Weekly ecommerce tips, deals & news.
The General Data Protection Regulation, or GDPR, is the European Union’s privacy law. It governs how you collect, store, and use personal data. It applies to any store handling data about people in the EU.
Think of it as a set of house rules for someone else’s information. You are borrowing it, not owning it. The person it belongs to keeps the right to see it, correct it, or ask for it back.
GDPR has a reputation for being impenetrable. Most of it comes down to a simple idea, which is that personal data belongs to the person.
This is the part most store owners get wrong. GDPR is not limited to businesses based in Europe.
It follows the person, not the company. If you handle data about someone in the EU, the rules apply to you.
An Australian store shipping to Germany is covered. So is a shop that merely lets EU visitors browse and sign up.
The practical test is whether you target those customers. Pricing in euros or offering EU delivery both suggest you do.
The definition is much broader than most people expect. It covers anything that can identify a living person.
Names, email addresses, and delivery addresses are obvious. IP addresses, device identifiers, and cookie IDs also qualify.
So your analytics and ad tools are usually in scope. Anything that follows a person around your site is handling personal data.
Even an order history counts, because it attaches behaviour to an identifiable individual. That includes saved items and abandoned carts.
You cannot process personal data just because it is useful. You need a reason the law recognises.
There are six: consent, contract, legal obligation, vital interests, public task, and legitimate interests. Most store activity relies on the first two.
Contract covers what you need to fulfil the order. Address, payment confirmation, and delivery updates all sit here comfortably.
Marketing is where stores slip. Sending a newsletter to someone because they once bought a lamp is not covered by contract.
GDPR gives individuals a specific set of rights. You have to be able to honour them, usually within a month.
They can ask what you hold about them, which is a subject access request. They can have errors corrected and, in many cases, have data deleted.
They can also ask for their data in a portable format. That means a machine-readable file, not a screenshot.
Being able to run a clean order export makes these requests routine. Visser Labs covers the practical side in its guide to WooCommerce GDPR compliance.
The most visible change is the end of pre-ticked boxes. Consent has to be an active choice.
Marketing opt-in must be separate from the purchase itself. Bundling them together makes the consent invalid.
You also cannot force account creation to buy. Keeping guest checkout available avoids collecting more than you need.
Data minimisation is the underlying principle. If a field is not necessary for the order, think hard before asking for it.
Marketing automations are easy to overlook. They run quietly and often predate anyone thinking about privacy.
An abandoned cart email needs a lawful basis like anything else. Recovering a cart for a logged-in customer is easier to justify than chasing an anonymous visitor.
The same applies to wishlist remarketing. Saved items reveal intent, and intent about an identifiable person is personal data.
There is an upside worth noticing here. Zero-party data, given deliberately by the customer, sits on far firmer ground than data you inferred.
GDPR sets a hard deadline for reporting. You have 72 hours from becoming aware of a breach to notify your supervisory authority.
That clock starts at awareness, not at certainty. Waiting until you fully understand the incident is a common and costly mistake.
If the breach is likely to harm people, you must tell them too. Vague reassurance does not satisfy that obligation.
Write the process down before you need it. A short entry in your internal knowledge base beats improvising during a bad week.
The headline fines belong to very large companies. Small stores are not the priority for regulators.
Enforcement is real at scale, though. Total GDPR fines have passed the 6 billion euro mark since the law took effect.
Most small-business trouble starts with a complaint rather than an audit. An annoyed customer who cannot get unsubscribed is a common trigger.
That makes basic hygiene the best protection. Honour requests promptly and keep your marketing list genuinely opted in.
Imagine a WooCommerce store called Tallow & Twine, selling candles from Australia. Around 15% of their orders ship to Europe.
The owner assumes GDPR is a European problem. The business is registered in Melbourne, so it feels like someone else’s rulebook.
Their checkout has a pre-ticked newsletter box. Every buyer joins the mailing list automatically.
Analytics and ad pixels load the moment anyone arrives. Nobody is asked about any of it.
Shipping to Europe puts them squarely in scope. The Melbourne registration changes nothing.
The pre-ticked box means their EU subscribers never gave valid consent. That part of the list is not lawfully theirs to email.
Loading tracking before any choice is offered is a second problem. Those cookie identifiers are personal data.
They untick the box and make marketing opt-in explicit. Existing EU subscribers get a re-permission email.
About 40% re-confirm, so the list shrinks noticeably. The remaining contacts are people who actually want the emails.
Open rates climb as a result, because the disengaged names are gone. Their unsubscribe rate falls at the same time.
Better email segmentation comes out of the same exercise. Knowing who genuinely opted in makes the remaining list easier to use well.
Adding a consent banner costs a little conversion at first. Against a typical 2.03% conversion rate, the trade is worth measuring rather than guessing.
Store owners often bundle these together as “the compliance stuff”. They are different things with different enforcers.
PCI compliance is an industry standard covering card data. The card networks enforce it, not a government.
GDPR is actual law covering all personal data. Public regulators enforce it, and the penalties are statutory.
They overlap at the payment step and diverge everywhere else. Card details fall under both, whereas an email address falls only under GDPR.
Using tokenization helps with both at once. Data you never hold cannot be leaked or misused.
Yes, if you handle data about people who are. The law follows the individual rather than your business address.
Shipping to the EU or marketing to EU customers brings you in scope. Simply having a website that Europeans can reach usually does not.
Transactional messages are fine, because they are part of the contract. Order confirmations and shipping updates count as transactional email.
Marketing is a separate question and generally needs consent. Using double opt-in gives you a clear record that it was given.
For the basics, no. Honest opt-ins, a real privacy policy, and the ability to find and delete a customer’s data cover most small stores.
Get proper advice if you sell at scale into Europe or handle sensitive categories. This article is general information rather than legal advice.
Rules also vary by country on top of GDPR itself. Local regulators publish plain-language guidance that is worth reading first.
GDPR is less about paperwork than about honesty with data you were lent. Collect only what you need and ask properly before marketing. Be able to produce or delete a customer’s records on request. Stores that do those three things well are rarely the ones regulators hear about.
Copyright © StoreOwnerTips.com. All Rights Reserved.