Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

My business takes credit card payment information from users. But it doesn't store that information - it just forwards it to Stripe.

So if a user asks me for details of all her personal information, do I have to go to Stripe and say, "Please give me the credit card information you have on Jenny Smith"? Or do I say to the user, "Please contact Stripe directly - your Stripe customer ID is cus_34534985798243"?



Neither, in this case. Under the GDPR, you'd be expected to reply something like "As described in our privacy policy we use Stripe for processing payments. The data you enter on our checkout is transferred directly to Stripe, and is not stored by us." You're expected to make sure that third parties your company works with are GDPR compliant, but that's just a case of "ensure Stripe's privacy policy reads as GDPR compliant".


It's also doesn't seem like a huge stretch for a GDPR-compliant 3rd party who's API you consume to add some GDPR-related API calls.

(Payment processors are probably a bad example, as they already have boatloads of legal and contractual requirements to deal with. IF they're at all reputable, the GDPR will impact them minimally. The flip side of this is ad tech, who's scummy business model is almost painfully incompatible with GDPR - at the moment.)


This is the sort of area where interpretation comes into play. Who is controlling and who is processing the different personal data involved there?

Logically, your business controls the personal information about the identity of your customer, and a Stripe token associated with their card or the equivalent. You're also presumably processing that information at least for accounting purposes.

It doesn't make much sense for your business to be considered the controller of the card data that never touches your network, so Stripe ought to be considered the controller in that case, and presumably they are also processing it and potentially passing it on to further parties within the relevant card network infrastructure in order to collect payments for you.

Hopefully a regulator would agree that this is a sensible interpretation of the responsibilities. However, given the mechanics involved, where your customer might not be aware at all that they are even dealing with Stripe when they provide their payment details on your business's web site, this is the kind of area where some official confirmation would be reassuring.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: