Last updated on 28 September 2026
Last updated on 28 September 2026
The PayPal Group’s goal is to apply uniform, adequate and global data protection and privacy standards for the handling of all User Personal Data throughout the PayPal Group. These User Corporate Rules apply to all User Personal Data:
Users globally provide their Personal Data to Group Members to utilize the services the Group offers. Most User Personal Data is collected and stored in the United States. PayPal’s global business requires User Personal Data to be shared with other PayPal entities in the United States and globally where PayPal currently has or intends to have a presence.
PayPal is committed to adequately protecting the User information regardless of where the Personal Data resides and to provide appropriate protection for the User Personal Data where it is transferred outside of the EEA.
A list of Group Members who are subject to these User Corporate Rules is set out in Annex I. Employees located in the jurisdictions listed in Annex II may have access to User Personal Data. These lists may change as the company’s business expands.
The material scope of these Rules is referred in to the definitions and sections of the present Rules, such as in section 12 (Users’ Personal Data and types of data subjects), section 2.1 for the types of processing, that is the purposes for which User Personal Data are processed, and a list of countries is made available in Annex II.
The User Corporate Rules are made legally binding by an agreement (the “IGA”) between PayPal (Europe) S.à r.l. & Cie, S.C.A. (“Lead Group Member”) and other PayPal Group Members. The IGA requires Group Members to comply with these User Corporate Rules. Group Members require their Employees to comply with these User Corporate Rules when handling User Personal Data.
Business leaders and senior management of the PayPal Group are responsible for enforcing compliance with these User Corporate Rules, including ensuring that Employees are aware of and abide by these User Corporate Rules.
The Compliance Privacy Lead drives the PayPal privacy program. He/she holds a senior position within PayPal Holdings, Inc. and reports directly to the chief compliance officer or the highest senior executive leading the compliance function at PayPal. The Compliance Privacy Lead oversees the PayPal Global Privacy Compliance Team and interacts with other internal organizations or teams, such as operations, information security, compliance, risk and internal audit to help ensure consistent privacy communications, practices and policies across the PayPal Group globally. The PayPal Global Privacy Compliance Team develops and coordinates implementation of its compliance strategy across the PayPal Group and verifies operational compliance. The PayPal Global Privacy Compliance Team has direct and indirect representatives throughout the PayPal Group who, among other things, help to ensure compliance with the User Corporate Rules and applicable data protection laws.
The Legal Privacy Lead oversees the PayPal Global Privacy Legal Team and reports directly to the chief legal officer or the highest senior executive leading the legal function at PayPal. The Legal Privacy Lead defines the company’s obligations under applicable data protection laws and these User Corporate Rules. The Legal Privacy Lead and the PayPal Global Privacy Legal Team work in close coordination with the Compliance Privacy Lead and the PayPal Global Compliance Privacy Team, and interact with other internal organizations and teams, such as legal, operations, information security, and risk to provide legal advice and interpret legal and regulatory implications on evolving privacy matters across the PayPal Group globally.
Collectively, The PayPal Global Privacy Compliance Team and the PayPal Global Privacy Legal Team form the PayPal Global Privacy Team.
The European Data Protection Officer located in Luxembourg, is appointed by and reports to the management of PayPal (Europe) S.à r.l. et Cie, S.C.A.. The European Data Protection Officer acts as the primary contact for the EEA data protection authorities and does not perform any tasks that could result in a conflict of interests. The European Data Protection Officer has, among others, the following duties: to inform and advise the Group Members and their employees, who are processing personal data, of their obligations under privacy legislation to ensure compliance with these User Corporate Rules; to work with the PayPal Global Privacy Team to monitor compliance with privacy legislation and with related policies of the Group Members; and, to provide legal advice to the Group Members where requested as regards the data protection impact assessments and their implementation. The European Data Protection Officer shall report to the highest management level, and can inform the highest management level if any questions or problems arise during the performance of their duties.
Group Members observe the following Processing principles for User Personal Data.
2.1 Purpose Limitation
User Personal Data shall be Processed for specific, explicit and legitimate purposes only. In particular, User Personal Data may be Processed to:
Processing of User Personal Data for other purposes than the above purposes is subject to prior approval from the PayPal Global Privacy Legal Team. When in doubt, Group Members will consult the PayPal Global Privacy Legal Team.
User Personal Data shall not be further Processed for a secondary purpose in a way that is incompatible with the above listed purposes, unless there is a legal basis for doing so under the applicable law of the Group Member in the EEA responsible for the collection and/or transfer of the User Personal Data (i.e. the exporting entity).
2.2 Data Minimisation, Accuracy and Storage Limitation
User Personal Data shall be:
2.3 Legal Grounds for Processing and Fairness
Group Members shall ensure that User Personal Data is Processed fairly and lawfully and in particular on the basis of at least one of the following legal grounds:
Where collection of Special Category Personal Data is required or where Users voluntarily provide such information, Group Members shall ensure that the Users’ Special Category Personal Data is only Processed on the basis of at least one of the following grounds:
Where a User may be subject to a decision based solely on automated Processing, including profiling, which produces legal or significant effects (an “Automated Decision”), Group Members shall ensure that the Automated Decision:
Further, in at least the first and third cases above, the Group Member shall provide suitable measures to safeguard the User’s rights and freedoms and legitimate interests, such as providing the User an opportunity to have a customer support representative review the decision individually and permit the User to provide their point of view. The customer support representative shall escalate the matter to the EU Data Protection Officer in case the User continues to disagree with an Automated Decision. When appropriate, the Legal Privacy Lead will be consulted and the Compliance Privacy Lead will be apprised.
2.4 Transparency
When collecting User Personal Data, Group Members shall inform Users of:
Group Members may provide the information in a Service privacy policy which shall be accessible via a link and/or displayed in a prominent location of each Service website or application and during registration. The obligation to inform Users does not apply if Users already are aware of the information.
Where the provision of information proves impossible or would involve a disproportionate effort, Group Members may refrain from providing the information. This would only be the case for User Personal Data that has not been obtained from the User directly.
In exceptional circumstances, the provision of specific information may be postponed or omitted, for example, in the context of investigations into wrongful conduct or to comply with applicable laws or where provision of the information could jeopardize the integrity of the investigation.
2.5 Accountability, Confidentiality and Security
Every Group Member acting as data controller shall be responsible for and able to demonstrate compliance with the User Corporate Rules.
In order to enhance compliance and when required, data protection impact assessments are carried out for processing operations that are likely to result in a high risk to the rights and freedoms of natural persons. Where a data protection impact assessment as set out in Regulation (EU) 2016/679 indicates that the processing would result in a high risk in the absence of measures taken by the Group Member to mitigate the risk, the competent Data Protection Authority, prior to processing, will be consulted.
Appropriate technical and organisational measures are implemented and are designed to implement data protection principles and to facilitate compliance with the requirements set up by the User Corporate Rules in practice (data protection by design and by default).
Group Members use physical, technical and organizational security controls commensurate with the amount and sensitivity of the User Personal Data to prevent unauthorized Processing, including but not limited to, unauthorized access to, acquisition and use of, loss, destruction, or damage to User Personal Data. Group Members use encryption, firewalls, access controls, standards and other procedures to protect User Personal Data from unauthorized access. Physical and logical access to electronic and hard copy files is further restricted based upon job responsibilities and business needs.
Upon discovery of a personal data breach as defined in Art 4(12), Art.33(1) and Art.34(1) of GDPR Regulation (EU) 2016/679 and Art 33.1, the affected Group Member shall notify without undue delay the Lead Group Member, the European Data Protection Officer and other required stakeholders as per applicable internal policies. Where the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the Group Member and the Lead Group Member, in consultation with the European Data Protection officer, shall inform the impacted data subjects and the Data Protection Authority as applicable. Personal data breaches shall be documented to record i) the facts relating to the personal data breach, ii) its effects and iii) the remedial action taken are listed. Such documentation shall be provided to the competent Data Protection Authority on its request.
2.6 Users Choices and Rights
Users may exercise the following rights:
In all cases, Users can exercise the above rights by contacting customer support. Where a User’s identity is difficult to verify, Group Members may require the User to provide additional proof of identification. Group Members will comply with requests in the timeframes prescribed by applicable law, except where applicable law provides for an exception to such obligation.
2.7 Disclosures and Transfers of Personal Data
Group Members may share User Personal Data in the normal course and scope of business with other Group Members worldwide for the purposes identified in Section 2.1.
In accordance with applicable law, treaties or applicable international conventions, Group Members may share Personal Data with law enforcement and regulatory authorities when necessary in a democratic society to safeguard national security, defense, public security, the prevention, investigation, detection and prosecution of criminal offences, and, in particular to comply with sanctions as laid down in international and/or national instruments, tax-reporting requirements or anti-money-laundering reporting requirements.
Where a non EU Group Member has reasons to believe that the legislation applicable to it prevents that entity from fulfilling its obligations under the User Corporate Rules, with a substantial effect on the guarantees provided by the Rules, the non-EU Group Member will (unless prohibited) promptly inform the Lead Group Member and/or the European Data Protection Officer. This includes if it:
If in specific cases the suspension and/or notification are prohibited, the requested Group Member shall endeavor to obtain the right to waive this prohibition in order to communicate as much information as it can and as soon as possible. The non-EU Group Member will review the legality of each request for disclosure by a non-EU public authority to assess if it is within the powers granted to that authority, and will challenge the request if it is not. It will document and keep a record of its review and, unless prohibited, make this available to the Lead Group Member and/or the European Data Protection Officer. It will also make it available to competent Data Protection Authorities upon request.
The non-EU Group Member will provide the minimum amount of information permissible when responding to a request for disclosure from a non-EU public authority, based on a reasonable interpretation of the request.
Group Members cannot transfer User Personal Data to a non-EU public authority in a massive, disproportionate and indiscriminate manner that would go beyond what is necessary in a democratic society.
When Group Members transfer User Personal Data to a Processor, the Processor will be subject to a privacy, data protection and information security risk assessment prior to the initiation of work and prior to any transfer of User Personal Data. The scope of the assessment will vary based upon the sensitivity of the User Personal Data processed. The privacy, data protection and information security assessment is not mandatory for Processors that already have been subject to such an assessment or that are Group Members, unless the Processing activities involve high risk activities taking into account the nature and amount of Personal Data and the type of Processing activities concerned.
Processors, including a Group Member intervening as a Processor, must enter into an agreement with the relevant Group Member that will be acting as the Controller of the User Personal Data to provide adequate privacy, data protection and information security measures. Such an agreement includes clauses ensuring the appropriate use of User Personal Data and security measures commensurate with the amount, nature and sensitivity of the User Personal Data involved.
At a minimum, the contractual safeguards must cover the following matters:
The agreements must contain provisions ensuring that failure to comply with the terms of the agreement may result in the suspension or termination of the agreement among other remedies identified in the agreement.
Where Group Members transfer EEA User Personal Data to Third Parties (including Processors that are not Group Members located in a non-EEA country that (i) does not provide adequate levels of protection (within the meaning of the EU General Data Protection Regulation), and (ii) does not have other arrangements that would satisfy EU adequacy requirements, the Group Member shall ensure that the Third Party implements appropriate contractual safeguards, such as standard contractual clauses approved by the European Commission, providing levels of protection commensurate with these User Corporate Rules or, alternatively, ensure that the transfer (i) takes place with the explicit consent of the User, (ii) is necessary to conclude or perform a contract concluded with the User, (iii) is necessary or legally required on important public interest grounds, (iv) is necessary to protect the vital interests of the User; or (v) is necessary for the exercise, establishment or defence of legal claims.
2.8 Transfer Impact Assessments
Members shall assess (and on an ongoing basis monitor) whether third-country laws or practices prevent compliance with these User Corporate Rules. Such assessments shall consider:
If adequate protection cannot be ensured, transfers must be suspended or ended. Assessments shall be documented and made available to Data Protection Authorities on request.
2.9 Public Authority Requests
Importers shall inform the Lead Group Member on request of public authority access requests. They shall reasonably challenge secrecy or unlawful requests, minimise disclosure and record actions.
If Users believe that their User Personal Data has been processed in violation of the User Corporate Rules, they may report concerns to the customer service function of the relevant Group Member via the relevant Service’s website, email or as otherwise indicated in the applicable terms and conditions. Users generally can find answers to the most common privacy questions and concerns by typing the word “privacy” into the relevant service’s help section, which will usually direct the User to a privacy specific page or policy. The “help” section of the relevant service is the unique entry point for all Users’ queries relating to their privacy or the processing of their User Information and provides User’s the opportunity to contact customer support.
In case of doubt as to which channel to use to report privacy related concerns, Users can contact the European Data Protection Officer Online.
Customer support investigates and attempts to resolve concerns raised by Users. Employees responsible for addressing privacy related concerns work closely with the PayPal Global Privacy Team and reply to Users in accordance with PayPal’s policies, procedures and guidance. If Users believe their concerns have not been addressed adequately, or if they did not get a response, they can request that their concern be escalated to the European Data Protection Officer. The Legal Privacy Lead will be consulted and the Compliance Privacy Lead will be apprised. Escalation paths shall be determined based upon the nature and scope of the concern and shall be forwarded to the appropriate team without delays. A response to the complaint shall be provided to the User within a reasonable timeframe, and in any case within a period of three (3) months after the date of inquiry, except in unusual circumstances or complex questions in which case the User will be informed that the reply will take longer than three (3) months.
The complaint handing mechanism does not prejudice Users’ right to bring complaints before competent Data Protection Authorities or courts. In particular, Users may bring a complaint:
EEA Users who suspect a breach of the User Corporate Rules outside the EEA have the right to judicial enforcement and the right to obtain redress and, where appropriate, compensation in case of any breach of one of the enforceable elements of the User Corporate Rules as third party beneficiaries, and specifically for Sections 2, 3, 4, 7, 8 and 9 of the User Corporate Rules before the competent data protection authorities or before the courts in accordance with Section 3. These enforcement rights are in addition to other remedies or rights provided by PayPal or available under applicable law.
While it is not required, EEA Users are encouraged to first report their concern directly to the Group Member rather than the Data Protection Authorities or the courts. This enables an efficient and prompt response from the PayPal Group and minimizes possible delays from Data Protection Authorities or court procedures.
PayPal Europe S.à r.l. et Cie, S.C.A., a Luxembourg private limited liability company accepts responsibility for and agrees to oversee the Group Members' adherence to the User Corporate Rules. The Lead Group Member undertakes (i) to take the necessary action to remedy a breach committed by Group Members outside of the EEA; and (ii) to pay the compensation to EEA Users awarded by the Lead Data Protection Authority or Luxembourg courts for any damages directly resulting from the breach of the User Corporate Rules by Group Members outside the EEA, should the relevant Group Member be unable or unwilling to pay the compensation or comply with the order.
The Lead Group Member acknowledges and accepts that it carries the burden of proof with regard to an alleged breach of the User Corporate Rules.
The Lead Group Member (or any other Group Member) shall not be liable if it reasonably demonstrates, based on the available facts and taking into account the comments of the User, that the non-EEA Group Member has not violated the User Corporate Rules or is not responsible for any damage alleged by the User.
Group Members will ensure that all Employees Processing User Personal Data as well as those Employees that are involved in the design of tools that will be used to collect or process User Personal Data receive privacy and information security awareness training to emphasize and inform Employees of the need to protect and secure User Personal Data consistent with these User Corporate Rules.
Employees are required to complete online compliance training centered around the Code of Business Conduct & Ethics, which includes a section on data protection, on an annual basis. New Employees are required to complete the online compliance training upon starting their employment.
In addition to this online compliance training, the PayPal Global Privacy Team and the European Data Protection Officer conduct privacy and information security awareness trainings to emphasize and inform Employees of the need to protect and secure Personal Data. Such trainings are conducted on an annual basis or more frequent if circumstances require it.
The training Employees receive shall be adapted to their levels of access to User Personal Data, and additional training shall be provided to Employees with greater levels of access.
Group Members shall inform Employees that failure to comply with these User Corporate Rules may result in disciplinary actions and other actions permitted by applicable law. A copy of these User Corporate Rules and other relevant privacy and security related policies and procedures is available to Employees at any time via the company’s Intranet. The User Corporate Rules are also included in the Code of Business Conduct & Ethics which all Employees are required to review and agree to abide by.
To help ensure compliance with these User Corporate Rules, the PayPal Global Privacy Compliance Team reviews, on an ongoing basis, User Personal Data Processing activities and practices. These activities are coordinated in close consultation with the European Data Protection Officer. These activities take place periodically, and at least annually, and assist with assessing compliance with the User Corporate Rules.
The Internal Audit team is an independent and objective advisor to management and the Board of Directors, which, through the audit committee, communicates audit findings to the Board of Directors, the privacy leads and to the European Data Protection Officer.
The Internal Audit team may conduct a review of activities or practices identified by the Global Privacy Team on a regular basis. The Internal Audit team, the privacy leads and the European Data Protection Officer, shall, if necessary, require that an action plan be executed to ensure compliance with these User Corporate Rules. To the extent that internal groups do not resolve matters adequately, the Group may appoint independent external auditors for further resolution.
The European Data Protection Officer, the PayPal Global Privacy Compliance Team or internal audit teams and external auditors develop detailed audit plans and schedules based upon the risk of the Processing.
Privacy audit findings will be available to competent Data Protection Authorities upon request.
With varying legal requirements throughout the world relating to data protection, the User Corporate Rules establish a consistent set of requirements to help ensure the appropriate Processing of User Personal Data. While the User Corporate Rules create a baseline requirement for Group Members to comply with, Group Members will comply with applicable laws that may impose a stricter standard than those set forth in these Corporate Rules.
Nothing in these User Corporate Rules affects a Group Members’ obligations under applicable banking laws, in particular in relation to bank secrecy. If applicable law conflicts with these User Corporate Rules in that it might prevent a Group Member from fulfilling its obligations under the User Corporate Rules and has a substantial effect on the guarantees provided therein, the Group Member shall promptly notify the European Data Protection Officer, except where providing such information is prohibited by a law enforcement authority or law. The European Data Protection Officer, the privacy leads and the Lead Group Member shall determine the appropriate course of action and, in case of doubt, consult with the competent Data Protection Authority.
Group Members will cooperate and assist each other to handle requests or complaints from Users with regard to these User Corporate Rules.
Group Members will respond diligently and appropriately to requests from Data Protection Authorities about the User Corporate Rules. If an Employee receives such a request from a Data Protection Authority, he or she should immediately inform the European Data Protection Officer.
Group Members will cooperate with inquiries and accept audits from competent Data Protection Authorities in the EEA in respect of compliance with these User Corporate Rules and will respect their decisions, consistent with applicable law and due process rights.
Group Members will comply with the advice of the Data Protection Authorities on issues related to the User Corporate Rules. Any dispute related to a competent Data Protection Authority’s exercise of supervision of compliance with the User Corporate Rules will be resolved by the courts of the Member State of that Data Protection Authority, in accordance with that Member State’s procedural law. Group Members agree to submit themselves to the jurisdiction of these courts.
PayPal reserves the right to modify these User Corporate Rules as necessary, for example, to comply with changes in applicable laws, rules, regulations, PayPal practices, procedures and organizational structure or requirements imposed by relevant Data Protection Authorities.
The PayPal Global Privacy Legal Team (under the leadership of the Legal Privacy Lead), will propose any necessary changes to these User Corporate Rules. The PayPal Global Privacy Compliance Team (under the leadership of the Compliance Privacy Lead) and the European Data Protection Officer must approve all changes to the User Corporate Rules and shall track all modifications to the User Corporate Rules as well as any change in the list of Group Members. Group Members shall report to the relevant Data Protection Authorities changes to the User Corporate Rules for formal approval and as required by applicable law.
The Lead Group Member will consult with the Lead Data Protection Authority regarding material changes to the User Corporate Rules that would affect data protection compliance or the operation of the User Corporate Rules. The Lead Group Member will communicate material changes to the User Corporate Rules and changes to the list of Group Members at least once a year to the Lead Data Protection Authority. If a material change is detrimental to the level of protection offered by these User Corporate Rules or would otherwise significantly affect the User Corporate Rules (e.g. changes to its binding character or changes to the Lead Group Member), such changes will be communicated in advance to the Lead Data Protection Authority with a brief explanation of the reasons for the update, so that the Lead Data Protection Authority may assess with other competent Data Protection Authorities whether the changes require a new approval.
The PayPal Global Privacy Teams will work together to support the European Data Protection Officer who, in particular, will coordinate responses and promptly address comments, suggestions or objections to the changes raised by the Lead Data Protection Authority on behalf of PayPal. Any comments, suggestions or objections raised by other Data Protection Authorities will be communicated to the European Data Protection Officer by the Lead Data Protection Authority who will act on behalf of the other Data Protection Authorities.
Changes to the User Corporate Rules shall be applicable to all Group Members on the effective date of implementation. The PayPal Global Privacy Team and European Data Protection Officer will inform the Group Members of changes in the User Corporate Rules prior to implementation. Group Members will provide notice of material changes to the User Corporate Rules to Users in accordance with the User’s Service preferences either by mass email or by website posting with a clear warning to Users, ahead of time, that the User Rules have changed. The Group Members shall post the revised User Corporate Rules on selected external websites or applications accessible by Users. Revisions to the User Corporate Rules are effective within a two month period after Group Members notify Users and post the revised User Corporate Rules.
No transfer is made to a new Group Member until the new Group Member BCR member is effectively bound by the User Corporate Rules and can deliver compliance.
The User Corporate Rules shall be published and a link shall be made available on the Service’s website or applications. They will be available in key EU languages. Users may request a copy from The European Data Protection Officer (DPO), PayPal (Europe) S.à r.l et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg or Online.
Effective date: Date when published
Contact: Users can raise any questions or concerns in relation to these User Corporate Rules by contacting:
The European Data Protection Officer (DPO)
PayPal (Europe) S.à r.l et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg or by contacting PayPal at the following link: https://www.paypal.com/uk/cshelp/contact-us/privacy
Group Members shall interpret the User Corporate Rules in a way that is most consistent with the basic concepts of the principles of Regulation (EU) 2016/679 or any superseding EU legislation.
For the purpose of these User Corporate Rules, the following definitions apply:
Board of Directors means the board of directors of the Lead Group Member.
Controller means the legal person which, alone or jointly with others, determines the purposes and means of the processing of Personal Data.
Data Protection Authorities means the independent public authorities that supervise, through investigative and corrective powers, the application of the data protection law, pursuant to Chapter VI of Regulation (EU) 2016/679 and other relevant national laws.
EEA means the European Economic Area, currently comprising the EU Member States, Iceland, Liechtenstein and Norway.
Employee means employees, workers, trainees and other personnel or staff members, including contingent or temporary workers, alternate work force, or contractors of a Group Member, whether employed or engaged on a full or part-time basis and irrespective of the type of employment or engagement.
European Data Protection Officer (DPO) means the employee who is appointed by and reports to the management of the Lead Group Member and also serves as a member of the PayPal Global Privacy Legal Team. The European DPO is located in Luxembourg.
Group Member means a PayPal Group entity that has executed a copy of the IGA.
IGA means the Intra-Group Agreement between the Lead Group Member and other PayPal Group Members that gives these User Corporate Rules binding effect within the PayPal Group.
Lead Data Protection Authority means the “Commission nationale pour la protection des données” (“CNPD”) in Luxembourg.
Lead Group Member means PayPal (Europe) S.à r.l. & Cie, S.C.A., a Luxembourg private limited liability company.
PayPal Global Privacy Team means the coordinated PayPal Global Privacy Compliance Team and the PayPal Global Privacy Legal Team.
PayPal Global Privacy Compliance Team means members of the Compliance Organization dealing specifically with the compliance and operation of the PayPal privacy program.
PayPal Global Privacy Legal Team means members of the Legal Department dealing specifically with privacy and data protection.
PayPal Group means PayPal Holdings, Inc. (“PayPal”) and any entity directly or indirectly Controlled by PayPal that processes User Personal Data, where Control means the ownership of greater than fifty percent (50%) of the voting power to elect the directors of the company, or greater than fifty percent (50%) of the ownership interest in the company.
Personal Data means any information relating to an identified or identifiable natural person; an identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identification number or to one or more factors specific to his/her physical, physiological, mental, economic, cultural or social identity.
Process means any operation or set of operations that is performed upon Personal Data, whether or not by automatic means, such as collection, recording, organization, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, blocking, erasure or destruction.
Processor means any natural or legal person that Processes Personal Data on behalf of a Group Member.
Special Category Personal Data means Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data for the purpose of uniquely identify a natural person, information relating to criminal offences, or information concerning health, sex life or sexual orientation.
Service means a website, application, or other product or service offered by a Group Member for use by a User.
Third Party means any natural or legal person, public authority, agency or any other body other than the User, the Group Member, and the individuals who, under the direct authority of the Group Member, such as Employees, are authorized to Process Personal Data. The term “Third Party” shall include Processors who are not Group Members.
User means past and existing PayPal Group customers, prospects, investors, business partners, and merchants.
User Personal Data means Personal Data relating to Users.
User Personal Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, User Personal Data transmitted, stored or otherwise Processed.
| Company name | Address | Country |
|---|---|---|
| PayPal Limited, Belgium Branch | Boulevard Saint-Michel 47, 1040 Etterbeek Brussels, Belgium | Belgium |
| PayPal Limited, French Branch | 21, rue de la Banque, 75002, Paris, France | France |
| PayPal Limited, German Branch (Niederlassung) | Marktplatz 1, 14532, Kleinmachnow, Germany | Germany |
| PayPal Europe Services Limited | Ballycoolin Business Park, Ballycoolin Road, Blanchardstown, Dublin 15, Ireland | Ireland |
| PayPal Giving Fund Ireland Company Limited by Guarantee | Ballycoolin Business Park, Ballycoolin Road, Dublin 15, D15 VNC4, Ireland | Ireland |
| PayPal Limited | Ballycoolin Business Park, Ballycoolin Road, Blanchardstown, Dublin, DUBLIN 15, Ireland | Ireland |
| PayPal Limited, Sede Secondaria Italiana | Richmond Upon Thames, Whittaker Avenue SNC, United Kingdom | Italy |
| PayPal (Europe) S.à r.l. | 22-24 Boulevard Royal, L-2449, Luxembourg | Luxembourg |
| PayPal (Europe) S.à r.l. et Cie, S.C.A. | 22-24 Boulevard Royal, L-2449 Luxembourg, Luxembourg | Luxembourg |
| PayPal 2 S.à r.l. | 22-24 Boulevard Royal, L-2449, Luxembourg | Luxembourg |
| PayPal International S.à.r.l | 22-24 Boulevard Royal, L-2449, Luxembourg | Luxembourg |
| PayPal International Treasury Centre S.à r.l. | 22-24 Boulevard Royal, L-2449, Luxembourg, Luxembourg | Luxembourg |
| PayPal Limited, Netherlands Branch | Barbara Strozzilaan 201, 1083 HN, Amsterdam, Netherlands | Netherlands |
| iZettle Merchant Services AS | Amesto Accountant House AS, Smeltedigelen 1, 0195, Osla, Norway | Norway |
| PayPal Polska Sp. z o.o. | ul. Emilii Plater 53, 00-113, Warszawa, Poland | Poland |
| Tapping Bunnies SRL | 46 Gen. Gheorghe Magheru Street, Entrance B, 2nd Floor, Apt. 8, Oradea City, Bihor County, Romania | Romania |
| PayPal Limited, Sucursal en España | Torre Picasso, Plaza Pablo Ruiz Picasso, 1, planta 13, 28020, Madrid, Spain | Spain |
| PayPal Spain, S.L. Sociedad Unipersonal | Torre Picasso, Plaza Pablo Ruiz Picasso, 1, floor 13, 28020, Madrid, Spain | Spain |
| iZettle Capital AB | Regeringsgatan 65, 111 56, Stockholm, Sweden | Sweden |
| iZettle Merchant Services AB | Regeringsgatan 65, 111 56, Stockholm, Sweden | Sweden |
| PayPal Limited, Filial Sweden | Regeringsgatan 65, 111 56, Stockholm, Sweden | Sweden |
| Company Name | Address | Country |
|---|---|---|
| PayPal UK Ltd. | Whittaker House, Whittaker Avenue, Richmond-Upon-Thames, Surrey, United Kingdom, TW9 1EH | United Kingdom |
| PayPal Giving Fund UK | Whittaker House, Whittaker Avenue, Richmond, Surrey, TW9 1EH, United Kingdom | United Kingdom |
| PayPal Limited, UK Branch | Whittaker House, Whittaker Avenue, Richmond Upon Thames, Surrey, England, TW9 1 EH, United Kingdom | United Kingdom |
| Company Name | Address | Country |
|---|---|---|
| Hyperwallet Systems Australia Pty Ltd | Level 24, 1 York Street, Sydney New South Wales 2000 | Australia |
| PayPal Australia Pty Limited | Level 24, 1 York Street, Sydney NSW 2000, Australia | Australia |
| PayPal Credit Pty Ltd | Level 24, 1 York Street, Sydney NSW 2000, Australia | Australia |
| PayPal Giving Fund Australia Company Ltd | Level 24, 1 York Street, Sydney New South Wales 2000 | Australia |
| iZettle do Brasil Meios de Pagamento Ltda. | Rua Alvorada, 1289, 19º Andar Vila Olimpia CEP 04550 004, São Paulo, Brazil | Brazil |
| PayPal do Brasil Holding Ltda | Av. Paulista, No. 1048, 13th floor, São Paulo, Sao Paulo, 01310-100, Brazil | Brazil |
| PayPal do Brasil Instituição de Pagamento Ltda. | Avenida Paulista, No. 1048, 8th, 13th and 17th floors, Bela Vista, São Paulo, 01310-100, Brazil | Brazil |
| FPayPal do Brasil Holding Ltda. | Av. Paulista, No. 1048, 13th floor, São Paulo, Sao Paulo, 01310-100, Brazil | Brazil |
| Hyperwallet Systems Inc. | Suite 2600, Three Bentall Centre, 595 Burrard Street, P.O. Box 49314, Vancouver BC V7X 1L3, Canada | Canada |
| PayPal Canada Co. | 600 - 1741, Lower Water Street, Halifax Nouvelle-Écosse NS B3J 0J2, Canada | Canada |
| PayPal Giving Fund Canada | 22 Adelaide Street West, Suite 3600, Toronto ON M5H4ED, Canada | Canada |
| Beijing Zhirong Xinda Technology Co., Ltd. | Unit 5-A3, Building 3, No. 11 East Hepingli Street, Dongcheng District, Beijing, China | China |
| PayPal Payments (Beijing) Co., Ltd. | Room 1005, Floor 10, 101, Building 3, No. 9 Jiaogezhuang Street, Shunyi District, Beijing, China | China |
| PayPal Payments (Beijing) Co., Ltd. Chaoyang Branch | Floor 12A, North Tower of CP Center, No.20 Jin He East Avenue, Chaoyang Districk, Beijing, P.R.China | China |
| PayPal Payments (Beijing) Co., Ltd., Shanghai Branch | Room 2303-2311, 23rd Floor, No. 175 Longyao Road, Xuhui District, Shanghai, China | China |
| PayPal Payments (Beijing) Co., Ltd. Qianhai Branch | Room 702B-C, Building T1, Qianhai Kerry Center, Qianhai Avenue, Nanshan Street, Qianhai Shenzhen-Hong Kong Cooperation Zone, Shenzhen | China |
| PayPal Information Technologies (Shanghai) Co. Ltd, Shenzhen Beibao Branch | Unit 301-1, Zhong Xin Si Road West, Fu Hua Yi Road South, Kerry Plaza, Futian District, Shenzhen, China | China |
| PayPal Information Technologies (Shanghai) Co., Ltd. | Unit 1901, 19F (actual 17F), No. 1217 Dongfang Road, Shanghai, Pilot Free Trade Zone, China | China |
| PayPal Network Information Services (Shanghai) Co., Ltd. | 22F No. 1217 Dongfang Road, Pudong New District, Shanghai, 200127, China | China |
| Shanghai An Jie Bao Tong Network Technology Co., Ltd. | Room 302, Building 6, No. 91 Zhangjiang Road, Pilot Free Trade Zone, Shanghai, China | China |
| PayPal Data Services, Inc., Sucursal Guatemala | Route 03 4-59 zone 4, Municipality of Guatemala, Department of Guatemala, Guatemala | Guatemala |
| Soluciones BK, Sociedad Anonima | Route 03 4-59 zone 4, Municipality of Guatemala, Department of Guatemala, Guatemala | Guatemala |
| PayPal Hong Kong Limited | Rooms 1506-07, 15/F Central Plaza, 18 Harbour Road, Wanchai, Hong Kong | Hong Kong |
| PayPal India Private Limited | Futura IT Park, Block A, 334 Old Mahabalipuram Road, Sholliganallur, Chennai, Tamil Nadu, 600119, India | India |
| PayPal India Private Limited, Hyderabad Branch | Level 2 Oval Building iLabs Centre Plot No. 18, Madhapur, Hyderabad, Circle 12, Circle 12, India | India |
| PayPal Payments Private Limited | 2nd Floor, B Quadrant, The IL&FS Financial Centre, Plot No. C 22, G Block, Bandra Kurla Complex, Bandra East, Maharashtra, 400051, India | India |
| PayPal Israel Holding (2008) Ltd. | 98 Yigal Alon St., P.O.Box 28218, zip code 6128102, Tel Aviv, 6789141, Israel | Israel |
| PayPal Israel Ltd. | Electra Tower, 98 Yigal Alon St., Tel Aviv, 6789141, Israel | Israel |
| PayPal Israel Payment Services Ltd. | Electra Tower, 98 Yigal Alon St., Tel Aviv, 6789141, Israel | Israel |
| Hyperwallet Japan KK | 1-20-3 Nishi-shimbashi, Minato-ku, Tokyo, Japan | Japan |
| Paidy Inc. | 9-7-1 Akasaka, Minato-ku, Tokyo, Japan | Japan |
| PayPal Pte. Ltd., Tokyo Branch | Ao Building 15F, 3-11-7 Kita Aoyama Minato-ku, Tokyo, 107-0061, Japan | Japan |
| PayPal Korea Services LLC | #3004, 30th floor ASEM Tower, 517 Yeongdong-daero, Gangnam-gu, Seoul, 135-798, Korea, Republic of | Korea, Republic of |
| PayPal Malaysia Services Sdn. Bhd. | Level 19-1, Menara Milenium, Jalan Damanlela, Pusat Bandar Damansara, 50490 Kuala Lumpur Wilayah Persekutuan, Malaysia | Malaysia |
| iZettle México, S. de R.L. de C.V. (in liquidation) | No 13 oficina 402. Col., San José Insurgentes Del. Benito Juárez, CP 03900, Mexico | Mexico |
| Operadora PayPal de México, S. de R.L. de C.V. | Mariano Escobedo 476 piso 14, Col. Nueva Anzures, Del. Miguel Hidalgo, Mexico City, 11590, Mexico | Mexico |
| PayPal Philippines, Inc. | Unit 309, Antonio Centre, Prime Street, Madrigal Business Park II, Ayala Alabang Muntinlupa City, 1770, Philippines | Philippines |
| Limited Liability Company Non-Banking Credit Institution “PayPal RU” (LLC NBCI “PayPal RU”) | Butirskiy Val, bl.10., 125047, Moscow, Russian Federation | Russian Federation |
| PayPal Payment Holdings Pte. Ltd. | 5 Temasek Boulevard, #09-01 Suntec Tower Five, 038985, Singapore | Singapore |
| PayPal Payments Pte. Ltd. | 5 Temasek Boulevard, #09-01 Suntec Tower Five, 038985, Singapore | Singapore |
| PayPal Pte. Ltd. | 5 Temasek Boulevard, #09-01 Suntec Tower Five, 038985, Singapore | Singapore |
| PayPal Network Pte. Ltd. | 5 Temasek Boulevard, #09-01 Suntec Tower Five, 038985, Singapore | Singapore |
| Zong SA | c/o Eversheds Sutherland AG, 20, rue du Marche, 1204 Geneve, Switzerland | Switzerland |
| PayPal (Thailand) Limited | No. 63 Athenee Tower, Room No. 27-29, 23rd Floor, Witthayu Road, Kwaeng Lumpini, Khet Pathumwan, Bangkok, Thailand | Thailand |
| Bill Me Later, Inc. | The Corporation Trust Company, 1209 Orange Street, Wilmington, New Castle County DE 19801, United States | United States |
| Chargehound LLC | The Corporation Trust Company, 1209 Orange Street, Wilmington, New Castle County DE 19801, United States | United States |
| Curv LLC | The Corporation Trust Company, 1209 Orange Street, Wilmington, New Castle County DE 19801, United States | United States |
| Global Express Money Orders, Inc. (in liquidation) | 351 W Camden Street, Baltimore MD 21201, United States | United States |
| Globex Financial Services, Inc. (in liquidation) | The Corporation Trust Incorporated, 2405 York Rd. Ste. 201, Lutherville Timonium MD 21093, United States | United States |
| Honey Science LLC | The Corporation Trust Company, 1209 Orange Street, Wilmington, New Castle County DE 19801, United States | United States |
| Payments Technology Holdings, LLC | CT Corporation System, 11 36 Union Mall, Suite 301, Honolulu HI 96813, United States | United States |
| Payments Technology Insurance Company, Inc. | CT Corporation System, 11 36 Union Mall, Suite 301, Honolulu HI 96813, United States | United States |
| PayPal Charitable Giving Fund | 1202 I Street NW, Washington DC 20005, United States | United States |
| PayPal Data Services, Inc. | The Corporation Trust Company, 1209 Orange Street, Wilmington, New Castle County DE 19801, United States | United States |
| PayPal Digital, Inc. | 117 Barrow Street, New York NY 10014 | United States |
| PayPal Global Holdings, Inc. | The Corporation Trust Company, 1209 Orange Street, Wilmington, New Castle County DE 19801, United States | United States |
| PayPal Holdings, Inc. | The Corporation Trust Company, 1209 Orange Street, Wilmington, New Castle County DE 19801, United States | United States |
| PayPal, Inc. | The Corporation Trust Company, 1209 Orange Street, Wilmington, New Castle County DE 19801 | United States |
| PayPal Ventures, LLC | The Corporation Trust Company, 1209 Orange Street, Wilmington DE 19801, United States | United States |
| Softgate Systems, Inc. (in liquidation) | The Corporation Trust Company, 820 Bear Tavern Road, West Trenton NJ 08628, United States | United States |
| Swift Financial, LLC | The Corporation Trust Company, 1209 Orange Street, Wilmington, New Castle County DE 19801, United States | United States |
| TIO Networks USA Inc. (in liquidation) | CT Corporation System, 711 Capitol Way S, Suite 204, Olympia WA 98501, United States | United States |
| PayPal FZ-LLC | 405, 6 Falak Building, Al Safouh Second, Emirate of Dubai, United Arab Emirates | United Arab Emirates |
| Australia |
| Brazil |
| Canada |
| China |
| Guatemala |
| Hong Kong |
| India |
| Israel |
| Japan |
| Korea, Republic of |
| Malaysia |
| Mexico |
| Philippines |
| Russian Federation |
| Singapore |
| Switzerland |
| Thailand |
| United States |
| United Arab Emirates |
| United Kingdom |
| Belgium |
| France |
| Germany |
| Ireland |
| Italy |
| Luxembourg |
| Norway |
| Poland |
| Romania |
| Spain |
| Sweden |