Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

GDPR Applicability to U.S. Merchants, Processors and Acquirers

By Nicole Meisner & Daniel Ungar on January 2, 2019
Email this postTweet this postLike this postShare this post on LinkedIn

The EU General Data Privacy Regulation (GDPR) was adopted in 2016 and went into effect on May 25, 2018. The GDPR is a framework regulation that is designed to provide a uniform regime to protect the privacy of an individual of the European Union (“data subject”) whose personal data is collected, stored, or processed.

The GDPR is extremely broad in scope. Accepting or processing payments may be classified as the collection and processing of personal data under the GDPR. As such, any company involved in processing payments from consumers should take steps to determine whether they or any of their business partners are collecting, storing, or processing personal information of a data subject.

The good news is that in order for the GDPR to apply to a U.S. entity, there must be an intent to market to an EU resident.

In-person transactions occurring in the U.S. that involve EU residents visiting the U.S. are unlikely to involve the GDPR. However, the application of the GDPR to online activity can be much more treacherous. For example, if a merchant sells goods or services online and markets to residents of the EU (as opposed to merely allowing purchases from residents of the EU), then the GDPR is likely to apply. Similarly, if a merchant maintains a website in the language of an EU country, it is more likely that the GDPR could apply to those online commerce activities. And, since the merchant could be collecting personal data of a data subject, all of the participants in the chain that process or assist with processing a payment transaction could be unintentionally subject to the GDPR.

So, what are some important questions to pose regarding your operations?

If you are a merchant:

  • Do you market to countries in the EU?
    • Do you maintain your website in alternate languages?
    • Do you accept currencies such as the Euro for purchases?
    • Do you allow EU residents to participate in your loyalty and awards programs?

If you are a processor or acquirer:

  • Do you monitor the online activities of your merchants? If so, do any of your merchant’s answer “yes” to the above questions?
    • Have you updated your merchant agreements to address GDPR concerns?

Merchants answering “yes” to any of the questions above should seek legal guidance to determine if and to what extent the GDPR may apply to them.

Processors or acquirers that do not monitor the online activities of merchants or that have not updated merchant agreements would be well advised to consult with knowledgeable counsel to ensure that they are not unintentionally subject to the GDPR through the activities of their merchant portfolios.

Photo of Nicole Meisner Nicole Meisner

Nicole chairs Taft’s PayTech and Payment Systems practice group. She counsels a wide range of companies in the payments and financial services industries, including acquiring banks, payment processors, independent sales organizations (ISOs), payment facilitators, marketplaces, mobile payment providers, FinTech companies, ACH providers, money…

Nicole chairs Taft’s PayTech and Payment Systems practice group. She counsels a wide range of companies in the payments and financial services industries, including acquiring banks, payment processors, independent sales organizations (ISOs), payment facilitators, marketplaces, mobile payment providers, FinTech companies, ACH providers, money transmitters, prepaid access providers, and digital currency companies.

Read more about Nicole MeisnerEmailNicole's Linkedin Profile
Show more Show less
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    Paytech & Payment Systems Insights
  • Organization:
    Taft Stettinius & Hollister LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo