Getlago

Sep 19, 2025

/

6 min read

Billing Compliance: GDPR, PCI DSS, and ASC 606 Explained

Anh-Tho Chuong

Anh-Tho Chuong

Share on

LinkedInX

Billing compliance isn't one requirement, it's several running at once. A subscription business has to protect personal data (GDPR, CCPA), secure payment data (PCI DSS), and recognize revenue correctly (ASC 606/IFRS 15) — and, if it's public or heading toward an IPO, keep its financial reporting controls in order (SOX). None of these frameworks were written with usage-based or hybrid pricing in mind, which is exactly why they're hardest to satisfy with a billing system that was built for flat, one-time payments.

The enterprise billing solutions market reflects how seriously companies are taking this: it's projected to grow from $4.57 billion in 2024 to $5.29 billion in 2025, a 15.7% CAGR. That growth tracks a shift in pricing itself — 50% of SaaS providers now rely on user-based pricing, 38% bill on usage, and 40% use value-based models. Each of those models adds a compliance surface a flat monthly invoice never had.

Why this gets harder as pricing gets more sophisticated

Accurate billing data isn't just an operations concern, it's the foundation for answering basic questions about the business: quarterly growth, net revenue retention, customer expansion. When those numbers don't add up, it's usually a billing compliance gap, not a reporting gap. Companies with sophisticated usage-based billing systems see 32% higher net revenue retention than those tracking usage manually, largely because the underlying data is trustworthy enough to act on.

At scale, this becomes an infrastructure problem before it's a policy problem. Lago ingests up to 1,000,000 billing events per second, which is the kind of throughput real-time metering and reporting require once usage volume gets serious.

The frameworks, at a glance

PCI DSS

Credit card processing sits at the center of most subscription businesses, and PCI DSS governs any environment that accepts, processes, stores, or transmits card data. Non-compliance is expensive: fines typically reach into the hundreds of thousands of dollars per incident, though card networks don't levy them directly on merchants — they fine the acquiring banks that process the transactions, and those costs usually flow back down. Outsourcing payments to a processor like Stripe reduces PCI scope, but it doesn't remove it; how a company stores references, logs, and metadata still matters.

PCI DSS 4.0, now in force, changes the operating model further, moving compliance from a once-a-year audit to continuous, always-on validation. For SaaS companies, scope has a way of expanding quietly through the systems built around payments, not the payment flow itself — APIs, application logs, and analytics tools can all end up touching data that pulls them into scope.

GDPR

GDPR applies to any company serving EU residents, regardless of where the company is headquartered. It requires:

  • Data minimization: collecting only what's necessary
  • Explicit consent: clear, unambiguous opt-in for data collection
  • Data protection: encryption and incident response as baseline security
  • Access and erasure rights: mechanisms for users to view or delete their data

For companies where data residency is part of their GDPR strategy, self-hosted deployment keeps billing data inside a company's own infrastructure or region rather than a third party's cloud.

CCPA and CPRA

The California Consumer Privacy Act was substantially amended by the California Privacy Rights Act (CPRA) in 2023, and the current thresholds reflect that update. A business is covered if it meets any of the following:

  • Annual gross revenue exceeding $25 million
  • Personal information from 100,000 or more California consumers or households annually
  • 50% or more of annual revenue from selling or sharing personal information

Violations run $2,500 per unintentional incident and $7,500 per intentional one. The CPRA also removed the 30-day cure period that used to let businesses fix a first violation before facing a penalty, so treating CCPA/CPRA compliance as a "we'll fix it if flagged" problem is no longer a safe assumption.

ASC 606 and IFRS 15

Usage-based and hybrid pricing make revenue recognition genuinely harder, not easier: revenue has to be recognized as performance obligations are satisfied, not when cash lands. With 38% of SaaS companies now billing on actual usage, recognizing revenue accurately across variable billing cycles has become a core system requirement rather than an accounting afterthought.

SOX

For public companies, and for many pre-IPO companies preparing for that transition, the Sarbanes-Oxley Act adds a fifth requirement: internal controls over financial reporting. Billing and revenue systems are directly in scope. If invoices, credits, or usage data can be edited without a clean audit trail, that's a control weakness auditors will flag during an audit — and one that's much easier to prevent with immutable logs and role-based access than to explain after the fact.

Where usage-based billing adds new pressure

59% of software companies expect usage-based revenue to grow as a share of the business in 2025, up 18% from 2023. That growth compounds every framework above:

  • Event volume: systems need to handle 100,000+ events per second at sub-second latency for reporting that's actually real-time
  • Multi-dimensional tracking: APIs, storage, data transfer, and compute hours all need to be metered simultaneously
  • Pricing complexity: progressive billing, tiered usage, and hybrid models require aggregation logic that a spreadsheet can't hold
  • Scope creep: the same usage data flowing through logs and analytics tools can quietly widen PCI or GDPR scope beyond the payment flow itself

Tax adds a second axis of complexity

EU VAT rules require charging based on the customer's location, not the company's, with rates that vary across all 27 member states. U.S. sales tax adds state-by-state variation and, in some cases, multiple jurisdictions inside a single ZIP code. Automating this layer is usually the fastest way to stop tax compliance from becoming a full-time job for someone on the finance team.

What automation actually changes

Modern billing systems recognize revenue over the subscription period rather than at the moment of payment, which matters most for prepaid and usage-based models. They provide real-time visibility into recognized versus deferred revenue, with audit trails that hold up to scrutiny.

On the security side, the baseline is SOC 2 Type II, GDPR compliance, and PCI DSS certification, plus encryption at rest and in transit. Role-based access control and real-time monitoring close the loop, so violations get caught as they happen rather than during a quarterly review.

Lago's platform is built to carry this load across subscriptions, usage-based billing, prepaid credits, and add-ons, with invoice generation handled automatically.

Getting there

Automate first. Manual billing processes introduce the errors that compliance frameworks exist to catch. Automated systems that eliminate 40% of time-to-cash delay and 25% of billing errors are also, not coincidentally, the ones that hold up under an audit.

Track the regulatory landscape, not just the rules. GDPR, CCPA/CPRA, and PCI DSS all change over time — CPRA's 2023 amendments are a good example of how much can shift under a name that stays the same. Regular compliance reviews catch drift before it becomes a finding.

Build for scale before you need it. The global enterprise billing software market is projected to grow from $15 billion in 2025 to around $40 billion by 2033. Platforms chosen for today's event volume tend to become the bottleneck at tomorrow's.

Keep customers informed. Clear, detailed invoices and advance notice of pricing changes reduce disputes just as much as they support compliance.

FAQ

What is billing compliance? The combination of data protection rules (GDPR, CCPA/CPRA), payment security standards (PCI DSS), and accounting standards (ASC 606/IFRS 15, plus SOX for public companies) that a subscription billing system has to satisfy simultaneously.

Does GDPR apply if my company isn't based in the EU? Yes. GDPR is scoped to whose data you process, not where your company is headquartered. Billing EU residents brings you into scope.

Is PCI DSS optional if I use a payment processor like Stripe? No. Outsourcing card processing reduces PCI scope, it doesn't remove it. How references, logs, and metadata are stored still matters.

Does ASC 606 apply to usage-based pricing? Yes, and it's often harder to apply than with flat pricing, since revenue has to be recognized as performance obligations are satisfied rather than when payment is collected.


Billing compliance is a strategic advantage, not just a regulatory checkbox. As pricing keeps moving toward usage-based and hybrid models, the companies that treat compliance as an infrastructure decision, not a policy document, are the ones that scale without rebuilding their billing stack under audit pressure.

Ready to implement compliant billing infrastructure? Talk to our team about how Lago handles usage-based billing, revenue recognition, and enterprise-grade security in one platform.

Anh-Tho Chuong

Anh-Tho Chuong

Anh-Tho Chuong is the co-founder and CEO of Lago, the open-source billing platform. She writes about pricing, business models as code, and using product as a monetization lever.


Share on

LinkedInX

More from the blog

Lago solves complex billing.