Retail & commerce
Data protection
for physical retail
Video surveillance, loyalty programmes and employee management turn any retail business into a data controller with concrete obligations. The GDPR applies from the very first customer.
30 days
maximum video surveillance retention
Art. 21.2
LSSI — prior customer exception
4 years
fiscal data retention
24 h
personalised proposal
Sector challenges
General obligations for physical retail
Video surveillance
Security cameras are the most common processing activity in physical retail. They require a clearly visible information sign, a maximum retention period of 30 days, and documentation in the RoPA (Record of Processing Activities).
Loyalty programmes
Loyalty cards, points and personalised offers involve the processing of purchase data and commercial communications, all requiring a documented legal basis.
Employee data
Payroll, contracts, schedules, occupational video surveillance and sick-leave health data generate continuous processing of staff data, each with its own obligations.
Returns and after-sales management
Data collected during the returns process (name, bank account, reason) are personal data that must be retained only for as long as necessary.
Marketing and communications
Sending advertising by email, SMS or WhatsApp to customers requires a valid legal basis (consent or the prior-customer exception) and a simple unsubscribe mechanism.
Natural-person suppliers
Data relating to self-employed individuals and natural persons who supply the business (name, email, IBAN) are personal data subject to the GDPR with the same rights as any other data subject.
The service
What the service for your retail business includes
RoPA (Record of Processing Activities)
Tailored Record of Processing Activities: customers, employees, video surveillance and loyalty programme.
Information clauses
Texts for the loyalty programme enrolment form and video surveillance signs.
Privacy policy and legal notice
Documentation for the business website.
Data Processing Agreements (DPA)
DPA for POS terminals, loyalty software and marketing platforms.
Data breach protocol
Response procedure with notification within 72 hours.
Data subject rights management
Procedure for handling requests from customers and employees.
Document management platform
Access to a private platform with documents and electronic signature.
Ongoing support
Unlimited queries. Updates in response to regulatory changes.
External DPO (if applicable)
As a general rule, physical retail businesses are not listed in the exhaustive provisions of art. 34 LOPDGDD or art. 37 GDPR. The final requirement will depend on the scale, volume and exact nature of each entity's processing activities. Each case requires individual analysis. Separate contract.
Do you need a proposal for your retail business?
Tell us the type of business and the number of employees. Proposal in under 24 hours.
FAQ
Frequently asked questions about data protection in retail
Is it mandatory to display an information sign where security cameras are installed?
Yes. The GDPR and the LOPDGDD require that video-surveilled areas be marked with a clearly visible information sign stating the data controller and how to exercise rights. The AEPD has sanctioned retailers for installing cameras without adequate signage. Furthermore, cameras must be directed exclusively at the private premises of the establishment: private individuals and businesses may not record the public highway or public spaces, which is the exclusive competence of the State Security Forces and Corps (art. 22 LOPDGDD).
Does a customer loyalty programme require consent?
Participation in the loyalty programme may be based on the performance of the contract with the customer. However, the sending of commercial communications and offers associated with the programme requires a separate consent from the data subject, who must be able to participate in the programme without being obliged to receive advertising.
How long must data relating to returns be retained?
The data associated with a return (name, national ID if required, bank account for the refund) must be retained for as long as necessary for the management of the process and to address any possible consumer claims. The invoicing data associated with the transaction must be retained for 4 years due to fiscal obligations.
Can a retailer send advertising by email or WhatsApp to its customers?
Yes, with the appropriate legal basis. To existing customers who have already made a purchase, advertising for similar products may be sent without prior consent (prior customer exception, art. 21.2 LSSI), provided that the option to unsubscribe is offered. For prospects, or for any other type of advertising, prior and explicit consent is required.
How must a retailer handle its employees' data?
Workers' data (payroll, contracts, schedules, sick leave) must be processed with an appropriate legal basis (performance of the employment contract and legal obligations) and employees must be informed. Access to other employees' data must be restricted. Images of employees captured by security cameras are also personal data.
Are supplier data subject to the GDPR?
Yes, when suppliers are natural persons or self-employed individuals. The contact, banking and tax details of natural-person suppliers are personal data subject to the GDPR. For companies (legal persons), the GDPR does not apply directly, although the data of contact persons are protected.
Sector resources
Learn more
Retail
Video surveillance in shops: how to install cameras complying with the GDPR and LOPDGDD
How to install cameras in a physical shop complying with the GDPR and LOPDGDD: security purpose, allowed and prohibited areas, signage, one-month maximum retention and processing record.
8 min·Read article
Retail
Loyalty programmes and customer cards: how to comply with the GDPR in retail
How to manage a loyalty programme with customer card under the GDPR: legal basis, express consent by purpose, commercial communications under the LSSICE and right to object.
7 min·Read article
Retail
Retail employee data: payroll, time tracking and workplace video surveillance
How to manage the data of shop workers under the GDPR and the Spanish Workers' Statute: payroll, time tracking with PIN or card, workplace video surveillance under art. 89 LOPDGDD and retention periods.
8 min·Read article
Free tool
Data protection self-check
Check in 5 minutes your overall adaptation level in personal data protection.
No email · Anonymous · No commitment
Retail & commerce
GDPR compliance
for your retail business.
An expert analyses your activity and proposes the right solution. No intermediaries.
Proposal within 24 h · info@certix.es
Legal notice: This content is for informational and educational purposes only; it does not constitute specialist legal advice. The application of the regulations to each specific case requires individual analysis.