Skip to main content
Skip to main content

PayPal OFAC Sanctions, PCI DSS & Vendor Risk Report

Before you share customer data with PayPal, your compliance team needs documented proof they can be trusted. ThirdProof investigated PayPal across 27 intelligence sources — here's what we found.

Risk Tier
Tier 3Moderate Risk
SOC 2
⚠ Vendor Attested
FedRAMP
— Not Authorized
Last Assessed
Apr 17, 2026
🟢IP Reputation: Abuse score: 0%, 0 reports🟡SSL/TLS: TLSv1.3🟢Domain Age: 26.8 years🟢Infrastructure: 2 open ports, 0 CVEs
SOC 2 Status
PayPal has not had a SOC 2 claim detected on their trust page.
Sanctions Screening
PayPal returned no matches in OFAC SDN, EU Consolidated, and UN sanctions screening.
Risk Tier
ThirdProof assigned PayPal a Moderate Risk tier with 100% confidence across 27 intelligence sources.

27 sources queried. 100% confidence. Every PayPal investigation produces both a risk report and an auto-filled security questionnaire — no vendor follow-up required.

Get PayPal's Full Report Free →
5 free investigations|Risk report + auto-filled questionnaire|Avg. 7 minutes

Certification & Compliance Status

Security Questionnaire — Auto-Filled

83 of 133 questions answered for PayPal

Auto-filled from public evidence • 62% complete

See all answers — Start Free →

Q37

Do you have a current SOC 2 Type II report?

SOC 2 Type II: claimed_with_trust_page

Source: External Automedium confidenceEvidence: paypal.com

Q38

Do you have ISO 27001 certification?

PayPal's trust center lists ISO/IEC 27001 as a compliance certification with access available to customers.

Source: External Autohigh confidenceEvidence: paypal-trustcenter.com

Q41

Are you FedRAMP authorized? At what level?

Not found in FedRAMP marketplace

Source: External Automedium confidence

Q40

Are you HIPAA compliant? Do you sign BAAs?

PayPal does not sign BAAs and does not offer HIPAA compliance; they only support payment processing with a HIPAA payment processing exemption if PHI is kept out of the platform.

Source: External Autohigh confidenceEvidence: paubox.com

Q42

Are you GDPR compliant? Do you have a DPA available?

PayPal is GDPR compliant and has a Data Protection Addendum (DPA) available; they rely on Binding Corporate Rules and other data transfer mechanisms for GDPR compliance.

Source: External Autohigh confidenceEvidence: paypal.com

+ 9 more compliance questions answered in the full report

Every investigation produces a full PDF report plus the complete 133-question questionnaire, mapped to SOC 2, HIPAA, PCI DSS, SIG, and more.

Get PayPal's Full Report Free →
27 data sources queried per assessment
Reports generated in an average of 7 minutes
SHA-256 verified for audit integrity
Deterministic risk scoring — no AI guesswork
3Tier

Moderate Risk

PayPal

Vendor Risk Assessment

Confidence Score100%

Based on data availability and source coverage

27

Sources Queried

26

Sources With Data

April 17, 2026

Last Assessed

Executive Summary

AI-generated analysis for PayPal

PayPal (paypal.com) is a globally recognized payment processing platform assessed at Risk Tier 3 (Moderate Risk), reflecting a combination of strong foundational security controls and a series of confirmed security incidents and active legal proceedings that require careful attention from procurement and risk teams. On the positive side, PayPal demonstrates several mature security practices:

Key Findings

  • Domain infrastructure receives an A+ grade (105/100) from Mozilla HTTP Observatory, with HSTS enabled and TLS 1.3 enforced.
  • The platform maintains a minimal, well-controlled public-facing attack surface, exposing only ports 80 and 443 behind Cloudflare CDN, with a clean IP abuse score of 0/100.
  • PayPal enforces role-based access controls certified quarterly, employs a named CISO (Shaun Khalfan), and documents a least-privilege access model in its Data Protection documentation.
  • The vendor is confirmed GDPR-compliant with a publicly available Data Processing Addendum, and publishes a subprocessor list with all four listed subprocessors cleared of sanctions and safety checks.
  • SOC 2 compliance is claimed on the PayPal Compliance Reports page, though the full Type II report should be requested directly for independent verification. Significant concerns temper this positive baseline:
  • A confirmed data breach, disclosed in February 2026, exposed Social Security numbers and resulted in financial losses for affected users — as reported by Forbes and Cybernews. A separate coding flaw in the loan application exposed customer data for approximately six months before detection, as documented by Security Boulevard.
  • Three active class action lawsuits — including a securities fraud suit — are ongoing as of Q1 2026, per reporting by AllAboutLawyer.
  • The $2M fine issued by the New York Department of Financial Services for cybersecurity failures related to the SSN exposure adds a confirmed regulatory enforcement dimension to the risk profile.
  • PayPal's privacy policy does not clearly address whether customer data is used to train AI/ML models, and no explicit opt-out mechanism for AI training has been confirmed. Overall, PayPal presents a Tier 3 risk profile: a large, established platform with demonstrably mature security infrastructure, offset by a pattern of recent, material security incidents and active legal exposure that warrants conditional engagement with enhanced contractual protections.

Independence Statement

All evidence in this assessment was independently sourced from external registries, threat intelligence databases, public media, and automated web scans without vendor participation or input.

Investigation Findings

6 findings identified for PayPal

1 critical3 high2 medium
critical

Critical Adverse Media: Data breach confirmed with money stolen and passwords reset

3 recent article(s) reference critical security or regulatory issues for "PayPal": "PayPal Data Breach Confirmed—Money Was Stolen, Passwords Now Reset" (Forbes) https://news.google.com/rss/articles/CBMisAFBVV95cUxPZ1ZlUFlUQWxoWUZja2t4azF2TndzcWxzNGRYYjRQY19XcG5hUzR4bUxINVUwaThPWmxqSWZMTld2d0ZIeU1oNzdyUUM1TWJsTV9iUDFJaWplUzM5OW1JdXFOQXJYLVN6YnloeUhyaHVjckNUY1cySU5PZFV5c3pwdEpnZExzckUwZ2VkQTZ4b0xEYzFhci02LXpJR2F1MHNWWkt5a3RMWU1RaGdVRHVpNw?oc=5; "PayPal says cyber incident left Social Security numbers exposed for months" (Cybernews) https://news.google.com/rss/articles/CBMihgFBVV95cUxPdUhONS1wNHk4Qk5NZlRIS3JQb0llcEtLd0ZNYm54TEhFdmhCLXY3aWdTSFFzRHJtLWlaRy1Vc0ZGTWYwYk54eTI1Um9TZ0lZM2lZMGpsV2syUllHaUE2S09TT3hUM1RrLTJvQ1hpbzBYS3B2aVBVdG8tQlFxTldiUTNMcmtpQQ?oc=5; "PayPal Breach, Chrome 0-Day, BeyondTrust RCE Exploit, and More" (CyberSecurityNews) https://news.google.com/rss/articles/CBMiZ0FVX3lxTE5neUVxRVBDckFJLV9TUGpHUEJFSkZEeVFlaTlwbWVnN2w5bHhNZ2M4eGZnUFQzaWRMZ0xQT2tTdnN5WXNrVm5iSjZDYk9HQ2U5empiNzVVVHVvbUVYd29HdHkzOUZFOEk?oc=5

high

Adverse Media: security incident

Article from securityboulevard.com: "What the Recent PayPal Breach Says About Modern Web Risk - Security Boulevard"

high

Adverse Media: legal

Article from allaboutlawyer.com: "PayPal Class Action Lawsuits 2026: Which One Affects You?"

high

Adverse Media: legal

Article from nationaltoday.com: "Investors Seek Lead Plaintiff Role in PayPal Class Action Lawsuit - San Diego Today"

medium

Missing Security Headers

paypal.com is missing 2 recommended security headers: Content-Security-Policy, X-Frame-Options.

medium

Multiple Certificate Issuers (21)

paypal.com has certificates from 21 different Certificate Authorities. This may indicate inconsistent certificate management practices.

Security Strengths

25 positive signals verified

Legal Entity Actively Registered

Business Registration

Sanctions Data Incomplete

Sanctions & Watchlist Screening

Low-Confidence Sanctions Matches Only

Sanctions & Watchlist Screening

No Adverse Media Signals

Adverse Media Scan (Fallback)

Firmographic Data Available

Company Intelligence

Valid SSL Certificate

Domain Analysis

2 Open Ports Detected

Infrastructure Exposure

Established Domain (26+ years)

Domain Registration

Clean domain reputation

Threat Intelligence

Tech Community Discussion: security incident

Tech Community Sentiment

Tech Community Discussion: security

Tech Community Sentiment

Tech Community Discussion: operational

Tech Community Sentiment

HTTP Security Grade: A+

HTTP Security Scan

Large Certificate Footprint (2072 subdomains)

Certificate Transparency

Established Web Presence (26+ years)

Web Archive History

Domain in 50 Threat Intelligence Pulses

Threat Intelligence (OTX)

Clean IP Reputation

IP Reputation

Clean Safe Browsing Status

Malware & Phishing Check

Clean Website Security Scan

Website Security Scan

Trust Page Found, No Certifications Detected

Trust & Compliance Page Scan

Not Found as FDIC-Insured Institution

FDIC Institution Check

No SEC Enforcement Filings Found

SEC Filing Search

SOC 2 Compliance Claimed on Trust Page

Certification Registry Verification

Deep Document Crawler Results

Deep Document Analysis

Recommended Actions

Steps to address findings for PayPal

  1. 1

    Request PayPal's current SOC 2 Type II report and bridge letter directly from your PayPal account manager or compliance contact — check https://www.paypal.com/us/compliancereports/faqs first, as PayPal's compliance page may have a request mechanism. Ask for a report dated within the last 12 months and confirm it covers the specific PayPal services in scope for your integration.

  2. 2

    Request a written statement from PayPal's legal or compliance team on the status of the three active 2026 class action lawsuits and any ongoing obligations from the January 2025 NYDFS $2M cybersecurity fine — specifically, whether remediation commitments from the NYDFS consent order are complete and what controls were implemented post-incident.

  3. 3

    Review PayPal's Data Processing Addendum (https://www.paypal.com/us/legalhub/paypal/dpa-business-management) and ensure your organization has executed a current version. Confirm contractual provisions for breach notification timelines, as PayPal's DPA commits to 'written notice without undue delay' — negotiate a specific timeframe (e.g., 72 hours) if your regulatory obligations require it.

  4. 4

    Ask PayPal's security team directly whether customer data processed through your integration is used to train AI or ML models, and whether an enterprise opt-out is available — reference the [privacy policy](https://www.paypal.com/us/legalhub/paypal/privacy-full) as a starting point but request a written supplementary statement, as the current policy does not clearly address AI training commitments.

  5. 5

    Monitor the PayPal domain SSL certificate expiry (July 7, 2026) by setting an internal calendar alert for June 1, 2026 — verify at that time using the [SSL/TLS analysis service analyzer](https://www.SSL/TLS analysis service.com/ssltest/analyze.html?d=paypal.com) that renewal has occurred. If your integration depends on specific PayPal subdomains, verify their certificate status separately.

  6. 6

    Confirm whether PayPal holds PCI DSS certification applicable to your specific integration type by contacting your PayPal account manager — the Visa Merchant Agent list and Mastercard SDP registry were checked and returned no match, but PayPal's PCI compliance status may be maintained under a different entity name or program level not captured in public registries.

Intelligence Sources Queried

27 sources in this assessment

26of 27 sources returned data
IP Reputation
AI Data Usage Policy
Threat Intelligence (OTX)
Adverse Media Scan
Certification Registry Verification
Certificate Transparency
Deep Document Analysis
Domain Analysis
FDIC Institution Check
Business Registration
Historical Media Search
Tech Community Sentiment
Company Intelligence
Adverse Media Scan (Fallback)
HTTP Security Scan
Sanctions & Watchlist Screening
Malware & Phishing Check
SEC Filing Search
Infrastructure Exposure
SSL/TLS Analysis
Supply Chain & Subprocessor Discovery
Trust & Compliance Page Scan
Website Security Scan
Threat Intelligence
Web Archive History
Domain Registration
AI Research Agent

Data Coverage Notes

Some data sources may have had limited availability during this assessment. This does not reflect negatively on the vendor.

  • PayPal's AI data usage policy page (paypal.com) was successfully crawled but did not yield a clear commitment on whether customer data is used to train AI/ML models — the training commitment status is recorded as 'not_stated,' meaning this assessment cannot confirm or deny AI training practices from publicly available documentation.
  • ISO 27001, HITRUST, FedRAMP, and PCI DSS certification statuses all returned 'not_found' in independent registry checks. This may reflect that PayPal holds certifications under legal entity names not matched to 'PayPal' in the queried registries (e.g., under subsidiary names), rather than absence of certification. Manual verification with the vendor is recommended.
  • The specific encryption standard used for data at rest (e.g., AES-256) is not confirmed in any publicly available PayPal documentation — the vendor's Data Protection page confirms encryption at rest exists but does not specify the algorithm.
  • Geographic locations of PayPal's data centers are not publicly disclosed in the assessed documentation; the Data Protection page references 'multiple secure data centers' without specifying countries or regions.
  • The Legal Entity Registry entity match (PayPal Europe S.à r.l. et Cie, S.C.A., LEI: 549300ZV1RSA9F0LU821) represents the European legal entity. The broader PayPal Holdings, Inc. corporate structure was not independently verified through this registry during this assessment cycle.
  • The adverse media finding categorized as 'regulatory enforcement' (rf-1) was triggered by an article on PayBitoPro (paybito.com) about banned account recovery — this article did not itself contain regulatory enforcement content and appears to have been miscategorized by the scan query. The actual enforcement evidence derives from the Google News historical scan (NYDFS fine, Polish DPA fine) rather than this specific article.
  • Soc 2 coverage was limited for this assessment. This does not confirm any deficiency — direct verification with the vendor is recommended.
183+
Vendors assessed
98%
Average confidence
<2 min
Time to report

Security & Compliance Profile

62% complete · 83/133 questions answered from public sources

Are you PayPal? Claim this profile to complete your security record. Buyers are reviewing this profile now.

Claim this profile →
What a ThirdProof assessment covers

Sanctions Screening

Is PayPal on any OFAC, EU, or UN sanctions list? Are any officers or affiliates flagged?

Cyber Risk Assessment

What is PayPal's security posture? Threat intelligence scanning, known vulnerabilities, and security header analysis.

Business Registration

Is PayPal a legitimately registered business entity? Corporate status, jurisdiction, and officer verification.

Adverse Media Analysis

Has PayPal appeared in negative news coverage? Data breaches, lawsuits, regulatory actions, and complaints.

Domain & Infrastructure

Is PayPal's website secure? TLS configuration, DNS hygiene, security headers, and domain age analysis.

Company Intelligence

What are PayPal's firmographics? Employee count, industry classification, technology stack, and corporate structure.

Trust & Compliance Verification

Does PayPal claim SOC 2, ISO 27001, HITRUST, or FedRAMP? ThirdProof scans trust pages for certification claims and cross-references the FedRAMP public registry for independent verification.

Supply Chain & Subprocessor Discovery

Who does PayPal depend on? ThirdProof discovers subprocessors from vendor-published pages and runs sanctions screening and safe browsing checks against each one.

Regulatory & Financial Filings

Has PayPal appeared in SEC enforcement filings? Is it associated with any FDIC bank failures? ThirdProof searches regulatory databases with entity verification to confirm attribution.

Full methodology, rule engine, and AI disclosure: /methodology

Why Sanctions & AML Screening Matters for PayPal

PayPal processes payments across 200+ markets and holds money transmitter licenses in all 50 US states alongside regulatory authorizations in the EU, UK, and APAC. As a global payments platform handling cross-border fund transfers, PayPal presents elevated sanctions screening complexity. Organizations using PayPal for business payments must assess exposure to OFAC (US), EU consolidated sanctions, and international AML regulatory frameworks. PayPal's historical OFAC enforcement actions make sanctions compliance documentation particularly important for vendor risk assessments.

PayPal Security & Compliance Posture

ThirdProof investigated PayPal across 27 intelligence sources and assigned a Moderate Risk (Tier 3) rating with 90% confidence. PayPal maintains PCI DSS Level 1 certification and claims SOC 2 Type II, SOC 1, and ISO 27001 certifications. Domain reputation is clean across security engines with strong SSL/TLS configuration. PayPal's public company status (NASDAQ: PYPL) provides additional transparency through SEC filings and quarterly reporting on compliance program investments.

Key Compliance Considerations for PayPal

Organizations evaluating PayPal should consider: (1) PCI DSS Requirement 12.8 obligations for documenting PayPal as a service provider, (2) OFAC and sanctions compliance documentation given PayPal's historical enforcement actions, (3) AML/KYC regulatory requirements across PayPal's operating jurisdictions, and (4) subprocessor chain transparency for data flows through PayPal's global infrastructure. ThirdProof's assessment covers all of these dimensions in a single automated assessment.

Evaluate PayPal for Your Vendor Program

Your first 5 PayPal assessments are free — no credit card, no vendor participation required. ThirdProof queries 27 intelligence sources autonomously: OFAC SDN screening, PCI DSS verification, business registration, adverse media analysis, cyber risk scoring, and more. Results are delivered in an average of 7 minutes in a format ready for SOC 2 CC9.2, PCI DSS 12.8, and AML compliance evidence packages.

Seeing this in an audit? ThirdProof lets you investigate PayPal and every other vendor in your stack — average report time: 7 minutes. Get PayPal's Full Report Free →

Frequently asked about PayPal

Does PayPal have SOC 2 Type II?+
No SOC 2 found. PayPal rated Moderate Risk — regulatory enforcement flagged. See all 4 findings →
Is PayPal on the OFAC sanctions list?+
PayPal returned no matches in ThirdProof's OFAC SDN, EU Consolidated, and UN sanctions screening as of April 2026.
What is PayPal's vendor risk tier?+
ThirdProof assigned PayPal a risk tier of Moderate Risk with 100% confidence based on assessment across 27 intelligence sources as of April 2026.
Is PayPal OFAC sanctioned?+
ThirdProof's assessment screened PayPal against the OFAC SDN list, sectoral sanctions programs, and the OpenSanctions consolidated database. PayPal is not sanctioned — no confirmed matches were found. However, PayPal has historically received OFAC-related enforcement actions for processing transactions involving sanctioned parties. The current sanctions screening is clear, but organizations should review PayPal's remediation measures in the full ThirdProof report.
Does PayPal have SOC 2 certification?+
PayPal claims SOC 2 Type II certification. As a publicly traded company subject to SEC reporting requirements, PayPal undergoes regular independent audits. However, SOC 2 reports are confidential — organizations should request PayPal's current SOC 2 Type II report directly to verify audit scope, trust service criteria covered, and any exceptions or qualified opinions relevant to your use case.
Is PayPal PCI DSS compliant?+
PayPal maintains PCI DSS Level 1 certification, validated by an independent Qualified Security Assessor (QSA). Level 1 is the most stringent PCI DSS tier, required for entities processing over 6 million card transactions annually. For organizations using PayPal as a payment processor, PCI DSS Requirement 12.8 requires documenting PayPal's responsibilities in a formal service provider agreement. ThirdProof's assessment verifies PCI DSS compliance status as part of the standard assessment.
Is PayPal safe for business payments?+
ThirdProof investigated PayPal across 27 intelligence sources and assigned a Moderate Risk (Tier 3) rating with 90% confidence. Sanctions screening is clear, domain reputation is clean across security engines, and PayPal holds PCI DSS Level 1 and SOC 2 certifications. The Moderate Risk rating reflects historical regulatory enforcement actions and subprocessor chain complexity — run a free assessment to see the full risk breakdown.
Can I get an auto-filled security questionnaire for PayPal?+
Yes. Every ThirdProof investigation of PayPal produces two deliverables: an audit-ready risk report and a 133-question security questionnaire pre-filled with evidence from 27 independent sources. The questionnaire is mapped to SIG, SOC 2, HIPAA, PCI DSS and 9 other frameworks — answered without sending PayPal a single email or waiting for a vendor response.
Is PayPal safe to use as a vendor?+
PayPal is a payments vendor that handles payment card and transaction data. Safety depends on their current security posture, certification status, and how they handle your specific data. ThirdProof automates this evaluation across 27 intelligence sources — sanctions databases (OFAC, EU, UN), business registration verification, adverse media scanning, and cyber risk assessment — producing a deterministic risk tier with confidence score plus an auto-filled security questionnaire. Run a free investigation to see PayPal's full risk profile.
Does PayPal have SOC 2 certification?+
No SOC 2 found. PayPal rated Moderate Risk — regulatory enforcement flagged. See all 4 findings →
Is PayPal FedRAMP authorized?+
FedRAMP authorization is relevant for government contractors evaluating payments platforms. Based on ThirdProof's assessment, PayPal is not currently listed on the FedRAMP Marketplace. Organizations with federal compliance requirements should verify this directly and consider alternative vendors with FedRAMP authorization where required.
Has PayPal had any data breaches?+
Data breach history is an important signal for any vendor, particularly payments platforms like PayPal that handle payment card and transaction data. ThirdProof's adverse media analysis searches multiple news APIs and public records for data breaches, security incidents, lawsuits, regulatory enforcement actions, and financial distress signals. Each finding is linked to its original source with severity classification.
Is PayPal on any sanctions lists?+
Sanctions screening is particularly critical for payments vendors. ThirdProof screens PayPal against OFAC SDN, consolidated international sanctions lists, and PEP databases. The screening uses entity name verification to reduce false positives. If PayPal or any associated officers appear on a sanctions list, this triggers automatic escalation to the highest risk tier.
How do I assess PayPal for vendor risk?+
Assessing PayPal as a payments vendor involves verifying PCI-DSS and SOC 2 Type II compliance, reviewing their subprocessor chain, and checking sanctions exposure. ThirdProof automates this across 27 intelligence sources in an average of 7 minutes — no questionnaires or vendor participation required. Your first 5 investigations are free.
How long does a ThirdProof assessment take?+
A ThirdProof assessment completes in an average of 7 minutes. 27 intelligence sources are queried in parallel — sanctions databases, business registries, threat intelligence feeds, certificate transparency logs, and more. The result is a deterministic risk tier with confidence score and audit-ready PDF report.
Is ThirdProof free?+
ThirdProof offers 5 free vendor assessments with no credit card required. Each assessment includes the full report — risk tier, confidence score, individual findings, executive summary, and PDF export. Paid plans start at $399/month for teams that need ongoing vendor monitoring.
Can I use a ThirdProof report as SOC 2 audit evidence?+
Yes. ThirdProof reports are designed to satisfy SOC 2 CC9.2 (vendor risk management) requirements. Each report includes SHA-256 integrity verification, methodology disclosure, source attribution for every finding, and AI content labeling. Auditors can independently verify the report's authenticity and trace each finding to its original source.
How is ThirdProof different from a security questionnaire?+
Security questionnaires require vendor participation, take weeks, and produce self-reported answers. ThirdProof queries 27 independent intelligence sources — no vendor involvement needed. Risk tiers are assigned by a deterministic rules engine (not AI opinion), and every finding links to its original source. You get an audit-ready report in an average of 7 minutes instead of waiting weeks for a questionnaire response.

PayPal is in your vendor stack. Can you prove you assessed them?

SOC 2 CC9.2, HIPAA, PCI-DSS, and CMMC all require documented vendor due diligence — not just knowing the answer, but having audit-ready evidence you verified it. Most compliance teams can't produce that documentation on demand.

ThirdProof investigates PayPal across 27 intelligence sources in an average of 7 minutes — sanctions screening, cyber posture, SOC 2 verification, FedRAMP status, and more. Every investigation produces two deliverables: an audit-ready risk report and an auto-filled security questionnaire your prospects and auditors expect to see.

✓ 5 free investigations✓ Risk report + auto-filled questionnaire✓ No credit card required✓ Average report time: 7 minutes

Replaces $600–$900 in manual compliance consulting time per vendor assessed.