GDPR for e-commerce: the complete guide to your obligations when selling online
If you run an online store and sell to customers in the European Union, GDPR for e-commerce isn't a formality you can put off: it's a set of legal obligations that kick in with the very first order you receive. Every time a customer enters a name, address, email or payment details, you're processing personal data. And the General Data Protection Regulation (EU Regulation 2016/679) sets precise rules on how to collect, store and protect it.
The good news is that getting compliant doesn't require an in-house legal department. It does require understanding what the concrete obligations are and working through them methodically. This pillar guide walks you through it step by step: from the legal basis for processing to the privacy notice, from the cookie banner to customer data handling, through newsletter consent, user rights, data breaches and fines. At the end you'll find a practical checklist and some pointers on how to check, in practice, whether your shop is compliant.
Disclaimer: this article is purely informational. It does not constitute legal advice and does not replace the opinion of a lawyer or a qualified DPO. For specific situations, consult a professional.
Why the GDPR applies to every online store
Many people think the GDPR is a big-company problem. In reality it applies to anyone processing the personal data of people located in the EU, regardless of size. A maker selling handmade products from a no-code site, a small boutique with a shop on a standard platform and an e-commerce business with thousands of orders a day all share the same baseline obligations.
The topic is even more delicate for anyone who built their site with AI and vibe coding tools (Lovable, Bolt.new, v0, Cursor). Those tools generate interfaces incredibly fast, but they rarely deal with compliance: the result is often a polished shop with no cookie banner, a generic privacy policy and trackers firing before consent. Errors invisible to the eye, but very visible to a supervisory authority.
The cardinal principle is accountability: complying with the rules isn't enough, you must be able to demonstrate that you comply. Documentation, records and proof of consent aren't bureaucracy: they're your defence.
The legal basis for processing: the starting point
Before you collect a single data point, you need to know why you have the right to do so. The GDPR doesn't allow processing data "because you need it": every processing activity must rest on one of the legal bases in Article 6. In e-commerce the most relevant are:
| Legal basis | When it applies in e-commerce |
|---|---|
| Performance of a contract | Processing the order, handling shipping, payment and returns. It's the basis for the data essential to the sale. |
| Legal obligation | Retaining invoices and tax documents for the period required by law. |
| Consent | Newsletters, email marketing, profiling cookies, remarketing. |
| Legitimate interest | Fraud prevention, site security, some statistical analysis (with a documented balancing test). |
The distinction is crucial. Data needed to ship an order doesn't require separate consent: the basis is the contract. But sending commercial offers by email to someone who has already bought, or firing a tracking pixel, are further processing activities that almost always require freely given, specific and informed consent. Confusing the two is one of the most common and most penalised mistakes.
The privacy notice specific to e-commerce
The privacy notice (or e-commerce privacy policy) is the document explaining to your customers how you handle their data. It isn't text copied from another site: it must reflect what actually happens in your shop.
What it must contain
A complete privacy policy for an online store includes at least:
- Identity and contact details of the controller (you or your company), and of the DPO if one has been appointed.
- Categories of data collected: identity, contact, payment, browsing data, order history.
- Purposes and legal bases for each processing activity, clearly separated.
- Recipients of the data: couriers, payment gateways, email marketing platforms, analytics services.
- Transfers outside the EU, if you use services with servers outside the European Economic Area.
- Retention periods, differentiated by purpose.
- User rights and how to exercise them.
- The right to lodge a complaint with the supervisory authority.
A frequent mistake in quickly built shops is having a default, generic or even missing policy. Dig into the topic in our dedicated guide on why a website privacy policy is required: it applies all the more when you collect payment data and shipping addresses.
Where and how to display it
The notice must be easy to find: typically linked in the footer of every page and referenced at every point where you collect data (checkout, newsletter signup, account creation). It must be written in plain language, not impenetrable legalese: transparency is a requirement, not an optional extra.
Cookie banner and consent: the most widespread mistake
E-commerce cookies are where most online stores trip up. The rule, repeatedly restated by European authorities and guidelines, is simple in theory: non-essential cookies and trackers (marketing, profiling, third-party analytics) may only be activated after the user has given explicit consent.
The classic error: trackers firing before consent
Here's the scenario you see constantly: a user lands on the shop, the cookie banner appears as an overlay, but in the meantime Google Analytics, the Meta pixel and other scripts have already collected data. That's a violation, even if the user then clicks "Accept". Consent must come first: no marketing or analytics tracker should load before the click.
A compliant cookie banner must meet some minimum requirements:
- No non-essential tracker active before the user's choice.
- Equivalent "Accept" and "Reject" buttons: refusing must be as easy as accepting.
- No implied consent: simply scrolling the page or closing the banner doesn't count as acceptance.
- Granularity: the ability to choose by category (analytics, marketing, etc.).
- Easy withdrawal: the user must be able to change their mind at any time.
Essential cookies, the ones strictly necessary for the site to work (the cart or the login session, for instance), don't require consent, but they still have to be described in the cookie policy.
If you're not sure how your banner behaves, a GDPR website audit tool can show you exactly which scripts fire and when, without hunting through the code by hand.
Handling customer and order data
Every order generates data you have to look after sensibly. Correct handling of customer data under the GDPR rests on three practical principles.
Minimisation
Collect only the data you genuinely need. Asking for a date of birth or a phone number when they aren't necessary for the sale is a practice to avoid: every extra data point is an extra liability.
Storage limitation
Data shouldn't be kept "forever". You must define how long you retain each category:
| Data category | Practical reference for retention |
|---|---|
| Tax data and invoices | The period required by tax legislation (commonly several years) |
| Account data and order history | While the account is active, then per a defined policy |
| Marketing data (with consent) | Until consent is withdrawn or a predefined period |
| Technical and security logs | Short periods, proportionate to the purpose |
These aren't absolute values valid in every case: define them with your adviser based on your business.
Data security
The GDPR requires appropriate technical and organisational measures. For e-commerce that means, at minimum: HTTPS across the whole site, secure password handling, constant CMS and plugin updates, restricted access and, where possible, encryption of sensitive data. A security flaw isn't just a technical risk: if it exposes personal data, it becomes a compliance problem in its own right. For a broader picture, see our guide on how to have a GDPR-compliant website.
Consent for newsletters and email marketing
Newsletter consent deserves its own chapter because it's one of the most delicate areas. Sending commercial communications by email nearly always requires specific, demonstrable consent.
The golden rules
- No pre-ticked boxes. Consent must come from a positive action by the user: the signup box must be empty by default. A pre-ticked box does not constitute valid consent.
- Consent separate from the purchase. Newsletter signup can't be a condition for completing the order, nor be buried in the acceptance of the terms of sale.
- Clear purpose. The user must know what they're consenting to: promotions, product news, personalised offers.
- Unsubscribe always available. Every email must contain a working, immediate unsubscribe link.
- Proof of consent. You must be able to show when and how the user signed up (double opt-in is the most robust practice).
A special case is so-called soft opt-in: under certain conditions you may send communications about similar products to people who have already bought from you, but only with specific safeguards and always offering the ability to object. The conditions are precise: check them with a professional before relying on them.
User rights: how to handle requests
The GDPR grants data subjects a set of rights that you, as controller, must respect, generally within one month of the request. The main ones are:
- Access: the user can ask which of their data you process and obtain a copy.
- Rectification: correction of inaccurate data.
- Erasure ("right to be forgotten"): removal of the data, save for retention obligations (tax ones, for example).
- Restriction and objection to processing.
- Portability: receiving their data in a structured format readable by another system.
- Withdrawal of consent, at any time and as easily as it was given.
In practice you need a clear channel (a dedicated privacy email address works fine for a small business) and an internal process to handle requests within the deadline. Ignoring a request or answering late is itself a violation.
Data breach: what to do when something goes wrong
A data breach is a security incident leading to the destruction, loss, alteration or unauthorised access to personal data. A stolen database, a compromised admin account, a backup that ended up online: those are all data breaches.
The obligations are precise:
- Notification to the supervisory authority within 72 hours of discovery, if the breach poses a risk to people's rights and freedoms.
- Communication to data subjects without undue delay, when the risk is high.
- Breach register: you must document every breach, including the ones you don't notify, along with the assessments you made.
To meet the 72-hour window you need to notice the breach in time. That's where security monitoring makes the difference: many small businesses discover a problem weeks later, when the deadline has long passed.
Processors: payment gateways, couriers and plugins
When you sell online, you're not the only one handling your customers' data. The payment gateway sees the transaction data, the courier the shipping address, the email marketing platform the subscriber addresses, some plugins collect browsing data. Under the GDPR, all of these are processors.
The DPA requirement
For every supplier processing data on your behalf you must have a Data Processing Agreement (DPA) in place under Article 28. The DPA defines what the supplier may do with the data, what guarantees it offers and how it protects the data. Major providers make a standard DPA available to accept or sign: check you have one for each.
An often-overlooked aspect concerns transfers outside the EU: if a supplier stores or processes data outside the European Economic Area, appropriate safeguards are required. Make an honest map of every tool connected to your shop: there are usually more than you think.
Fines: what's actually at stake
The GDPR provides for fines of up to 20 million euros or 4% of worldwide annual turnover, whichever is higher. Those figures are designed for major violations, but supervisory authorities regularly penalise small operators too, especially for non-compliant cookies, missing notices and marketing without consent.
Beyond the fine, the most concrete damage for a small e-commerce business is often reputational: a complaint or the loss of customer trust weighs as much as the penalty. Seen this way, compliance isn't a cost: it's part of the quality of your service.
Practical GDPR checklist for e-commerce
Use this list as a starting point to see where you stand:
- I've identified the legal basis for every processing activity (contract, legal obligation, consent, legitimate interest).
- I have a privacy policy specific to my e-commerce, reachable from the footer and from the data collection points.
- I have an up-to-date cookie policy listing the cookies and trackers in use.
- My cookie banner blocks non-essential trackers until the user consents.
- The "Accept" and "Reject" buttons are equivalent and easy to use.
- I apply minimisation: I only collect the data I need.
- I've defined retention periods for every category of data.
- The newsletter signup box isn't pre-ticked and is separate from the purchase.
- I keep proof of consent for marketing communications.
- I have a channel for handling access, erasure and withdrawal requests within the deadline.
- I have a data breach procedure and know who to notify within 72 hours.
- I have a DPA with every external supplier (payments, shipping, marketing, plugins).
- I've mapped any transfers outside the EU and the corresponding safeguards.
- The site uses HTTPS and the software is up to date.
How to check your e-commerce's compliance
Ticking a checklist from memory is a good start, but the most reliable way to know whether your shop is genuinely compliant is to observe what the site actually does when a user visits: which scripts fire, in what order, before or after consent, and whether the privacy and cookie policies are present and consistent.
Doing that kind of check by hand takes technical skill and time. An automated scanner like Appurai analyses your e-commerce and shows you GDPR compliance problems and any security flaws in minutes: non-compliant cookie banners, missing or generic privacy policy, trackers firing before consent. It's useful even if you built the shop with AI tools, where these problems are especially frequent. The free version shows you where to act; if you also need to generate the basic legal documents, dedicated tools such as privacy policy generators give you a pre-structured text to start from.
Whatever tool you use, remember: compliance isn't a milestone you reach once and forget. Every new plugin, every new marketing tool and every change to the site can introduce a risk. Treat it as periodic maintenance, not a one-off task.
Frequently asked questions
Does the GDPR apply to a small e-commerce or a solo maker?
Yes. The GDPR applies to anyone processing the personal data of people in the EU, regardless of turnover or order volume. Even a single maker selling from a no-code site has the same baseline obligations as a large online store.
Can I use Google Analytics on my online store?
You can, but only after obtaining the user's consent through the cookie banner and after checking the conditions around data transfers. Analytics must not fire before the acceptance click: it's one of the most penalised mistakes in e-commerce.
Can the newsletter signup box be pre-ticked?
No. Consent must come from a positive action by the user, so the box must be empty by default. A pre-ticked box does not constitute valid consent under the GDPR.
Do I have to appoint a DPO for my e-commerce?
Not always. Appointing a DPO (Data Protection Officer) is mandatory only in specific cases, typically for large-scale processing or special categories of data. Many small e-commerce businesses aren't required to, but the assessment should be made case by case with a professional.
How long must I keep customer data?
It depends on the purpose. Tax data follows the deadlines in tax legislation, marketing data lasts until consent is withdrawn, other data should be deleted when it's no longer needed. You need a differentiated retention policy.
What should I do if I'm attacked and data is stolen?
If the breach poses a risk to users, you must notify the supervisory authority within 72 hours of discovery and, in the most serious cases, inform the data subjects as well. In any case you must document what happened in a breach register.