Glossary
/
gdpr-rgpd
E-commerce GDPR: definition of personal data protection, customer rights, Shopify, cookies, legal bases, and key points for EU merchants.
Updated on
June 4, 2026
The GDPR (General Data Protection Regulation) is the European framework that regulates the collection, use, and retention of personal data of European Union residents. For an e-commerce merchant, it applies as soon as you process names, emails, addresses, order history, or marketing consents, including via Shopify, Klaviyo, or ad pixels. It is complementary to cookie rules (tracking cookie) and T&Cs.
Summary
Definition of GDPR in e-commerce
Having entered into force on May 25, 2018, the GDPR harmonizes data protection in the EU. Personal data is any information that allows for the identification of an individual (directly or indirectly): email, IP, postal address, order number linked to a name.
Key actors:
The concept is best understood by distinguishing several components: Data controller (data controller): you, the merchant, who decides why and how the data is used; Processor (processor): service provider who processes on your behalf (Shopify, Klaviyo, carrier, helpdesk); Data subject: the customer or visitor whose data is being processed.
Typical e-commerce data concerned:
The concept is best understood by distinguishing several components: Identity and contact (name, email, telephone); Delivery and billing addresses; Order history, payments (without storing full card numbers); Email/SMS marketing consents; Browsing data if linked to a profile (cookies, customer account); Customer service exchanges, chat, support tickets.
Useful distinctions:
The concept is best understood by distinguishing several components: GDPR vs tracking cookie: the GDPR governs all data processing; cookies also fall under the ePrivacy directive / CNIL guidelines on trackers; GDPR vs T&C: GDPR = privacy; T&C = commercial contract (sales, returns); Personal data vs anonymized data: anonymized data is outside the scope of the GDPR if re-identification is impossible; GDPR vs PCI-DSS: PCI concerns card payment security, which is not the same standard; Legal basis vs consent: consent is only one of the possible bases (see section 3).
Why the GDPR concerns all online stores
Even a small Shopify store processes personal data with every order. The GDPR is not reserved for large groups: it targets any player targeting European customers.
Its effects can be seen at several levels: Customer trust: a clear privacy policy reassures before purchase; Sanctions: administrative fines possible in the event of serious breach (amounts capped by the text); Legal marketing: email/SMS without a legal basis = spam and risk of complaint; Third-party apps: each tool (ESP, chatbot, reviews) processes data for you; Export outside the EU: international sales = check transfers (United States, contractual clauses); Customer base: data governance in the customer database; Reputation: leakage or poor management of erasure requests harms the brand.
GDPR compliance is a framework of points of attention: minimize data, document uses, respond to people's rights. Legal advice remains recommended depending on your volume, your markets and your specific processing.
Principles, legal bases and customer rights
GDPR fundamental principles: lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, accountability (accountability).
Common legal bases in e-commerce:
The elements to observe are as follows: Performance of a contract: processing an order, delivery, billing, customer service related to the purchase; Consent: newsletter, marketing cookies, promotional SMS (free, specific, revocable); Legitimate interest: fraud prevention, website security (case-by-case analysis, right to object); Legal obligation: accounting retention, invoices.
Customer rights to be provided for:
The elements to observe are as follows: Access: copy of the data held; Rectification: correcting an incorrect address; Erasure ("right to be forgotten"), subject to legal exemptions; Portability: structured export (e.g., CSV); Objection: refusing marketing or certain profiling; Restriction: temporary freezing of processing dog during a dispute.
In practice, French store "BioPantry", 2,000 orders/month. Customer requests erasure via customer service email. Verifications: active order in progress (no), accounting obligation to retain invoices for 10 years (retention restricted to legal fields). Deletion of Klaviyo marketing profile + partial anonymization of Shopify order according to internal procedure. Response within 30 days with confirmation. Marketing cookie consent managed via CMP; promotional email only if checkout opt-in is checked.
GDPR and Shopify
Shopify acts as a data processor for shop hosting and customer data (Shopify Help Center). You remain responsible for marketing choices, installed apps, and displayed policies.
In Shopify, this is notably reflected by: Privacy Policy: dedicated page (identity of controller, purposes, retention periods, rights, processors); Customer Privacy: consent API, cookie preference management; Customer export / deletion: from admin customer profile or custom request; Marketing consent: email opt-in recorded on customer profile; Apps: check DPA (Data Processing Agreement) with Klaviyo, Gorgias, etc; Checkout: marketing consent checkbox separate from T&C (checkout); Chatbot / AI: conversations may contain personal data; inform the user and limit retention.
Merchant checklist:
The workflow can be understood as follows: first Draft or have the privacy policy + legal notices validated; then Install a CMP if using analytics/ad cookies (EU); next Document the processing register (CNIL template for SMEs); after that Internal procedure for GDPR requests (dedicated email, 1-month deadline); finally List processors and sign DPAs if offered; then Train the support team: do not ask for unnecessary data via chat.
chat.
Points of attention for responsible data management
The points of vigilance notably relate to: Minimize collection: strictly useful checkout fields; Separate transactional and marketing: separate legal basis (email campaigns); Cookie consent before non-essential pixels; Retention periods: define how long to keep inactive prospects; Security: strong admin passwords, restricted access, Shopify 2FA; Transparency: explain why you collect the pop-up email; Log consents: proof of marketing opt-in.
To watch out for:
The points of vigilance notably relate to: Pre-checked marketing box at checkout (invalid consent); Importing a purchased email list without a legal basis; Generic privacy policy not adapted to your apps; Ignoring deletion requests > 30 days; Installing 20 apps without checking where customer data goes; Confusing T&Cs and privacy policy (two separate documents); Storing card numbers or passwords in clear text (prohibited).
In brief
To remember: GDPR = EU regulation on personal data protection; Merchant = controller; Shopify/apps = processors; Legal bases: contract, consent, legitimate interest, legal obligation; Customer rights: access, rectification, erasure, portability, objection; Distinct from cookies (ePrivacy), T&C, PCI-DSS; Shopify: privacy policy, Customer Privacy, consent marketing, customer export.
Associated terms, FAQ, and useful resources
Associated Terms
Tracking Cookie: trackers subject to consent in the EU.
Customer database: data subject to the GDPR.
T&C: sales contract, distinct from privacy.
Customer account: personal data space.
Customer support: data processing via after-sales support tickets.
FAQ
RGPD and GDPR: the same thing?
Yes. GDPR (General Data Protection Regulation) is the English name for the French RGPD. Same European regulation.
Does the GDPR apply if my shop is outside the EU?
If you sell to or target EU resident customers, the GDPR generally applies to their data, even if your business is based in the United States or elsewhere. Check with an advisor depending on your structure.
Can I send emails without explicit consent?
In B2C in the EU, email prospecting generally requires prior consent or, in certain countries, a very regulated "soft opt-in" exception (existing customer, similar products). In practice, explicit opt-in at checkout or via pop-up remains the safest path.
Is Shopify GDPR compliant on my behalf?
Shopify provides tools and contractually acts as a processor, but overall compliance depends on your apps, pixels, emails, retention periods, and responses to individuals' rights. You remain the data controller.
Going further
Sources: Shopify Help Center (Privacy), EU Regulation 2016/679 (GDPR), CNIL (SME guides, cookies). This content is informative, not legal advice.

Enzo
June 4, 2026





