FlowConsent
ServicesHow it worksPricingBlogDocumentation
ServicesHow it worksPricingBlogDocumentationLog inTry FlowConsent
Log inTry FlowConsent
FlowConsent

GDPR-compliant consent, EU-hosted, live in under ten minutes — without a cookie wall.

EU-HOSTED·RGPD·SOC 2
Product
  • Services
  • How it works
  • Pricing
  • Extension
Company
  • Blog
  • Documentation
  • Solutions
  • FlowConsent App
Legal
  • Privacy Policy
  • Terms of Service
  • Legal notice
  • Cookies
© 2026 FlowConsent by BeBranded. All rights reserved.
FrancaisDeutschEspanol
All systems operational

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. E-commerce
  4. SumUp

SumUp

PreferencesWebsite

Related services

24nettbutikk

24nettbutikk is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. 24nettbutikk supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, 24nettbutikk ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Preferences

2ClickShop

2ClickShop is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 2ClickShop integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 2ClickShop helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4-Tell

4-Tell is a marketing platform that equips businesses with tools to amplify their digital presence and drive customer acquisition. It supports audience segmentation, campaign automation, and cross-channel engagement. 4-Tell provides real-time analytics and reporting dashboards for performance measurement and strategy optimization. By combining data intelligence with marketing execution, 4-Tell helps deliver the right message to the right audience at the right time.

Preferences

42stores

42stores is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 42stores integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 42stores helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4Partners

4Partners is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 4Partners integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 4Partners helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences
4

4Partners CMS

4Partners CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 4Partners CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with.

Preferences
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does SumUp do?

SumUp is a German fintech headquartered in Berlin that provides payment processing, online checkout pages and an embeddable card payment widget. Its checkout sets strictly necessary cookies to operate the payment and prevent fraud, and where enabled it adds performance, analytics and advertising cookies that require consent. Core payment data is processed within the European Union, though some fraud prevention and analytics partners may sit outside the EU. Because it handles card payments, it is governed by both GDPR and PSD2.

What SumUp Is

SumUp is a German fintech company headquartered in Berlin that provides payment acceptance for businesses of all sizes. For websites it offers hosted checkout pages and an embeddable card payment widget that collects card details and processes the transaction. Because card data is captured inside SumUp controlled fields, the merchant generally stays out of scope for handling raw card numbers, which simplifies card industry compliance. SumUp operates under EU financial regulation and is subject to the revised Payment Services Directive known as PSD2. The widget loads from SumUp domains and sets cookies needed to run the payment and to detect fraud. Understanding which cookies are strictly necessary and which require consent is the key to compliant deployment.

Cookies and Data Collected

SumUp sets strictly necessary cookies that allow access to the checkout, identify irregular site behaviour, prevent fraudulent activity and improve security, and these cannot be refused without breaking the payment. Where enabled it also uses performance and analytics cookies to understand how visitors use the service and to measure page speed, and it can set advertising cookies for marketing. The data collected at checkout includes payment details, transaction amounts, contact information and technical metadata such as IP address and device information used for fraud prevention. The strictly necessary and fraud related cookies do not need consent, but the analytics and advertising cookies do. It is important to keep this distinction clear in your cookie banner and policy. Always confirm the live cookie set, as it can vary by region and configuration.

GDPR and ePrivacy Implications

Under the GDPR the legal basis for processing a payment is contract performance, because the customer asks you to take the payment, while fraud prevention and securing the transaction rest on legitimate interest. Under the ePrivacy Directive the strictly necessary payment and fraud cookies are exempt from consent, but any analytics or advertising cookies require prior opt in. SumUp acts as a processor or in some respects an independent controller for payment data, so you need the appropriate agreement and a clear understanding of the roles. PSD2 adds obligations such as strong customer authentication, which interacts with the data you collect at checkout. You remain responsible for informing customers about the processing in your privacy notice. Keeping necessary and optional cookies clearly separated is central to compliance.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent Requirements and CMP Integration

You do not need consent for the strictly necessary checkout and fraud cookies, so the payment widget itself can load to let customers pay. You do need prior consent for the analytics and advertising cookies, which should be wired into your consent management platform and blocked until the visitor accepts the relevant category. A good pattern is to let the payment function work while gating only the optional tracking. Your consent banner should explain that some cookies are essential to complete and secure the payment, and that others are optional. Make sure declining the optional categories genuinely prevents those cookies from being set. Document the consent choices so you can demonstrate compliance to a supervisory authority.

International Data Transfers

SumUp is a German company and processes core payment data within the European Union, which is favourable for data residency. However, it relies on service providers including fraud prevention, identity verification and analytics partners, some of which may be located outside the EU. Where personal data flows to such providers in a third country, the transfer must be covered by an appropriate safeguard such as the EU US Data Privacy Framework or Standard Contractual Clauses, supported by a transfer impact assessment. Optional analytics and advertising tools can also involve third country transfers and these are tied to consent. Review the SumUp documentation and subprocessor list to confirm where data goes. Record the safeguards in your processing records and privacy notice.

Practical Compliance Steps

Start by putting the right data processing terms in place with SumUp and reviewing its subprocessor list and transfer safeguards. Configure your consent management platform so the strictly necessary payment and fraud cookies run while analytics and advertising cookies are blocked until consent. Update your privacy notice and cookie policy to explain the payment processing, the legal bases of contract and legitimate interest, and the consent based optional cookies. Set retention periods for transaction data that respect financial record keeping rules and apply data minimisation elsewhere. Implement strong customer authentication as required by PSD2 and make sure your checkout flow supports it. Complete a transfer impact assessment for any non EU providers and, where the risk is significant, a Data Protection Impact Assessment. Finally, keep your documentation aligned with the live configuration.

GDPR consent category

Preferences

Websites using SumUp must obtain user consent under GDPR regulations.

Legal basisContract performance (GDPR Article 6(1)(b)) for processing a payment the customer requested, plus Legitimate Interest (Article 6(1)(f)) for fraud prevention and securing the transaction. Consent (Article 6(1)(a)) is required for any analytics or advertising cookies beyond what is strictly necessary.
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive, PSD2, TTDSG (Germany), CNIL guidelines, LOPDGDD (Spain)

DPIA considerations

Payment processing involves financial data and fraud detection, so a careful assessment is warranted, especially for high transaction volumes or where payment behaviour is profiled. A Data Protection Impact Assessment should document the categories of data collected at checkout, the strictly necessary versus consent based cookies, the fraud prevention processing under legitimate interest, and any transfers to service providers outside the EU. Record the PSD2 obligations such as strong customer authentication and how they interact with data minimisation. Note retention periods for transaction records, which may be set by financial regulation.

Sample consent text

This website uses SumUp to process payments securely. Cookies that are strictly necessary to complete your payment and to prevent fraud are always active. With your consent, we also set analytics and advertising cookies; you can accept or decline these at any time.

Technical details

Tracking methodHosted payment checkout and card widget loaded from SumUp domains. It sets strictly necessary cookies to operate the checkout, identify irregular site behaviour and prevent fraud, and, where enabled, performance and analytics cookies plus advertising cookies that require consent. Card data is handled by SumUp so the merchant stays out of scope for raw card numbers.
Server locationEuropean Union. SumUp is a German fintech headquartered in Berlin and operates under EU financial regulation, processing payment data within the EU. Some service providers and analytics partners may be located outside the EU.
Data transferred outside the EUCore payment processing is performed within the EU by a German company, but SumUp uses service providers including fraud prevention, verification and analytics partners, some of which may be located outside the EU. Any such transfer must be covered by an appropriate safeguard such as the EU US Data Privacy Framework or Standard Contractual Clauses. Optional analytics and advertising cookies can involve third country transfers and require consent.

Third-party domains contacted

sumup.comapi.sumup.compay.sumup.comgateway.sumup.com

Cookies placed

NameTypeDurationPurpose
Checkout sessionstrictly_necessarysessionOperates the checkout and maintains the secure payment session so the customer can complete the transaction.
Fraud preventionstrictly_necessarysession to persistentIdentifies irregular site behaviour, detects unusual transaction patterns and prevents fraudulent activity to secure the payment.
Performance and analyticsanalyticsup to 2 yearsMeasures how visitors use the service and metrics such as page speed. Not strictly necessary and requires consent.
Advertisingmarketingup to 1 yearUsed for advertising and marketing purposes. Not strictly necessary and requires consent.

SumUp uses cookies for user preferences — inform visitors with a consent banner.

Get started freeScan your site

Frequently asked questions

What cookies does SumUp set?

SumUp sets strictly necessary cookies that operate the checkout, identify irregular site behaviour and prevent fraud, which cannot be refused without breaking the payment. Where enabled it also sets performance and analytics cookies and advertising cookies, which are not strictly necessary and require consent. Always confirm the live cookie set, as it can vary by region and configuration.

Is consent required to use SumUp?

Consent is not required for the strictly necessary payment and fraud prevention cookies, so the checkout can function. Consent is required for the optional analytics and advertising cookies, which must be blocked until the visitor accepts the relevant category through your consent banner.

What is the legal basis for using SumUp?

The legal basis is contract performance under GDPR Article 6(1)(b) for processing the payment the customer requested, plus legitimate interest under Article 6(1)(f) for fraud prevention and securing the transaction. Any analytics or advertising cookies need consent under Article 6(1)(a).

Does SumUp transfer data to the United States?

Core payment processing is performed within the EU by a German company. However, SumUp uses service providers including fraud prevention, verification and analytics partners, some of which may be outside the EU, so a transfer can occur. Such transfers must be covered by a safeguard such as the EU US Data Privacy Framework or Standard Contractual Clauses.

Do I need a DPIA for SumUp?

A Data Protection Impact Assessment is advisable because payment processing involves financial data and fraud detection, particularly for high transaction volumes or where payment behaviour is profiled. The DPIA should cover the data collected at checkout, the cookie categories, the fraud prevention processing and any transfers to non EU providers.

How do I implement SumUp compliantly?

Put the right data processing terms in place, review the subprocessor list, and configure your consent management platform so necessary payment and fraud cookies run while analytics and advertising cookies are blocked until consent. Update your privacy and cookie policies, set retention for transaction data, and implement strong customer authentication required by PSD2.

What are alternatives to SumUp?

Other payment providers include Stripe, Mollie, Adyen and Worldpay, each with its own cookie and data processing profile. For the strongest EU data residency, prefer a provider that processes payment data in the EU and keeps optional analytics and advertising cookies clearly separated and consent based, as SumUp does.

How do I update my cookie policy for SumUp?

List the strictly necessary payment and fraud cookies separately from the optional analytics and advertising cookies, with their purpose and approximate duration. State that SumUp is the payment processor, that core data is handled in the EU, and disclose any non EU service providers and the safeguard relied on. Review the entry whenever the configuration changes.