GDPR
GDPR (General Data Protection Regulation) is the EU General Data Protection Regulation that regulates how companies collect, process and store personal data. All online stores that sell to EU customers must comply with the GDPR.
What is GDPR?
The GDPR came into force on May 25, 2018 and is an EU-wide regulation. Its purpose is to protect citizens' personal data and give them control over how their data is used. For online stores, this means clear rules on how you handle customer data - from email addresses and order history to tracking cookies.
What is personal data?
Personal data is any information that can identify a person, directly or indirectly:
- Directly: Name, email address, phone number, social security number.
- Indirect: IP addresses, cookie IDs, order numbers that can be linked to a person.
- Sensitive data: Health information, political opinions, biometric data - requires special protection.
GDPR requirements for webshops
Consent
- Cookies: You need explicit consent before setting marketing and statistics cookies. Necessary cookies (e.g. basket cookies) do not require consent.
- Newsletters: Customer must actively opt-in - no pre-ticked boxes. Double opt-in is recommended.
- Documentation: You must be able to document when and how consent was given.
Privacy policy
- Who is the data controller: Your company contact details.
- What data is collected: Specify all types of personal data you process.
- Purpose: Why you process the data (order management, marketing, etc.).
- Storage period: How long you store the data.
- Third parties: Who you share data with (payment providers, shipping companies, analytics tools).
- Rights: Customer rights (access, deletion, data portability, etc.).
Customer rights
- Access: The customer can ask to see any data you have about them.
- Rectification: The customer can ask to have incorrect data corrected.
- Erasure: The customer can ask to have their data deleted ("right to be forgotten").
- Data portability: The customer can ask for their data to be provided in a machine-readable format.
- Objection: The customer can object to marketing.
Fines for non-compliance
GDPR fines can be up to €20 million or 4% of global annual turnover, whichever is higher. In practice, fines for smaller webshops are somewhat lower, but the Danish Data Protection Agency actively monitors and issues injunctions.
GDPR in Shoporama
Shoporama has several built-in features to help with GDPR compliance:
- Cookie Consent: Built-in cookie popup with granular categories (necessary, statistics, marketing). Uses interceptor technology to block cookies before consent is given.
- Google Consent Mode v2: Integrated support that controls which Google tags are enabled based on the user's cookie choice.
- Double opt-in: Newsletter sign-up with confirmation email for stronger consent documentation.
- Privacy policy page: You can create a privacy policy page via the article system.
We know online marketing in Shoporama
We've been working with online marketing ourselves for decades. As the only shop system in the country, we have spoken multiple times at conferences such as Marketingcamp, SEOday, Shopcamp, Digital Marketing, E-commerce Manager, Ecommerce Day, Web Analytics Wednesday and many more.