Back To Home Page

PayPal User Corporate rules

PayPal User Corporate rules

Last updated on 28 September 2026

The PayPal Group’s goal is to apply uniform, adequate and global data protection and privacy standards for the handling of all User Personal Data throughout the PayPal Group.  These User Corporate Rules apply to all User Personal Data:

  • transferred from an EEA Group Member (as Controller) to a non-EEA Group Member (as Controller or Processor); and
  • onward transferred by a recipient non-EEA Group Member under these User Corporate Rules to another non-EEA Group Member (as Controller or Processor).

Users globally provide their Personal Data to Group Members to utilize the services the Group offers.  Most User Personal Data is collected and stored in the United States.  PayPal’s global business requires User Personal Data to be shared with other PayPal entities in the United States and globally where PayPal currently has or intends to have a presence.

PayPal is committed to adequately protecting the User information regardless of where the Personal Data resides and to provide appropriate protection for the User Personal Data where it is transferred outside of the EEA.

A list of Group Members who are subject to these User Corporate Rules is set out in Annex I. Employees located in the jurisdictions listed in Annex II may have access to User Personal Data. These lists may change as the company’s business expands.

The material scope of these Rules is referred in to the definitions and sections of the present Rules, such as in section 12 (Users’ Personal Data and types of data subjects), section 2.1 for the types of processing, that is the purposes for which User Personal Data are processed, and a list of countries is made available in Annex II.

1. Privacy Governance Structure and Responsibilities

The User Corporate Rules are made legally binding by an agreement (the “IGA”) between PayPal (Europe) S.à r.l. & Cie, S.C.A. (“Lead Group Member”) and other PayPal Group Members.  The IGA requires Group Members to comply with these User Corporate Rules. Group Members require their Employees to comply with these User Corporate Rules when handling User Personal Data.

Business leaders and senior management of the PayPal Group are responsible for enforcing compliance with these User Corporate Rules, including ensuring that Employees are aware of and abide by these User Corporate Rules.

The Compliance Privacy Lead drives the PayPal privacy program. He/she holds a senior position within PayPal Holdings, Inc. and reports directly to the chief compliance officer or the highest senior executive leading the compliance function at PayPal.  The Compliance Privacy Lead oversees the PayPal Global Privacy Compliance Team and interacts with other internal organizations or teams, such as operations, information security, compliance, risk and internal audit to help ensure consistent privacy communications, practices and policies across the PayPal Group globally. The PayPal Global Privacy Compliance Team develops and coordinates implementation of its compliance strategy across the PayPal Group and verifies operational compliance.  The PayPal Global Privacy Compliance Team has direct and indirect representatives throughout the PayPal Group who, among other things, help to ensure compliance with the User Corporate Rules and applicable data protection laws.

The Legal Privacy Lead oversees the PayPal Global Privacy Legal Team and reports directly to the chief legal officer or the highest senior executive leading the legal function at PayPal. The Legal Privacy Lead defines the company’s obligations under applicable data protection laws and these User Corporate Rules. The Legal Privacy Lead and the PayPal Global Privacy Legal Team work in close coordination with the Compliance Privacy Lead and the PayPal Global Compliance Privacy Team, and interact with other internal organizations and teams, such as legal, operations, information security, and risk to provide legal advice and interpret legal and regulatory implications on evolving privacy matters across the PayPal Group globally.

Collectively, The PayPal Global Privacy Compliance Team and the PayPal Global Privacy Legal Team form the PayPal Global Privacy Team.

The European Data Protection Officer located in Luxembourg, is appointed by and reports to the management of PayPal (Europe) S.à r.l. et Cie, S.C.A.. The European Data Protection Officer acts as the primary contact for the EEA data protection authorities and does not perform any tasks that could result in a conflict of interests. The European Data Protection Officer has, among others, the following duties: to inform and advise the Group Members and their employees, who are processing personal data, of their obligations under privacy legislation to ensure compliance with these User Corporate Rules; to work with the PayPal Global Privacy Team to monitor compliance with privacy legislation and with related policies of the Group Members; and, to provide legal advice to the Group Members where requested as regards the data protection impact assessments and their implementation. The European Data Protection Officer shall report to the highest management level, and can inform the highest management level if any questions or problems arise during the performance of their duties.

2. Principles For Processing User Personal Data

Group Members observe the following Processing principles for User Personal Data.

2.1 Purpose Limitation

User Personal Data shall be Processed for specific, explicit and legitimate purposes only.  In particular, User Personal Data may be Processed to:

  • communicate with Users in relation to services
  • offer, administer and facilitate the provision of Services at Users’ requests, including opening an account and administer Users’ payments;
  • improve the Services and develop new Services;
  • resolve disputes, manage litigation, troubleshoot problems, and provide customer service, including for data analysis, testing, research and statistical purposes;
  • perform risk management;
  • process transactions and collect fees owed, including proving that transactions have been executed;
  • check creditworthiness and solvency;
  • measure Users’ interest in and feedback and opinion concerning Services, and inform Users about online and offline offers, Services, and updates;
  • customize Users’ experiences;
  • detect and protect against error, fraud and other criminal activity, including confirming User’s identities and contact information;
  • fulfill PayPal Group’s legal, contractual or regulatory obligations;
  • enforce the Service’s terms and conditions and as otherwise described to Users at the time of collection and in the Service’s privacy policy;
  • protect the security, integrity and availability of the Services and the PayPal Group network;
  • protect the PayPal Group’s legal rights and interests, including, but not limited to, establishing, exercising, or defending against legal claims or collection procedures;
  • assess which payment options and services to offer Users, for example by carrying out internal and external credit assessments; and
  • comply with internal PayPal procedures.

Processing of User Personal Data for other purposes than the above purposes is subject to prior approval from the PayPal Global Privacy Legal Team.  When in doubt, Group Members will consult the PayPal Global Privacy Legal Team.

User Personal Data shall not be further Processed for a secondary purpose in a way that is incompatible with the above listed purposes, unless there is a legal basis for doing so under the applicable law of the Group Member in the EEA responsible for the collection and/or transfer of the User Personal Data (i.e. the exporting entity).   

2.2 Data Minimisation, Accuracy and Storage Limitation

User Personal Data shall be:

  • Accurate and, where necessary, kept up-to-date;
  • Adequate, relevant and limited to what is necessary in relation to the purposes for which it is Processed;
  •  Retained for no longer than necessary to achieve the purposes for which it was collected or further Processed; and
  • Erased, deleted, destroyed or anonymized in accordance with applicable PayPal policies, where they are no longer required for the purposes for which they were Processed unless there is a legal ground for further Processing or retention is required by applicable law or applicable PayPal policies.

2.3 Legal Grounds for Processing and Fairness

  1. Legal basis for processing User Personal Data

Group Members shall ensure that User Personal Data is Processed fairly and lawfully and in particular on the basis of at least one of the following legal grounds:

  • Unambiguous, freely given, specific and informed consent of the User;
  • Processing necessary for the performance of a contract to which the User is party or in order to take steps at the request of the User prior to entering into a contract;
  • Processing necessary for compliance with a legal obligation to which Group Members are subject;
  • Processing necessary in order to protect the vital interests of the User or another natural person;
  • Processing necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in Group Members or in a Third Party to whom the data are disclosed; or
  • Processing necessary for the purposes of the legitimate interests pursued by the Group Member or by the Third Party or Parties to whom the data are disclosed, except where such interests are overridden by the interests for fundamental rights and freedoms of the User.
  1. Legal basis for processing Users’ Special Category Personal Data

Where collection of Special Category Personal Data is required or where Users voluntarily provide such information, Group Members shall ensure that the Users’ Special Category Personal Data is only Processed on the basis of at least one of the following grounds:

  • Express consent of the User;
  • Processing necessary to protect the vital interests of the User or of another person where the User is physically or legally incapable of giving his/her consent;
  • Processing relates to User Personal Data manifestly made public by the User; or
  • Processing necessary for the establishment, exercise or defense of legal claims or whenever courts are acting in their judicial capacity.
  1. Legal basis for processing involving automatic decision-making

Where a User may be subject to a decision based solely on automated Processing, including profiling, which produces legal or significant effects (an “Automated Decision”), Group Members shall ensure that the Automated Decision:

  • is necessary for entering into, or performance of, a contract between the User and a Group Member;
  • is authorised by EU or Member State law to which the Group Member is subject and which also lays down suitable measures to safeguard the User’s rights and freedoms and legitimate interests; or
  • is based on the User’s explicit consent.

Further, in at least the first and third cases above, the Group Member shall provide suitable measures to safeguard the User’s rights and freedoms and legitimate interests, such as providing the User an opportunity to have a customer support representative review the decision individually and permit the User to provide their point of view. The customer support representative shall escalate the matter to the EU Data Protection Officer in case the User continues to disagree with an Automated Decision. When appropriate, the Legal Privacy Lead will be consulted and the Compliance Privacy Lead will be apprised.

2.4 Transparency

When collecting User Personal Data, Group Members shall inform Users of:

  • The identity and the contact details of the Group Member responsible for the original collection and Processing;
  • The contact details of the European Data Protection Officer. The relevant details are: The European Data Protection Officer (DPO) PayPal (Europe) S.à r.l et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg, or Online.
  • The intended purposes of the Processing as well as the legal basis for the Processing;
  • Where the Processing is based on legitimate interests, the legitimate interests pursued by the Group Member or by a third party
  • The recipients or categories of recipients (including Processors) of the User Personal Data;
  • Where applicable, the fact that the Group Member intends to transfer User Personal Data to a third country or international organization and the existence or absence of an adequacy decision by the European Commission, or a reference to the appropriate or suitable safeguards (including these User Corporate Rules) where these are relied upon and the means by which to obtain a copy of them or where they have been made available;
  • The period for which the User Personal Data will be stored or, if that is not possible, the criteria used to determine that period;
  • The existence of User rights, including the right to request from the Group Member access to and rectification or erasure of User Personal Data or restriction of Processing concerning the User or to object to Processing as well as the right to data portability;
  • Where the Processing is based on consent, the existence of the right to withdraw consent at any time, without affecting the lawfulness of Processing based on consent before its withdrawal;
  • The right to lodge a complaint with a Data Protection Authority;
  • Where the provision of User Personal Data is a statutory or contractual requirement, or a requirement necessary to enter into a contract, as well as whether replies to the questions are obligatory or voluntary, as well as the possible consequences of failure to reply; and
  • In case of Automated Decisions, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the User.

Group Members may provide the information in a Service privacy policy which shall be accessible via a link and/or displayed in a prominent location of each Service website or application and during registration.  The obligation to inform Users does not apply if Users already are aware of the information.  

Where the provision of information proves impossible or would involve a disproportionate effort, Group Members may refrain from providing the information.  This would only be the case for User Personal Data that has not been obtained from the User directly. 

In exceptional circumstances, the provision of specific information may be postponed or omitted, for example, in the context of investigations into wrongful conduct or to comply with applicable laws or where provision of the information could jeopardize the integrity of the investigation.

2.5 Accountability, Confidentiality and Security

  1. Accountability

Every Group Member acting as data controller shall be responsible for and able to demonstrate compliance with the User Corporate Rules.

In order to enhance compliance and when required, data protection impact assessments are carried out for processing operations that are likely to result in a high risk to the rights and freedoms of natural persons. Where a data protection impact assessment as set out in Regulation (EU) 2016/679 indicates that the processing would result in a high risk in the absence of measures taken by the Group Member to mitigate the risk, the competent Data Protection Authority, prior to processing, will be consulted.

Appropriate technical and organisational measures are implemented and are designed to implement data protection principles and to facilitate compliance with the requirements set up by the User Corporate Rules in practice (data protection by design and by default).

  1. Confidentiality and Security

Group Members use physical, technical and organizational security controls commensurate with the amount and sensitivity of the User Personal Data to prevent unauthorized Processing, including but not limited to, unauthorized access to, acquisition and use of, loss, destruction, or damage to User Personal Data. Group Members use encryption, firewalls, access controls, standards and other procedures to protect User Personal Data from unauthorized access.  Physical and logical access to electronic and hard copy files is further restricted based upon job responsibilities and business needs.

  1. Personal Data Breach

Upon discovery of a personal data breach as defined in Art 4(12), Art.33(1) and Art.34(1) of GDPR Regulation (EU) 2016/679 and Art 33.1, the affected Group Member shall notify without undue delay the Lead Group Member, the European Data Protection Officer and other required stakeholders as per applicable internal policies. Where the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the Group Member and the Lead Group Member, in consultation with the European Data Protection officer, shall inform the impacted data subjects and the Data Protection Authority as applicable. Personal data breaches shall be documented to record i) the facts relating to the personal data breach, ii) its effects and iii) the remedial action taken are listed. Such documentation shall be provided to the competent Data Protection Authority on its request.

2.6 Users Choices and Rights

Users may exercise the following rights:

  • Users may access and rectify most of the User Personal Data relating to them that Group Members maintain using the appropriate online tool or self-service process made available to them through the Service website or application.
  • In all cases, Users have the right to submit a data subject access request to view or receive a copy of their User Personal Data not accessible via the Service’s website or application. Users should contact customer support via directions provided via the Service’s website or application.
  • Users also may request the rectification of their data if they are incomplete or inaccurate. Group Members will comply with such request and will inform Users when their data have been rectified. Group Members will notify third parties to whom the User’s data have been disclosed of any rectification, unless this proves impossible or involves a disproportionate effort.
  • Users can exercise their right to obtain a human review of any Automated Decision taken by a Group Member in accordance with Section 2.3 (c).
  • Users may object to the Processing of their User Personal Data. Group Members will comply with such requests, unless retention of User Personal Data is required by applicable law or to defend the PayPal Group against legal claims. Users will be informed about the outcome of their request and the measures taken by the Group Members.
  • Furthermore, Users may request to have their accounts closed by following the instructions provided via the Service’s website or application. They may also exercise their rights to restriction of Processing of their User Personal Data, or erasure of User Personal Data, in connection with such account closure. Group Members will remove or render anonymous a User’s information from a Service as soon as reasonably possible based upon account activity.  In some instances, Group Members may delay the closure of an account or retain User Personal Data to conduct an investigation or where required by applicable law. Group Members also may retain User Information from closed accounts to detect and prevent fraud, collect any fees owed, resolve disputes, troubleshoot problems, assist with any investigations, manage risk, enforce a Service’s terms and conditions, comply with legal or regulatory requirements and take other actions otherwise permitted by applicable law. The data will be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the data were collected or for which they are further processed and will be deleted once the underlying reason for retaining it has been addressed or resolved.
  • With the exception of those Users who have selected not to receive certain communications, Group Members may use User Personal Data to target communications to Users based on their interests according to applicable law.  Users that do not wish to receive marketing communications from the PayPal Group will be offered easily accessible means to oppose further advertising, for example, in their account settings or by following the directions provided in an email or from a link on the communication.

In all cases, Users can exercise the above rights by contacting customer support. Where a User’s identity is difficult to verify, Group Members may require the User to provide additional proof of identification. Group Members will comply with requests in the timeframes prescribed by applicable law, except where applicable law provides for an exception to such obligation.

2.7 Disclosures and Transfers of Personal Data

Group Members may share User Personal Data in the normal course and scope of business with other Group Members worldwide for the purposes identified in Section 2.1.

  1. Disclosures and transfers to external public authorities

In accordance with applicable law, treaties or applicable international conventions, Group Members may share Personal Data with law enforcement and regulatory authorities when necessary in a democratic society to safeguard national security, defense, public security, the prevention, investigation, detection and prosecution of criminal offences, and, in particular to comply with sanctions as laid down in international and/or national instruments, tax-reporting requirements or anti-money-laundering reporting requirements.

Where a non EU Group Member has reasons to believe that the legislation applicable to it prevents that entity from fulfilling its obligations under the User Corporate Rules, with a substantial effect on the guarantees provided by the Rules, the non-EU Group Member will (unless prohibited) promptly inform the Lead Group Member and/or the European Data Protection Officer. This includes if it:

  1. receives a legally binding request by a non-EU public authority for disclosure of User Personal Data transferred under these User Corporate Rules, in which case the non-EU Group Member will (unless prohibited) provide the Lead Group Member and/or the European Data Protection Officer with information about the User Personal Data requested, the requesting non-EU public authority, the legal basis for the request and the response provided;
  2. becomes aware of any direct access by non-EU public authorities to User Personal Data transferred pursuant to the User Corporate Rules, in which case the non-EU Group Member will (unless prohibited) provide the Lead Group Member and/or the European Data Protection Officer with such information as is known to the non-EU Group Member.

If in specific cases the suspension and/or notification are prohibited, the requested Group Member shall endeavor to obtain the right to waive this prohibition in order to communicate as much information as it can and as soon as possible. The non-EU Group Member will review the legality of each request for disclosure by a non-EU public authority to assess if it is within the powers granted to that authority, and will challenge the request if it is not. It will document and keep a record of its review and, unless prohibited, make this available to the Lead Group Member and/or the European Data Protection Officer. It will also make it available to competent Data Protection Authorities upon request.

The non-EU Group Member will provide the minimum amount of information permissible when responding to a request for disclosure from a non-EU public authority, based on a reasonable interpretation of the request.

Group Members cannot transfer User Personal Data to a non-EU public authority in a massive, disproportionate and indiscriminate manner that would go beyond what is necessary in a democratic society.

  1. Disclosures of Personal Data to a Processor

When Group Members transfer User Personal Data to a Processor, the Processor will be subject to a privacy, data protection and information security risk assessment prior to the initiation of work and prior to any transfer of User Personal Data.  The scope of the assessment will vary based upon the sensitivity of the User Personal Data processed. The privacy, data protection and information security assessment is not mandatory for Processors that already have been subject to such an assessment or that are Group Members, unless the Processing activities involve high risk activities taking into account the nature and amount of Personal Data and the type of Processing activities concerned.

Processors, including a Group Member intervening as a Processor, must enter into an agreement with the relevant Group Member that will be acting as the Controller of the User Personal Data to provide adequate privacy, data protection and information security measures. Such an agreement includes clauses ensuring the appropriate use of User Personal Data and security measures commensurate with the amount, nature and sensitivity of the User Personal Data involved. 

At a minimum, the contractual safeguards must cover the following matters:

  • Requirements to comply with the law and to Process User Personal Data only in accordance with the terms of the agreement and only on the instructions of the Group Members concerned;
  • Assurance that persons authorised to process the User Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
  • Assurance that no prior engagement of another processor is conducted without prior specific or general written authorisation of the Group Member, and where such processor shall respect the same contractual safeguards when engaging another processor itself.
  • Appropriate technical and organizational measures adapted to the sensitivity of the User Personal Data and Processing concerned;
  • Assistance to Group Member by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Group Member's obligation to respond to requests for exercising the data subject's rights;
  • Security breach notification obligations such as to notify PayPal promptly in writing, without undue delay after becoming aware of a security breach.
  • At the choice of the disclosing Group Member, the deletion or return all the personal data to that Group Member after the end of the provision of services relating to processing, and deletion of existing copies unless Union or Member State law requires storage of the personal data;
  • A right to audit Processors’ compliance with the contractual guarantees;
  • Provisions on remediation in the event of non-compliance by the Processor with its legal or contractual obligations.

The agreements must contain provisions ensuring that failure to comply with the terms of the agreement may result in the suspension or termination of the agreement among other remedies identified in the agreement.

  1. Disclosures of Personal Data to Third Parties

Where Group Members transfer EEA User Personal Data to Third Parties (including Processors that are not Group Members located in a non-EEA country that (i) does not provide adequate levels of protection (within the meaning of the EU General Data Protection Regulation), and (ii) does not have other arrangements that would satisfy EU adequacy requirements, the Group Member shall ensure that the Third Party implements appropriate contractual safeguards, such as standard contractual clauses approved by the European Commission, providing levels of protection commensurate with these User Corporate Rules or, alternatively, ensure that the transfer (i) takes place with the explicit consent of the User, (ii) is necessary to conclude or perform a contract concluded with the User, (iii) is necessary or legally required on important public interest grounds, (iv) is necessary to protect the vital interests of the User; or (v) is necessary for the exercise, establishment or defence of legal claims.

2.8 Transfer Impact Assessments

Members shall assess (and on an ongoing basis monitor) whether third-country laws or practices prevent compliance with these User Corporate Rules. Such assessments shall consider:

  • The specific circumstances of the transfers or set of transfers, and of any envisaged onward transfers within the same third country or to another third country, including:
    • the purposes for which the data are transferred and processed (e.g. marketing, HR, storage, IT support, clinical trials);
    • the types of entities involved in the processing (the data importer and any further recipient of any onward transfer);
    • the economic sector in which the transfer or set of transfers occur;
    • the categories and format of the personal data transferred;
    • the location of the processing, including storage; and
    • the transmission channels used;
  • The laws and practices of the third country of destination relevant in light of the circumstances of the transfer, including those requiring to disclose data to public authorities or authorising access by such authorities and those providing for access to these data during the transit between the country of the data exporter and the country of the data importer; and
  • Any relevant contractual, technical or organisational safeguards put in place to supplement the safeguards under the User Corporate Rules, including measures applied during the transmission and to the processing of the User Personal Data in the country of destination.

If adequate protection cannot be ensured, transfers must be suspended or ended. Assessments shall be documented and made available to Data Protection Authorities on request.

2.9 Public Authority Requests

Importers shall inform the Lead Group Member on request of public authority access requests. They shall reasonably challenge secrecy or unlawful requests, minimise disclosure and record actions.

3. Complaint Mechanism

If Users believe that their User Personal Data has been processed in violation of the User Corporate Rules, they may report concerns to the customer service function of the relevant Group Member via the relevant Service’s website, email or as otherwise indicated in the applicable terms and conditions.  Users generally can find answers to the most common privacy questions and concerns by typing the word “privacy” into the relevant service’s help section, which will usually direct the User to a privacy specific page or policy.  The “help” section of the relevant service is the unique entry point for all Users’ queries relating to their privacy or the processing of their User Information and provides User’s the opportunity to contact customer support. 

In case of doubt as to which channel to use to report privacy related concerns, Users can contact the European Data Protection Officer Online.

Customer support investigates and attempts to resolve concerns raised by Users. Employees responsible for addressing privacy related concerns work closely with the PayPal Global Privacy Team and reply to Users in accordance with PayPal’s policies, procedures and guidance. If Users believe their concerns have not been addressed adequately, or if they did not get a response, they can request that their concern be escalated to the European Data Protection Officer. The Legal Privacy Lead will be consulted and the Compliance Privacy Lead will be apprised. Escalation paths shall be determined based upon the nature and scope of the concern and shall be forwarded to the appropriate team without delays.  A response to the complaint shall be provided to the User within a reasonable timeframe, and in any case within a period of three (3) months after the date of inquiry, except in unusual circumstances or complex questions in which case the User will be informed that the reply will take longer than three (3) months.

The complaint handing mechanism does not prejudice Users’ right to bring complaints before competent Data Protection Authorities or courts. In particular, Users may bring a complaint:

  • before a competent Data Protection Authority, in particular in the Member State of the Users’s habitual residence, place of work or place of the alleged infringement; and
  • before the competent court of the Member States where the Group Member that is the Controller or Processor of the User Personal Data has an establishment, or where the User has their habitual residence.

4. Third-Party Beneficiary Rights and Liability

EEA Users who suspect a breach of the User Corporate Rules outside the EEA have the right to judicial enforcement and the right to obtain redress and, where appropriate, compensation in case of any breach of one of the enforceable elements of the User Corporate Rules as third party beneficiaries, and specifically for Sections 2, 3, 4, 7, 8 and 9 of the User Corporate Rules before the competent data protection authorities or before the courts in accordance with Section 3. These enforcement rights are in addition to other remedies or rights provided by PayPal or available under applicable law.

While it is not required, EEA Users are encouraged to first report their concern directly to the Group Member rather than the Data Protection Authorities or the courts.  This enables an efficient and prompt response from the PayPal Group and minimizes possible delays from Data Protection Authorities or court procedures.

PayPal Europe S.à r.l. et Cie, S.C.A., a Luxembourg private limited liability company accepts responsibility for and agrees to oversee the Group Members' adherence to the User Corporate Rules.  The Lead Group Member undertakes (i) to take the necessary action to remedy a breach committed by Group Members outside of the EEA; and (ii) to pay the compensation to EEA Users awarded by the Lead Data Protection Authority or Luxembourg courts for any damages directly resulting from the breach of the User Corporate Rules by Group Members outside the EEA, should the relevant Group Member be unable or unwilling to pay the compensation or comply with the order. 

The Lead Group Member acknowledges and accepts that it carries the burden of proof with regard to an alleged breach of the User Corporate Rules.

The Lead Group Member (or any other Group Member) shall not be liable if it reasonably demonstrates, based on the available facts and taking into account the comments of the User, that the non-EEA Group Member has not violated the User Corporate Rules or is not responsible for any damage alleged by the User.

5. Training

Group Members will ensure that all Employees Processing User Personal Data as well as those Employees that are involved in the design of tools that will be used to collect or process User Personal Data receive privacy and information security awareness training to emphasize and inform Employees of the need to protect and secure User Personal Data consistent with these User Corporate Rules. 

Employees are required to complete online compliance training centered around the Code of Business Conduct & Ethics, which includes a section on data protection, on an annual basis.  New Employees are required to complete the online compliance training upon starting their employment.

In addition to this online compliance training, the PayPal Global Privacy Team and the European Data Protection Officer conduct privacy and information security awareness trainings to emphasize and inform Employees of the need to protect and secure Personal Data. Such trainings are conducted on an annual basis or more frequent if circumstances require it.

The training Employees receive shall be adapted to their levels of access to User Personal Data, and additional training shall be provided to Employees with greater levels of access. 

Group Members shall inform Employees that failure to comply with these User Corporate Rules may result in disciplinary actions and other actions permitted by applicable law.  A copy of these User Corporate Rules and other relevant privacy and security related policies and procedures is available to Employees at any time via the company’s Intranet. The User Corporate Rules are also included in the Code of Business Conduct & Ethics which all Employees are required to review and agree to abide by.

6. Audits and Monitoring

To help ensure compliance with these User Corporate Rules, the PayPal Global Privacy Compliance Team reviews, on an ongoing basis, User Personal Data Processing activities and practices. These activities are coordinated in close consultation with the European Data Protection Officer. These activities take place periodically, and at least annually, and assist with assessing compliance with the User Corporate Rules.

The Internal Audit team is an independent and objective advisor to management and the Board of Directors, which, through the audit committee, communicates audit findings to the Board of Directors, the privacy leads and to the European Data Protection Officer. 

The Internal Audit team may conduct a review of activities or practices identified by the Global Privacy Team on a regular basis. The Internal Audit team, the privacy leads and the European Data Protection Officer, shall, if necessary, require that an action plan be executed to ensure compliance with these User Corporate Rules. To the extent that internal groups do not resolve matters adequately, the Group may appoint independent external auditors for further resolution.

The European Data Protection Officer, the PayPal Global Privacy Compliance Team or internal audit teams and external auditors develop detailed audit plans and schedules based upon the risk of the Processing.

Privacy audit findings will be available to competent Data Protection Authorities upon request.

7. Relationship between User Corporate Rules and National Law

With varying legal requirements throughout the world relating to data protection, the User Corporate Rules establish a consistent set of requirements to help ensure the appropriate Processing of User Personal Data. While the User Corporate Rules create a baseline requirement for Group Members to comply with, Group Members will comply with applicable laws that may impose a stricter standard than those set forth in these Corporate Rules.

Nothing in these User Corporate Rules affects a Group Members’ obligations under applicable banking laws, in particular in relation to bank secrecy.   If applicable law conflicts with these User Corporate Rules in that it might prevent a Group Member from fulfilling its obligations under the User Corporate Rules and has a substantial effect on the guarantees provided therein, the Group Member shall promptly notify the European Data Protection Officer, except where providing such information is prohibited by a law enforcement authority or law.  The European Data Protection Officer, the privacy leads and the Lead Group Member shall determine the appropriate course of action and, in case of doubt, consult with the competent Data Protection Authority.

8. Mutual Assistance and Cooperation with Data Protection Authorities

Group Members will cooperate and assist each other to handle requests or complaints from Users with regard to these User Corporate Rules.

Group Members will respond diligently and appropriately to requests from Data Protection Authorities about the User Corporate Rules.  If an Employee receives such a request from a Data Protection Authority, he or she should immediately inform the European Data Protection Officer.   

Group Members will cooperate with inquiries and accept audits from competent Data Protection Authorities in the EEA in respect of compliance with these User Corporate Rules and will respect their decisions, consistent with applicable law and due process rights.

Group Members will comply with the advice of the Data Protection Authorities on issues related to the User Corporate Rules. Any dispute related to a competent Data Protection Authority’s exercise of supervision of compliance with the User Corporate Rules will be resolved by the courts of the Member State of that Data Protection Authority, in accordance with that Member State’s procedural law. Group Members agree to submit themselves to the jurisdiction of these courts.

9. Updates of the Content of these User Corporate Rules and List of Bound Members

PayPal reserves the right to modify these User Corporate Rules as necessary, for example, to comply with changes in applicable laws, rules, regulations, PayPal practices, procedures and organizational structure or requirements imposed by relevant Data Protection Authorities.

The PayPal Global Privacy Legal Team (under the leadership of the Legal Privacy Lead), will propose any necessary changes to these User Corporate Rules. The PayPal Global Privacy Compliance Team (under the leadership of the Compliance Privacy Lead) and the European Data Protection Officer must approve all changes to the User Corporate Rules and shall track all modifications to the User Corporate Rules as well as any change in the list of Group Members. Group Members shall report to the relevant Data Protection Authorities changes to the User Corporate Rules for formal approval and as required by applicable law.

The Lead Group Member will consult with the Lead Data Protection Authority regarding material changes to the User Corporate Rules that would affect data protection compliance or the operation of the User Corporate Rules.  The Lead Group Member will communicate material changes to the User Corporate Rules and changes to the list of Group Members at least once a year to the Lead Data Protection Authority. If a material change is detrimental to the level of protection offered by these User Corporate Rules or would otherwise significantly affect the User Corporate Rules (e.g. changes to its binding character or changes to the Lead Group Member), such changes will be communicated in advance to the Lead Data Protection Authority with a brief explanation of the reasons for the update, so that the Lead Data Protection Authority may assess with other competent Data Protection Authorities whether the changes require a new approval.

The PayPal Global Privacy Teams will work together to support the European Data Protection Officer who, in particular, will coordinate responses and promptly address comments, suggestions or objections to the changes raised by the Lead Data Protection Authority on behalf of PayPal. Any comments, suggestions or objections raised by other Data Protection Authorities will be communicated to the European Data Protection Officer by the Lead Data Protection Authority who will act on behalf of the other Data Protection Authorities.  

Changes to the User Corporate Rules shall be applicable to all Group Members on the effective date of implementation. The PayPal Global Privacy Team and European Data Protection Officer will inform the Group Members of changes in the User Corporate Rules prior to implementation. Group Members will provide notice of material changes to the User Corporate Rules to Users in accordance with the User’s Service preferences either by mass email or by website posting with a clear warning to Users, ahead of time, that the User Rules have changed. The Group Members shall post the revised User Corporate Rules on selected external websites or applications accessible by Users.  Revisions to the User Corporate Rules are effective within a two month period after Group Members notify Users and post the revised User Corporate Rules.

No transfer is made to a new Group Member until the new Group Member BCR member is effectively bound by the User Corporate Rules and can deliver compliance.

10. Publication

The User Corporate Rules shall be published and a link shall be made available on the Service’s website or applications.  They will be available in key EU languages. Users may request a copy from The European Data Protection Officer (DPO), PayPal (Europe) S.à r.l et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg or Online.

11. Final provisions

Effective date: Date when published

Contact: Users can raise any questions or concerns in relation to these User Corporate Rules by contacting:

The European Data Protection Officer (DPO)

PayPal (Europe) S.à r.l et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg or by contacting PayPal at the following link: https://www.paypal.com/uk/cshelp/contact-us/privacy

12. Definitions

Group Members shall interpret the User Corporate Rules in a way that is most consistent with the basic concepts of the principles of Regulation (EU) 2016/679 or any superseding EU legislation.

For the purpose of these User Corporate Rules, the following definitions apply:

Board of Directors means the board of directors of the Lead Group Member.

Controller means the legal person which, alone or jointly with others, determines the purposes and means of the processing of Personal Data.

Data Protection Authorities means the independent public authorities that supervise, through investigative and corrective powers, the application of the data protection law, pursuant to Chapter VI of Regulation (EU) 2016/679 and other relevant national laws.

EEA means the European Economic Area, currently comprising the EU Member States, Iceland, Liechtenstein and Norway.

Employee means employees, workers, trainees and other personnel or staff members, including contingent or temporary workers, alternate work force, or contractors of a Group Member, whether employed or engaged on a full or part-time basis and irrespective of the type of employment or engagement.

European Data Protection Officer (DPO) means the employee who is appointed by and reports to the management of the Lead Group Member and also serves as a member of the PayPal Global Privacy Legal Team. The European DPO is located in Luxembourg.

Group Member means a PayPal Group entity that has executed a copy of the IGA.

IGA means the Intra-Group Agreement between the Lead Group Member and other PayPal Group Members that gives these User Corporate Rules binding effect within the PayPal Group.

Lead Data Protection Authority means the “Commission nationale pour la protection des données” (“CNPD”) in Luxembourg.

Lead Group Member means PayPal (Europe) S.à r.l. & Cie, S.C.A., a Luxembourg private limited liability company.

PayPal Global Privacy Team means the coordinated PayPal Global Privacy Compliance Team and the PayPal Global Privacy Legal Team.

PayPal Global Privacy Compliance Team means members of the Compliance Organization dealing specifically with the compliance and operation of the PayPal privacy program. 

PayPal Global Privacy Legal Team means members of the Legal Department dealing specifically with privacy and data protection.

PayPal Group means PayPal Holdings, Inc. (“PayPal”) and any entity directly or indirectly Controlled by PayPal that processes User Personal Data, where Control means the ownership of greater than fifty percent (50%) of the voting power to elect the directors of the company, or greater than fifty percent (50%) of the ownership interest in the company.

Personal Data means any information relating to an identified or identifiable natural person; an identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identification number or to one or more factors specific to his/her physical, physiological, mental, economic, cultural or social identity.

Process means any operation or set of operations that is performed upon Personal Data, whether or not by automatic means, such as collection, recording, organization, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, blocking, erasure or destruction.

Processor means any natural or legal person that Processes Personal Data on behalf of a Group Member.

Special Category Personal Data means Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data for the purpose of uniquely identify a natural person, information relating to criminal offences, or information concerning health, sex life or sexual orientation.

Service means a website, application, or other product or service offered by a Group Member for use by a User.

Third Party means any natural or legal person, public authority, agency or any other body other than the User, the Group Member, and the individuals who, under the direct authority of the Group Member, such as Employees, are authorized to Process Personal Data. The term “Third Party” shall include Processors who are not Group Members.

User means past and existing PayPal Group customers, prospects, investors, business partners, and merchants.

User Personal Data means Personal Data relating to Users.

User Personal Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, User Personal Data transmitted, stored or otherwise Processed.

Annex I

List of Group Members


EU/EEA Entities

Company nameAddressCountry
PayPal Limited, Belgium BranchBoulevard Saint-Michel 47, 1040 Etterbeek Brussels, BelgiumBelgium
PayPal Limited, French Branch21, rue de la Banque, 75002, Paris, FranceFrance
PayPal Limited, German Branch (Niederlassung)Marktplatz 1, 14532, Kleinmachnow, GermanyGermany
PayPal Europe Services LimitedBallycoolin Business Park, Ballycoolin Road, Blanchardstown, Dublin 15, IrelandIreland
PayPal Giving Fund Ireland Company Limited by GuaranteeBallycoolin Business Park, Ballycoolin Road, Dublin 15, D15 VNC4, IrelandIreland
PayPal LimitedBallycoolin Business Park, Ballycoolin Road, Blanchardstown, Dublin, DUBLIN 15, IrelandIreland
PayPal Limited, Sede Secondaria ItalianaRichmond Upon Thames, Whittaker Avenue SNC, United KingdomItaly
PayPal (Europe) S.à r.l.22-24 Boulevard Royal, L-2449, LuxembourgLuxembourg
PayPal (Europe) S.à r.l. et Cie, S.C.A.22-24 Boulevard Royal, L-2449 Luxembourg, LuxembourgLuxembourg
PayPal 2 S.à r.l.22-24 Boulevard Royal, L-2449, LuxembourgLuxembourg
PayPal International S.à.r.l22-24 Boulevard Royal, L-2449, LuxembourgLuxembourg
PayPal International Treasury Centre S.à r.l.22-24 Boulevard Royal, L-2449, Luxembourg, LuxembourgLuxembourg
PayPal Limited, Netherlands BranchBarbara Strozzilaan 201, 1083 HN, Amsterdam, NetherlandsNetherlands
iZettle Merchant Services ASAmesto Accountant House AS, Smeltedigelen 1, 0195, Osla, NorwayNorway
PayPal Polska Sp. z o.o.ul. Emilii Plater 53, 00-113, Warszawa, PolandPoland
Tapping Bunnies SRL46 Gen. Gheorghe Magheru Street, Entrance B, 2nd Floor, Apt. 8, Oradea City, Bihor County, RomaniaRomania
PayPal Limited, Sucursal en EspañaTorre Picasso, Plaza Pablo Ruiz Picasso, 1, planta 13, 28020, Madrid, SpainSpain
PayPal Spain, S.L. Sociedad UnipersonalTorre Picasso, Plaza Pablo Ruiz Picasso, 1, floor 13, 28020, Madrid, SpainSpain
iZettle Capital ABRegeringsgatan 65, 111 56, Stockholm, SwedenSweden
iZettle Merchant Services ABRegeringsgatan 65, 111 56, Stockholm, SwedenSweden
PayPal Limited, Filial SwedenRegeringsgatan 65, 111 56, Stockholm, SwedenSweden


UK Entities

Company NameAddressCountry
PayPal UK Ltd.Whittaker House, Whittaker Avenue, Richmond-Upon-Thames, Surrey, United Kingdom, TW9 1EHUnited Kingdom
PayPal Giving Fund UKWhittaker House, Whittaker Avenue, Richmond, Surrey, TW9 1EH, United KingdomUnited Kingdom
PayPal Limited, UK BranchWhittaker House, Whittaker Avenue, Richmond Upon Thames, Surrey, England, TW9 1 EH, United KingdomUnited Kingdom


Non-EU/EEA/UK Entities

Company NameAddressCountry
Hyperwallet Systems Australia Pty LtdLevel 24, 1 York Street, Sydney New South Wales 2000Australia
PayPal Australia Pty LimitedLevel 24, 1 York Street, Sydney NSW 2000, AustraliaAustralia
PayPal Credit Pty LtdLevel 24, 1 York Street, Sydney NSW 2000, AustraliaAustralia
PayPal Giving Fund Australia Company LtdLevel 24, 1 York Street, Sydney New South Wales 2000Australia
iZettle do Brasil Meios de Pagamento Ltda.Rua Alvorada, 1289, 19º Andar Vila Olimpia CEP 04550 004, São Paulo, BrazilBrazil
PayPal do Brasil Holding LtdaAv. Paulista, No. 1048, 13th floor, São Paulo, Sao Paulo, 01310-100, BrazilBrazil
PayPal do Brasil Instituição de Pagamento Ltda.Avenida Paulista, No. 1048, 8th, 13th and 17th floors, Bela Vista, São Paulo, 01310-100, BrazilBrazil
FPayPal do Brasil Holding Ltda.Av. Paulista, No. 1048, 13th floor, São Paulo, Sao Paulo, 01310-100, BrazilBrazil
Hyperwallet Systems Inc.Suite 2600, Three Bentall Centre, 595 Burrard Street, P.O. Box 49314, Vancouver BC V7X 1L3, CanadaCanada
PayPal Canada Co.600 - 1741, Lower Water Street, Halifax Nouvelle-Écosse NS B3J 0J2, CanadaCanada
PayPal Giving Fund Canada22 Adelaide Street West, Suite 3600, Toronto ON M5H4ED, CanadaCanada
Beijing Zhirong Xinda Technology Co., Ltd.Unit 5-A3, Building 3, No. 11 East Hepingli Street, Dongcheng District, Beijing, ChinaChina
PayPal Payments (Beijing) Co., Ltd.Room 1005, Floor 10, 101, Building 3, No. 9 Jiaogezhuang Street, Shunyi District, Beijing, ChinaChina
PayPal Payments (Beijing) Co., Ltd. Chaoyang BranchFloor 12A, North Tower of CP Center, No.20 Jin He East Avenue, Chaoyang Districk, Beijing, P.R.ChinaChina
PayPal Payments (Beijing) Co., Ltd., Shanghai BranchRoom 2303-2311, 23rd Floor, No. 175 Longyao Road, Xuhui District, Shanghai, ChinaChina
PayPal Payments (Beijing) Co., Ltd. Qianhai BranchRoom 702B-C, Building T1, Qianhai Kerry Center, Qianhai Avenue, Nanshan Street, Qianhai Shenzhen-Hong Kong Cooperation Zone, ShenzhenChina
PayPal Information Technologies (Shanghai) Co. Ltd, Shenzhen Beibao BranchUnit 301-1, Zhong Xin Si Road West, Fu Hua Yi Road South, Kerry Plaza, Futian District, Shenzhen, ChinaChina
PayPal Information Technologies (Shanghai) Co., Ltd.Unit 1901, 19F (actual 17F), No. 1217 Dongfang Road, Shanghai, Pilot Free Trade Zone, ChinaChina
PayPal Network Information Services (Shanghai) Co., Ltd.22F No. 1217 Dongfang Road, Pudong New District, Shanghai, 200127, ChinaChina
Shanghai An Jie Bao Tong Network Technology Co., Ltd.Room 302, Building 6, No. 91 Zhangjiang Road, Pilot Free Trade Zone, Shanghai, ChinaChina
PayPal Data Services, Inc., Sucursal GuatemalaRoute 03 4-59 zone 4, Municipality of Guatemala, Department of Guatemala, GuatemalaGuatemala
Soluciones BK, Sociedad AnonimaRoute 03 4-59 zone 4, Municipality of Guatemala, Department of Guatemala, GuatemalaGuatemala
PayPal Hong Kong LimitedRooms 1506-07, 15/F Central Plaza, 18 Harbour Road, Wanchai, Hong KongHong Kong
PayPal India Private LimitedFutura IT Park, Block A, 334 Old Mahabalipuram Road, Sholliganallur, Chennai, Tamil Nadu, 600119, IndiaIndia
PayPal India Private Limited, Hyderabad BranchLevel 2 Oval Building iLabs Centre Plot No. 18, Madhapur, Hyderabad, Circle 12, Circle 12, IndiaIndia
PayPal Payments Private Limited2nd Floor, B Quadrant, The IL&FS Financial Centre, Plot No. C 22, G Block, Bandra Kurla Complex, Bandra East, Maharashtra, 400051, IndiaIndia
PayPal Israel Holding (2008) Ltd.98 Yigal Alon St., P.O.Box 28218, zip code 6128102, Tel Aviv, 6789141, IsraelIsrael
PayPal Israel Ltd.Electra Tower, 98 Yigal Alon St., Tel Aviv, 6789141, IsraelIsrael
PayPal Israel Payment Services Ltd.Electra Tower, 98 Yigal Alon St., Tel Aviv, 6789141, IsraelIsrael
Hyperwallet Japan KK1-20-3 Nishi-shimbashi, Minato-ku, Tokyo, JapanJapan
Paidy Inc.9-7-1 Akasaka, Minato-ku, Tokyo, JapanJapan
PayPal Pte. Ltd., Tokyo BranchAo Building 15F, 3-11-7 Kita Aoyama Minato-ku, Tokyo, 107-0061, JapanJapan
PayPal Korea Services LLC#3004, 30th floor ASEM Tower, 517 Yeongdong-daero, Gangnam-gu, Seoul, 135-798, Korea, Republic ofKorea, Republic of
PayPal Malaysia Services Sdn. Bhd.Level 19-1, Menara Milenium, Jalan Damanlela, Pusat Bandar Damansara, 50490 Kuala Lumpur Wilayah Persekutuan, MalaysiaMalaysia
iZettle México, S. de R.L. de C.V. (in liquidation)No 13 oficina 402. Col., San José Insurgentes Del. Benito Juárez, CP 03900, MexicoMexico
Operadora PayPal de México, S. de R.L. de C.V.Mariano Escobedo 476 piso 14, Col. Nueva Anzures, Del. Miguel Hidalgo, Mexico City, 11590, MexicoMexico
PayPal Philippines, Inc.Unit 309, Antonio Centre, Prime Street, Madrigal Business Park II, Ayala Alabang Muntinlupa City, 1770, PhilippinesPhilippines
Limited Liability Company Non-Banking Credit Institution “PayPal RU” (LLC NBCI “PayPal RU”)Butirskiy Val, bl.10., 125047, Moscow, Russian FederationRussian Federation
PayPal Payment Holdings Pte. Ltd.5 Temasek Boulevard, #09-01 Suntec Tower Five, 038985, SingaporeSingapore
PayPal Payments Pte. Ltd.5 Temasek Boulevard, #09-01 Suntec Tower Five, 038985, SingaporeSingapore
PayPal Pte. Ltd.5 Temasek Boulevard, #09-01 Suntec Tower Five, 038985, SingaporeSingapore
PayPal Network Pte. Ltd.5 Temasek Boulevard, #09-01 Suntec Tower Five, 038985, SingaporeSingapore
Zong SAc/o Eversheds Sutherland AG, 20, rue du Marche, 1204 Geneve, SwitzerlandSwitzerland
PayPal (Thailand) LimitedNo. 63 Athenee Tower, Room No. 27-29, 23rd Floor, Witthayu Road, Kwaeng Lumpini, Khet Pathumwan, Bangkok, ThailandThailand
Bill Me Later, Inc.The Corporation Trust Company, 1209 Orange Street, Wilmington, New Castle County DE 19801, United StatesUnited States
Chargehound LLCThe Corporation Trust Company, 1209 Orange Street, Wilmington, New Castle County DE 19801, United StatesUnited States
Curv LLCThe Corporation Trust Company, 1209 Orange Street, Wilmington, New Castle County DE 19801, United StatesUnited States
Global Express Money Orders, Inc. (in liquidation)351 W Camden Street, Baltimore MD 21201, United StatesUnited States
Globex Financial Services, Inc. (in liquidation)The Corporation Trust Incorporated, 2405 York Rd. Ste. 201, Lutherville Timonium MD 21093, United StatesUnited States
Honey Science LLCThe Corporation Trust Company, 1209 Orange Street, Wilmington, New Castle County DE 19801, United StatesUnited States
Payments Technology Holdings, LLCCT Corporation System, 11 36 Union Mall, Suite 301, Honolulu HI 96813, United StatesUnited States
Payments Technology Insurance Company, Inc.CT Corporation System, 11 36 Union Mall, Suite 301, Honolulu HI 96813, United StatesUnited States
PayPal Charitable Giving Fund1202 I Street NW, Washington DC 20005, United StatesUnited States
PayPal Data Services, Inc.The Corporation Trust Company, 1209 Orange Street, Wilmington, New Castle County DE 19801, United StatesUnited States
PayPal Digital, Inc.117 Barrow Street, New York NY 10014United States
PayPal Global Holdings, Inc.The Corporation Trust Company, 1209 Orange Street, Wilmington, New Castle County DE 19801, United StatesUnited States
PayPal Holdings, Inc.The Corporation Trust Company, 1209 Orange Street, Wilmington, New Castle County DE 19801, United StatesUnited States
PayPal, Inc.The Corporation Trust Company, 1209 Orange Street, Wilmington, New Castle County DE 19801United States
PayPal Ventures, LLCThe Corporation Trust Company, 1209 Orange Street, Wilmington DE 19801, United StatesUnited States
Softgate Systems, Inc. (in liquidation)The Corporation Trust Company, 820 Bear Tavern Road, West Trenton NJ 08628, United StatesUnited States
Swift Financial, LLCThe Corporation Trust Company, 1209 Orange Street, Wilmington, New Castle County DE 19801, United StatesUnited States
TIO Networks USA Inc. (in liquidation)CT Corporation System, 711 Capitol Way S, Suite 204, Olympia WA 98501, United StatesUnited States
PayPal FZ-LLC405, 6 Falak Building, Al Safouh Second, Emirate of Dubai, United Arab EmiratesUnited Arab Emirates

Annex II

List of Countries

Non-EU

Australia
Brazil
Canada
China
Guatemala
Hong Kong
India
Israel
Japan
Korea, Republic of
Malaysia
Mexico
Philippines
Russian Federation
Singapore
Switzerland
Thailand
United States
United Arab Emirates

UK

United Kingdom

EU

Belgium
France
Germany
Ireland
Italy
Luxembourg
Norway
Poland
Romania
Spain
Sweden