Data protection (GDPR)
Payout data contains personal data such as names, addresses, IDs and bank details, so privacy laws like the GDPR usually apply.
Definition
The EU General Data Protection Regulation (GDPR) applies when companies established in the EU process personal data. It also applies to companies outside the EU that offer goods or services to people in the EU or monitor their behavior there.1 Comparable laws, each with its own scope and rules, exist in the UK (UK GDPR), Brazil (LGPD), California (CCPA) and many other places.234
Good practice for payout data
- Collect only the data a payout needs1
- Sign a data processing agreement when your payout provider processes data on your behalf1
- Avoid bank details and ID copies in spreadsheets and email
- Keep data no longer than you need it, apart from records that tax or AML rules require you to keep1
Payee rights
Under the GDPR, payees can ask what data you hold about them, ask for corrections and, in some cases, ask for deletion.1 Tax and AML rules can require you to keep some records anyway, so document which rule applies.
How Talentir helps
Payees enter their details in Talentir directly, so you do not need to collect bank details in spreadsheets or email. See how Talentir handles compliance
Related topics
KYC and KYB
KYC (Know Your Customer) verifies a person's identity. KYB (Know Your Business) verifies a company, its owners and the people who act for it.
AML (Anti-Money Laundering)
AML rules require financial companies, and some other businesses, to prevent, detect and report money laundering and terrorist financing.
Liability in creator payouts
When a creator payout breaks tax or compliance rules, the business that paid can be held responsible. A Merchant of Record can take on much of that liability, within the limits of its contract and the law.
What is a Merchant of Record?
A Merchant of Record (MoR) is the legal entity that is the counterparty to a transaction and generally carries the tax, invoicing and compliance obligations for it.