Skip to content

Potentially.

Some consumers may assume that a company owns the payment card-related information that it collects when it accepts payment cards (e.g., credit or debit cards). In order to process payment cards, however, a company typically must enter into a written contract with a payment processor or merchant-bank. Those contracts often specify that payment card-related data is “owned” by the payment brands (i.e., Visa, MasterCard, American Express, and Discover) and require the company that accepts the payment card to agree to the payment brands’ published rules and procedures (collectively referred to as the “payment brand rules”).1 The payment brand rules contractually govern how a company may use payment-card related information.

The CCPA requires that a service provider agree to three substantive restrictions involving their use, disclosure, and retention of personal information. The CPRA amended the CCPA to require that, beginning on Jan. 1, 2023, a written contract with a service provider include additional clarifications and provisions regarding the use, disclosure, and retention of personal information.

The following chart compares the substantive requirements within the CCPA’s definition of a service provider with those requirements that would be contractually imposed upon a company that has agreed to comply with the payment brand rules:

Requirement CCPA Payment Brand Rules
1. Use Restrictions. A service provider can only process personal data consistent with a controller’s documented instructions. 2 3
2. Disclosure Restrictions. Confidentiality provision that ensures that persons authorized to process personal data have committed themselves to confidentiality. 4 5
3. Delete or return data. Service provider will delete or return data at the end of the engagement. 6 7

1 See, e.g., American Express Merchant Operating Guide § 3.5 (stating that all Cardmember information is the “sole property” of American Express.

2 Cal. Civ. Code 1798.140(v) (Oct. 2020).

3 For example, American Express’s Merchant Operating Guide states that a merchant must not “use” Cardmember information for any purpose not specified in the Merchant Operating Guide. American Express Merchant Operating Guide dated Oct. 2020 at 11 (Section 3.5).

4 Cal. Civ. Code 1798.140(v) (Oct. 2020).

5 For example, Mastercard’s rules prohibit a merchant from “in any manner disclos[ing] Account or Transaction data, including but not limited to the Account PAN [Primary Account Number] . . . or personal information of or about a Cardholder to anyone other than its Acquirer, to the Corporation, or in response to a valid government demand.” Mastercard Rules dated Aug. 4, 2020, at 110 (Rule 5.13). The American Express Merchant Operating Guide also provides that a member may not “disclose Cardmember Information” other than as permitted by American Express. American Express Merchant Operating Guide dated Oct. 2020 at 11 (Section 3.5).

6 Cal. Civ. Code 1798.140(v) (Oct. 2020).

7 For example, American Express’s Merchant Operating Guide states that a merchant must not “store” Cardmember information for any purpose not specified in the Merchant Operating Guide. American Express Merchant Operating Guide dated Oct. 2020 at 11 (Section 3.5). It further states that after the termination of the agreement, such information may only be retained as permitted by the PCI DSS. Id.

Print:
Email this postTweet this postLike this postShare this post on LinkedIn
Photo of David A. Zetoony David A. Zetoony

David Zetoony, Co-Chair of the firm’s U.S. Data, Privacy and Cybersecurity Practice, focuses on helping businesses navigate data privacy and cyber security laws from a practical standpoint. David has helped hundreds of companies establish and maintain ongoing privacy and security programs, and he

David Zetoony, Co-Chair of the firm’s U.S. Data, Privacy and Cybersecurity Practice, focuses on helping businesses navigate data privacy and cyber security laws from a practical standpoint. David has helped hundreds of companies establish and maintain ongoing privacy and security programs, and he has defended corporate privacy and security practices in investigations initiated by the Federal Trade Commission, and other data privacy and security regulatory agencies around the world, as well as in class action litigation.

Photo of Jena M. Valdetero Jena M. Valdetero

Jena M. Valdetero serves as Co-Chair of the firm’s U.S. Data Privacy and Cybersecurity Practice, and is a trusted advisor to clients facing complex and high-stakes data privacy and security challenges. With a track record of leading thousands of data breach investigations for…

Jena M. Valdetero serves as Co-Chair of the firm’s U.S. Data Privacy and Cybersecurity Practice, and is a trusted advisor to clients facing complex and high-stakes data privacy and security challenges. With a track record of leading thousands of data breach investigations for more than 20 years, Jena combines her broad litigation experience with a deep understanding of the evolving privacy landscape to protect her clients’ interests. She is highly skilled in defending companies in privacy and data breach litigation, particularly class actions, and is proactive in helping clients prepare for incidents by designing and facilitating customized tabletop exercises.

Jena offers practical, results-driven counsel on data privacy and security compliance programs and guides clients through privacy and cyber risk considerations in mergers, acquisitions, venture capital, and securities transactions. Her experience spans a wide range of privacy laws, including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), the Gramm Leach Bliley Act (GLBA), and the Health Insurance Portability and Accountability Act (HIPAA). Certified as a privacy professional through the International Association of Privacy Professionals (CIPP/US),  Jena provides clients with actionable insights on both current and emerging privacy regulations. She previously served as KnowledgeNet Co-Chair for the International Association of Privacy Professionals, further reflecting her leadership in the field. Jena is a founding board member of the Chicago Compassion Project, a nonprofit supporting low-income families in Chicago.

Jena has been recognized by Chambers USA as a leading privacy and data security lawyer, with clients praising her “very deep knowledge of subject matter” and calling her “extremely responsive and business-minded.” She is trusted for her “great strategic advice” and practical approach to complex data privacy issues, with one client saying, “I’d unequivocally recommend her to anybody with any kind of privacy or data breach concerns.”

About Greenberg Traurig

Greenberg Traurig, LLP has more than 3,100 lawyers across 51 locations in the United States, Europe, the Middle East, Latin America, and Asia. The firm’s broad geographic and practice range enables the delivery of innovative and strategic legal services across borders and industries. Recognized as a 2025 BTI “Best of the Best Recommended Law Firm” by general counsel for trust and relationship management, Greenberg Traurig is consistently ranked among the top firms on the Am Law Global 100, NLJ 500, and Law360 400. Greenberg Traurig is also known for its philanthropic giving, culture, innovation, and pro bono work. Web: www.gtlaw.com.

Law blog design & platform by LexBlog