Compliance frameworks, security audits, and quality certifications this company maintains.
Nuvei is a PCI DSS Level 1 certified payment service provider — the highest certification level — ensuring that its acquiring, processing, and tokenization infrastructure meets the most rigorous cardholder data security standards required for processing over 6 million card transactions annually.
Nuvei undergoes annual SOC 2 Type II audits across its payment platform infrastructure, validating that security, availability, and confidentiality controls protecting merchant and cardholder data meet the AICPA Trust Services Criteria.
Nuvei holds ISO 27001 certification for its information security management system, providing enterprise merchants and regulated-industry customers with assurance that payment data and system access are governed under an internationally recognized security framework.
Nuvei processes payment transaction data for merchants and cardholders across the European Union and maintains GDPR compliance through data processing agreements, EU data residency options, and documented lawful bases for processing personal financial data through its platform.
As a Canadian-headquartered payment company, Nuvei complies with the Personal Information Protection and Electronic Documents Act (PIPEDA) governing how personal and financial data of Canadian merchants and consumers is collected, used, and protected across its Montreal-based operations.
Nuvei supports Payment Services Directive 2 (PSD2) Strong Customer Authentication requirements for European card transactions, including 3DS2 implementation, exemption management, and transaction risk analysis to balance fraud prevention with checkout conversion for merchant customers.
Nuvei complies with FINTRAC anti-money laundering and terrorist financing regulations as a registered Money Services Business in Canada, maintaining KYC, transaction monitoring, and suspicious transaction reporting programs across its payment processing and payout operations.
Nuvei complies with the California Consumer Privacy Act for California-resident consumers and merchants, providing transparent data collection disclosures, opt-out rights, and documented data deletion procedures as part of its global privacy compliance program.
Nuvei is EMVCo 3DS2 certified, enabling merchants on its platform to implement frictionless and challenge-based authentication flows for card-not-present transactions, reducing fraud liability and meeting SCA mandates for European and global card scheme compliance.
Regulatory
MiCA (EU Crypto)
In ProgressNuvei is pursuing compliance with the EU Markets in Crypto-Assets (MiCA) regulation to continue providing its Nuvei Crypto on-ramp and off-ramp services to European merchants and exchanges under the new harmonized EU crypto-asset regulatory framework effective 2025.