Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Atome is a buy now pay later (BNPL) provider that lets shoppers split a purchase into interest free instalments at checkout. When a merchant adds the Atome widget or checkout, it sets cookies for session management, fraud prevention and conversion attribution, and processes shopper and order data. Under the GDPR and the ePrivacy Directive, its non essential cookies require prior consent and cross border transfers must be safeguarded.
Atome is a buy now pay later service that lets shoppers split the cost of a purchase into several interest free instalments. Merchants add Atome as a payment option through a widget on the product or checkout page, and shoppers complete an eligibility check before the order is approved. It is operated by the Singapore based Advance Intelligence Group and is widely used across Asia.
When the Atome widget loads it sets cookies for session management, fraud prevention and conversion attribution, and reads device data such as IP address and browser. To approve an instalment plan, Atome processes identity, contact and order information and runs an affordability or fraud assessment. Some cookies are persistent identifiers used to recognise the device and attribute the sale.
The attribution and fraud cookies are not strictly necessary, so storing them is governed by Article 5(3) of the ePrivacy Directive and requires consent. The instalment eligibility check can involve profiling of the shopper financial situation, which carries heightened obligations under the GDPR, including transparency about the logic and possible effects of any automated decision.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Block Atome non essential cookies until the shopper accepts them through a Consent Management Platform, while genuinely necessary checkout cookies may load to complete a requested payment. Provide clear information about the instalment assessment, log consent, and let shoppers refuse non essential tracking as easily as they accept it.
Because Atome is operated from Singapore, personal data of EU shoppers may be transferred to Singapore and other Asia Pacific locations that do not benefit from an EU adequacy decision. Such transfers must rely on Standard Contractual Clauses or another Chapter V safeguard, supported by a Transfer Impact Assessment. Document the recipients and the safeguards in your records of processing.
List the Atome cookies and domains in your cookie policy, classify them and gate non essential ones behind consent. Clarify the controller roles between your business and Atome, sign the appropriate data processing or sharing terms, and inform shoppers about the affordability assessment and their rights. Reassess the transfer safeguards periodically and after any change to the integration.
Websites using Atome must obtain user consent under GDPR regulations.
DPIA considerations
Atome processes identity, contact, device and order data to assess instalment eligibility and to prevent fraud, and sets cookies including persistent identifiers for attribution. Key DPIA considerations: (1) BNPL involves a creditworthiness or affordability assessment that may amount to profiling with legal or significant effects; (2) fraud prevention and device cookies create persistent identifiers; (3) data may be transferred to Singapore and other Asia Pacific countries without an EU adequacy decision; (4) the merchant and Atome must define their respective controller roles. A DPIA is recommended because BNPL combines financial profiling with international transfers.
Sample consent text
We offer Atome so you can pay in interest free instalments. The Atome checkout sets cookies and processes your identity, device and order data to assess eligibility and prevent fraud, and may transfer data to Singapore. You can withdraw your consent to non essential cookies at any time through our cookie settings.
Third-party domains contacted
atome.sgapi.atome.sgstatic.atome.sgCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| atome_session | Functional | Session | Maintains the shopper session through the Atome instalment checkout. |
| _atm_id | Attribution / Analytics | 1 year | Persistent identifier used to attribute completed orders and recognise returning devices. |
| atm_fraud | Security | 6 months | Supports device recognition and fraud prevention during the instalment eligibility check. |
Atome uses cookies for user preferences — inform visitors with a consent banner.
Atome sets cookies for session management, fraud prevention and conversion attribution when its widget or checkout loads. The attribution and fraud cookies are persistent identifiers that are not strictly necessary, so they require consent, while a narrow set of cookies needed to complete a requested payment may be treated as essential.
Yes for the non essential cookies. The attribution and tracking cookies Atome sets need prior consent under the GDPR and the ePrivacy Directive, so they should not load until the shopper accepts. Cookies strictly necessary to process a payment the shopper has requested can rely on a different basis.
Consent under Article 6(1)(a) GDPR covers the attribution cookies, while processing needed to provide the instalment service the shopper requested can rely on contract under Article 6(1)(b). Fraud prevention may rely on legitimate interest, but any profiling with significant effects requires careful justification and transparency.
Yes. Atome operates from Singapore, so shopper data may be transferred to Singapore and other Asia Pacific countries that lack an EU adequacy decision. These transfers must use Standard Contractual Clauses or another Chapter V mechanism with a Transfer Impact Assessment, and you should document them.
A DPIA is recommended because BNPL combines an affordability or fraud assessment, which can amount to profiling with significant effects, with international transfers. Documenting the purposes, the logic of any automated decision, the risks and the safeguards helps you meet Article 35 GDPR and demonstrate accountability.
Add Atome through a CMP that blocks its non essential cookies until consent, keep payment essential cookies separate, and disclose everything in your cookie and privacy notices. Define the controller relationship with Atome, sign the relevant terms, document transfer safeguards, and explain the instalment assessment to shoppers.
Other BNPL providers include Klarna, Clearpay, Scalapay and Alma, the last two being European, which can reduce transfer complexity for EU merchants. All BNPL options involve an eligibility assessment and tracking cookies, so the compliance work is similar regardless of provider.
Describe the Atome cookies, their purpose and duration in your cookie policy, list the Atome domains, and state that data may be transferred to Singapore and other Asia Pacific locations. Explain the affordability assessment in your privacy notice and keep both aligned with the live integration.