Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
HiPay is a French payment service provider that processes online transactions and runs fraud prevention. Its payment cookies are strictly necessary and rely on contract and legal obligation, while the device data it analyses for fraud relies on legitimate interest, all within the European Union.
HiPay is a French payment service provider that handles online card and alternative payments for merchants, along with fraud prevention and payment analytics. When integrated into a checkout, it processes the transaction, verifies the payment, and applies risk scoring to detect fraudulent activity.
HiPay sets cookies needed to run the payment session securely and collects device and transaction data, including elements used for fraud detection such as a device fingerprint, IP address, and payment metadata. This information is personal data under the GDPR and supports both completing the payment and preventing fraud.
Cookies strictly necessary to process a payment the customer has requested are exempt from consent under Article 5(3) ePrivacy. Processing payment data rests on the payment contract and on legal obligations such as anti money laundering rules, while the device analysis for fraud prevention relies on legitimate interest with appropriate safeguards.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
You generally do not need consent for the strictly necessary payment and fraud prevention processing, but you must be transparent about the device data used and the risk scoring applied. If HiPay or your setup adds analytics or marketing beyond payment, those require consent like any other non essential tracking.
Sign a data processing agreement, document contract, legal obligation, and legitimate interest as the relevant bases, and run a legitimate interest assessment for the fraud scoring. Explain the payment and fraud processing in your privacy notice, confirm EU processing, and keep transaction data only as long as legal retention rules require.
Websites using HiPay must obtain user consent under GDPR regulations.
DPIA considerations
HiPay processes payment data and applies fraud scoring that profiles transactions, so a legitimate interest assessment is needed and a DPIA may be appropriate where the scoring significantly affects customers. Processing stays within the EU, which reduces transfer risk.
Sample consent text
We use HiPay to process your payment securely and to prevent fraud. These functions rely on data that is necessary to complete and protect your transaction.
Third-party domains contacted
hipay.comsecure.hipay.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| hipay_session | Functional | Session | Secures the payment session while a transaction is processed |
| hipay_device | Security | 1 year | Stores a device identifier used to detect and prevent payment fraud |
HiPay uses cookies for user preferences — inform visitors with a consent banner.
HiPay sets a functional cookie to secure the payment session and a security cookie that stores a device identifier used for fraud prevention. Both support completing and protecting the transaction.
The strictly necessary payment cookies are exempt from consent under Article 5(3) ePrivacy, and fraud prevention relies on legitimate interest, so consent is generally not required. Consent applies only to any analytics or marketing added on top.
Payment processing relies on performance of a contract and on legal obligations under Article 6(1)(b) and (c), while fraud prevention relies on legitimate interest under Article 6(1)(f) supported by a documented assessment.
No. HiPay is a French provider and payment and transaction data are processed within the European Union in a standard setup. Confirm the processing locations in your agreement.
A legitimate interest assessment is needed for the fraud scoring, and a DPIA may be appropriate where automated scoring significantly affects customers. The EU processing limits transfer related risk.
Sign a data processing agreement, document the payment, legal obligation, and fraud prevention bases, run a legitimate interest assessment, explain the processing in your privacy notice, and keep transaction data only as long as legally required.
Other European payment service providers offer comparable processing and fraud prevention. The compliance position is similar because payment cookies are strictly necessary and fraud scoring relies on legitimate interest.
List the HiPay payment and fraud prevention cookies as strictly necessary or security cookies with their purpose and duration, and explain the device data used for fraud detection. Add any analytics separately under consent.