When you are collecting payments, it usually means you are handling people’s personal data. This can include a name, address, a sort coded, an account number or a card number. These all count as personal data under UK law.
Every business that takes a payment is a data controller with responsibilities that reach well beyond the finance team. Getting this right protects customers and it will protect the business too.
At SmarterPay we help organisations of every size collect payments through Direct Debit and recurring card payments. Over the years we have found that businesses who treat data protection as part of how they collect, rather than a box to tick afterwards, are the ones who avoid trouble later. This guide sets out what collectors need to know, in plain terms.
This is general guidance rather than legal advice. Every organisation has its own circumstances, so it is worth checking your specific obligations with a suitably qualified adviser.
What Counts as Payment Data
Under UK GDPR, personal data is any information that relates to an identifiable person. In a payment context that covers more than most people expect. It includes:
- Names and contact details
- Home or billing addresses
- Bank account numbers and sort codes
- Card numbers, expiry dates and security codes
- Payment references that can be tied back to a person
- Transaction history and payment schedules
Bank and card details are not classes as special category data, but they are sensitive in the everyday sense of the word. If they fall into the wrong hands the consequences for the customer are real and immediate. That is why they deserve careful handling.
The Rules Have Changed, But Have Not Been Torn Up
UK data protection law rests on three pieces: the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations. The Data Act 2025 has amended all three, with most of the changes phasing in through 2025 and 2026. One point is worth being clear about. The Act does not replace the UK GDPR. The core principles collectors have worked to for years still apply.
There are some useful updates. A new lawful basis called recognised legitimate interests has been added, the rules on responding to data requests have been clarified, and organisations now need a proper process for handling data protection complaints, including acknowledging them within 30 days. For most collectors the day-to-day approach stays the same. Know why you hold payment data, hold only what you need, keep it safe and be ready to answer for it.
Finding the Right Lawful Basis
Every use of personal data needs a lawful basis. For payment collection, the right one is usually contract. When someone agrees to buy a product, subscribe to a service or setup a Direct Debit, processing their payment details is necessary to deliver on that agreement. Some processing rests on legal obligation instead, for example keeping the records that tax rules require.
Consent is often not the right basis for taking a payment someone already owes. If a customer has signed up to pay, the business does not need separate consent to process the payment, and leaning on consent can even cause problems, because consent can be withdrawn at any rime. Choosing the correct basis at the outset saves confusion later.
Collect Only What You Need
Two Principles do a lot of work here, data minimisation and purpose limitation. Data minimisation means collecting only the information needed for the payment. If a sort code and account number will do, there is no reason to ask for more. Purpose limitation means using that data only for the reason it was collected. Payment details gathered to take a Direct Debit should not quietly find their way onto a marketing list.
Here at SmarterPay, we build our platform around this idea. Collectors capture what they need to process a payment and nothing more, which keeps both the data footprint and the risk low.
Keep Payment Data Secure
UK GDPR asks for appropriate technical and organisational measures to keep personal data safe. In practice, for payment data, that means encryption in transit and at rest, strict access controls so only the right people can see it, secure storage rather than spreadsheets on a shared drive, and clear internal processes for handling it.
Card payments carry an extra layer. The Payment Card Industry Data Security Standard, better known ac PCI DSS, sets specific rules for storing and processing card data. It sits alongside GDPR rather than replacing it, so businesses taking card payments need to meet both. The simplest way to reduce the burden is to handle as little card data in house as possible, which is exactly what a compliant payment provider is there for.
How Long to Keep Payment Records
Storage limitation is a principle people often overlook. Payment data should not be kept for longer than it is needed. That said, needed includes meeting other legal duties. Financial and tax records, for instance, usually have to be kept for around six years. The sensible approach is a clear retention policy that sets out what is kept, why and for how long, followed by secure deletion once that period ends. Holding on to old payment details just in case it is a risk, not a safeguard.
Working With Payment Providers and Third Parties
Very few businesses handle the whole payment journey along. Most work with a provider, a Bacs Bureau or software like ours. In data protection terms the collector is usually the data controller and the provider is the data processor. That relationship needs a written data processing agreement setting out how the processor may handle the data and what protections are in place.
Here at SmarterPay we act as a processor for many of our customers, so we take this seriously. Our systems are built to keep payment data secure, our UK based team is GDPR trained, and we are clear about how data moves through our platform. Choosing a provider who understands these duties takes a real weigh off the collector.
Respect People’s Rights
UK GDPR gives peoples rights over their data, and those rights apply to payment data. They can ask what a business holds about them, ask for mistakes to be corrected and, in some cases, ask for data to be deleted. Erasure is not absolute. Where records must be kept for legal reasons, that duty can override a deletion request, but the business should be able to explain its reasoning clearly.
The Data Act has added a duty to handle data protection complaints properly, including acknowledging them within 30 days. A straightforward way for customers to raise a concern is now part of good practice, not just good manners.
When Something Goes Wrong
Even careful organisations can suffer a data breach. What matters is the response. If a breach risks people’s rights and freedoms, it must be reported to the Information Commissioner’s Office without undue delay and withing 72 hours where feasible. If the risk is high, the affected people usually need to be told as well.
The penalties for getting data protection seriously wrong are steep, up to £17.5 million of 4% of global annual turnover. But the reputational damage of mishandling customer payment can cost far more than any fine.
Having a plan ready before anything happens makes all the difference. Know who to contact, what to record and how quickly to act.
Build It in From the Start
The thread running through all of this is simple. Data protection works best when it is built into how payments are collected, not bolted on afterwards. Choose the right lawful basis, collect only what is needed, keep it secure, hold it no longer than necessary and be ready to answer for it.
Here at SmarterPay we have spent years helping UK organisations collect payments in a way that keeps them on the right side of these rules. Our software is Bacs approved, our team knows the regulations inside out, and we own our products, so we can build around what each customer actually needs. If your business collects payments and you want the data side handled properly, we would be glad to help.
Get in touch with our team on 01482 240886 or by our contact page.