GDPR Data processing modelUse of a payment card number in connection with the sale of goods or the provision of services at a distance
Purposes (6)
A purpose is the objective pursued by the setting up of your file. It indicates what the processing of personal data will be used for, its purpose. This purpose must be clear and understandable
Data categories (1)
Personal data is any information relating to an identified or identifiable natural person. A natural person can be identified either directly (eg surname and first name) or indirectly (eg phone number, social security number, email or postal address, but also voice or image)
Data required to carry out a remote payment card transaction
Data details
Data conservation rules
Active base:
Until transaction is completed and reconciled (typically up to 13 months)
To process payment, handle immediate disputes, and comply with card scheme rules (e.g. Mastercard, Visa); supported by UK GDPR Article 6(1)(b) – performance of a contract
Intermediate archiving:
Up to 6 years (after transaction date, but without storing full PAN or CVV)
For accounting records and potential contractual claims; aligns with the Limitation Act 1980 (6 years for most civil claims) and Companies Act 2006 for record-keeping
Destruction
Data subject (1)
A data subject is any person whose data is collected, retained or processed by the data processing. e.g. In a recruitement process, any candidate for a position proposed in recruitement management process
- Other
Attribution / Pas d'utilisation commerciale
CC-BY-NC

