Compliance
As the Merchant of Record, Neon is the legal seller on every transaction. That means the regulatory burden that would otherwise fall on each game publisher - payment-data security, privacy law, anti-money laundering, cookie consent - sits with Neon. Compliance is therefore one of the clearest reasons to choose to work with an MoR: Publishers can focus on the game while Neon handles the legal and operational burden of selling to a global, cross-border player base.
PCI DSS
What it is: The Payment Card Industry Data Security Standard is the card networks' mandatory framework for anyone who stores, processes, or transmits cardholder data. It governs encryption, network security, access control, and regular testing. Non-compliance risks fines and loss of card acceptance; a breach can be catastrophic.
Neon’s role: Because Neon is the MoR and processes payments on the publisher's behalf, Neon absorbs PCI scope. Publishers never touch raw card data, which removes their PCI obligations to build and audit a secure payment environment themselves.
AML & sanctions
What it is: Anti-money-laundering (AML) and sanctions rules require any business in the payment flow to verify who it is dealing with, screen them against government watchlists, monitor transactions for suspicious activity, and report and retain records of any findings. The obligations come from card-network rules, and from financial-crime regulation in every market a business sells into (e.g., the US Bank Secrecy Act and OFAC, the EU AML directives, the UK sanctions regime). Breaching sanctions or running inadequate AML controls carries severe penalties and loss of access to payments.
Neon’s role: As the Merchant of Record, Neon is the party that must satisfy these controls, so it absorbs them on the publisher's behalf: business verification (KYC/KYB) at onboarding, screening of merchants against sanctions and PEP lists (OFAC, EU, UN, UK HMT), automated transaction monitoring for laundering and abuse patterns, and the escalation, reporting, and recordkeeping that follow.
Data Protection and Privacy
GDPR — EU/UK data protection
What it is: The General Data Protection Regulation governs the processing of personal data of individuals in the EU (with the UK GDPR mirroring it). It requires a lawful basis for processing, data-subject rights (access, deletion, portability), breach notification, data minimization, and controls on international data transfers. Fines reach the greater of €20M or 4% of global annual turnover.
Neon’s role: For payment processing, Neon acts as the data controller/processor for the transaction relationship, handling the lawful basis, retention, and cross-border transfer mechanics for player payment data. Publishers still control their own product relationship and their own player data outside the transaction, but the payment-side GDPR exposure is managed by Neon.
CCPA / US state privacy — consumer data rights
What it is: The California Consumer Privacy Act (as amended by the CPRA) gives California residents rights over their personal information: to know what is collected and how it is used, to have it deleted, and to opt out of its "sale" or "sharing." A growing set of comparable state laws (e.g., Virginia's VCDPA, Colorado's CPA) extend similar rights across the US. These sit alongside GDPR rather than duplicating it as the rights, thresholds, and definitions differ by state.
Neon’s role: For the payment relationship it owns, Neon absorbs CCPA/state-privacy handling on the transaction data: honoring access, deletion, and opt-out requests, and not selling personal data. Publishers keep control of their own product-side player data, but the payment surface Neon presents applies the right consumer-privacy rules per jurisdiction, so the checkout doesn't become a separate source of state-law exposure the publisher has to track.
Age verification
COPPA — children's online privacy (US)
What it is: The US Children's Online Privacy Protection Act regulates the collection of personal information from children under 13. It requires verifiable parental consent before collecting a child's data, clear privacy disclosures, and data-minimization. The FTC enforces it and has issued multi-million-dollar penalties; a strengthened rule (updated 2025) expands obligations around data retention and third-party disclosure. Gaming is a primary enforcement target because so many players are minors.
Neon’s role: As a reseller Neon does not perform age verification. Neon relies on the game publisher to:
- Verify player age during account creation
- Linking any minor’s account to a verified parent or guardian account
It’s the publishers responsibility to allow or deny that player access to the Neon web store and checkout.
Texas SB 2420 — App Store Accountability Act
What it is: Texas SB 2420 (signed May 2025, in effect June 4, 2026) requires app stores to verify the age of every Texas user at account creation and sort them into four categories: child (under 13), younger teenager (13–15), older teenager (16–17), and adult (18+). Minors' accounts must be linked to a verified parent/guardian, and parental consent is required for each individual download or in-app purchase by a minor. Developers must publish age ratings, and app stores must pass developers the user's age category and consent status. Penalties run to ~$10,000 per violation for developers.
Neon’s role: As a reseller Neon does not perform age verification. Neon relies on the game publisher to:
- Verify player age during account creation
- Linking any minor’s account to a verified parent or guardian account
It’s the publishers responsibility to allow or deny that player access to the Neon web store and checkout.
Updated about 1 hour ago

