Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Paysafe is a global payments group that provides hosted payment fields, JavaScript checkout, 3D Secure and tokenization, with fraud and anti money laundering controls.
Paysafe is a global payments group headquartered in the United Kingdom and operated by Paysafe Limited. It also runs brands such as Paysafecard, Skrill and Neteller, and processes payments across the United Kingdom, the European Union, the United States and Canada.
The integration uses hosted payment fields and a JavaScript checkout with tokenization and 3D Secure. It sets strictly necessary cookies to complete the payment, remember privacy preferences and meet legal and regulatory duties including anti money laundering and fraud prevention, and it processes payment and device data for those purposes.
Strictly necessary payment cookies are generally exempt from the consent rule in the ePrivacy Directive because they are required to deliver a service the user has requested. Processing rests on contract, on legal obligations for anti money laundering, and on legitimate interests for fraud prevention.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Consent is not needed for the necessary payment cookies, but any analytics or marketing cookies that a merchant adds around the checkout do require prior consent. Merchants should keep the necessary and optional categories clearly separated in their consent banner.
Paysafe processes data across several countries, including outside the European Economic Area. Transfers rely on adequacy decisions where they apply and on Standard Contractual Clauses with supplementary measures elsewhere, and these arrangements should be reflected in the data processing agreement.
Sign the Paysafe data processing agreement, document the legal bases and transfers, and describe the necessary payment cookies in your cookie policy. Gate any added analytics behind consent and keep records of the AML and fraud processing that applies to your account.
Websites using Paysafe must obtain user consent under GDPR regulations.
DPIA considerations
A DPIA may be warranted given the scale of payment processing, fraud and AML profiling, and global data flows. Strictly necessary payment cookies are generally exempt from consent, but any analytics added by the merchant and the breadth of transfers should be assessed.
Sample consent text
We use Paysafe to process your payment securely. Strictly necessary cookies that complete the transaction and meet legal and fraud prevention duties are always active. Any analytics or marketing cookies are set only with your consent, which you can withdraw at any time.
Third-party domains contacted
paysafe.comhosted.paysafe.comapi.paysafe.comcdn.paysafe.compay.paysafe.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| Payment session cookie | Third-party | Session | Maintains the secure payment session and completes the checkout the user requested |
| Privacy preference cookie | Third-party | 1 year | Stores the visitor privacy and cookie preferences |
| Fraud and AML cookie | Third-party | 1 year | Supports fraud prevention and anti money laundering checks required by regulation |
| Analytics cookie | Third-party | 2 years | Measures site performance on Paysafe owned websites where consent is given |
Paysafe uses cookies for user preferences — inform visitors with a consent banner.
Paysafe sets strictly necessary cookies that complete the payment, remember privacy preferences and meet legal and regulatory duties such as anti money laundering and fraud prevention. On its own websites it may also use analytics cookies that depend on consent.
Consent is not required for the strictly necessary payment cookies, which are exempt because they deliver a service the user requested. Consent is required for any analytics or marketing cookies that a merchant adds around the Paysafe checkout.
Processing rests on performance of a contract under Article 6(1)(b) for completing payments, legal obligation under Article 6(1)(c) for anti money laundering and regulatory duties, and legitimate interests under Article 6(1)(f) for fraud prevention.
Yes. Paysafe operates globally and may process data in the United Kingdom, the European Union, the United States and Canada. Transfers outside the EEA rely on adequacy decisions where available and on Standard Contractual Clauses with supplementary measures otherwise.
A DPIA may be warranted given the scale of payment processing, fraud and AML profiling and the global data flows. Where the merchant only uses the standard checkout, a focused assessment of transfers and added analytics is usually sufficient.
Sign the Paysafe data processing agreement, document the legal bases and transfers, and describe the necessary payment cookies in your cookie policy. Keep any added analytics behind consent and retain records of the AML and fraud processing for your account.
Alternatives include other global payment processors such as Stripe, Adyen, Worldpay and Checkout.com. Each offers hosted fields or tokenized checkout but differs in server locations, cookie behaviour and transfer mechanisms that should be reviewed individually.
Add a Paysafe entry that describes the strictly necessary payment cookies, their purposes and durations and the relevant transfers. Note any analytics you add separately under an optional category and keep the entry current as your integration evolves.