GDPR
GDPR (General Data Protection Regulation) is the EU General Data Protection Regulation that regulates how companies collect, process and store personal data. All online stores that sell to EU customers must comply with the GDPR.
What is the GDPR?
The GDPR took effect on May 25, 2018, and is a regulation that applies throughout the EU. Its purpose is to protect citizens’ personal data and give them control over how their data is used. For online stores, this means clear rules for how you handle customer data—from email addresses and order history to tracking cookies.
What is personal data?
Personal data is any information that can identify a person, either directly or indirectly:
- Directly: Name, email address, phone number, social security number.
- Indirectly: IP addresses, cookie IDs, order numbers that can be linked to a person.
- Sensitive data: Health information, political opinions, biometric data—requires special protection.
GDPR Requirements for Online Stores
Consent
- Cookies: You must obtain explicit consent before setting marketing and analytics cookies. Necessary cookies (e.g., shopping cart cookies) do not require consent.
- Newsletter: The customer must actively sign up—no pre-checked boxes. Double opt-in is recommended.
- Documentation: You must be able to document when and how consent was given.
Privacy Policy
- Who is the data controller: Your company’s contact information.
- What data is collected: Specify all types of personal data you process.
- Purpose: Why you process the data (order processing, marketing, etc.).
- Retention Period: How long you store the data.
- Third Parties: Who you share data with (payment providers, shipping companies, analytics tools).
- Rights: The customer’s rights (right of access, right to erasure, right to data portability, etc.).
Customer rights
- Access: The customer can request to see all the data you have about them.
- Correction: The customer can request that incorrect data be corrected.
- Deletion: The customer can request that their data be deleted (“the right to be forgotten”).
- Data portability: The customer may request that their data be provided in a machine-readable format.
- Objection: The customer may object to marketing.
Fines for Violations
GDPR fines can be up to 20 million euros or 4% of global annual revenue—whichever is higher. In practice, fines for smaller online stores are somewhat lower, but the Danish Data Protection Agency actively monitors compliance and issues orders.
GDPR in Shoporama
Shoporama has several built-in features that help ensure GDPR compliance:
- Cookie Consent: Built-in cookie pop-up with granular categories (necessary, analytics, marketing). Uses interceptor technology to block cookies until consent is given.
- Google Consent Mode v2: Integrated support that controls which Google tags are activated based on the user’s cookie preferences.
- Double Opt-In: Newsletter sign-up with a confirmation email for stronger consent documentation.
- Privacy Policy Page: You can create a privacy policy page via the article system.
How to Use Shoporama
Guides that demonstrate the concept in practice
GDPR and Cookie Policies for Your Online Store
Overview of the GDPR and cookie regulations for online stores: consent before tracking, documentation, and cookie...
GDPR - Data Processing Agreement
Information about data processing agreement with Shoporama according to GDPR.
Data Processor Agreement
Guide to approving the data processing agreement with Shoporama under the GDPR.
What cookies does Shoporama set?
A complete overview of the cookies set by a Shoporama online store: name, purpose, and duration. Use this list as the...
We know online marketing in Shoporama
We've been working with online marketing ourselves for decades. As the only shop system in the country, we have spoken multiple times at conferences such as Marketingcamp, SEOday, Shopcamp, Digital Marketing, E-commerce Manager, Ecommerce Day, Web Analytics Wednesday and many more.