Skip to main content
IA

iATS

GDPR evidence

iatspayments.comLast verified 17 Sep 2026
GDPR mark, CertReports state No public evidenceNo public evidence

iATS and GDPR

CertReports found no public GDPR evidence for iATS as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.

Evidence

ExpiredInactive
as of 17 Sep 2026 · confidence 100%
Kind
listing
Issued or listed
3 Jan 2017
Scope
iATS collects personally identifiable information from a merchant, when a merchant registers for an iATS merchant account. The information iATS receives is limited to only that which is relevant to fulfill its intended payment transaction processing purpose, billing facilitation, and payment service delivery. iATS does not acquire PII directly from consumers on the Site. Our web site is not directed at persons under the age of 18 and iATS does not knowingly collect or maintain information on our Web site from persons under the age of 18. The below information provides you with the various types of data collected and the collection reason: Contact information Name, Street address, E-mail address, and Telephone number The above contact information is required for payment transaction processing, billing facilitation, and payment service delivery. The information may also be used to communicate sales and marketing information. Business Payment information Bank account and routing number, and Credit card information The above payment information is required to fulfill the payment services requested, upon registering for an iATS merchant account. Web cookie (small text files stored on users' computers) iATS may also use cookies to help track and customize access and use of the Site. Cookies store and retain information that helps us recognize individuals when they return to the Site following a previous visit. Most popular Internet browser packages allow one to configure the browser so as not to accept cookies. However, setting your browser to reject cookies may, in certain instances, prevent you from taking full advantage of the Site and the materials, products, and or services that are available on the Site. Non-personal metadata The purposes for which this type of information is collected and used includes Site operation facilitation, system administration, aggregate generation, non-identifiable statistical information, Site traffic monitoring, analyzing, usage patterns, and improving the content and content delivery with regard to the Site and its content, materials, opportunities, and services that are described or available on the Site. iATS shares PII with third parties, such as, banks, credit card processors and or business partners, only to the extent which is necessary to fulfill the requested payment processing services acquired by a merchant. iATS will disclose personally identifiable information, to a third party only when: (1) You, as a merchant, have provided your prior consent to do so (2) Sharing the information is required, to fulfill the product and or service requested, by you, the merchant. (3) The Third party works on behalf of iATS, to fulfill the product and or service requested, by you, the merchant. If we were to engage in any onward transfers of your data with third parties for a purpose other than which it was originally collected or subsequently authorized, iATS would provide you with an opt-out choice to limit the use and disclosure of your personal data. iATS also may be required to disclose PII in response to a lawful request by public authorities, including meeting national security or law enforcement requirements. iATS is also subject to the investigatory and enforcement powers of the Federal Trade Commission (FTC). iATS's accountability for personal data that it receives under the Privacy Shield and subsequently transfers to a third party is described in the Privacy Shield Principles. In particular, iATS remains responsible and liable under the Privacy Shield Principles if third-party agents that it engages to process the personal data on its behalf do so in a manner inconsistent with the Principles, unless iATS proves that it is not responsible for the event giving rise to the damage.
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
17 Sep 2026iATS: Inactive
Live pagesha256 7cf5b5f3f2
What GDPR means, and what it does not

"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.

Read the GDPR guide and browse all vendors with evidence

Questions buyers ask

Is iATS GDPR compliant?

There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.

How does CertReports verify this?

Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.

Alternatives with GDPR evidence

Similar vendors (shared product tags) whose GDPR row is verified or vendor-stated, ranked by similarity.

No same-category vendor has GDPR evidence in the index yet.