Javascript is required
logo-dastralogo-dastra

GDPR Data processing modelUse of a payment card number in connection with the sale of goods or the provision of services at a distance

PrivateOrders and Payments
This processing model relates to the use of payment card numbers in the sale of goods or the provision of remote services, including subscriptions taken out online or goods reservations

Purposes (6)

A purpose is the objective pursued by the setting up of your file. It indicates what the processing of personal data will be used for, its purpose. This purpose must be clear and understandable

1
Fight against fraud
Legal obligation
2
Simplification of any subsequent purchases on the merchant's site
Consent
3
Reservation of a good or service
Contract
4
Offer of payment solutions dedicated to distance selling by payment service providers
Legitimate interest
5
Settlement of subscriptions taken out online involving defined and regular payments
Contract
6
Completion of a transaction for the delivery of a good or the provision of a service in return for payment
Contract

Data categories (1)

Personal data is any information relating to an identified or identifiable natural person. A natural person can be identified either directly (eg surname and first name) or indirectly (eg phone number, social security number, email or postal address, but also voice or image)

Data required to carry out a remote payment card transaction

Data details


Cardholder identityoptional
Visual cryptogramrequired
expiration daterequired
Credit card numberrequired

Data conservation rules

Active base:

Until transaction is completed and reconciled (typically up to 13 months)

To process payment, handle immediate disputes, and comply with card scheme rules (e.g. Mastercard, Visa); supported by UK GDPR Article 6(1)(b) – performance of a contract

Intermediate archiving:

Up to 6 years (after transaction date, but without storing full PAN or CVV)

For accounting records and potential contractual claims; aligns with the Limitation Act 1980 (6 years for most civil claims) and Companies Act 2006 for record-keeping

Destruction

Data subject (1)

A data subject is any person whose data is collected, retained or processed by the data processing. e.g. In a recruitement process, any candidate for a position proposed in recruitement management process

  • Other

Created at:07/08/2023

Updated on:06/14/2025

License: © Creative commons :
Attribution / Pas d'utilisation commerciale
CC-BY-NC AttributionPas d'utilisation commerciale

Nb using:5


Access the full processing template

Try Dastra now to access all of our data processing templates that you can customize for your organization.It's free and there's no obligation for the first 30 days (no credit card required)

Add to my data processings record
Subscribe to our newsletter

We'll send you occasional emails to keep you informed about our latest news and updates to our solution

* You can unsubscribe at any time using the link provided in each newsletter.