If you take payments through Stripe, you are processing your customers' personal data through a third party. Under UK GDPR, that requires a written contract. The good news is Stripe has already signed one with you. The less good news is that most small businesses have never read it.
This post explains what Stripe's Data Processing Agreement (DPA) actually contains, what it means for your obligations, and the three things you need to do beyond just having the agreement in place.
---
Under Article 28 of UK GDPR, whenever a controller uses a processor to handle personal data on their behalf, a written contract must be in place. No contract, no lawful processing. It is that simple.
When a customer checks out on your website using Stripe, Stripe processes their name, email address, billing and shipping address, payment card details, IP address, device ID, and transaction data. All of that is personal data. You are the data controller (you decide the purpose). Stripe is the data processor (they do the processing on your behalf).
Stripe's DPA forms part of your Stripe Services Agreement. You accepted it when you signed up. You did not need to negotiate it or sign a separate document. That is deliberate. Stripe applies it automatically to all business users.
For UK-based businesses, the relevant Stripe entity is Stripe Payments Europe, Limited (SPEL), an Irish company. SPEL has primary responsibility for contracting with Stripe users outside the Americas. Stripe Technology Company, Limited (STC), also Irish, handles the data processing itself.
---
Stripe's DPA is a substantive document. It addresses the requirements the ICO sets out for Article 28 contracts. Here is what it includes.
Processing on your instructions only. Stripe commits to process personal data only according to your instructions. If Stripe believes an instruction would breach data protection law, it will tell you.
Breach notification within 48 hours. If Stripe experiences a data incident affecting personal data subject to UK GDPR, it will notify you no later than 48 hours after becoming aware of it. The notification will describe the type of data affected, the categories and approximate number of individuals involved, and the status of Stripe's investigation. This is tighter than the 72-hour window the ICO requires of you as a controller, which gives you time to then report to the ICO if needed.
Sub-processor management. Stripe uses sub-processors (other companies that help it deliver its services). You grant Stripe general written authorisation to engage sub-processors when you accept the DPA. Stripe publishes its sub-processor list at stripe.com/legal/service-providers. If Stripe intends to add a new sub-processor, it will notify you at least 30 days before the change takes effect if you have subscribed to email notifications. You have 30 days to object. If you do object and Stripe proceeds anyway, Stripe is not obligated to provide you the services that rely on that sub-processor.
Audit rights. Following a written request, Stripe will contribute to audits or inspections by making audit reports available, no more than once annually. This satisfies the Article 28 requirement for processor accountability without giving you unlimited access to Stripe's infrastructure.
Data subject rights assistance. Stripe will assist you in responding to requests from your customers to access, correct, or erase their data. Stripe will not respond to those requests directly unless you instruct it to in writing.
DPIA support. Stripe will provide reasonable information to help you conduct a data protection impact assessment (DPIA) or consult with a supervisory authority. If the assistance you need goes beyond Stripe's legal obligations, it may charge a reasonable fee.
---
This is where things get more involved, and where many small businesses have a gap in their records.
Stripe is a US company. When your customer's payment data flows through Stripe, it is transferred to Stripe, LLC in the United States. Under UK GDPR, transferring personal data to a country without an adequacy decision requires a lawful transfer mechanism. The US does not have a blanket UK adequacy decision.
Stripe handles this through two mechanisms, and they operate in order of precedence.
First: the UK Extension to the EU-US Data Privacy Framework. Stripe, LLC is self-certified under the Data Privacy Framework, including the UK Extension. When you transfer personal data from the UK to Stripe in the US, Stripe receives it under the Data Privacy Framework and commits to comply with its principles. This is currently the primary mechanism.
Second: the UK International Data Transfer Addendum (IDTA). On 21 March 2022, the ICO's International Data Transfer Agreement and the UK Addendum to the EU Standard Contractual Clauses came into force. For transfers of personal data from the UK, the UK International Data Transfer Addendum is incorporated into Stripe's Data Transfers Addendum. This sits alongside the Data Privacy Framework as a fallback. Stripe's Data Transfers Addendum is incorporated into your DPA and available at stripe.com/legal/dta.
In plain English: Stripe has done the legal plumbing for international transfers. You do not need to execute a separate IDTA with Stripe. But you do need to record that these mechanisms exist and reference them in your Record of Processing Activities (ROPA).
One thing worth noting: you may still need to conduct a Transfer Risk Assessment (TRA) to document that the transfer is safe, even when relying on an approved mechanism. The ICO expects controllers to have something to show in this space. A brief documented assessment is better than nothing.
---
The ICO can fine organisations up to £17.5 million or 4% of global annual turnover for serious breaches of UK GDPR. The lower tier covers procedural failures at up to £8.7 million or 2% of turnover.
To be clear: there is no ICO enforcement action specifically against Stripe on record. Stripe is a well-resourced company with a mature compliance programme. The risk here is not Stripe failing you. The risk is you failing to meet your own obligations as a controller.
The ICO is explicit: a controller is primarily responsible for its own compliance and for ensuring the compliance of its processors. That means you cannot point to Stripe's DPA and call the job done. You need to have recorded that you use Stripe, what data flows through it, what the legal basis for that processing is, and what transfer mechanism covers the US transfer.
In practice, the ICO takes size and resources into account when setting fines. A small business that has made a genuine effort to document its processing and cooperate with any investigation is in a materially different position from one that has done nothing. The gap between those two positions is mostly paperwork.
---
Here is what typically goes wrong for small businesses using Stripe.
A sole trader or small e-commerce business sets up Stripe, starts taking payments, and adds Stripe to their privacy policy. So far, so reasonable. But they never record Stripe as a processor in their ROPA. They have no note of the UK IDTA or Data Privacy Framework as the transfer mechanism. They have not subscribed to Stripe's sub-processor update emails. And they have not thought about whether they need a TRA.
None of this is malicious. It is just not visible. Stripe's compliance machinery runs quietly in the background. The DPA is accepted by clicking through a sign-up flow. Nothing prompts you to go and document it.
The problem surfaces when something goes wrong. A customer makes a subject access request and asks who processes their data. A regulator asks for your ROPA. A potential enterprise client runs a supplier due diligence check. At that point, having nothing documented is a problem, even if the underlying processing was fine.
---
Four specific actions, in order of priority.
1. Record Stripe in your ROPA. Your Record of Processing Activities should include Stripe as a processor, the categories of data it processes (names, payment details, email addresses, IP addresses, device data), the legal basis for the processing (typically contract performance under Article 6(1)(b)), and the transfer mechanism for the US transfer (UK Extension to the EU-US Data Privacy Framework, backed by the UK IDTA in Stripe's Data Transfers Addendum).
2. Subscribe to Stripe's sub-processor update emails. Go to stripe.com/legal/service-providers and subscribe. You will get 30 days' notice of any new sub-processor. You do not need to do anything with that notice most of the time, but you need to have the option to object, and you cannot object if you did not know.
3. Note the DPA in your privacy policy. Your privacy policy should tell customers that their payment data is processed by Stripe, reference Stripe's role as a processor, and mention that data may be transferred to the US under appropriate safeguards. Stripe's own guidance confirms you are responsible for making these disclosures to your customers.
4. Consider a brief Transfer Risk Assessment. It does not need to be long. A one-page document noting the transfer, the mechanism, and why you consider the risk acceptable is enough to demonstrate you have thought about it. The ICO expects controllers to have something on file.
You do not need a lawyer to do any of this. You need a system that prompts you to do it and keeps a record.
---
If you are not sure whether your business is covered, Rowpa generates your full ROPA in 15 minutes. Start free at rowpa.app
---
This post is for information only and does not constitute legal advice.