GB EN IT IT ES ES
GDPR · E-commerce & online shops
⚠ Consent & cookies

GDPR for e-commerce.
Your trackers fire before anyone says yes.

An online shop processes customer and payment data at scale — names, addresses, orders, card details — plus marketing, cookies and analytics. Most shops fire Google Analytics and the Meta Pixel before anyone consents, send marketing with no valid opt-in, and pipe customer data into US tools with no transfer safeguards. Convenient, and a textbook GDPR breach waiting to happen.

€20M
or 4% turnover — max fine
72h
to report a breach to the authority
Consent
required BEFORE any tracking fires
SCCs
needed for international data transfers

What most shops
are getting wrong.

None of this is malicious — it's just how online stores are set up by default. But each one is a real GDPR gap a customer, a competitor or a regulator can act on.

🍪

Trackers load before consent

The cookie banner is cosmetic: Google Analytics and the Meta Pixel fire on page load, before the visitor clicks anything. That's tracking without valid consent — one of the most reported issues in e-commerce.

📣

Marketing with no valid consent

Customers get added to newsletters and promo lists just for buying, with no freely given consent and no easy, working unsubscribe in every email.

💳

Storing full card data

Card numbers saved in the shop database or order records instead of being handled by a compliant payment processor — a serious breach risk you don't need to carry.

🔑

Weak access to the back office

The admin / store dashboard has no multi-factor authentication and shared logins passed around the team — the single richest target in your whole setup.

🔗

No DPAs with your processors

No data-processing agreements with Stripe/PayPal, Mailchimp, Google Analytics or your hosting provider — all of whom process your customers' data on your behalf.

🌍

Data kept forever, sent to the US

Customer records kept indefinitely with no retention rule, and US tools (analytics, email, hosting) used with no transfer safeguards such as Standard Contractual Clauses.

⚠️

It only takes one. A cookie/consent complaint, a customer asking "what data do you hold on me?", or a single breach of your store database — any of these can turn into a complaint to the data protection authority. The fix is far cheaper than the incident.

How we make your
shop compliant — for real.

We don't hand you a policy and leave. We change how data actually flows through your store, with tools your team and your customers will actually use.

🍪

Consent & cookie management

A consent solution that genuinely blocks Google Analytics, the Meta Pixel and other non-essential trackers until the visitor actively opts in — not just a banner over the top.

Valid marketing consent & opt-out

Clean, documented consent capture at checkout and signup, plus a working unsubscribe in every email — so your marketing stays lawful.

💳

Remove card storage

We take full card data off your systems and move you to a PCI-compliant processor flow (Stripe/PayPal) that tokenises payments so sensitive data never touches your server.

🔑

MFA & admin access control

Multi-factor authentication and named, role-based logins on the store back office — no more shared credentials on your most valuable target.

📄

DPAs with your stack

Data-processing agreements with your payment, marketing, analytics and hosting providers — so your whole supply chain is covered.

🌍

Retention, transfers & breach plan

A retention schedule with automated clean-up, Standard Contractual Clauses (SCCs) for international transfers, and a simple breach procedure with the records an authority will ask for.

A path that fits
how online shops actually work.

01

Data-flow audit

We follow a real order end-to-end: which cookies fire, where customer and payment data goes, and into which tools and countries.

02

Gap analysis

We flag the non-compliant flows and the concrete risks — prioritised, in plain language, not a 90-page report.

03

Remediation

We set up consent that blocks trackers, remove card storage, add MFA, and put DPAs, retention and SCCs in place.

04

Train & document

A short team briefing, a breach plan and the records of processing — so it stays compliant day to day.

← All GDPR sectors

GDPR for online shops,
answered.

The questions shop owners ask us most.

Does my cookie banner need to block trackers before consent?+
Yes. Analytics and advertising cookies — Google Analytics, the Meta Pixel and similar — must not load or fire until the visitor has actively consented. A banner that sets these cookies on page load, or treats scrolling as acceptance, is not valid consent and is one of the most reported issues in e-commerce. We set up a consent solution that genuinely blocks non-essential trackers until the user opts in.
Do I need consent for marketing emails?+
In almost all cases, yes. Adding customers to a newsletter just because they bought something, or importing old lists, generally needs valid, freely given consent and a clear, working unsubscribe in every email. A narrow soft opt-in can exist for similar products to your own existing customers, but it's limited and still requires an easy opt-out. We set up compliant consent capture and opt-out.
Can I store customers' card details?+
You should not store full card data on your own systems. Card numbers belong with a PCI-DSS compliant payment processor such as Stripe or PayPal, which tokenises payments so the sensitive data never touches your server. Storing full card numbers yourself creates a serious breach risk and heavy compliance obligations. We remove any card storage and move you to a compliant processor flow.
Is it a problem to use US tools (Analytics, email, hosting)?+
Not automatically, but it has to be done correctly. Tools like Google Analytics, US email platforms and US hosting transfer personal data outside the EU, so you need a valid transfer mechanism — typically Standard Contractual Clauses (SCCs) — plus a DPA and an assessment of the safeguards. We map where your customer data actually goes and put the right agreements and SCCs in place.
E-commerce · Free GDPR assessment

See exactly where your shop is exposed.

Tell us what tools your store runs today. We'll show you the gaps and the fix — response within 4 working hours, no commitment.

Free GDPR Check → Free GDPR Assessment →