Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Worldpay is a global payment gateway and acquirer (UK/US, now GTCR-owned following divestiture from FIS) that provides merchants with card payment processing, fraud screening and 3D Secure authentication. A JavaScript SDK is loaded on the checkout page to collect card data and perform fraud assessments. Session cookies and device fingerprinting strictly necessary to complete a payment transaction are exempt from consent under the ePrivacy Directive. However, fraud profiling that extends beyond the checkout session and involves broader behavioural data collection may require a separate legal basis or consent. Data is processed in the UK and US/global infrastructure.
Worldpay is one of the world's largest payment gateways, with origins in the UK and a global footprint spanning the US and beyond. Now owned by private equity firm GTCR following divestiture from FIS, Worldpay provides card payment acceptance, fraud screening and 3D Secure authentication. Merchants integrate via a JavaScript SDK loading scripts from worldpay.com or secure.worldpay.com. Worldpay is a payment gateway and acquirer, not an e-commerce platform or shopping cart.
Worldpay sets session cookies during checkout to maintain payment session integrity and support 3D Secure authentication required under PSD2. Worldpay's integrated fraud tools may also perform device fingerprinting, collecting browser and device attributes to generate a fraud risk score. Cookies and fingerprinting used strictly to complete the current payment transaction and satisfy PSD2 SCA requirements are technically necessary for the service the user has requested.
Cookies and fingerprinting strictly necessary to complete the user-initiated payment fall under performance of a contract (Art. 6(1)(b) GDPR) and the ePrivacy strictly-necessary exemption. These do not require consent. When Worldpay's JavaScript is loaded on pages beyond the checkout, collecting fraud signals from all visitors not actively paying, that broader processing cannot rely on the contract basis. It would require a documented Legitimate Interests Assessment under Art. 6(1)(f) GDPR or, if particularly intrusive, explicit consent.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Worldpay's UK infrastructure benefits from the EU adequacy decision for the UK. Processing in the United States and other global locations requires Standard Contractual Clauses (SCCs) or the EU-US Data Privacy Framework (DPF). Merchants should review and retain Worldpay's current Data Processing Agreement, confirm the applicable transfer mechanism, and disclose international data transfers in their privacy notices.
Worldpay is regulated under PSD2 for EU card transactions. PSD2's Strong Customer Authentication requirement mandates two-factor authentication for most online card payments. Worldpay's 3DS2 integration satisfies SCA. Data processed for SCA, including device binding and authentication signals, is required by financial regulation and does not need separate GDPR consent. Merchants should explain SCA processing in their privacy notices and ensure their DPA is current.
Sign and retain Worldpay's Data Processing Agreement. Update your privacy notice to name Worldpay as payment processor, describe the data processed, reference the UK adequacy decision and note the SCCs or DPF for US transfers. Do not include Worldpay's strictly necessary payment cookies in your consent layer. Scope the SDK to the checkout page and if you use fraud tools across the full site, document your Legitimate Interests Assessment. Review your implementation and DPA annually or after any Worldpay ownership or infrastructure changes.
Websites using Worldpay must obtain user consent under GDPR regulations.
DPIA considerations
A DPIA is unlikely to be required for standard Worldpay payment gateway use, as the processing is necessary for the performance of a contract. However, if Worldpay's fraud-detection JavaScript or SDK is deployed across pages outside the checkout flow, performing behavioural profiling of all site visitors, a DPIA should be assessed given the scale and intrusiveness of such processing. Document the processing in your Art. 30 records, noting the UK adequacy decision and the SCCs or DPF for US-side transfers via FIS/GTCR infrastructure.
Sample consent text
Worldpay is our payment gateway. When you proceed to payment, Worldpay loads its payment SDK to securely process your card details and carry out fraud prevention checks. This processing is strictly necessary to complete your purchase and does not require your separate consent. For more details, see our privacy notice.
Third-party domains contacted
worldpay.comsecure.worldpay.comaccess.worldpay.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| Payment session cookie | session | Session | Maintains the integrity of the payment session between the customer browser and Worldpay's payment infrastructure, correlating the payment attempt with the authorisation response. |
| 3D Secure authentication cookie | session | Session | Supports the 3DS2 Strong Customer Authentication flow required by PSD2, binding the authentication challenge to the payment authorisation. |
| Fraud risk fingerprint cookie | persistent | Up to 1 year | Stores device and browser fingerprint identifiers used by Worldpay's fraud-scoring engine to assess the risk level of a payment transaction and flag potentially fraudulent attempts. |
Worldpay uses cookies for user preferences — inform visitors with a consent banner.
Worldpay sets session-scoped cookies during the payment process to maintain the integrity of the payment session and support 3D Secure (3DS2) authentication. Worldpay's fraud tools may also collect device fingerprint data (browser attributes, IP address, timezone, screen resolution) and store related identifiers as part of fraud risk scoring. Cookies strictly necessary for the secure completion of the payment transaction are not advertising cookies. Their exact names and behaviour may vary by integration type (JS SDK, hosted payment page, or direct API); use browser developer tools or a cookie scanner on your checkout page to identify the current set.
No, for standard payment gateway processing. Cookies and device signals strictly necessary to complete a payment transaction initiated by the user are exempt from the consent requirement under Art. 5(3) of the ePrivacy Directive. You do not need to present a cookie banner consent option for Worldpay's payment session cookies. However, if Worldpay's JavaScript is loaded on pages other than the checkout (e.g. product or category pages) and collects fraud signals from all visitors, that broader profiling may require a Legitimate Interests Assessment or, in some cases, explicit consent.
For payment processing, the legal basis is performance of a contract (Art. 6(1)(b) GDPR): the user has made a purchase and the payment must be processed to fulfil the order. Fraud prevention during the transaction is also justified by Art. 6(1)(b) and by legal obligations under PSD2 (Art. 6(1)(c)). If Worldpay is used for broader behavioural fraud profiling of site visitors beyond the checkout page, Legitimate Interests (Art. 6(1)(f)) may apply, but this requires a documented Legitimate Interests Assessment showing the processing is proportionate and does not override users' interests.
Yes. Worldpay operates UK infrastructure (covered by the EU adequacy decision) and US/global infrastructure via its parent company (GTCR, formerly FIS). US and other third-country transfers require Standard Contractual Clauses (SCCs) or the EU-US Data Privacy Framework (DPF). You should obtain Worldpay's current Data Processing Agreement (DPA), verify the transfer mechanisms in place, and disclose them in your privacy notice, specifying the countries to which data may be transferred and the safeguards applied.
A DPIA is not typically required for standard Worldpay payment gateway processing. However, if you deploy Worldpay's fraud-screening JavaScript across your entire website, potentially profiling all visitors (not just those transacting), the combination of scale and intrusiveness of the device fingerprinting may trigger the DPIA threshold under Art. 35 GDPR. Consult your supervisory authority's published list of processing types requiring a mandatory DPIA. Document your assessment in your Art. 30 records either way.
Sign Worldpay's Data Processing Agreement and retain a copy. Update your privacy notice to name Worldpay as your payment processor, describe the categories of data processed (card details, IP address, device fingerprint, authentication data), reference the UK adequacy decision and cite the SCCs or DPF for US transfers. Do not include Worldpay's strictly necessary payment cookies in your cookie consent layer. Keep the Worldpay SDK scoped to the checkout page. If you deploy fraud tools more broadly, document your Legitimate Interests Assessment. Review DPA and SDK documentation annually or after any Worldpay ownership changes.
Alternatives include Adyen (Netherlands, strong EU data residency, listed company), Stripe (US, with EU data processing options and SCCs), Checkout.com (UK, similar risk profile to Worldpay), and Mollie (Netherlands, EU-focused). All major payment gateways have similar data transfer considerations; the key compliance differentiators are the strength of their DPA, availability of EU-side processing, SCA compliance track record, and whether they offer server-side integration options that minimise browser-level data collection.
In your cookie policy or privacy notice, include a section on payment processing. Name Worldpay as the payment gateway, describe the cookies as strictly necessary for completing a card payment transaction, state that they do not require consent, and note that they are session-scoped and expire after the transaction. Reference the transfer of data to the UK (adequacy decision) and to the US and other countries (SCCs or DPF). Link to Worldpay's own privacy notice for further detail and review your cookie policy after any Worldpay integration changes.