Stradenova
La oss snakke
HjemTjenesterGuiderKontakt→

GDPR Checklist for E-commerce Stores

Complete GDPR compliance checklist for online stores. Privacy, cookies, data processing agreements, enforcement and fines.

GDPRPrivacyChecklistE-commerce

Last updated: 2026-09-28

GDPR Checklist for E-commerce Stores

Complete GDPR compliance checklist for online stores. Privacy, cookies, data processing agreements, enforcement and fines.

Introduction

The General Data Protection Regulation (GDPR) has been in force since May 2018, yet a significant number of online stores still fall short of full compliance. For Norwegian stores, GDPR is implemented through the Personal Data Act (Personopplysningsloven) and enforced by Datatilsynet, Norway’s Data Protection Authority. Non-compliance is not a theoretical risk — Datatilsynet actively investigates complaints, conducts audits, and issues substantial fines.

This guide provides a comprehensive, actionable checklist that covers every aspect of GDPR compliance for e-commerce. Whether you run a WooCommerce shop, a Magento store, or a Shopify site, these requirements apply equally.

Before diving into the checklist, you must understand that GDPR requires a lawful basis for every type of personal data you process. For e-commerce, the most relevant bases are:

  • Contract performance (Article 6(1)(b)) — Processing necessary to fulfill an order. This covers collecting name, address, email, and payment information during checkout.
  • Legal obligation (Article 6(1)(c)) — Processing required by law. Norwegian bookkeeping law requires you to retain transaction records for 5 years. Tax authorities may require specific data retention.
  • Legitimate interest (Article 6(1)(f)) — Processing necessary for your legitimate business interests, provided they do not override the individual’s rights. This can cover fraud prevention and basic analytics, but requires a documented balancing test.
  • Consent (Article 6(1)(a)) — Freely given, specific, informed, and unambiguous consent. Required for marketing emails, non-essential cookies, and any processing that does not fall under the other bases.

You must document which legal basis applies to each category of data processing in your Records of Processing Activities (ROPA).

  • Records of Processing Activities (ROPA) documented — list every category of personal data you collect, the purpose, legal basis, retention period, and any third parties it is shared with
  • Privacy policy published and easily accessible from every page (typically in the footer) — written in clear, plain language, not legalese
  • Data Processing Agreements (DPAs) signed with all processors — this includes your hosting provider, email service (Mailchimp, Klaviyo), payment gateway (Stripe, Klarna, Vipps, Dintero), analytics tools, CRM, shipping providers (Bring, PostNord), and any other service that handles personal data on your behalf
  • Data Protection Officer (DPO) appointed if required — mandatory if you process personal data on a large scale or handle special categories of data. Even if not required, designating a privacy contact person is best practice
  • Lawful basis identified and documented for each type of processing activity
  • Legitimate interest assessments conducted and documented for any processing relying on legitimate interest
  • Cookie consent banner implemented with granular consent options — users must be able to accept or reject each category (necessary, analytics, marketing) individually
  • Pre-checked boxes are prohibited — consent must be an affirmative action
  • Consent is as easy to withdraw as to give — a persistent settings link or button must allow users to change their preferences at any time
  • Consent records stored — you must be able to prove when and how consent was obtained, including the exact version of the privacy policy the user agreed to
  • No cookie walls — access to your store must not be conditional on accepting non-essential cookies (Datatilsynet and the EDPB have taken a strict stance on this)
  • Google Consent Mode v2 implemented if using Google Analytics or Google Ads — required since March 2024 for EU/EEA audience measurement
  • Third-party scripts blocked until consent — Meta Pixel, TikTok Pixel, Hotjar, and similar tools must not fire before the user gives explicit consent for marketing/analytics cookies

Checklist 3 — Customer rights (Data Subject Rights)

GDPR grants individuals specific rights that you must facilitate:

  • Right of access (Article 15) — customers can request a copy of all personal data you hold about them. You must respond within 30 days
  • Right to rectification (Article 16) — customers can correct inaccurate data. Provide this through account settings or a simple request process
  • Right to erasure / right to be forgotten (Article 17) — customers can request deletion of their data, unless you have a legal obligation to retain it (e.g., bookkeeping records)
  • Right to data portability (Article 20) — customers can request their data in a structured, machine-readable format (typically JSON or CSV)
  • Right to object (Article 21) — customers can object to processing based on legitimate interest, including profiling for marketing purposes
  • Right to restrict processing (Article 18) — in certain circumstances, customers can request that you stop processing their data while a dispute is resolved
  • Automated decision-making (Article 22) — if you use automated profiling that significantly affects customers (e.g., automated credit decisions), they have the right to human review

Implementation tip: WooCommerce has built-in tools for data export and erasure requests. Magento 2 provides a Privacy module. For Shopify, customer data requests are handled through the Shopify admin or via the mandatory GDPR webhooks.

Checklist 4 — Email marketing and newsletters

  • Explicit opt-in consent obtained before sending marketing emails — a pre-checked checkbox during checkout is NOT valid consent
  • Double opt-in implemented — the subscriber confirms their email address by clicking a verification link. This is not strictly required by GDPR but is strongly recommended and considered best practice by Datatilsynet
  • Unsubscribe link included in every marketing email — one-click unsubscribe, not a multi-step process
  • Consent separated from terms and conditions — the marketing consent checkbox must be separate from the “I agree to the terms” checkbox
  • Consent records include timestamp, source (which form), IP address, and the exact text the user agreed to
  • Segmentation and profiling documented — if you segment customers based on behavior or purchase history, document the legal basis and inform customers in your privacy policy
  • Suppression list maintained — when someone unsubscribes, add them to a suppression list to ensure they are never re-added

Checklist 5 — Data security (Article 32)

GDPR requires “appropriate technical and organizational measures” to protect personal data:

  • Encryption in transit — TLS/SSL on all pages, not just checkout
  • Encryption at rest — database encryption for sensitive fields (especially if you store payment tokens, personal identification numbers, or health data)
  • Access control — principle of least privilege for all staff and systems
  • Strong authentication — 2FA for admin accounts, strong password policies
  • Regular backups — automated, encrypted, stored separately from production
  • Incident response plan — documented procedure for detecting, containing, and reporting breaches
  • Breach notification — process in place to notify Datatilsynet within 72 hours and affected individuals “without undue delay” if the breach poses a high risk
  • Vendor security assessment — evaluate the security practices of your processors (hosting, payment, email)

Checklist 6 — International transfers

  • Data transfer mapping — identify all personal data transfers outside the EEA (common examples: US-based email providers, CDNs, analytics tools)
  • Transfer mechanisms — ensure each transfer has a valid legal mechanism: EU adequacy decision, Standard Contractual Clauses (SCCs), or Binding Corporate Rules
  • US transfers — since the EU-US Data Privacy Framework (DPF), transfers to DPF-certified US companies are permitted. Verify certification status for each provider
  • Transfer Impact Assessments (TIAs) conducted for transfers to countries without adequacy decisions and not covered by DPF

Common GDPR mistakes in e-commerce

1. Relying on cookie consent banners alone. A cookie banner does not make you GDPR-compliant. It is one small part of a much larger compliance framework.

2. Not having DPAs with all processors. Many store owners have DPAs with their hosting provider but forget about email marketing tools, chat widgets, review platforms, shipping integrations, and social media pixels.

3. Treating the privacy policy as a legal formality. Your privacy policy must accurately describe your actual data processing activities. A generic template copied from another site is insufficient and potentially misleading.

4. Ignoring data subject requests. Every request must be acknowledged and responded to within 30 days. Failure to respond is itself a GDPR violation.

5. No data retention policy. Keeping customer data indefinitely “just in case” violates the data minimization principle. Define clear retention periods for each data category and implement automated deletion or anonymization.

6. Conflating bookkeeping requirements with unlimited data retention. Norwegian bookkeeping law (Bokforingsloven) requires retention of accounting records for 5 years (3.5 years for supporting documentation). This covers transaction data, not browsing history, marketing preferences, or abandoned cart data.

Enforcement in Norway — real examples

Datatilsynet has been increasingly active in e-commerce enforcement:

  • Grindr was fined NOK 65 million (later reduced to NOK 45 million) for sharing personal data with advertising partners without valid consent
  • Ferde received a NOK 5 million fine for excessive data collection through toll road systems
  • Multiple smaller Norwegian businesses have received fines in the NOK 50,000–500,000 range for inadequate consent mechanisms, missing DPAs, and failure to respond to data subject requests

The trend is clear: enforcement is increasing, fines are growing, and e-commerce stores are firmly within Datatilsynet’s scope.

Tools and resources

  • Datatilsynet’s website (datatilsynet.no) — official guidance, templates, and a breach notification portal
  • Cookie consent platforms — Cookiebot, CookieYes, Complianz (WordPress), or Iubenda
  • DPIA templates — available from Datatilsynet and the EDPB
  • WooCommerce GDPR plugin — built-in data export/erasure tools since WooCommerce 3.4
  • Magento 2 Privacy module — handles data export and deletion requests

Conclusion

GDPR compliance is not optional, and it is not just about avoiding fines. It is about building trust with your customers. In a competitive e-commerce market, transparent data practices are a differentiator. Customers are increasingly aware of their privacy rights, and they prefer to buy from stores they trust.

Start with the checklist above. Address the highest-risk items first (consent mechanisms, DPAs, security measures), then work through the rest systematically. If you need help, we offer GDPR audits and implementation services specifically designed for online stores.


Read also

Frequently asked questions

Does GDPR apply to my online store if I am based outside the EU/EEA?+

Yes. GDPR applies to any business that offers goods or services to individuals in the EU/EEA, regardless of where the business is located. If you sell to Norwegian or European customers, you must comply with GDPR.

What is the difference between a data controller and a data processor?+

The data controller determines the purposes and means of processing personal data — this is typically you, the store owner. A data processor processes data on behalf of the controller — for example, your email marketing provider, payment gateway, or hosting company. You must have a Data Processing Agreement (DPA) with every processor.

Do I need a cookie consent banner?+

Yes. Under the ePrivacy Directive (implemented in Norway through the Electronic Communications Act / Ekomloven), you must obtain informed consent before setting non-essential cookies. This includes analytics cookies (Google Analytics), marketing cookies (Meta Pixel, Google Ads), and any third-party tracking scripts. Strictly necessary cookies (session, cart, authentication) do not require consent.

How long can I keep customer data?+

GDPR requires data minimization — you should only keep personal data for as long as it is necessary for the purpose it was collected. Order data typically must be retained for 5 years under Norwegian bookkeeping law (Bokforingsloven). Marketing consent records should be kept for as long as the consent is active, plus a reasonable period to demonstrate compliance. Inactive customer accounts should be deleted or anonymized after a defined period (commonly 24-36 months).

What are the fines for GDPR non-compliance?+

Fines can reach up to 20 million EUR or 4% of global annual turnover, whichever is higher. In practice, Datatilsynet (the Norwegian DPA) has issued fines ranging from NOK 50,000 for small violations to several million NOK for serious breaches. Even without fines, non-compliance can result in orders to stop processing data, which can effectively shut down your online store.

Can Stradenova help with GDPR compliance?+

Yes. We provide GDPR audits, privacy policy drafting, cookie consent implementation, and ongoing compliance monitoring specifically tailored for e-commerce stores. Contact us for a no-obligation assessment.

Klar for å vokse med oss?

Fortell kort hva dere vil skape, forbedre eller skalere. Dere får et konkret forslag til neste steg.

Start en samtale→