Adyen

Adyen

Adyen embeds hosted payment components on merchant checkout pages. Scripts render card input fields, handle 3D Secure authentication flows, and process payment tokenization, enabling secure card-not-present transactions on e-commerce checkouts.

Overview

Adyen is a global payment technology company processing transactions for major merchants including Uber, Spotify, and Microsoft. Unlike payment aggregators, Adyen holds acquiring licenses directly in most major markets, enabling end-to-end payment processing. Its web integration embeds secure, PCI-compliant payment components directly into merchant checkout pages, handling card entry, authentication challenges, and tokenization without redirecting customers away from the merchant site.

What This Script Does

Adyen's Web Components or Drop-in library loads from checkoutshopper-live.adyen.com (or the test equivalent). The script renders payment method selection interfaces and secure card input fields inside isolated iframes, ensuring that raw card data never touches the merchant's DOM or JavaScript scope.

When a customer enters card details, the library tokenizes the data client-side and transmits it directly to Adyen's PCI Level 1 certified infrastructure. For cards enrolled in 3D Secure (Visa Secure, Mastercard Identity Check), the library manages the authentication challenge flow within a modal or redirect, handling the full EMV 3DS2 protocol.

Adyen sets a session cookie to maintain payment state during the checkout flow. The adyen-checkout__session cookie (or similar session identifier) persists only for the browser session and is strictly necessary for completing the transaction. No long-lived tracking cookies are set by the payment components.

The scripts communicate with checkoutshopper-live.adyen.com for payment method configuration, tokenization, and transaction status polling. Device fingerprinting data (screen dimensions, timezone, browser capabilities) is collected as part of the 3DS2 authentication flow, which is a regulatory requirement under PSD2 Strong Customer Authentication rather than optional analytics.

Consent & Compliance

Adyen is classified as functional. Its scripts provide payment processing functionality that is strictly necessary for completing a purchase the customer has initiated.

Under GDPR and the ePrivacy Directive, payment processing cookies and scripts fall under the "strictly necessary" exemption. The session cookies maintain payment state during an active transaction, and the device fingerprinting serves a regulatory requirement (PSD2 SCA). No consent is required for these operations.

Under CCPA/CPRA, payment data processed by Adyen is covered by the financial data exception and is used solely to complete the requested transaction. Standard privacy policy disclosures are sufficient.

Should You Block This Without Consent?

No. Adyen provides essential payment processing functionality. Blocking it would prevent customers from completing purchases. The scripts handle only transaction-related data and set no tracking cookies beyond session-scoped payment state.

Visit website

Consent Categories

Functional

Also Known As

Adyen checkoutAdyen paymentsAdyen Drop-inAdyen Web ComponentsAdyen payment gateway

Industries

Finance

Tracked Domains (1)

adyen.comFunctional

Frequently Asked Questions

Does Adyen require user consent before loading on a checkout page?

No. Adyen provides strictly necessary payment processing functionality. Session cookies maintain payment state during an active transaction, and device fingerprinting is a PSD2 Strong Customer Authentication regulatory requirement rather than optional analytics. No consent is required under GDPR or ePrivacy for Adyen's checkout components.

What does the Adyen script do during a checkout session?

Adyen loads from checkoutshopper-live.adyen.com and renders PCI-compliant card input fields inside isolated iframes so raw card data never touches the merchant DOM. It tokenizes card data client-side, manages 3D Secure authentication challenges, and sets a session-scoped checkout cookie. No long-lived tracking cookies are set.

How does ConsentStack treat Adyen on a merchant website?

ConsentStack classifies Adyen as functional and allows it to load without prior consent. It is never blocked, ensuring customers can proceed through checkout uninterrupted. Device fingerprinting collected for 3DS2 authentication is treated as a PSD2 regulatory requirement, not discretionary tracking, and requires no consent action.

Related Vendors

Google Maps
Google Maps
Google Maps is the dominant web mapping service used for embedded maps and location features on websites. Scripts load interactive map tiles, geocoding, and Places API functionality through the Maps JavaScript API. May set cookies to remember map preferences and manage API quota.
Google Search
Google Search
Google Search appears on websites through the Programmable Search Engine, enabling custom site-specific search functionality. Scripts load the search widget from Google's servers to render search bars and display results within the host website. Sends search queries to Google's index and may set cookies for search personalization and query history.
Google
Google
Google is the dominant provider of web analytics, advertising, and infrastructure tools. Scripts like Google Analytics, Tag Manager, Ads, and reCAPTCHA collect behavioral data, manage tag firing, serve targeted ads, and detect bots. Sets persistent cookies to track users and correlate activity across sites.
Microsoft Teams
Microsoft Teams
Microsoft Teams is a workplace communication and collaboration platform that can be embedded on websites for chat, meetings, and document sharing. Embedded widgets load from Microsoft's servers to enable real-time messaging, video calls, and file collaboration. Sets authentication and session cookies to verify participant identity and maintain connection state.
Apple Maps JS
Apple Maps JS
Apple Maps JS is Apple's JavaScript mapping framework for embedding interactive maps on websites. Scripts load map tiles, location pins, and routing data from Apple's MapKit servers to render navigable maps within web pages. Requires a MapKit JS token for authentication but does not set tracking cookies or collect behavioral analytics data.
Apple Business Chat
Apple Business Chat
Apple Business Chat enables direct customer messaging between websites and Apple's Messages app. Scripts load chat buttons and conversation interfaces that connect visitors to business support agents through iMessage. Sets minimal session cookies to maintain conversation context but does not track browsing behavior or collect analytics data.

Manage consent for Adyen

ConsentStack automatically detects and manages Adyen trackers so your site stays compliant with global privacy regulations.