Description

Adopted EDPB recommendations on credit card data storage

The European Data Protection Board issues recommendation 2/2021 on the legal basis for the storage of credit card data. The purpose is the facilitation of online transactions with sufficient data protection. The recommendations encourage a harmonised application of data protection rules regarding credit card data storage following transactions. It concludes that for such storage consent (art. 6(1)(a) GDPR) is the sole appropriate legal basis. The consent must be free, specific, informed and unambigous, devilered through clear affirmative action (e.g. not combined with the consent to terms of use) and requested in a user friendly way, allowing for withdrawal.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Data protection regulation
Regulated Economic Activity
other service provider
Implementation Level
supranational
Government Branch
executive
Government Body
data protection authority

Complete timeline of this policy change

Hide details
2021-05-19
adopted

The European Data Protection Board issues recommendation 2/2021 on the legal basis for the storage …