Certix

Ecommerce privacy policy: what it must include and how to draft it

Certix
Certix®
· 1 Jun 2026 · 8 min read

Informative article. It does not replace individualised professional advice.

The privacy policy is the most visited and least read document in any online store. It appears linked from the website footer, the customer registration screen, the contact form and the order checkout. Even so, most ecommerce privacy policies suffer from the same problem: they are texts copied from generic templates that do not reflect the operational reality of the business. When a complaint or inspection arrives, that gap between what the policy says and what actually happens is what triggers the sanction.

This guide summarises the minimum mandatory content of an ecommerce privacy policy in line with Art. 13 of the GDPR (Regulation (EU) 2016/679) and the LOPDGDD (Spain's Organic Law 3/2018 on Data Protection), with the specific features of electronic commerce: payment gateway, logistics, marketing, accounting retention and retargeting.

Why the privacy policy matters more in ecommerce than in other sectors

Three factors make the document especially critical for an online store:

  • Data collection without human contact: the customer signs up alone, without anyone explaining anything. The policy is the only effective way to comply with the duty to inform under Art. 13 GDPR.
  • Long chain of processors: a typical sale involves a payment gateway, a logistics company, an ERP, an email platform, a reviews manager and a chatbot. Each one processes customer data and must appear in some form in the policy.
  • Routine international transfers: hosting sits in a cloud whose providers are global, email marketing is usually American, and so is the CRM. The policy must reflect that reality with legal honesty.

Minimum mandatory content

Art. 13 GDPR sets a minimum content when data is collected directly from the data subject (the ecommerce case). These are the blocks no policy can omit, translated into the reality of an online store:

Block What it must say in an ecommerce site
Identity of the controller Full corporate name, tax ID, registered office, privacy email and, where applicable, contact details of the Data Protection Officer.
Purposes Customer account management, order processing and delivery, invoicing, customer service, marketing where applicable, reviews management, fraud prevention, compliance with legal obligations.
Legal bases Performance of the contract (Art. 6(1)(b)) for the order; legal obligation (6(1)(c)) for invoicing; consent (6(1)(a)) or legitimate interest (6(1)(f)) for marketing; legitimate interest for fraud prevention.
Recipients Payment gateway, logistics company, email marketing platform where applicable, hosting, ERP, reviews manager, tax authorities where legally required.
International transfers Explicit mention if hosting or any provider operates outside the EEA, the basis for the transfer (Data Privacy Framework, standard contractual clauses) and how the user may obtain a copy of the safeguards.
Retention periods By blocks: invoicing under the Spanish Commercial Code and the Spanish General Tax Act; customer account data while the account is active plus the claims period; marketing data while consent lasts.
Data subject rights Access, rectification, erasure, objection, restriction, portability, no automated decisions; a specific channel to exercise them and a mention of the right to lodge a complaint with the AEPD (the Spanish Data Protection Authority).
Source of the data Clarify that the data comes from the data subject (registration, order, form) and, where applicable, from external sources (payment verification, fraud prevention agencies).

How to break down the legal bases without contradictions

The most typical mistake of template policies is assigning a single legal basis — usually consent — to all purposes. In an ecommerce site this is legally incorrect and operationally harmful: if the user withdraws consent, the ecommerce site could not process the order or issue the invoice.

The correct approach is to split the purposes and assign each one its natural legal basis:

  • Order management, delivery, returns and after-sales: performance of the contract (Art. 6(1)(b) GDPR). No consent required.
  • Invoicing, accounting, withholdings: legal obligation (Art. 6(1)(c) GDPR). No consent required either.
  • Customer account with order history: performance of the contract and associated legal obligations. Once the account is closed, residual retention for the minimum legal periods.
  • Newsletter and commercial communications to existing customers about similar products: the controller's legitimate interest (Art. 6(1)(f) GDPR), combined with the provision of Art. 21(2) LSSICE for email.
  • Newsletter and commercial communications to users who are not customers (mailing list subscribers): express consent (Art. 6(1)(a) GDPR).
  • Retargeting, profiling for campaigns, marketing cookies: express consent via the cookie banner.
  • Fraud prevention: legitimate interest, with a clear explanation and a written balancing test recorded in the RoPA.

International transfers: what cannot be hidden

The vast majority of Spanish ecommerce sites operate with at least one provider whose servers or sub-processors are located outside the European Economic Area. The privacy policy must be honest about this. The points it is advisable to expressly mention where they exist:

  • Hosting or cloud in the United States or other countries without an adequacy decision: name the provider, the country and the legal basis. For the United States, the usual basis is the provider's adherence to the Data Privacy Framework (DPF). If the provider is not adhered to the DPF, the operation must rely on standard contractual clauses and a transfer impact assessment must have been performed.
  • Email marketing: most platforms are US-based. Same analysis.
  • CRM and customer service: if hosted outside the EEA, same analysis.
  • Reviews manager: if the service stores reviews and customer data outside the EEA, identify the country and the basis.

Users have the right to obtain a copy of the safeguards applied to the transfer. The policy must explain how to request it (email to the controller or to the DPO if there is one).

Data subject rights: the contact channel matters

The policy must identify a specific and operational channel for the customer to exercise their rights. The reasonable approach in ecommerce is to offer at least two routes:

  • Privacy email: typically privacy@ or dataprotection@ followed by the ecommerce domain. The mailbox must be effectively monitored and the response provided within the one-month period set out in Art. 12(3) GDPR.
  • Specific web form for exercising rights. Useful for customers who prefer a traceable channel and usually facilitates prior identification.
  • Postal mail: optional, but necessary for customers who prefer that channel.

The policy must also expressly mention the right to lodge a complaint with the AEPD, with the link to or address of the authority's offices.

"In ecommerce, the privacy policy is not legal marketing: it is the accurate picture of how the business operates with its customers' data. If the picture does not match reality — providers that do not appear, international transfers that are not mentioned, periods that are not respected — the problem is not the policy, it is the business."

Mario P. Talamillo · Managing Partner, Certix®

Maintenance: the policy is not a static document

An ecommerce privacy policy should be reviewed at least:

  • Whenever a relevant provider changes (new payment gateway, new email marketing platform, change of logistics provider).
  • Whenever a new purpose is added (launch of a loyalty programme, new social media integration, AI-powered chatbot).
  • Whenever the applicable regulation or the AEPD's doctrine on a relevant point changes.
  • As a minimum, an annual review, recording the last-update date in the policy itself.

Final checklist

  • Complete and verifiable identification of the controller, with tax details and address.
  • Purposes broken down by block with their correct legal bases.
  • Recipients identified by name or by recognisable categories, with specific mention of payment gateway, logistics and email marketing.
  • International transfers declared, with country and legal basis.
  • Retention periods per purpose, with regulatory references where applicable.
  • Data subject rights and an operational channel to exercise them, with response time and a mention of the AEPD.
  • Last-update date visible at the bottom of the policy.
  • Effective alignment between what the policy says and what the ecommerce site actually does in technical and operational reality.

Frequently asked questions

Is a generic privacy policy copied from a template enough for my online store?

As a formal starting point yes, as a final document no. The policy must reflect the specific controller, the real purposes of the business, the actual providers (gateway, logistics, ERP, marketing) and the transfer countries. Generic templates tend to fail precisely where the AEPD sanctions: real periods, actual recipients, international transfers and legal bases coherent with each purpose.

Do I have to mention every provider one by one in the privacy policy?

The GDPR requires informing of recipients or categories (Art. 13(1)(e)). The recommended practice is to identify by name at least the main ones: payment gateway, usual carrier, email marketing, hosting if outside the EEA and CRM. The list may be kept in an updatable annex linked from the policy.

How long can I keep a customer's data after their last purchase?

It depends on the purpose. Data linked to the invoice while the accounting and tax rules require. Data linked to possible civil claims until they lapse. Data for commercial use while the consent or contractual relationship lasts. The policy must explain those periods by blocks of purpose rather than setting a single one.

Do I need to ask the customer for consent to send them the transactional email about their order?

No. The confirmation email, dispatch notice, tracking and invoice rely on the performance of the contract (Art. 6(1)(b) GDPR). What does require a marketing basis (consent or legitimate interest with similar products plus Art. 21 LSSICE) is the newsletter, promotions and recommendations not linked to the purchase made.

This content is for informational and educational purposes only and does not constitute legal advice. Applying the regulation to each specific case requires individual analysis. Regional sectoral regulations may extend or modify time limits and requirements.

Does your ecommerce privacy policy reflect what actually happens?

At Certix we assign you a compliance specialist for the ecommerce sector. No commercial intermediaries, no generic templates.

Speak to a specialist

Initial assessment

Need data protection advice?

At Certix you will deal directly with an expert, with no sales teams involved.

BASIC DATA PROTECTION INFORMATION: In accordance with Data Protection regulations, we provide the following processing information: Controller: Certificación y Gestión Normativa S.L.U. Purpose: to handle your request and contact you to provide the requested information. Rights: access, rectification, portability, erasure, restriction and objection, and other rights detailed in the additional information. More info: You can find more detailed information in our Privacy Policy.

Or tell us your full case →