
GDPR in E-commerce: 8 Rules You Must Not Break
E-commerce stores process more personal data than average businesses—names, addresses, payments, purchase history. Learn the key GDPR risks for retailers.
Author: Meiko Neuman
Founder and web strategist, Kodulehe Haldus
Why is E-commerce Particularly Sensitive to GDPR?
An e-commerce store processes at least 8 personal data fields for every purchase: name, email, phone, address, payment details, purchase history, IP address, and cookies. According to the Data Protection Inspectorate (AKI), 38% of GDPR violations in Estonia are related to e-commerce (AKI 2024).
8 Critical Rules
1. Collect Only What is Necessary During Checkout **Required:** - Name, email, phone number - Delivery address - Payment details (credit card data should be collected by the payment provider, not on your server)
Optional: - Birthday (only if you offer a gift/discount) - Social media profiles - Company name (for B2C)
Prohibited: - Personal identification code (except for B2B invoicing) - Family information without a specific reason
2. Account Creation Must Be Optional "Guest checkout" is mandatory. The practice of forcing account creation has been sanctioned repeatedly by data protection authorities.
3. Newsletter Consent via a Separate Checkbox ```html <!-- ✗ PROHIBITED --> [x] I want to receive the newsletter
<!-- ✓ PERMITTED -->
[ ] I want to receive the newsletter (optional)
`
Pre-ticked checkboxes are invalid according to GDPR Article 7.
4. Retain Data Only as Long as Necessary
| Data Category | Maximum | Reason |
|---|---|---|
| Order | 7 years | Accounting Act |
| Account | Until deletion | User rights |
| Cart (anonymous) | 30 days | Technical necessity |
| Newsletter | Until withdrawal | Consent |
| Logs | 90-365 days | Security |
| Payment details | Do not store | PCI DSS |
5. PCI DSS Compliance If you **store** credit card data (rather than just processing it), you must comply with the [PCI DSS](https://www.pcisecuritystandards.org/) standard. The simpler solution: use intermediaries like **Stripe, Maksekeskus, Montonio**, etc. – then they bear the responsibility.
6. Data Processing Agreements (DPA) with Intermediaries You need a DPA with all third parties: - Hosting (e.g., [Veebimajutus.ee](https://www.veebimajutus.ee/)) - Payment solutions - Email / Newsletter services - Shipping providers (Itella, Omniva, DPD) - Analytics (Google, Meta) - Live chat providers
7. The Right to Access and Deletion Users must be able to: - **Download their data** (CSV/JSON, including purchase history) - **Delete their account** (though accounting data remains for 7 years)
This is available in WooCommerce (WooCommerce → Privacy) and Shopify (Customer profile → Erase personal data).
8. Data Breach Notification Within 72 Hours See our [data breach guide](/blogi/gdpr-andmeleke-mida-teha).
Estonian Specifics
Parcel Machines If you transmit data to Omniva, DPD, or Itella, you must have a DPA with **each one**. Usually, these are part of their standard terms and conditions.
14-Day Right of Withdrawal [Law of Obligations Act § 56](https://www.riigiteataja.ee/en/eli/511012024003/archive/current) – collect information required for returns (bank IBAN, gift card, etc.) **only at the moment of return**, not in advance.
VAT and Invoicing On B2B invoices, the **registry code and VAT number are required** – these are business data, not personal data. For invoices to individuals, only name and address are needed.
E-commerce Platform Support
| Platform | GDPR Support | Status |
|---|---|---|
| Shopify | Good | Data export, deletion included |
| WooCommerce | Average | Requires additional plugins (Cookiebot, etc.) |
| Magento | Good | Built-in |
| PrestaShop | Average | Additional module required |
Examples of Fines
- Carrefour France – €3M (2020) – cookies without consent
- H&M – €35M (2020) – monitoring employee data
- Amazon – €35M (2020) – France, cookies
- Estonian E-store – AKI reprimand + enforcement (2024)
Action Plan
- Audit conversion paths – what data is collected at each step?
- Remove the excessive – do not demand personal ID codes for B2C
- DPAs with third parties
- Update Privacy Policy (use our template)
- Correct Cookie Banner (guide)
- Plan for leaks (see data breach guide)
Further Reading
Need a GDPR audit for your online store? Check out our website maintenance services and contact us.
Need help with your website?
Our team maintains, optimises and protects your website. Pricing is agreed based on scope.
Request a quoteAbout the author
Meiko Neuman — Founder and web strategist, Kodulehe Haldus. Meiko leads the Kodulehehaldus team and has spent over a decade helping companies maintain and optimise their websites for measurable business results. He writes about website management, SEO, AEO/GEO and the commercial side of the web.