FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. E-commerce
  4. authorize.net

authorize.net

PreferencesWebsite

Related services

24nettbutikk

24nettbutikk is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. 24nettbutikk supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, 24nettbutikk ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Preferences

2ClickShop

2ClickShop is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 2ClickShop integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 2ClickShop helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4-Tell

4-Tell is a marketing platform that equips businesses with tools to amplify their digital presence and drive customer acquisition. It supports audience segmentation, campaign automation, and cross-channel engagement. 4-Tell provides real-time analytics and reporting dashboards for performance measurement and strategy optimization. By combining data intelligence with marketing execution, 4-Tell helps deliver the right message to the right audience at the right time.

Preferences

42stores

42stores is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 42stores integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 42stores helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4Partners

4Partners is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 4Partners integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 4Partners helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences
4

4Partners CMS

4Partners CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 4Partners CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with.

Preferences
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Authorize.Net do?

Authorize.Net is a US payment gateway owned by Visa that lets merchants accept cards online via Accept.js, Accept Hosted forms and the Customer Information Manager, with built in fraud detection.

Authorize.Net is one of the oldest payment gateways on the internet. Founded in 1996 and acquired by Visa in 2010, it lets merchants accept credit and debit cards, e-checks, digital wallets, and recurring billing. European merchants typically use it when they also sell in the United States, when they integrate with US shopping carts, or when their acquiring bank routes through Visa.

What Authorize.Net does

Authorize.Net exposes a REST API plus three integration patterns: Accept.js (client side tokenisation, the merchant never sees the card number), Accept Hosted (a fully hosted payment page on accept.authorize.net), and the Customer Information Manager for stored profiles. Visa''s Advanced Fraud Detection Suite enriches every transaction with rule based and machine learning scores.

Cookies and data collected

When Accept.js loads, it sets first party cookies on its own domain (ASP.NET_SessionId, .ASPXAUTH) to maintain the tokenisation context. Accept Hosted runs on accept.authorize.net and sets additional cookies for fraud and session continuity. Authorize.Net processes the card number (or its token), expiry date, CVV, billing address, IP, user agent, and the device fingerprint used by the fraud engine.

GDPR and ePrivacy implications

Cookies set strictly to render the payment form and complete the purchase are considered strictly necessary under Article 5(3) ePrivacy and do not require consent. Fraud and analytics cookies that go beyond that scope do require consent. The processing of payment data has multiple legal bases stacked: contract performance for the payment itself, legitimate interest for fraud prevention, and legal obligation for tax and PSD2 obligations.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Data transfers to the United States

Authorize.Net runs in the United States. Cardholder and fraud data crosses the Atlantic. Visa, the parent company, is certified under the EU-US Data Privacy Framework and offers Standard Contractual Clauses. A Transfer Impact Assessment should be documented.

How to deploy it compliantly

Sign the Authorize.Net DPA, document the transfer mechanism, and prefer Accept Hosted or Accept.js to keep your PCI DSS scope as low as SAQ A. Disclose Authorize.Net in your privacy notice, with the categories of data, the US transfer, retention, and rights. Restrict access to the merchant portal and enable 2FA. If you target the EU only, consider a European acquirer (Stripe, Adyen, Mollie) to avoid the transfer altogether.

GDPR consent category

Preferences

Websites using Authorize.Net must obtain user consent under GDPR regulations.

Legal basisContract performance (Art. 6(1)(b) GDPR) for the payment, legitimate interest (Art. 6(1)(f)) for fraud prevention, consent (Art. 6(1)(a)) for non strictly necessary cookies
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive, PSD2 / Strong Customer Authentication, PCI DSS, EU-US Data Privacy Framework

DPIA considerations

A DPIA can be useful when Authorize.Net is used to process consumer payments at scale in the EU. Document the data flow (cardholder data, billing address, IP, device fingerprint), the US transfer mechanism, the fraud detection signals, and the retention applied by Visa.

Sample consent text

We use Authorize.Net (operated by Visa) to process card payments. Authorize.Net sets cookies on its domain when its hosted form or Accept.js loads, and transfers payment and fraud data to the United States. The payment form is strictly necessary for the transaction; we still inform you about the international transfer.

Technical details

Tracking methodPayment gateway API and hosted payment forms (Accept.js, Accept Hosted, Accept Customer), iFrame integration, fraud detection scripts
Server locationUnited States (operated by Visa, subsidiary of Visa Inc)
Data transferred outside the EUAuthorize.Net is owned by Visa and operated from the United States. All cardholder data, transaction data and fraud signals are transferred to the US. Transfers rely on the EU-US Data Privacy Framework (Visa is certified) and on Standard Contractual Clauses combined with a Transfer Impact Assessment.

Third-party domains contacted

accept.authorize.netapi.authorize.netjstest.authorize.netjs.authorize.netsecure2.authorize.net

Cookies placed

NameTypeDurationPurpose
ASP.NET_SessionIdhttp_cookieSessionSession identifier set by Authorize.Net during payment processing, strictly necessary to complete the transaction.
.ASPXAUTHhttp_cookieSessionAuthentication cookie used by the Authorize.Net merchant portal and Accept Hosted iFrame.
tokenhttp_cookieSessionShort lived payment token cookie used during the Accept Hosted flow to bind the form submission to the merchant transaction.
akamai_bothttp_cookie30 minutesSet by the Akamai bot management layer in front of Authorize.Net for fraud and bot prevention.

Authorize.Net uses cookies for user preferences — inform visitors with a consent banner.

Get started freeScan your site

Frequently asked questions

What cookies does Authorize.Net set?

Accept.js and Accept Hosted typically set ASP.NET_SessionId and .ASPXAUTH on the Authorize.Net domain for session continuity. Additional fraud and tokenisation cookies may be set during the payment flow. These cookies are not stored on the merchant domain when using the hosted variants.

Does Authorize.Net require GDPR consent?

Cookies that are strictly necessary to render the payment form and complete the transaction are exempt from consent under Article 5(3) ePrivacy. Fraud or analytics cookies beyond that scope require consent. Inform users about the payment processor and the US transfer.

What is the legal basis for processing?

Contract performance under Article 6(1)(b) GDPR for the payment, legitimate interest under Article 6(1)(f) for fraud prevention, and legal obligation under Article 6(1)(c) for PSD2 strong customer authentication and tax retention.

Are data transferred outside the EU?

Yes. Authorize.Net is operated by Visa in the United States. Transfers rely on the EU-US Data Privacy Framework and on Standard Contractual Clauses. A Transfer Impact Assessment is recommended for European merchants.

Do I need a DPIA?

A DPIA is recommended for high volume consumer payments, especially when combined with the fraud detection suite that profiles users. Document the data flow, the AI fraud model, the retention, and the safeguards for the US transfer.

How do I implement Authorize.Net compliantly?

Use Accept Hosted or Accept.js to limit PCI scope, sign the DPA, configure Strong Customer Authentication for European cards (3D Secure 2), set retention for stored profiles, and disclose Authorize.Net in your privacy notice with the categories and the US transfer mechanism.

Are there alternatives to Authorize.Net?

For European merchants, consider Stripe, Adyen, Mollie, Worldline, Checkout.com or PayPlug. These providers offer EU acquiring, native SCA support, and clearer EU data residency. Pick based on geography, ticket size, and integration depth.

How do I update my cookie policy for Authorize.Net?

Add a payment processor section that names Authorize.Net, lists the cookies set during the payment, mentions the US transfer mechanism, the legal bases stacked for payment, fraud, and tax, and links to the Authorize.Net privacy notice.