The European Union’s General Data Protection Regulation (Regulation (EU) 2016/679) regulates the processing of personal data, which applies to financial data processed by Issuers of payment instruments.
Data type | Types of personal data processed |
---|---|
Transaction data | Cardholder data, which may include name, email, SSN and/or physical address, PAN information, transaction location, and payment and transaction data. |
Anti-money Laundering (AML) data | Know-Your-Customer (KYC) data: full name, email address, passport image with Date of Birth (DOB) and Nationality, and verification of same with public registers, Politically Exposed Person (PEP) lists, sanction lists and credit agencies. |
Open Banking Compliance Data | Customer authorisation information and cookies-related information; third-party developer cookies-related information and username, password and use of sandbox. |
My Carbon Action data | Customer’s nutrition, housing, mobility, consumer goods, leisure and services use and preferences-related information. |