Skip links

MonitorPay IS COMPLIANT WITH GDPR

1. Background: The General Data Protection Regulation

The General Data Protection Regulation (GDPR) has governed data protection across the European Union since 25 May 2018, with the UK GDPR applying an equivalent framework domestically. Because MonitorPay's verification infrastructure processes account, payee, and ownership data connected to individuals and businesses across 150+ countries — including throughout the EU and UK — GDPR compliance is built into the foundation of how our platform is designed and operated.

2. Why GDPR Compliance Is Central to Our Business

MonitorPay exists to help banks, fintechs, payment service providers, and finance teams validate IBANs, verify payee names, confirm account ownership, and monitor for changes — all in real time, via a single API. This work inherently involves processing personal data connected to account holders, payees, and beneficial owners. Given that our customers rely on us specifically for their own regulatory compliance (PSD2, AML, KYB), we hold ourselves to a correspondingly high standard when it comes to our own GDPR obligations.

Non-compliance carries serious consequences for any organisation processing personal data: fines of up to 4% of global annual turnover or €20 million, whichever is greater; mandatory breach notification within 72 hours; and enforceable rights for individuals, including access, rectification, and erasure. Beyond the regulatory exposure, maintaining rigorous data protection standards is fundamental to the trust our customers place in us as verification infrastructure for their own mission-critical payment flows.

3. How MonitorPay Applies the Six Data Protection Principles

Article 5 of the GDPR sets out six principles governing all processing of personal data. We explain below how each applies to MonitorPay's specific role as a real-time payment and account verification provider.

a. Lawfulness, Fairness, and Transparency

The GDPR provides six possible lawful bases for processing. For the verification data MonitorPay processes on behalf of its customers — payee names, IBANs, account ownership details, and VAT registration data — legitimate interest and contractual necessity are the primary applicable bases, since this data is processed specifically to allow our customers (and, indirectly, the account holders themselves) to complete legitimate payment transactions safely and accurately.

Where MonitorPay processes personal data relating to our own account holders and platform users (such as billing contacts), we rely on the performance of our contract with them.

MonitorPay's Legitimate Interests Assessment (for verification data)

Purpose of processing
MonitorPay has a legitimate interest — and, in many cases, our customers have a contractual and regulatory necessity — in processing personal data connected to payment verification: payee names, IBAN-linked account details, and account ownership information. This data is processed in real time, specifically to confirm that a payment is being sent to the correct, legitimate account holder before funds are transferred.

Lawful business objective
Our processing supports an objective explicitly recognised under EU and UK financial regulation: helping regulated entities meet their obligations under PSD2 (including Confirmation of Payee-style verification) and AML/KYB frameworks, and helping any business reduce payment fraud, misdirected funds, and failed transactions. Verifying account ownership before a payment is sent is widely recognised across the payments industry, and increasingly required by regulation, as a critical fraud-prevention control.

Reasonable expectation
Individuals who hold a bank account, or who are named as a payee in a business transaction, can reasonably expect that their account and identity details may be verified by the paying party (or a verification provider acting on their behalf) before funds are transferred — this is a standard and expected part of how legitimate payments are processed safely, and is precisely the kind of check increasingly mandated by "Confirmation of Payee" style regulation across multiple jurisdictions.

Necessity and proportionality — a stateless, no-storage approach
Unlike many data platforms, MonitorPay is architected around a stateless verification model. Sensitive financial data submitted through our API — including IBANs, account numbers, and payee names — is processed in real time to generate a verification result, and is not persisted after that result is returned. We do not build or maintain a long-term database of the sensitive financial details submitted to us; we verify, respond, and discard. This "no-storage" approach is a deliberate design choice that directly supports the GDPR's data minimisation and storage limitation principles.

Your right to object
Because MonitorPay does not retain the sensitive financial data submitted for verification beyond the momentary processing required to generate a response, there is generally no ongoing record to erase in relation to a specific verification request. Where you have concerns about a specific verification performed on your account or payee details, please contact us using the details in our Privacy Notice.

The balancing test
Weighing the interests of individuals against the interests of MonitorPay and our customers, we believe processing is justified because: the data is processed momentarily and in real time, specifically to prevent misdirected or fraudulent payments; the underlying activity (payment verification) is widely recognised and increasingly mandated across financial regulation; individuals whose accounts are verified benefit directly from reduced fraud risk; and MonitorPay's stateless, no-storage architecture significantly limits the privacy impact compared to platforms that retain sensitive financial data on an ongoing basis.

b. Purpose Limitation

Personal and financial data submitted through our API is processed for one clearly defined purpose: generating a real-time verification result (such as IBAN validity, payee name match, or account ownership confirmation) for the specific transaction or onboarding check submitted by our customer. We do not repurpose this data for unrelated activities.

c. Data Minimisation

Our verification model is deliberately narrow: we process only the specific data fields necessary to complete a given check — for example, an IBAN and a payee name for a name-matching check, or a VAT number and country for a VAT validation check. We do not request or process additional personal data beyond what a given verification type genuinely requires.

d. Accuracy

Because our verification results are generated in real time by querying official registries and banking sources at the moment of the request, our results reflect the most current information available from those sources at that moment, rather than a static or potentially outdated internal record.

e. Storage Limitation

MonitorPay's stateless architecture means that sensitive financial data submitted through our API — IBANs, account numbers, payee names — is not stored after a verification response is delivered. Only anonymised, non-identifying metadata (such as timestamps, response status codes, and request volumes) is retained, solely for billing and operational diagnostics, for a limited period as set out in our Privacy Notice.

f. Integrity and Confidentiality (Security)

Given the sensitivity of payment and account data, MonitorPay applies rigorous technical and organisational security measures, including encryption of data in transit and at rest, isolated network environments, and strict access controls, as detailed further in our Privacy Notice and Security & Compliance page.

4. Your Rights Under the GDPR

You have the right to request access to, correction of, or erasure of personal data we hold about you, to object to certain processing, and to restrict processing in certain circumstances. Given our stateless, no-storage verification model, many requests will relate to the limited account and billing data we do retain, rather than transactional verification data, which is not stored beyond the moment of processing. To exercise any of these rights, please contact us using the details on our Privacy Notice page.

5. Supervisory Authority

If you believe your personal data has not been handled in accordance with the GDPR, you are entitled to lodge a complaint with the relevant supervisory authority in your jurisdiction. We would welcome the chance to address your concerns directly first — please contact us before escalating a complaint.