDPR (Regulation (EU) 2016/679, in force since May 25, 2018). A payment flow must therefore meet both the security requirements of PCI DSS and the requirements of data protection law. Data protection covers lawfulness, minimization, retention and individuals’ rights. The two frameworks govern the same data for different ends. PCI DSS protects the security of card data; the GDPR governs whether processing it is legitimate.

Every processing activity needs a legal basis. In payments, three bases dominate: performance of a contract (collecting payment for the order), legal obligation (keeping invoices, meeting AML/CFT rules), and legitimate interest (fraud prevention). Consent comes into play only for uses the transaction does not require, typically storing the card for one-click checkout.

🔑
Minimize first
The data minimization principle bars collecting or keeping more data than the purpose requires. Storing a card security code, a full card number without justification, or data kept “just in case” violates the GDPR and PCI DSS. Data you never collected cannot be stolen in a breach.

Controllers and processors

The controller is the entity that determines the purposes and means of processing. The processor acts on the controller’s behalf and on its instructions. This classification determines who carries which obligations and who is liable for a violation. In payments, the merchant is generally the controller for its sales, while the PSP often acts as a processor. The PSP’s role changes, however, when it processes the same data for its own purposes.

🏪
Merchant: controller
It decides to collect the data to sell and deliver. It chooses its providers and is accountable for its customers’ rights.
🔁
PSP: often a processor
It processes card data on the merchant’s instructions, under a data processing agreement (GDPR Article 28).
🛡️
PSP or bank: sometimes a controller
For its own purposes (fraud prevention, AML/CFT obligations, account management), the provider acts as an independent controller.
ℹ️
The data processing agreement (Article 28)
Once a provider processes data on the merchant’s behalf, GDPR Article 28 requires a processing contract (Data Processing Agreement). The contract sets the purposes, duration and security measures. It also covers the use of sub-processors, what happens to the data when the contract ends, and cooperation on individuals’ rights.

Retention periods: each type of data has its own rule

The GDPR bars keeping data longer than the purpose requires, but it sets no specific period. The period therefore varies by purpose, and other laws, on accounting or anti-money laundering, impose their own. A single database is thus subject to several retention rules at once, which is why mistakes on this point are so common.

→ archive: restricted access, outside the live databaseCVV/CVC cryptogramPAN / card tokenInvoice, proof of paymentKYC / AML-CFT identificationFraud signals✕destroyed after authorization (3.3.1)contract, or consent if recordedFrench Commercial Code L123-22: 10 yearsMonetary Code L561-12: 5 years after endlegitimate interest: limited durationnon-linear scaleT0 · authorizationend of contractend of relationship+ 5 years+ 10 yearsAn erasure request doesn't delete what the law requires you to keep: the data is locked in an archive, not erased.
DataTermLegal basis
Card number (PAN)For the duration of the transaction; beyond that, only with consent (one-click checkout) or to bill a subscriptionPerformance of contract / consent
Card security code (CVV)Never stored after the transactionGDPR + PCI DSS
Order and invoice data10 yearsFrench legal requirement (Commercial Code, art. L123-22)
KYC / AML/CFT data5 years after the business relationship ends or the transaction is completedFrench legal requirement (Monetary and Financial Code, art. L561-12)
Proof of consentAs long as needed to prove consentAccountability principle
Fraud data (lists)A proportionate, justified period (often rolling)Legitimate interest, with conditions
Retention periods for payment data
⚠️
Active storage ≠ archiving
Once data kept under a legal obligation is no longer needed day to day, it must move to intermediate archiving: a separate database that only authorized staff can access. The duty to keep invoices for 10 years is a duty to retain them, not to leave them open every day to an entire customer service team.

Individuals’ rights versus AML/CFT

The GDPR gives data subjects a set of rights: access, rectification, erasure (the “right to be forgotten”), portability, and objection. These rights are not absolute. They give way when a legal obligation requires the data to be kept. The tension between the right to erasure and AML/CFT rules is the clearest example.

A customer can ask for their data to be erased, yet an institution subject to anti-money laundering and counter-terrorist financing rules must keep their identification (KYC) data. In France, the period is 5 years after the relationship ends; each member state sets its own period within the common baseline of the EU AML/CFT directives. Here the legal obligation overrides the right to erasure. The data is locked in an archive, out of reach of any commercial use, and kept until the regulatory period expires.

  • Erasure: granted, unless the law requires retention (AML/CFT, accounting) or a dispute is pending.
  • Access: customers can get a copy of their payment data, except for items covered by confidentiality or concerning third parties.
  • Objection: valid against marketing; harder to exercise against fraud-prevention processing based on a compelling legitimate interest.
  • Portability: limited to data the individual provided and that is processed on the basis of consent or a contract.
ℹ️
Fraud prevention databases
Adding a customer to a fraud list (returned payments, incidents) is a tightly regulated form of processing. It requires a specific purpose, a proportionate retention period, notice to the person listed, and a way to challenge the listing. The CNIL penalizes fraud databases that are disproportionate in scope or opaque about their listing criteria.

CNIL guidance and penalties

In France, the CNIL is the supervisory authority. Its key guidance on card data in remote sales is Deliberation No. 2018-303 of September 6, 2018, which replaced its previous recommendation of July 20, 2017. The text restates that the card security code must never be stored and sets conditions for storing a card for future purchases (consent, notice, security).

Sept. 6, 2018
CNIL Deliberation No. 2018-303 on card data in remote sales
CNIL
€20M / 4%
maximum GDPR fine: €20 million or 4% of worldwide revenue, whichever is higher
GDPR, art. 83
5 years
retention of KYC data after the business relationship ends
Monetary and Financial Code, art. L561-12

The violations most often penalized in payments are excessive retention (data kept with no legal basis), a stored security code, inadequate notice to customers, and weak security. Fines can reach €20 million or 4% of worldwide annual revenue. Regulators can also issue compliance orders and publish the penalty.

✅
The GDPR and PCI DSS reinforce each other
The two frameworks converge on the same technical measures. The minimization the GDPR requires reduces the amount of card data held, and with it the scope that PCI DSS requires you to protect. Tokenization and outsourcing card entry to a hosted page satisfy both frameworks at once. Data protection compliance and payment security thus rest largely on the same measures.

Elsewhere in the world. The same mechanism, elsewhere.

Maximum fines for data protection violations

Brazil

In Brazil, the LGPD caps a simple fine at 2% of the revenue the company, group or conglomerate earned in Brazil in its last fiscal year, net of taxes, up to R$50 million per violation. The ANPD, Brazil’s data protection authority, can also block or delete the data concerned and suspend the processing activity for six months, renewable.

Lei nº 13.709/2018 (LGPD), art. 52, https://www.planalto.gov.br/ccivil_03/_ato2015-2018/2018/lei/l13709.htm

China

In China, the Personal Information Protection Law (PIPL) sets a fine of up to 1 million yuan when a company refuses to correct a violation, rising to 50 million yuan or 5% of the prior year’s revenue for serious violations. Regulators can also suspend the business, potentially revoke its license, fine the directly responsible executives 100,000 to 1 million yuan, and temporarily bar them from serving as directors, senior managers or data protection officers (art. 66).

中华人民共和国个人信息保护法 (PIPL), art. 66, http://www.npc.gov.cn/npc/c2/c30834/202108/t20210820_313088.html

India

In India, the Digital Personal Data Protection Act 2023 sets fixed amounts rather than a percentage of revenue: up to ₹250 crore for failing to take reasonable security safeguards that led to a breach, ₹200 crore for failing to notify that breach to the regulator or the individuals affected, and ₹50 crore for any other violation of the Act.

The Digital Personal Data Protection Act, 2023, “The Schedule,” https://egazette.gov.in/WriteReadData/2023/248045.pdf

Statutory retention period for accounting records and invoices

Germany

In Germany, § 147(3) of the Fiscal Code (Abgabenordnung) sets three periods instead of one: 10 years for books, inventories and annual financial statements, eight years for accounting vouchers (Buchungsbelege, including invoices), and six years for business correspondence sent or received. The clock starts only at the end of the calendar year in which the entry was made or the letter sent.

Abgabenordnung (AO), § 147(3) and (4), https://www.gesetze-im-internet.de/ao_1977/__147.html

In the UK, the Companies Act 2006 requires accounting records to be kept for three years from the date they are made for a private company and six years for a public company. For a small or midsize business, that is less than a third of France’s 10 years.

Companies Act 2006, section 388(4), https://www.legislation.gov.uk/ukpga/2006/46/section/388

Brazil

In Brazil, the National Tax Code sets no period in years. Mandatory commercial and tax books, and the vouchers supporting their entries, must be kept until the tax claims arising from those transactions are time-barred (art. 195), which is five years under Articles 173 and 174.

Código Tributário Nacional (Lei nº 5.172/1966), arts. 173, 174 and 195, https://www.planalto.gov.br/ccivil_03/leis/l5172compilado.htm

Deadline for reporting a data breach to the supervisory authority

Brazil

In Brazil, ANPD Resolution CD/ANPD nº 15 of April 24, 2024 cuts the deadline to three business days for reporting a security incident to the ANPD and to the individuals affected. A controller that does not yet have all the facts can file a preliminary report and complete it within the following 20 business days.

ANPD, Resolução CD/ANPD nº 15 of April 24, 2024, https://www.gov.br/anpd/pt-br/assuntos/incidente-de-seguranca

In the US, the FTC Safeguards Rule requires non-bank financial institutions, which covers most payment companies, to report an incident to the FTC as soon as possible and no later than 30 days after discovery when it involves unencrypted data on at least 500 consumers. A law enforcement agency can request a 30-day delay, which it can extend by 60 days with a written request.

16 CFR § 314.4(j), https://www.govinfo.gov/content/pkg/CFR-2024-title16-vol1/pdf/CFR-2024-title16-vol1-sec314-4.pdf

China

In China, the PIPL grants no grace period. When personal information is leaked, altered or lost, or may have been, the handler must take remedial measures immediately and notify both the competent authority and the individuals affected. It can skip notifying individuals only if it shows that it has prevented any harm, and even then the authority can order it to notify them (art. 57).

中华人民共和国个人信息保护法 (PIPL), art. 57, http://www.npc.gov.cn/npc/c2/c30834/202108/t20210820_313088.html