

Starting May 25, 2018, e-commerce stores are required to keep track of personal data processing activities, to erase them at the request of individuals and, in the case of large online stores, even to appoint a Data Protection Officer (DPO) .
More specifically, all online merchants and not only (all data operators) need to know what data they can collect, what obligations they have and for what purpose they can use them. Whether we are talking about sales data, billing data or employee information, in order to comply with GDPR (General Data Protection Regulation) legislation, online stores need to make sure they use data for a clear purpose without doing abuse.
GDPR or General Data Protection Regulation is the legal abridgement of EU Regulation 2016/679, designed to protect individuals with regard to the processing of personal data and their circulation.
Types of collected data
With regard to online stores, the main personal data they collect are the data of customers who buy a product or service (used for contract execution, but sometimes also for marketing), but personal data of employees can also be considered.
Except for special categories of data or so-called sensitive data (related to health, sexual life, policy orientation), there are no limitations on the types of data collected.
We can have the following categories of data collected by online merchants:
How and where the collected data can be used:
GDPR does not set goals or places where the collected data could not be used. Only the purpose has to be considered in relation to the legal basis of the processing, in order to be considered “legitimate”.
Let’s take an example: all online stores collect customers personal data to send them their products. Here the goal is the legal fulfilment of the purchase process and the delivery of the order, a goal that accordingly to GDPR is “legitimate”.
Problems may occur when the online stores want to use data for marketing, and then they need to consider: