Does your E-commerce comply with the GDPR?
The GDPR (Regulation (EU) 2016/679), the LSSI (Law 34/2002) and the LOPDGDD regulate the processing of personal data in the e-commerce sector. The most critical aspects are:
Cookies (LSSI + GDPR): The LSSI regulates the use of cookies in information society services. Non-technical cookies (analytics, advertising, personalisation) require prior, free, specific and informed consent. Consent must be withdrawable at any time. The AEPD has published a guide on the use of cookies and the EDPB has published the Cookie Banner Taskforce report (2023).
Legal bases for profiling (Art. 6): Common bases for profiling and recommendations are: consent (Art. 6(1)(a)), legitimate interest (Art. 6(1)(f)), or contract (Art. 6(1)(b)). The choice depends on the type of profiling and the impact on the data subject.
Right to object to profiling (Art. 21): Art. 21(1) GDPR allows the data subject to object to processing based on legitimate interest, including profiling. Art. 21(2) allows objecting to processing for direct marketing.
Automated decisions (Art. 22): If the e-commerce makes automated decisions that produce legal effects or significantly affect the data subject (e.g. automated service refusal, pricing decisions with exclusionary effect), Art. 22 applies.
Special data (Art. 9): Purchase/behaviour data are not themselves special categories, but may become so if they reveal health, religion, ethnicity or other sensitive data.
Dark patterns: The use of manipulative techniques to obtain consent or influence decisions may violate the fairness principle of Art. 5(1)(a) GDPR and, if AI is used, may be a prohibited practice under Art. 5(1)(a) AI Act.
- Cookie audit — We verify LSSI and GDPR compliance in your cookie banner
- Legal basis analysis — We identify the appropriate Art. 6 basis for profiling and recommendations
- Right to object — We implement mechanisms for Art. 21 (objection to profiling and marketing)
- Art. 22 analysis — We assess whether your automated decisions require exceptions and safeguards
- Dark patterns audit — We verify your e-commerce does not use prohibited manipulative techniques
GDPR obligations for E-commerce
GDPR and LSSI obligations for an e-commerce include:
Cookies and consent:
- Categorise cookies (technical vs non-technical)
- Obtain prior, free, specific and informed consent for non-technical cookies
- Allow consent withdrawal at any time
- Do not load non-technical cookies before consent
- Cookie banner with equivalent accept/reject options
Legal bases and transparency:
- Identify the Art. 6 legal basis for each processing operation (consent, legitimate interest, contract)
- Information to the data subject (Arts. 13-14): identity, purposes, legal basis, recipients, transfers, rights
- Clear and accessible privacy policy
Data subject rights:
- Access, rectification, erasure, restriction, portability, objection (Arts. 15-21)
- Right to object to legitimate interest and profiling (Art. 21(1))
- Right to object to direct marketing (Art. 21(2))
- Right not to be subject to automated decisions (Art. 22)
Security and breaches:
- Technical and organisational measures (Art. 32): encryption, access control
- Breach notification within 72 hours (Art. 33)
Fines: Up to €20 million or 4% of global turnover (GDPR). The LSSI provides additional fines. The AEPD fined SEAT €12,000 (2024) for cookies without consent and no withdrawal possibility.
Most relevant GDPR articles for E-commerce
| Article | Topic | Application in e-commerce |
|---|---|---|
| Art. 6 | Legal bases | Consent, legitimate interest, contract for profiling |
| Art. 9 | Special categories | If data reveal health, religion, ethnicity |
| Art. 13-14 | Information | Privacy policy, cookie notice |
| Art. 21 | Objection | Objection to profiling (21(1)) and marketing (21(2)) |
| Art. 22 | Automated decisions | Automated refusal, exclusionary pricing |
| Art. 32 | Security | Encryption, access control, payments |
| Art. 5(1)(a) | Fairness | Prohibition of dark patterns |
| LSSI | Cookies | Prior, free, specific consent, withdrawal |
Real enforcement cases in e-commerce
- AEPD — SEAT, €12,000 (2024) — Non-technical cookies without consent and no consent withdrawal (PS/00284/2024). Source: Confilegal
- AEPD — Guide on the use of cookies: AEPD
- AEPD — Guide to safe online shopping: AEPD
- AEPD — Decalogue for privacy policies: AEPD
- EDPB — Guidelines 8/2020 on social media targeting: EDPB
- EDPB — Guidelines 05/2020 on consent: EDPB
- EDPB — Cookie Banner Taskforce Report (2023): EDPB
GDPR compliance checklist for E-commerce
- Categorise cookies (technical vs non-technical)
- Implement cookie banner with equivalent accept/reject options
- Do not load non-technical cookies before consent
- Allow cookie consent withdrawal at any time
- Identify the Art. 6 legal basis for profiling and recommendations
- Draft clear privacy policy (Arts. 13-14)
- Implement data subject rights mechanisms (Arts. 15-21)
- Implement right to object to profiling (Art. 21(1))
- Implement right to object to marketing (Art. 21(2))
- Assess whether there are Art. 22 automated decisions
- Verify no dark patterns are used (Art. 5(1)(a))
- Implement security measures (Art. 32): encryption, payments
- Establish 72-hour breach notification procedure (Art. 33)
- Coordinate with AEPD in inspections and complaints
Related resources
- GDPR Hub — Resource centre on the GDPR
- GDPR Glossary — 45+ key terms with article references
- AI Act vs GDPR — Comparative table of both regulations
- GDPR Compliance Checker — Self-assess your compliance
- AI & Data Regulation Service — Integrated advisory
- AI Act for E-commerce — Sectoral AI Act guide for e-commerce
This page is general information, not legal advice. Each data processing operation must be analysed individually. Fines cited are based on public AEPD decisions.