Certix

Retail & commerce

Data protection
for physical retail

Video surveillance, loyalty programmes and employee management turn any retail business into a data controller with concrete obligations. The GDPR applies from the very first customer.

30 days

maximum video surveillance retention

Art. 21.2

LSSI — prior customer exception

4 years

fiscal data retention

24 h

personalised proposal

Sector challenges

General obligations for physical retail

Video surveillance

Security cameras are the most common processing activity in physical retail. They require a clearly visible information sign, a maximum retention period of 30 days, and documentation in the RoPA (Record of Processing Activities).

Loyalty programmes

Loyalty cards, points and personalised offers involve the processing of purchase data and commercial communications, all requiring a documented legal basis.

Employee data

Payroll, contracts, schedules, occupational video surveillance and sick-leave health data generate continuous processing of staff data, each with its own obligations.

Returns and after-sales management

Data collected during the returns process (name, bank account, reason) are personal data that must be retained only for as long as necessary.

Marketing and communications

Sending advertising by email, SMS or WhatsApp to customers requires a valid legal basis (consent or the prior-customer exception) and a simple unsubscribe mechanism.

Natural-person suppliers

Data relating to self-employed individuals and natural persons who supply the business (name, email, IBAN) are personal data subject to the GDPR with the same rights as any other data subject.

The service

What the service for your retail business includes

RoPA (Record of Processing Activities)

Tailored Record of Processing Activities: customers, employees, video surveillance and loyalty programme.

Information clauses

Texts for the loyalty programme enrolment form and video surveillance signs.

Privacy policy and legal notice

Documentation for the business website.

Data Processing Agreements (DPA)

DPA for POS terminals, loyalty software and marketing platforms.

Data breach protocol

Response procedure with notification within 72 hours.

Data subject rights management

Procedure for handling requests from customers and employees.

Document management platform

Access to a private platform with documents and electronic signature.

Ongoing support

Unlimited queries. Updates in response to regulatory changes.

External DPO (if applicable)

As a general rule, physical retail businesses are not listed in the exhaustive provisions of art. 34 LOPDGDD or art. 37 GDPR. The final requirement will depend on the scale, volume and exact nature of each entity's processing activities. Each case requires individual analysis. Separate contract.

Do you need a proposal for your retail business?

Tell us the type of business and the number of employees. Proposal in under 24 hours.

Request a proposal

FAQ

Frequently asked questions about data protection in retail

Is it mandatory to display an information sign where security cameras are installed?

Yes. The GDPR and the LOPDGDD require that video-surveilled areas be marked with a clearly visible information sign stating the data controller and how to exercise rights. The AEPD has sanctioned retailers for installing cameras without adequate signage. Furthermore, cameras must be directed exclusively at the private premises of the establishment: private individuals and businesses may not record the public highway or public spaces, which is the exclusive competence of the State Security Forces and Corps (art. 22 LOPDGDD).

Does a customer loyalty programme require consent?

Participation in the loyalty programme may be based on the performance of the contract with the customer. However, the sending of commercial communications and offers associated with the programme requires a separate consent from the data subject, who must be able to participate in the programme without being obliged to receive advertising.

How long must data relating to returns be retained?

The data associated with a return (name, national ID if required, bank account for the refund) must be retained for as long as necessary for the management of the process and to address any possible consumer claims. The invoicing data associated with the transaction must be retained for 4 years due to fiscal obligations.

Can a retailer send advertising by email or WhatsApp to its customers?

Yes, with the appropriate legal basis. To existing customers who have already made a purchase, advertising for similar products may be sent without prior consent (prior customer exception, art. 21.2 LSSI), provided that the option to unsubscribe is offered. For prospects, or for any other type of advertising, prior and explicit consent is required.

How must a retailer handle its employees' data?

Workers' data (payroll, contracts, schedules, sick leave) must be processed with an appropriate legal basis (performance of the employment contract and legal obligations) and employees must be informed. Access to other employees' data must be restricted. Images of employees captured by security cameras are also personal data.

Are supplier data subject to the GDPR?

Yes, when suppliers are natural persons or self-employed individuals. The contact, banking and tax details of natural-person suppliers are personal data subject to the GDPR. For companies (legal persons), the GDPR does not apply directly, although the data of contact persons are protected.

Free tool

Data protection self-check

Check in 5 minutes your overall adaptation level in personal data protection.

No email · Anonymous · No commitment

Start the test

Retail & commerce

GDPR compliance
for your retail business.

An expert analyses your activity and proposes the right solution. No intermediaries.

INFORMACIÓN BÁSICA DE PROTECCIÓN DE DATOS: De conformidad con las normativas de Protección de Datos, le facilitamos la siguiente información del tratamiento: Responsable: Certificación y Gestión Normativa S.L.U. Finalidad: atender su solicitud y contactarle para ofrecerle la información solicitada. Derechos: acceso, rectificación, portabilidad, supresión, limitación y oposición, así como otros derechos detallados en la información adicional. + info: Puedes encontrar información más detallada en nuestra Política de privacidad.

Or tell us your full case →

Proposal within 24 h · info@certix.es

Legal notice: This content is for informational and educational purposes only; it does not constitute specialist legal advice. The application of the regulations to each specific case requires individual analysis.