
checkout and GDPR
checkout states it holds a data processing agreement. CertReports captured this on 17 Sep 2026 from its trust centre (Vanta); it is a vendor statement, not an independent confirmation.
Evidence
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is checkout GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Change history
- 17 Sep 2026GDPR evidence addedA GDPR row entered the index with state Vendor-stated.
- 17 Sep 2026Subprocessor added: Amazon Web ServicesAmazon Web Services appeared on the subprocessor list.
- 17 Sep 2026Subprocessor added: Checkout Technology Ltd.Checkout Technology Ltd. appeared on the subprocessor list.
- 17 Sep 2026Subprocessor added: Google Cloud PlatformGoogle Cloud Platform appeared on the subprocessor list.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the Payments category) whose GDPR row is verified or vendor-stated, ranked by similarity.
No Payments vendor has GDPR evidence in the index yet.