Glossary

Data protection (GDPR)

Payout data contains personal data such as names, addresses, IDs and bank details, so privacy laws like the GDPR usually apply.

General information only, not legal, tax, financial or investment advice. Laws, rates and thresholds change often and depend on your situation, so check the official sources below and confirm with a qualified advisor before you act. Last reviewed September 2026.

Definition

The EU General Data Protection Regulation (GDPR) applies when companies established in the EU process personal data. It also applies to companies outside the EU that offer goods or services to people in the EU or monitor their behavior there.1 Comparable laws, each with its own scope and rules, exist in the UK (UK GDPR), Brazil (LGPD), California (CCPA) and many other places.234

Good practice for payout data

  • Collect only the data a payout needs1
  • Sign a data processing agreement when your payout provider processes data on your behalf1
  • Avoid bank details and ID copies in spreadsheets and email
  • Keep data no longer than you need it, apart from records that tax or AML rules require you to keep1

Payee rights

Under the GDPR, payees can ask what data you hold about them, ask for corrections and, in some cases, ask for deletion.1 Tax and AML rules can require you to keep some records anyway, so document which rule applies.

How Talentir helps

Payees enter their details in Talentir directly, so you do not need to collect bank details in spreadsheets or email. See how Talentir handles compliance

Sources

  1. EUR-Lex: Regulation (EU) 2016/679 (GDPR) ↩ ↩2 ↩3 ↩4 ↩5

  2. ICO: UK GDPR guidance and resources ↩

  3. Planalto: Lei 13.709/2018 (LGPD, in Portuguese) ↩

  4. California Attorney General: CCPA ↩