FlowConsent
ServicesHow it worksPricingBlogDocumentation
ServicesHow it worksPricingBlogDocumentationLog inTry FlowConsent
Log inTry FlowConsent
FlowConsent

GDPR-compliant consent, EU-hosted, live in under ten minutes — without a cookie wall.

EU-HOSTED·RGPD·SOC 2
Product
  • Services
  • How it works
  • Pricing
  • Extension
Company
  • Blog
  • Documentation
  • Solutions
  • FlowConsent App
Legal
  • Privacy Policy
  • Terms of Service
  • Legal notice
  • Cookies
© 2026 FlowConsent by BeBranded. All rights reserved.
FrancaisDeutschEspanol
All systems operational

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. E-commerce
  4. WorldPay

WorldPay

PreferencesWebsite

Related services

24nettbutikk

24nettbutikk is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. 24nettbutikk supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, 24nettbutikk ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Preferences

2ClickShop

2ClickShop is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 2ClickShop integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 2ClickShop helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4-Tell

4-Tell is a marketing platform that equips businesses with tools to amplify their digital presence and drive customer acquisition. It supports audience segmentation, campaign automation, and cross-channel engagement. 4-Tell provides real-time analytics and reporting dashboards for performance measurement and strategy optimization. By combining data intelligence with marketing execution, 4-Tell helps deliver the right message to the right audience at the right time.

Preferences

42stores

42stores is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 42stores integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 42stores helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4Partners

4Partners is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 4Partners integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 4Partners helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences
4

4Partners CMS

4Partners CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 4Partners CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with.

Preferences
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Worldpay do?

Worldpay is a global payment gateway and acquirer (UK/US, now GTCR-owned following divestiture from FIS) that provides merchants with card payment processing, fraud screening and 3D Secure authentication. A JavaScript SDK is loaded on the checkout page to collect card data and perform fraud assessments. Session cookies and device fingerprinting strictly necessary to complete a payment transaction are exempt from consent under the ePrivacy Directive. However, fraud profiling that extends beyond the checkout session and involves broader behavioural data collection may require a separate legal basis or consent. Data is processed in the UK and US/global infrastructure.

What is Worldpay?

Worldpay is one of the world's largest payment gateways, with origins in the UK and a global footprint spanning the US and beyond. Now owned by private equity firm GTCR following divestiture from FIS, Worldpay provides card payment acceptance, fraud screening and 3D Secure authentication. Merchants integrate via a JavaScript SDK loading scripts from worldpay.com or secure.worldpay.com. Worldpay is a payment gateway and acquirer, not an e-commerce platform or shopping cart.

Cookies and device data collected

Worldpay sets session cookies during checkout to maintain payment session integrity and support 3D Secure authentication required under PSD2. Worldpay's integrated fraud tools may also perform device fingerprinting, collecting browser and device attributes to generate a fraud risk score. Cookies and fingerprinting used strictly to complete the current payment transaction and satisfy PSD2 SCA requirements are technically necessary for the service the user has requested.

GDPR legal basis: strictly necessary vs. contested fraud profiling

Cookies and fingerprinting strictly necessary to complete the user-initiated payment fall under performance of a contract (Art. 6(1)(b) GDPR) and the ePrivacy strictly-necessary exemption. These do not require consent. When Worldpay's JavaScript is loaded on pages beyond the checkout, collecting fraud signals from all visitors not actively paying, that broader processing cannot rely on the contract basis. It would require a documented Legitimate Interests Assessment under Art. 6(1)(f) GDPR or, if particularly intrusive, explicit consent.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Data transfers: UK, US and global processing

Worldpay's UK infrastructure benefits from the EU adequacy decision for the UK. Processing in the United States and other global locations requires Standard Contractual Clauses (SCCs) or the EU-US Data Privacy Framework (DPF). Merchants should review and retain Worldpay's current Data Processing Agreement, confirm the applicable transfer mechanism, and disclose international data transfers in their privacy notices.

PSD2, SCA and regulatory context

Worldpay is regulated under PSD2 for EU card transactions. PSD2's Strong Customer Authentication requirement mandates two-factor authentication for most online card payments. Worldpay's 3DS2 integration satisfies SCA. Data processed for SCA, including device binding and authentication signals, is required by financial regulation and does not need separate GDPR consent. Merchants should explain SCA processing in their privacy notices and ensure their DPA is current.

Practical compliance steps for merchants

Sign and retain Worldpay's Data Processing Agreement. Update your privacy notice to name Worldpay as payment processor, describe the data processed, reference the UK adequacy decision and note the SCCs or DPF for US transfers. Do not include Worldpay's strictly necessary payment cookies in your consent layer. Scope the SDK to the checkout page and if you use fraud tools across the full site, document your Legitimate Interests Assessment. Review your implementation and DPA annually or after any Worldpay ownership or infrastructure changes.

GDPR consent category

Preferences

Websites using Worldpay must obtain user consent under GDPR regulations.

Legal basisStrictly necessary (Art. 6(1)(b) GDPR) for payment gateway processing; Legitimate Interests (Art. 6(1)(f)) or Consent for fraud profiling beyond the checkout session
Risk levelmedium
Applicable regulationsGDPR, UK GDPR, ePrivacy Directive, PCI DSS, PSD2

DPIA considerations

A DPIA is unlikely to be required for standard Worldpay payment gateway use, as the processing is necessary for the performance of a contract. However, if Worldpay's fraud-detection JavaScript or SDK is deployed across pages outside the checkout flow, performing behavioural profiling of all site visitors, a DPIA should be assessed given the scale and intrusiveness of such processing. Document the processing in your Art. 30 records, noting the UK adequacy decision and the SCCs or DPF for US-side transfers via FIS/GTCR infrastructure.

Sample consent text

Worldpay is our payment gateway. When you proceed to payment, Worldpay loads its payment SDK to securely process your card details and carry out fraud prevention checks. This processing is strictly necessary to complete your purchase and does not require your separate consent. For more details, see our privacy notice.

Technical details

Tracking methodJavaScript payment SDK, session cookies, device fingerprinting via integrated fraud tools
Server locationUnited Kingdom, United States, global
Data transferred outside the EUData processed in the UK (adequacy decision) and US/global infrastructure (FIS/GTCR). US transfers require SCCs or EU-US Data Privacy Framework (DPF).

Third-party domains contacted

worldpay.comsecure.worldpay.comaccess.worldpay.com

Cookies placed

NameTypeDurationPurpose
Payment session cookiesessionSessionMaintains the integrity of the payment session between the customer browser and Worldpay's payment infrastructure, correlating the payment attempt with the authorisation response.
3D Secure authentication cookiesessionSessionSupports the 3DS2 Strong Customer Authentication flow required by PSD2, binding the authentication challenge to the payment authorisation.
Fraud risk fingerprint cookiepersistentUp to 1 yearStores device and browser fingerprint identifiers used by Worldpay's fraud-scoring engine to assess the risk level of a payment transaction and flag potentially fraudulent attempts.

Worldpay uses cookies for user preferences — inform visitors with a consent banner.

Get started freeScan your site

Frequently asked questions

What cookies does Worldpay set?

Worldpay sets session-scoped cookies during the payment process to maintain the integrity of the payment session and support 3D Secure (3DS2) authentication. Worldpay's fraud tools may also collect device fingerprint data (browser attributes, IP address, timezone, screen resolution) and store related identifiers as part of fraud risk scoring. Cookies strictly necessary for the secure completion of the payment transaction are not advertising cookies. Their exact names and behaviour may vary by integration type (JS SDK, hosted payment page, or direct API); use browser developer tools or a cookie scanner on your checkout page to identify the current set.

Is consent required to use Worldpay?

No, for standard payment gateway processing. Cookies and device signals strictly necessary to complete a payment transaction initiated by the user are exempt from the consent requirement under Art. 5(3) of the ePrivacy Directive. You do not need to present a cookie banner consent option for Worldpay's payment session cookies. However, if Worldpay's JavaScript is loaded on pages other than the checkout (e.g. product or category pages) and collects fraud signals from all visitors, that broader profiling may require a Legitimate Interests Assessment or, in some cases, explicit consent.

What is the legal basis for Worldpay processing data?

For payment processing, the legal basis is performance of a contract (Art. 6(1)(b) GDPR): the user has made a purchase and the payment must be processed to fulfil the order. Fraud prevention during the transaction is also justified by Art. 6(1)(b) and by legal obligations under PSD2 (Art. 6(1)(c)). If Worldpay is used for broader behavioural fraud profiling of site visitors beyond the checkout page, Legitimate Interests (Art. 6(1)(f)) may apply, but this requires a documented Legitimate Interests Assessment showing the processing is proportionate and does not override users' interests.

Does Worldpay transfer data to the US or other countries?

Yes. Worldpay operates UK infrastructure (covered by the EU adequacy decision) and US/global infrastructure via its parent company (GTCR, formerly FIS). US and other third-country transfers require Standard Contractual Clauses (SCCs) or the EU-US Data Privacy Framework (DPF). You should obtain Worldpay's current Data Processing Agreement (DPA), verify the transfer mechanisms in place, and disclose them in your privacy notice, specifying the countries to which data may be transferred and the safeguards applied.

Do I need a DPIA for Worldpay?

A DPIA is not typically required for standard Worldpay payment gateway processing. However, if you deploy Worldpay's fraud-screening JavaScript across your entire website, potentially profiling all visitors (not just those transacting), the combination of scale and intrusiveness of the device fingerprinting may trigger the DPIA threshold under Art. 35 GDPR. Consult your supervisory authority's published list of processing types requiring a mandatory DPIA. Document your assessment in your Art. 30 records either way.

How do I implement Worldpay in a GDPR-compliant way?

Sign Worldpay's Data Processing Agreement and retain a copy. Update your privacy notice to name Worldpay as your payment processor, describe the categories of data processed (card details, IP address, device fingerprint, authentication data), reference the UK adequacy decision and cite the SCCs or DPF for US transfers. Do not include Worldpay's strictly necessary payment cookies in your cookie consent layer. Keep the Worldpay SDK scoped to the checkout page. If you deploy fraud tools more broadly, document your Legitimate Interests Assessment. Review DPA and SDK documentation annually or after any Worldpay ownership changes.

What alternatives to Worldpay exist for European merchants?

Alternatives include Adyen (Netherlands, strong EU data residency, listed company), Stripe (US, with EU data processing options and SCCs), Checkout.com (UK, similar risk profile to Worldpay), and Mollie (Netherlands, EU-focused). All major payment gateways have similar data transfer considerations; the key compliance differentiators are the strength of their DPA, availability of EU-side processing, SCA compliance track record, and whether they offer server-side integration options that minimise browser-level data collection.

How should I mention Worldpay in my cookie policy?

In your cookie policy or privacy notice, include a section on payment processing. Name Worldpay as the payment gateway, describe the cookies as strictly necessary for completing a card payment transaction, state that they do not require consent, and note that they are session-scoped and expire after the transaction. Reference the transfer of data to the UK (adequacy decision) and to the US and other countries (SCCs or DPF). Link to Worldpay's own privacy notice for further detail and review your cookie policy after any Worldpay integration changes.