GDPR · E-commerce

GDPR for E-commerce: Cookies, Profiling and Automated Decisions

The GDPR and the LSSI regulate cookies, profiling and automated decisions in e-commerce. Learn the legal bases, the right to object to profiling and AEPD fines.

Does your E-commerce comply with the GDPR?

The GDPR (Regulation (EU) 2016/679), the LSSI (Law 34/2002) and the LOPDGDD regulate the processing of personal data in the e-commerce sector. The most critical aspects are:

Cookies (LSSI + GDPR): The LSSI regulates the use of cookies in information society services. Non-technical cookies (analytics, advertising, personalisation) require prior, free, specific and informed consent. Consent must be withdrawable at any time. The AEPD has published a guide on the use of cookies and the EDPB has published the Cookie Banner Taskforce report (2023).

Legal bases for profiling (Art. 6): Common bases for profiling and recommendations are: consent (Art. 6(1)(a)), legitimate interest (Art. 6(1)(f)), or contract (Art. 6(1)(b)). The choice depends on the type of profiling and the impact on the data subject.

Right to object to profiling (Art. 21): Art. 21(1) GDPR allows the data subject to object to processing based on legitimate interest, including profiling. Art. 21(2) allows objecting to processing for direct marketing.

Automated decisions (Art. 22): If the e-commerce makes automated decisions that produce legal effects or significantly affect the data subject (e.g. automated service refusal, pricing decisions with exclusionary effect), Art. 22 applies.

Special data (Art. 9): Purchase/behaviour data are not themselves special categories, but may become so if they reveal health, religion, ethnicity or other sensitive data.

Dark patterns: The use of manipulative techniques to obtain consent or influence decisions may violate the fairness principle of Art. 5(1)(a) GDPR and, if AI is used, may be a prohibited practice under Art. 5(1)(a) AI Act.

  • Cookie audit — We verify LSSI and GDPR compliance in your cookie banner
  • Legal basis analysis — We identify the appropriate Art. 6 basis for profiling and recommendations
  • Right to object — We implement mechanisms for Art. 21 (objection to profiling and marketing)
  • Art. 22 analysis — We assess whether your automated decisions require exceptions and safeguards
  • Dark patterns audit — We verify your e-commerce does not use prohibited manipulative techniques

GDPR obligations for E-commerce

GDPR and LSSI obligations for an e-commerce include:

Cookies and consent:

  • Categorise cookies (technical vs non-technical)
  • Obtain prior, free, specific and informed consent for non-technical cookies
  • Allow consent withdrawal at any time
  • Do not load non-technical cookies before consent
  • Cookie banner with equivalent accept/reject options

Legal bases and transparency:

  • Identify the Art. 6 legal basis for each processing operation (consent, legitimate interest, contract)
  • Information to the data subject (Arts. 13-14): identity, purposes, legal basis, recipients, transfers, rights
  • Clear and accessible privacy policy

Data subject rights:

  • Access, rectification, erasure, restriction, portability, objection (Arts. 15-21)
  • Right to object to legitimate interest and profiling (Art. 21(1))
  • Right to object to direct marketing (Art. 21(2))
  • Right not to be subject to automated decisions (Art. 22)

Security and breaches:

  • Technical and organisational measures (Art. 32): encryption, access control
  • Breach notification within 72 hours (Art. 33)

Fines: Up to €20 million or 4% of global turnover (GDPR). The LSSI provides additional fines. The AEPD fined SEAT €12,000 (2024) for cookies without consent and no withdrawal possibility.

Most relevant GDPR articles for E-commerce

ArticleTopicApplication in e-commerce
Art. 6Legal basesConsent, legitimate interest, contract for profiling
Art. 9Special categoriesIf data reveal health, religion, ethnicity
Art. 13-14InformationPrivacy policy, cookie notice
Art. 21ObjectionObjection to profiling (21(1)) and marketing (21(2))
Art. 22Automated decisionsAutomated refusal, exclusionary pricing
Art. 32SecurityEncryption, access control, payments
Art. 5(1)(a)FairnessProhibition of dark patterns
LSSICookiesPrior, free, specific consent, withdrawal

Real enforcement cases in e-commerce

  • AEPD — SEAT, €12,000 (2024) — Non-technical cookies without consent and no consent withdrawal (PS/00284/2024). Source: Confilegal
  • AEPD — Guide on the use of cookies: AEPD
  • AEPD — Guide to safe online shopping: AEPD
  • AEPD — Decalogue for privacy policies: AEPD
  • EDPB — Guidelines 8/2020 on social media targeting: EDPB
  • EDPB — Guidelines 05/2020 on consent: EDPB
  • EDPB — Cookie Banner Taskforce Report (2023): EDPB

GDPR compliance checklist for E-commerce

  • Categorise cookies (technical vs non-technical)
  • Implement cookie banner with equivalent accept/reject options
  • Do not load non-technical cookies before consent
  • Allow cookie consent withdrawal at any time
  • Identify the Art. 6 legal basis for profiling and recommendations
  • Draft clear privacy policy (Arts. 13-14)
  • Implement data subject rights mechanisms (Arts. 15-21)
  • Implement right to object to profiling (Art. 21(1))
  • Implement right to object to marketing (Art. 21(2))
  • Assess whether there are Art. 22 automated decisions
  • Verify no dark patterns are used (Art. 5(1)(a))
  • Implement security measures (Art. 32): encryption, payments
  • Establish 72-hour breach notification procedure (Art. 33)
  • Coordinate with AEPD in inspections and complaints

This page is general information, not legal advice. Each data processing operation must be analysed individually. Fines cited are based on public AEPD decisions.

Featured Services

Frequently Asked Questions

Which cookies require consent?

The LSSI distinguishes between technical cookies (no consent required) and non-technical cookies (consent required). Technical cookies include: those necessary for functioning, user preferences, and session cookies. Non-technical cookies include: analytics, advertising, personalisation, social media. Non-technical cookies require prior, free, specific and informed consent, and consent must be withdrawable at any time.

Which legal basis applies to profiling in e-commerce?

Common bases are: consent (Art. 6(1)(a)) if the user explicitly accepts profiling; legitimate interest (Art. 6(1)(f)) if profiling is necessary to personalise the experience and does not disproportionately invade privacy; contract (Art. 6(1)(b)) if profiling is necessary to execute a contract (e.g. product recommendations). The choice depends on the type of profiling and the impact on the data subject. The data subject may object to legitimate interest (Art. 21(1)).

What is the right to object to profiling?

Art. 21(1) GDPR allows the data subject to object to processing based on legitimate interest (Art. 6(1)(f)), including profiling. If the data subject objects, the controller must stop processing the data unless it demonstrates a prevailing legitimate interest or that the processing is necessary for the exercise of a right. Art. 21(2) allows objecting to processing for direct marketing, without justification.

When is an automated decision under Art. 22?

Art. 22 GDPR applies when the e-commerce makes decisions based solely on automated processing (including profiling) that produce legal effects or significantly affect the data subject. Examples: automated service refusal, pricing decisions with exclusionary effect, automatic selection for offers. In that case, an exception is required (contract, legal authorisation, explicit consent) and additional safeguards (human intervention, information, right to express a point of view).

What fines has the AEPD imposed in e-commerce?

The AEPD fined SEAT €20,000 (reduced to €12,000) in 2024 for deploying non-technical cookies without consent and no consent withdrawal (PS/00284/2024). The AEPD has also published guides on cookies, safe online shopping and privacy policies. The EDPB has published the Cookie Banner Taskforce report (2023) with recommendations to improve cookie banner implementation.

Are purchase data special categories under Art. 9?

Not per se. Purchase and behaviour data (products viewed, purchased, time on page) are not special categories under Art. 9 GDPR. However, they may become special categories if they reveal information about health, religion, ethnicity, sexual orientation or other sensitive data. For example, if a health product e-commerce collects data revealing medical conditions, Art. 9 applies and a specific legal basis is required.

Are dark patterns prohibited in e-commerce?

The use of manipulative techniques (dark patterns) to obtain consent or influence decisions may violate the fairness principle of Art. 5(1)(a) GDPR (lawfulness, fairness and transparency). If dark patterns use AI, they may be a prohibited practice under Art. 5(1)(a) AI Act (subliminal manipulation). The AEPD and the EDPB have published guidance on valid consent and cookies, requiring that consent be free and not induced.

Which authorities supervise the GDPR in e-commerce in Spain?

The AEPD supervises the GDPR and the LSSI in Spain. At European level, the EDPB coordinates enforcement between Member States. The AEPD has published guides on cookies, safe online shopping, and a decalogue for privacy policies. The EDPB has published guidelines on social media targeting and the Cookie Banner Taskforce report.

Contact

If you want to talk about intellectual property protection, AI and data regulation, startup formation or international expansion, write us a few lines and schedule a conversation with the team.

A2 Estudio Legal
María de Molina, 41
28006 Madrid · Spain

Tel: +34 913 451 406
Email: info@a2estudiolegal.com

Tell us briefly about your project, development stage and target countries. We will respond with the next steps to start working together.

Let's talk
Contact us