Skip to main content
Back to news
5 min readCifrago team

Personal data in payments: what GDPR says about emails, addresses, and purchase history

GDPR requires limiting data collection to the minimum necessary, but tax laws and fraud prevention mandate retaining transaction records. We analyse which legal bases justify each data point and for how long.

Operating an online store or digital platform requires handling sensitive customer information on a daily basis. During checkout, buyers submit their names, email addresses, delivery details, and billing data, generating a transactional footprint stored in databases. The General Data Protection Regulation (GDPR) sets clear boundaries on how this data is gathered and stored, requiring a balance between consumer privacy, statutory accounting obligations, and operational defence.

Understanding what data can be stored, under which legal basis, and for what duration protects businesses from administrative penalties by European supervisory authorities (such as the Spanish AEPD) as well as complications during tax audits or commercial disputes.

Legal bases across the payment flow

GDPR principle of lawfulness requires every processing activity to rest on a valid legal ground. In an online payment workflow, merchants generally rely on three complementary bases under Article 6:

  • Contract performance (Article 6.1.b): Allows processing data essential to capture the payment, deliver goods, and send operational notifications. When a user buys a physical item, collecting their shipping address and email to deliver the product and dispatch receipt notes falls squarely under this contractual need.
  • Legal obligation (Article 6.1.c): Commercial and tax regulations compel businesses to issue invoices and preserve accounting books. Consequently, storing fiscal records does not depend on user consent; it is mandated by statutory invoicing and tax rules.
  • Legitimate interest (Article 6.1.f): Justifies collecting and analysing technical telemetry (such as IP addresses, device fingerprints, or coarse geolocation) to assess transaction risk, counter fraud schemes, and defend the business during friendly fraud chargeback disputes.

Explicit consent is rarely the proper legal basis for executing standard checkouts. Requiring a checkbox to 'consent to data processing' simply to execute a purchase is legally flawed. Consent checkboxes should be reserved for optional secondary purposes, such as newsletter subscriptions or third-party marketing transfers.

Permitted data points and proportionality boundaries

The data minimisation principle (Article 5.1.c of the GDPR) mandates that processed information must be adequate, relevant, and strictly limited to what is necessary for the stated purpose.

Email addresses and transactional messaging

The email address provided during checkout serves primarily as an account identifier and operational communication channel. Merchants are entitled to use it for order confirmations, shipping updates, and service notices. However, using that same address for marketing campaigns requires compliance with e-privacy rules (such as Article 21.2 of Spain's LSSI-CE, mirroring the EU ePrivacy Directive), which only permits unprompted marketing for similar products to existing customers when a simple, free opt-out mechanism is included in every message.

Shipping addresses and billing locations

For purely digital goods or downloadable services, demanding a physical street address breaches data minimisation. For digital delivery, merchants only need data points required to calculate taxes correctly, such as the customer country of residence and postal code under the EU VAT One Stop Shop (OSS) framework.

When shipping tangible goods, shipping addresses should be decoupled internally from billing addresses. The recipient is not always the payer, and collecting more data than the courier requires is not legally justifiable.

Order history and payment logs

Order history enables consumers to track previous purchases and allows businesses to manage warranty claims and refunds. Furthermore, technical logs generated by the payment gateway (exact timestamps, transaction IDs, issuing bank response codes, and strong customer authentication indicators) are essential for diagnosing failed charges.

However, primary cardholder data—such as the full Primary Account Number (PAN) or the card verification value (CVV/CVC)—must never enter merchant databases. These details must be handled exclusively by PCI DSS-compliant payment gateways, leaving the merchant with only an abstract token.

Retention schedules and data blocking

GDPR prohibits indefinite retention of personal data. Information should generally be deleted once its primary purpose expires. However, when a customer requests account closure or erasure under the right to be forgotten (Article 17), businesses cannot simply purge accounting records.

In Spain, the Commercial Code requires companies to preserve account books, invoices, and trade correspondence for 6 years. Similarly, the General Tax Act establishes a 4-year statutory limitation period for tax assessments. Card scheme rules also allow between 120 and 540 days for issuers to lodge formal chargebacks.

To reconcile these competing demands, Spanish data protection law (LOPDGDD, Article 32) implements the concept of data blocking:

  • Identifying records and purchase details are removed from active operational systems, meaning regular staff cannot view them and users cannot log in.
  • The records are safeguarded under strict technical and organisational security measures, encrypted, with access restricted to designated compliance officers.
  • Data is retained solely to make it available to courts, public prosecutors, or tax authorities if claims arise during limitation periods.
  • Once statutory limitation windows expire, records must be permanently destroyed or irreversibly anonymised.

Practical conclusion

Complying with GDPR in payment workflows does not mean asking consent for every transaction step. Instead, it requires mapping each data element to its correct legal basis and segregating records according to their purpose. Requesting only what is necessary for delivery and taxation, storing tokens instead of raw card numbers, and enforcing automated data blocking ensures full regulatory compliance without hindering commercial operations.

Building subscriptions?

Check the pricing and try the dashboard with sample data before integrating anything.

Keep reading

2 min read

Card routing modernization, UK open banking architecture, and ECB consumer expectations

Bank Pekao upgrades its card infrastructure with NCR Atleos, while UK open banking faces credit crunch debates and the ECB releases consumer data.

4 min read

Apple Pay and Google Pay without the marketing: network tokens and fraud reduction

Far from simple digital wallets, Apple Pay and Google Pay rely on network tokens and dynamic cryptograms. We examine their technical mechanics and fraud impact.