Overview
Mollie is one of Europe's leading payment service providers, particularly popular in the Netherlands, Belgium, and Germany. The platform supports a wide range of European payment methods beyond standard credit cards — including iDEAL, Bancontact, SOFORT, and Klarna — making it a go-to choice for merchants serving European customers. When Mollie's scripts appear on merchant websites, they're handling the critical payment step of the checkout process.
Unlike marketing or analytics scripts, Mollie's code serves a transactional purpose that's directly tied to completing a purchase the customer has initiated.
What This Script Does
Mollie's scripts handle payment processing on merchant sites:
- Hosted payment components: Renders secure card entry fields (card number, expiry, CVV) as iframe-embedded components that keep sensitive payment data off the merchant's servers, reducing PCI DSS compliance scope
- Payment method selection: Displays available payment options based on the customer's location and the merchant's configuration, including local methods like iDEAL bank selection
- Checkout flow management: Handles redirects to external payment providers (bank login pages for iDEAL, Klarna's checkout, PayPal authorization) and processes the return flow
- Session cookies: Sets cookies to maintain payment session state, linking the customer's cart to their payment attempt and tracking the transaction through completion
- Fraud prevention: Collects device fingerprinting data and behavioral signals to assess transaction risk and prevent payment fraud
- Error handling: Manages failed payment attempts, retries, and fallback payment method suggestions
Consent & Compliance
Mollie's scripts operate in a well-defined compliance context:
- GDPR: Payment processing has a clear lawful basis under "performance of a contract" (Article 6(1)(b)) — the customer initiated a purchase, and processing payment is necessary to fulfill it. Mollie acts as both a data processor and, for certain payment methods, a data controller.
- ePrivacy Directive: Cookies used for payment session management and fraud prevention are "strictly necessary" for the service explicitly requested by the user, exempting them from consent requirements.
- PCI DSS: Mollie's hosted payment components are designed to minimize merchant PCI scope by keeping card data within Mollie's certified infrastructure.
- PSD2/SCA: Mollie handles Strong Customer Authentication requirements for European transactions, managing 3D Secure flows and exemption requests.
Mollie maintains compliance certifications (PCI DSS Level 1) and provides DPAs to merchants.
Should You Block This Without Consent?
Mollie's scripts are essential to completing purchases on your site. They handle the payment transaction that the customer explicitly initiated by proceeding to checkout. The cookies set are strictly necessary for managing the payment session and preventing fraud — both purposes that fall under the "strictly necessary" exemption in privacy regulations. Blocking Mollie's scripts would prevent customers from completing purchases entirely.
No.
Is Mollie GDPR compliant?
Mollie's trackers are classified as essential (strictly necessary), so they are generally exempt from prior consent under the GDPR. You should still list them in your cookie policy and privacy notice so visitors know they are there.
Consent Categories
Also Known As
Industries
Tracked Domains (1)
mollie.comEssentialmollie.com is an essential domain operated by Mollie, used to keep the site working, including security, load balancing, and sessions.
Cookies Mollie Sets (1)
MOLLIE_GEO_REDIRECTEDMollie checkout locale/redirect state for the active payment session.
Frequently Asked Questions
Related Vendors
Manage consent for Mollie
ConsentStack automatically detects and manages Mollie trackers so your site stays compliant with global privacy regulations.