GDPR
GDPR is the EU’s data privacy law governing how stores collect, use, and delete personal data of people in the EU.
What GDPR is
GDPR, the General Data Protection Regulation, is the EU’s data privacy law: rules on how personal data of people in the EU is collected, used, stored, and deleted, applying to any store serving them, wherever the store sits.
Why GDPR matters for stores
Ecommerce runs on personal data, emails, addresses, order histories, behavior, and GDPR sets the terms: a lawful basis for each use, consent that’s real, and rights customers can actually exercise. Enforcement carries fines scaled to make ignoring it irrational.
What compliance looks like day to day
- Consent collected properly: unticked boxes, granular choices
- A privacy policy saying what’s collected and why, truthfully
- Access and deletion requests handled within deadlines
- Processor agreements with the tools touching customer data
Frequently asked questions
Does GDPR apply to stores outside the EU?
Selling to or tracking people in the EU, yes: the law follows the data subject, not the company’s address. Many non-EU stores comply globally rather than run two regimes.
Is marketing email allowed under GDPR?
With a proper basis: consent freely given, or the existing-customer exception for similar products with easy opt-out. Purchased lists and pre-ticked boxes are exactly what the law ended.