The recommendations are designed to standardize the application of data protection rules in the context of the processing of credit card data. The focus is on the storage of credit card data by online providers of goods and services, particularly for facilitating future purchases by data subjects. The document addresses scenarios where a data subject inputs credit card information on a website or application for a one-time transaction, providing guidance on how this data should be handled and stored.
Author: European Data Protection Board
Status: Adopted / Published
Adoption date: 2021-05-19
Last updated: 08 Aug 2025
Category: Guidance
Subcategory: Official recommendations