E-commerce
Data protection for
e-commerce and online shops
Online shops manage cookies, purchase data, marketing automation, retargeting and payment gateways. The GDPR and cookie regulations (ePrivacy) impose specific obligations that the AEPD actively supervises.
Cookies
prior consent required
Art. 21.2
LSSI — existing customer exception
4 years
tax data retention
24 h
personalised proposal
Sector challenges
General obligations for e-commerce and online shops
Cookies and consent
The cookie banner must make it equally easy to reject all non-essential cookies as to accept them. Analytics, advertising and social media cookies require prior active consent.
Marketing automation
Abandoned cart emails, product recommendations and newsletters to natural persons require prior consent or the existing customer exception under the LSSI.
Payment gateways
Payment providers (Stripe, Redsys, PayPal) process buyers' financial data. The legal relationship with each provider determines whether they act as data processors or independent data controllers.
Retargeting and personalised advertising
Retargeting on Meta, Google and other platforms requires advertising cookies with prior consent. Without it, retargeting campaigns may raise regulatory compliance issues.
Order and return data
Shipping, tracking and return data must be retained for the guarantee period and the tax retention period. Data of buyers who request erasure cannot be deleted if tax obligations remain outstanding.
Reviews and user-generated content
Review systems that display the buyer's real name publish personal data. The buyer must be able to choose a pseudonym and must be informed of this publication.
The service
What the service includes for your online shop
RoPA (Record of Processing Activities)
Tailored RoPA: buyers, employees, cookies, marketing tools and payment gateways.
Privacy policy and cookies
Complete legal documentation for the online shop: privacy policy, legal notice and cookie policy.
Cookie banner
Advisory on implementing a cookie banner that meets AEPD requirements.
Data Processing Agreements (DPA)
DPA for e-commerce platforms (Shopify, WooCommerce), email marketing tools and payment gateways.
Data breach protocol
Response procedure with notification within 72 hours.
Data subject rights management
Procedure for buyers' requests: access, erasure, portability and objection.
Document management platform
Access to a private platform with documents and electronic signature.
Ongoing support
Unlimited consultations. Updates on regulatory changes.
External DPO (if applicable)
As a general rule, e-commerce businesses are not listed in the exhaustive provisions of art. 34 LOPDGDD or art. 37 GDPR. The final requirement will nonetheless depend on the scale, volume and exact nature of each entity's processing activities. Each case requires individual analysis. Separate contract.
Do you need a proposal for your online shop?
Tell us about your platform and volume. Proposal within 24 hours.
FAQ
Frequently asked questions about data protection in e-commerce
Is a cookie banner required for an online shop?
In general, the use of non-technically-necessary cookies (analytics, advertising, social media) requires prior user consent under the ePrivacy rules and the AEPD Cookie Guidelines. The banner must make it as easy to reject cookies as to accept them. The AEPD has published detailed criteria on this requirement, which should be reviewed for each specific case.
What legal basis is used for marketing automation in e-commerce?
To send automated emails such as abandoned cart reminders, product recommendations or newsletters to natural persons, prior consent is required, or the existing customer exception (art. 21.2 LSSI) for similar products. The legitimate interest basis is not valid for direct marketing communications to natural persons in Spain.
Is the payment gateway a data processor?
It depends on the model. If the payment gateway (Stripe, PayPal, Redsys) processes payment data on behalf of the shop, it acts as a data processor. If card data is entered directly into the gateway's system without the shop seeing it, the gateway may act as an independent data controller. The shop must review the terms and conditions of each provider.
How long must order data be retained?
Order data must be retained for the statutory guarantee period (at least 2 years for consumer goods) and for the tax retention period (4 years). If a customer exercises the right of erasure before these periods expire, the data must be blocked (not deleted) until the legal obligations expire.
Does retargeting require user consent?
In general, retargeting (showing adverts to users who have visited the shop) involves the use of advertising and profiling cookies. According to ePrivacy rules and AEPD doctrine, this type of cookie requires prior informed consent. Non-compliance may give rise to infringements, although the specific circumstances of each case must be analysed separately.
Can product reviews contain personal data?
Yes. If the review system displays the real name of the buyer or another identifiable piece of data, it is publishing personal data. The shop must inform the buyer that their name will appear in the review and allow them to use a pseudonym if they prefer. Reviews must not include personal data of third parties (such as the name of another buyer or an employee).
Sector resources
Learn more
Ecommerce
Cookies and consent on an online store: how to comply with the GDPR and LSSICE
Cookie banner compliant with the AEPD Guide, GA4 integration, Meta and TikTok pixels, equal weight for accept and reject, consent expiry and accessible configuration link.
9 min·Read article
Ecommerce
Ecommerce privacy policy: what it must include and how to draft it
Mandatory content of an online store's privacy policy: controller, purposes, legal bases, recipients, international transfers, retention periods, customer rights and ecommerce-specific obligations.
8 min·Read article
Free tool
Data protection self-check
Check in 5 minutes your overall adaptation level in personal data protection.
No email · Anonymous · No commitment
E-commerce
GDPR compliance
for your online shop.
An expert analyses your shop and proposes the right solution. No intermediaries.
Proposal within 24 h · info@certix.es
Legal note: This content is for informational and educational purposes only; it does not constitute specialist legal advice. The application of the regulations to each specific case requires individual analysis.