Certix

E-commerce

Data protection for
e-commerce and online shops

Online shops manage cookies, purchase data, marketing automation, retargeting and payment gateways. The GDPR and cookie regulations (ePrivacy) impose specific obligations that the AEPD actively supervises.

Cookies

prior consent required

Art. 21.2

LSSI — existing customer exception

4 years

tax data retention

24 h

personalised proposal

Sector challenges

General obligations for e-commerce and online shops

Cookies and consent

The cookie banner must make it equally easy to reject all non-essential cookies as to accept them. Analytics, advertising and social media cookies require prior active consent.

Marketing automation

Abandoned cart emails, product recommendations and newsletters to natural persons require prior consent or the existing customer exception under the LSSI.

Payment gateways

Payment providers (Stripe, Redsys, PayPal) process buyers' financial data. The legal relationship with each provider determines whether they act as data processors or independent data controllers.

Retargeting and personalised advertising

Retargeting on Meta, Google and other platforms requires advertising cookies with prior consent. Without it, retargeting campaigns may raise regulatory compliance issues.

Order and return data

Shipping, tracking and return data must be retained for the guarantee period and the tax retention period. Data of buyers who request erasure cannot be deleted if tax obligations remain outstanding.

Reviews and user-generated content

Review systems that display the buyer's real name publish personal data. The buyer must be able to choose a pseudonym and must be informed of this publication.

The service

What the service includes for your online shop

RoPA (Record of Processing Activities)

Tailored RoPA: buyers, employees, cookies, marketing tools and payment gateways.

Privacy policy and cookies

Complete legal documentation for the online shop: privacy policy, legal notice and cookie policy.

Cookie banner

Advisory on implementing a cookie banner that meets AEPD requirements.

Data Processing Agreements (DPA)

DPA for e-commerce platforms (Shopify, WooCommerce), email marketing tools and payment gateways.

Data breach protocol

Response procedure with notification within 72 hours.

Data subject rights management

Procedure for buyers' requests: access, erasure, portability and objection.

Document management platform

Access to a private platform with documents and electronic signature.

Ongoing support

Unlimited consultations. Updates on regulatory changes.

External DPO (if applicable)

As a general rule, e-commerce businesses are not listed in the exhaustive provisions of art. 34 LOPDGDD or art. 37 GDPR. The final requirement will nonetheless depend on the scale, volume and exact nature of each entity's processing activities. Each case requires individual analysis. Separate contract.

Do you need a proposal for your online shop?

Tell us about your platform and volume. Proposal within 24 hours.

Request a proposal

FAQ

Frequently asked questions about data protection in e-commerce

Is a cookie banner required for an online shop?

In general, the use of non-technically-necessary cookies (analytics, advertising, social media) requires prior user consent under the ePrivacy rules and the AEPD Cookie Guidelines. The banner must make it as easy to reject cookies as to accept them. The AEPD has published detailed criteria on this requirement, which should be reviewed for each specific case.

What legal basis is used for marketing automation in e-commerce?

To send automated emails such as abandoned cart reminders, product recommendations or newsletters to natural persons, prior consent is required, or the existing customer exception (art. 21.2 LSSI) for similar products. The legitimate interest basis is not valid for direct marketing communications to natural persons in Spain.

Is the payment gateway a data processor?

It depends on the model. If the payment gateway (Stripe, PayPal, Redsys) processes payment data on behalf of the shop, it acts as a data processor. If card data is entered directly into the gateway's system without the shop seeing it, the gateway may act as an independent data controller. The shop must review the terms and conditions of each provider.

How long must order data be retained?

Order data must be retained for the statutory guarantee period (at least 2 years for consumer goods) and for the tax retention period (4 years). If a customer exercises the right of erasure before these periods expire, the data must be blocked (not deleted) until the legal obligations expire.

Does retargeting require user consent?

In general, retargeting (showing adverts to users who have visited the shop) involves the use of advertising and profiling cookies. According to ePrivacy rules and AEPD doctrine, this type of cookie requires prior informed consent. Non-compliance may give rise to infringements, although the specific circumstances of each case must be analysed separately.

Can product reviews contain personal data?

Yes. If the review system displays the real name of the buyer or another identifiable piece of data, it is publishing personal data. The shop must inform the buyer that their name will appear in the review and allow them to use a pseudonym if they prefer. Reviews must not include personal data of third parties (such as the name of another buyer or an employee).

Free tool

Data protection self-check

Check in 5 minutes your overall adaptation level in personal data protection.

No email · Anonymous · No commitment

Start the test

E-commerce

GDPR compliance
for your online shop.

An expert analyses your shop and proposes the right solution. No intermediaries.

INFORMACIÓN BÁSICA DE PROTECCIÓN DE DATOS: De conformidad con las normativas de Protección de Datos, le facilitamos la siguiente información del tratamiento: Responsable: Certificación y Gestión Normativa S.L.U. Finalidad: atender su solicitud y contactarle para ofrecerle la información solicitada. Derechos: acceso, rectificación, portabilidad, supresión, limitación y oposición, así como otros derechos detallados en la información adicional. + info: Puedes encontrar información más detallada en nuestra Política de privacidad.

Or tell us your full case →

Proposal within 24 h · info@certix.es

Legal note: This content is for informational and educational purposes only; it does not constitute specialist legal advice. The application of the regulations to each specific case requires individual analysis.