Online stores: collecting personal data from GDPR perspective

How can we help you to implement GDPR correctly
May 20, 2018
What should online stores be careful about in order not to risking fines after GDPR enters into force
June 7, 2018

 

Starting May 25, 2018, e-commerce stores are required to keep track of personal data processing activities, to erase them at the request of individuals and, in the case of large online stores, even to appoint a Data Protection Officer (DPO) .

 

More specifically, all online merchants and not only (all data operators) need to know what data they can collect, what obligations they have and for what purpose they can use them. Whether we are talking about sales data, billing data or employee information, in order to comply with GDPR (General Data Protection Regulation) legislation, online stores need to make sure they use data for a clear purpose without doing abuse.

GDPR or General Data Protection Regulation is the legal abridgement of EU Regulation 2016/679, designed to protect individuals with regard to the processing of personal data and their circulation.

Types of collected data

With regard to online stores, the main personal data they collect are the data of customers who buy a product or service (used for contract execution, but sometimes also for marketing), but personal data of employees can also be considered.

Except for special categories of data or so-called sensitive data (related to health, sexual life, policy orientation), there are no limitations on the types of data collected.

We can have the following categories of data collected by online merchants:

  • Consumers data obtained as a result of an order
  • Data of people who subscribed to the newsletter
  • Web site visitors data
  • Data of Facebook page visitors
  • Employees data
  • Customers data stored in a CRM
  • Data of job candidates

How and where the collected data can be used:

GDPR does not set goals or places where the collected data could not be used. Only the purpose has to be considered in relation to the legal basis of the processing, in order to be considered “legitimate”.

Let’s take an example: all online stores collect customers personal data to send them their products. Here the goal is the legal fulfilment of the purchase process and the delivery of the order, a goal that accordingly to GDPR is “legitimate”.

Problems may occur when the online stores want to use data for marketing, and then they need to consider:

  • how they define this new goal;
  • what is the legal basis for it (because in this case the processing is NOT required for fulfillment of a contract);
  • what other obligations they should have (information, data retention duration, etc.).