FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. E-commerce
  4. PayPal
P

PayPal

EssentialWebsite

Related services

24nettbutikk

24nettbutikk is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. 24nettbutikk supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, 24nettbutikk ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Preferences

2ClickShop

2ClickShop is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 2ClickShop integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 2ClickShop helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4-Tell

4-Tell is a marketing platform that equips businesses with tools to amplify their digital presence and drive customer acquisition. It supports audience segmentation, campaign automation, and cross-channel engagement. 4-Tell provides real-time analytics and reporting dashboards for performance measurement and strategy optimization. By combining data intelligence with marketing execution, 4-Tell helps deliver the right message to the right audience at the right time.

Preferences

42stores

42stores is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 42stores integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 42stores helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4Partners

4Partners is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 4Partners integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 4Partners helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences
4

4Partners CMS

4Partners CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 4Partners CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with.

Preferences
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does PayPal do?

PayPal is a leading online payment platform enabling businesses to accept payments without storing card data. For EU merchants, PayPal (Europe) S.à r.l. et Cie, S.C.A. (Luxembourg) acts as the payment data controller for the transaction. The core PayPal checkout process relies on contract performance — no separate consent is needed for payment processing. However, the PayPal JavaScript button script may set additional tracking cookies beyond pure payment functionality, which require consent management on non-checkout pages.

What is PayPal?

PayPal is a global online payment platform enabling consumers and businesses to send and receive payments digitally. For e-commerce, PayPal offers checkout solutions (PayPal Checkout, PayPal Buttons, Pay Later) that allow customers to pay without sharing card details with the merchant. PayPal also provides business tools including invoicing, subscriptions, and payment links.

The EU entity: PayPal (Europe)

For European transactions, PayPal (Europe) S.à r.l. et Cie, S.C.A. is the licensed payment service provider and data controller for the payment transaction. This Luxembourg entity is regulated by the Commission de Surveillance du Secteur Financier (CSSF) and subject to EU law including GDPR. The existence of a EU-regulated entity simplifies GDPR compliance compared to pure US-hosted alternatives.

PayPal cookies and tracking

The PayPal checkout button JavaScript loads scripts from paypal.com that set cookies when loaded on any page — not just checkout pages. If the PayPal button is embedded on product pages or homepage, it may set tracking cookies (tsrce, x-csrf-jwt, PYPF) before any purchase intent. Loading the PayPal script only on checkout pages where contract performance applies reduces consent complexity significantly.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Practical compliance steps

Only load the PayPal JavaScript on checkout pages (not site-wide). Accept PayPal''s Merchant Agreement which includes GDPR DPA terms for EU merchants. Disclose PayPal in your privacy policy as a payment processor, including that PayPal is an independent controller for fraud detection. For the PayPal button outside checkout, use a CMP to block until payment/functional consent is given.

GDPR consent category

Essential

Websites using PayPal must obtain user consent under GDPR regulations.

Legal basisContract performance (Art. 6(1)(b)) for payment processing — no consent required for the core PayPal checkout transaction. Legitimate interest for fraud detection and security. Consent required for PayPal marketing cookies and cross-site tracking if the PayPal button script loads tracking beyond payment functionality on non-checkout pages.
Risk levellow
Applicable regulationsGDPR, PCI DSS Level 1, EU Payment Services Directive (PSD2). PayPal (Europe) operates under Luxembourg financial regulation.

DPIA considerations

A DPIA is not required for standard PayPal payment integration. PayPal handles PCI DSS compliance for payment card data, reducing the merchant's compliance burden for the payment data itself.

Sample consent text

This website uses PayPal for secure payment processing. PayPal processes your payment information to complete your transaction. For payments, PayPal (Europe) is the data controller. See PayPal's privacy policy for full details on payment data processing.

Technical details

Tracking methodPayment processing, PayPal checkout button JavaScript, cookies for fraud detection, cross-site tracking for logged-in PayPal users
Server locationUnited States (PayPal Inc., Luxembourg entity for EU)
Data transferred outside the EUPayPal is a US payment company with a European entity (PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg). For EU transactions, PayPal (Europe) is the data controller for payment processing under Luxembourg law. Some data may still be transferred to US infrastructure for fraud detection and global risk management. PayPal provides GDPR-compliant terms for EU merchants.

Third-party domains contacted

paypal.comwww.paypal.comjs.braintreegateway.com

Cookies placed

NameTypeDurationPurpose
ENFORCE_POLICYsessionSessionPayPal payment session enforcement cookie strictly necessary for secure checkout processing
tsrcesessionSessionPayPal telemetry and session cookie for maintaining the active payment session

PayPal is an essential service, but transparency matters. Manage all your consent with FlowConsent.

Get started freeScan your site

Frequently asked questions

Does PayPal require consent for payment processing?

No. Contract performance applies. However if the PayPal button loads on non-checkout pages it may set tracking cookies requiring consent management.

What is PayPal (Europe) and why does it matter?

PayPal (Europe) S.à r.l. et Cie, S.C.A. is Luxembourg-licensed and the EU data controller for payment transactions, subject to EU law and GDPR directly.

What cookies does the PayPal button set?

tsrce (fraud detection), x-csrf-jwt (security), PYPF (browser fingerprint for fraud), l7_az (session routing). Necessary on checkout pages; may need consent elsewhere.

Do I need a DPA with PayPal?

PayPal's Merchant Agreement includes data processing terms for EU merchants. Enterprise merchants can request a formal DPA. Standard acceptance covers most requirements.

How should I disclose PayPal in my privacy policy?

State: PayPal processes payments, PayPal (Europe) is an independent controller, what data is shared, that PayPal has its own privacy policy, and link to PayPal's Privacy Statement.

Is PayPal Pay Later subject to automated decision GDPR obligations?

Yes. Pay in instalments involves automated credit assessment under GDPR Art. 22. PayPal manages this as the credit provider. Merchants should disclose it in their privacy policy.

Does PayPal process data in the US?

Some data may transfer to US infrastructure for fraud detection. PayPal's merchant terms include SCCs. The Luxembourg entity provides a stronger position than pure US alternatives.

What are EU-based PayPal alternatives?

Stripe (Irish entity), Adyen (Dutch), Mollie (Dutch), Klarna (Swedish). For maximum EU data residency, Mollie and Adyen are the strongest EU-first options.