Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Moneris is a major Canadian payment gateway that processes cardholder data under PCI DSS, with checkout scripts that may set cookies and pixels.
Moneris is a major Canadian payment gateway and processor used by merchants to accept card payments online and in store. It offers hosted tokenization, which keeps payment details on Moneris systems while the customer stays on the merchant website. By handling the sensitive card data itself, Moneris helps merchants reduce their own exposure to cardholder information. It operates under the strict requirements of the Payment Card Industry Data Security Standard.
During checkout Moneris processes cardholder data such as the card number, expiry and security code, along with transaction amounts and identifiers. Its hosted payment pages and scripts may set cookies and use pixel tags, including a cookie that links a browser to tokenized card numbers, and in some deployments the Offlinx cookie. This information is personal data under the GDPR and includes financial details that are particularly sensitive. The card number itself is also regulated cardholder data under PCI DSS.
Processing payment data to fulfil an order generally rests on the performance of a contract under the GDPR, so consent is not required for the payment itself. However, any cookies that are not strictly necessary, such as marketing or analytics cookies set at checkout, still require prior consent under Art. 5(3) of the ePrivacy Directive. The merchant and Moneris must clarify their respective controller and processor roles and put an appropriate agreement in place. Transparency about the financial processing and the parties involved is essential.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
The payment processing does not need consent because it is necessary to perform the contract with the customer. Strictly necessary checkout cookies that simply make the payment work are also exempt from the consent rule. Any additional cookies used for marketing, fraud profiling beyond what is necessary, or analytics must be gated behind a consent banner. Where the Offlinx cookie or similar advertising features are present, they must remain off until the visitor opts in.
Moneris processes data in Canada, which benefits from a partial EU adequacy decision covering commercial activity under PIPEDA, so transfers from the EU to Canada require no additional safeguards. This is an important nuance that distinguishes Moneris from United States based providers. However, Moneris states it may transfer personal data onward to the United States and the Philippines, and those onward transfers need Standard Contractual Clauses, a transfer impact assessment and supplementary measures. The merchant should confirm where data actually flows and document the safeguards accordingly.
Confirm the controller and processor roles with Moneris and conclude a data processing agreement that addresses cardholder data and onward transfers. Rely on hosted tokenization to keep card data out of your own systems and stay within PCI DSS scope. Gate any non essential checkout cookies behind a consent banner and disclose Moneris clearly in the privacy and cookie policies. Map the data flows to Canada, the United States and the Philippines, and document the adequacy decision and the clauses used.
Websites using Moneris Payment Gateway must obtain user consent under GDPR regulations.
DPIA considerations
Although payment processing relies on contract rather than consent, the sensitivity of cardholder data and the volume of transactions can still warrant a data protection impact assessment, especially where fraud scoring or profiling is involved. Assess the data flows to Moneris in Canada and any onward transfers to the United States or the Philippines, the PCI DSS scope and the cookies set at checkout. Document the lawful basis, the transfer mechanisms and the security measures protecting the payment data.
Sample consent text
We process your payment through Moneris, a Canadian payment provider, to complete your order securely. Card data is handled under PCI DSS and Canada benefits from an EU adequacy decision. Optional cookies set during checkout run only after you accept them.
Third-party domains contacted
moneris.comwww3.moneris.comgateway.moneris.comesqa.moneris.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| moneris_token | third party | Session | Links the customer browser to tokenized card numbers during hosted tokenization so the payment can be completed securely. |
| Offlinx | third party | 2 years | Advertising and behavioural cookie used by Moneris on participating merchant sites, which requires consent and can be opted out. |
| JSESSIONID | third party | Session | Maintains the secure session on the Moneris hosted payment page so the checkout flow works correctly. |
Moneris Payment Gateway collects user analytics data — you legally need a consent banner. Try FlowConsent free.
During hosted checkout Moneris may set a session cookie such as JSESSIONID and a token cookie that links the browser to tokenized card numbers, both used to complete the payment securely. On participating merchant sites it may also set the Offlinx advertising cookie. The payment cookies are strictly necessary, while advertising cookies like Offlinx require consent.
Consent is not required for the payment processing itself or for the strictly necessary cookies that make checkout work, because these rest on contract and the ePrivacy exemption. Consent is required for any non essential cookies, such as the Offlinx advertising cookie or analytics scripts set at checkout. Those must stay blocked until the visitor opts in.
The lawful basis for processing payment data is the performance of a contract under Art. 6(1)(b) GDPR, since the payment is needed to fulfil the order. Compliance with legal obligations may also apply to record keeping and fraud prevention. Any non essential cookies require consent under Art. 5(3) of the ePrivacy Directive.
Moneris processes data primarily in Canada, which has an EU adequacy decision for commercial data under PIPEDA, so EU to Canada transfers need no extra safeguards. However Moneris states it may transfer personal data onward to the United States and the Philippines. Those onward transfers require Standard Contractual Clauses, a transfer impact assessment and supplementary measures.
A data protection impact assessment may be warranted because cardholder data is sensitive and processing volumes are typically high, particularly where fraud scoring or profiling occurs. The assessment should consider the Canada adequacy decision, the onward transfers and the PCI DSS controls. Document the safeguards even where the core payment relies on contract.
Use hosted tokenization so cardholder data stays with Moneris and your PCI DSS scope is reduced. Conclude a data processing agreement, define controller and processor roles and record the transfer position for Canada and any onward countries. Block non essential checkout cookies behind a consent banner and keep your security measures and documentation current.
European payment service providers such as Adyen, Stripe Europe or Worldline can keep payment processing within the EU or EEA and simplify the transfer analysis. Other adequacy covered or framework certified providers may also be suitable depending on the markets served. Any alternative still needs PCI DSS compliance, a clear lawful basis and proper handling of checkout cookies.
Distinguish the strictly necessary payment cookies, which do not need consent, from advertising cookies like Offlinx, which do. Name Moneris as a Canadian payment provider and note the adequacy decision plus any onward transfers to the United States and the Philippines. Explain how visitors can opt out of advertising cookies and keep the policy aligned with the live checkout configuration.