Do you process personal data in your online shop? Then you must comply with the General Data Protection Regulation (GDPR) . Many shops violate the GDPR – often unknowingly. This can be costly. Here you can find out how to check if your shop is legally compliant.
1. Is a privacy policy available and up-to-date?
Every online shop needs a complete privacy policy . It must explain exactly:
What data you collect
What you can use them for
What rights do users have?
How they can have their data deleted or changed
Do not use old texts or templates without checking them first. There are reputable generators like eRecht24.
2. Cookie Banner: Consent required before setting
Tracking and marketing cookies require consent . A correctly implemented cookie banner must:
Only set technically necessary cookies in advance.
When transferring customer data (e.g., during checkout ), you must use HTTPS . This protects against unauthorized access.
Here's how to check your certificate:
Is a lock symbol visible in the browser?
Is your certificate valid and up-to-date?
4. Enable data access and deletion
Your customers have the right to:
To obtain information about stored data
To change or delete this data
Your shop must support these functions technically and organizationally – via customer account or support request.
5. Order processing with external service providers
They use tools such as:
Newsletter software (e.g. Mailchimp)
Cloud services
payment provider
Then you need a data processing agreement (DPA) with these providers. Otherwise, you risk receiving a cease-and-desist letter.
6. Legal notice and terms and conditions: complete and up-to-date
Even though it's not directly GDPR compliant: Your shop needs a legally compliant imprint and terms and conditions . They must be clear, easily accessible, and up-to-date.
7. Form fields: Only the essentials
Collect only the data you really need. Example:
Newsletter registration: email address only
Customer account: Limit required fields
An optional feedback field? No problem. But don't make it mandatory unless absolutely necessary.
8. Data protection information regarding tracking and analysis
Are you using Google Analytics or Meta Pixel? Then you need to:
anonymize the IP address
Conclude a data processing agreement
Provide correct data protection information
Alternatives like Matomo host locally and are easier to use in compliance with GDPR.
9. Newsletter: Double Opt-In
You need verifiable consent for shipping . This means:
Double opt-in with confirmation link
Logging of consent
Unsubscribe link in every email
10. Technical and organizational measures
You must ensure that your data is protected – including internally:
Regular backups
Strong passwords and access controls
Firewall, antivirus programs
⚖️ FAQ: How to tell if your shop is GDPR compliant
The critical checkpoints that protect you from fines of up to €20 million
€ 20 million Maximum fine
72 hrs Notification deadline
4% from sales
€
What are the actual fines for GDPR violations in e-commerce?
Typical penalties for small shops:
• Missing privacy policy: €5.000-20.000
• No cookie banners: €5.000-15.000
• Newsletter Without DOI: €10.000-€30.000
Theoretically, fines can reach up to €20 million or 4% of annual revenue. In practice, small shops usually pay €5.000-€50.000 for initial violations. The most common penalties are: missing privacy policy (€5.000-€20.000), no cookie banners (€5.000-€15.000), newsletters without double opt-in (€10.000-€30.000), and failure to report a data breach (€20.000+).
📄 Does my privacy policy really need to be 20 pages long?
No, but it must be complete! Average for online shops: 8-12 pages. Mandatory information: Data controller, legal basis, all tools/services (Google Analytics, Facebook Pixel, etc.), storage period, data subject rights, recipients of the data, detailed information on cookies. Shorter versions are usually incomplete and can lead to legal action.
🍪 Cookie banners annoy customers – what is the legal minimum?
Technically necessary cookies: No banner needed. All other cookies (analytics, marketing ): Explicit consent required BEFORE cookies are set. Minimum requirement: Decline button equivalent to Accept, no pre-selection, granular selection possible. 'By continuing to browse, you agree' is illegal and expensive (€5.000-€15.000).
€10-30k risk
📊 Will Google Analytics still be possible in 2025 without consent?
No! GA4 also requires consent. ECJ ruling 2022: US data transfers problematic. Solution: Consent Mode v2, IP anonymization, data processing agreement (DPA), cookie banner. Alternative: Matomo or Plausible (GDPR-compliant without a banner). Penalty for lack of consent: €10.000-€30.000.
✉️ Newsletter subscription – is single opt-in sufficient for existing customers?
⚠️ Double opt-in is mandatory!
Documentation: Timestamp + IP address + consent text
Old lists without DOI: Register again or delete!
No! Double opt-in is mandatory, even for existing customers. Exception: Soft opt-in for similar products after purchase. Documentation is crucial: save the timestamp, IP address, and consent text. Errors can cost €10.000-€30.000. Old lists without a double opt-in (DOI): Re-register or delete!
☁️ Customer data in the cloud (Shopify, WooCommerce) – GDPR problem?
Shopify: US server ⚠️ WooCommerce: EU Hosting ✓ Without AV: €5-20k
It depends! Shopify: Standard Data Processing Agreement (DPA) is okay, but US servers are problematic. WooCommerce: Self-hosting in the EU is more secure. Important: Data processing agreement (DPA) with EVERY service (hosting, payment, shipping). Without DPAs: Fines of €5.000-€20.000 are possible.
⏱️ What rights do customers have to information and how quickly do I have to react?
Response time: 1 month (extendable to 3 months in complex cases). Rights: Access to stored data, rectification, erasure, restriction of processing, data portability. Provide free of charge! Format: Structured, common, machine-readable (PDF/CSV). Ignoring this will cost €5.000-€50.000.
👤 Does my small shop really need a data protection officer?
A data protection policy is mandatory for businesses with 20 or more employees involved in data processing, or for those processing sensitive data on a large scale. Most shops with less than €1 million in revenue don't need one. However, data protection documentation is still mandatory! A record of processing activities is required for businesses with 250 or more employees, or for those processing data regularly.
72-hour deadline!
🚨 Data breach in the shop – when do I need to inform the authorities?
Report immediately to:
• hack or data loss
• Accidental publication
• Customer data affected Penalty for failure to report: €10.000-100.000!
72 hours from the time you become aware of a risk to those affected! Hacking, data loss, accidental publication = reportable. Inform the authorities AND affected customers in cases of high risk. Always document, even if not legally required to report. Failure to report: €10.000-€100.000 fine. Example: Customer data CSV accidentally published online = report immediately!
🛠️ Which tools and plugins will make my shop more GDPR-compliant immediately?
Cookie banner: Borlabs Cookie, Cookiebot (€300-500/year). Analytics: Matomo instead of Google Analytics. Privacy policy: Händlerbund, IT law firm (€10-30/month). Data processing agreement manager for contracts. GDPR tools for WordPress. Important: Tools alone are not enough; correct configuration is crucial!
✅ GDPR quick check for your shop
🚨 Critical (Check immediately)
⚠️ Important (This Week)
✓ Optimization (This month)
⚖️ Disclaimer: This is not legal advice!
If you are unsure, always consult a specialist lawyer for data protection law.
Have you already checked your shop?
Which tools do you use for data protection and cookie management? Write it in the comments – or ask your questions. Let's learn from each other.
We use cookies to optimize our website and our service.
Functional
always active
The technical storage or access is absolutely necessary for the legitimate purpose of enabling the use of a certain service that is expressly requested by the subscriber or user, or for the sole purpose of transmitting a message via an electronic communication network.
preferences
Technical storage or access is necessary for the legitimate purpose of storing preferences that have not been requested by the subscriber or user.
Statistics
The technical storage or the access, which takes place exclusively for statistical purposes.Technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, the voluntary consent of your Internet service provider or additional records from third parties, the information stored or retrieved for this purpose cannot usually be used to identify you alone.
Marketing
The technical storage or access is required to create user profiles, to send advertising or to track the user on a website or across several websites for similar marketing purposes.
{% if featuredImage and featuredImage != "" %}
{% endif %} {% if title and title != "" %}
{{ title }}
{% endif %} {% if excerpt and excerpt != "" %}
{{ excerpt | truncatewords: 25 }}
{% endif%}
🛒
Cart
0
✓ Article added
🛒
0
Cart0,00 €
<
Ahoy! I'll keep you on course.Captain Ole here, your guide to e-commerce. I'll let you know as soon as a new article is published—directly in your browser. No newsletter, unsubscribe anytime.Yes, let me know.No thank youYou will receive notifications from now on.We will notify you as soon as a new article is published.No more messages.You will no longer receive any messages from us.Your browser is blocking notifications for this page. You can re-enable this in your browser's page settings.That didn't work. Please try again later.One moment …Unsubscribe from notificationsReceive notifications
Should I notify you when something new is published? Then I'll notify you directly in the browser — no newsletter, you can unsubscribe at any time.Yes, let me know.No thank youOne moment …Registered. I'll get in touch as soon as a new article is published.Your browser is blocking notifications for this page. You can re-enable this in the page settings.They are following my message — Captain Ole Questions about this post? Just click and we'll sort it out.
Captain Ole is an AI and can be wrong. Please do not share any personal data.
Hi! I'm Captain Ole⚓ — Your guide for e-commerce & websites. Questions about online shops, websites, SEO, or our services? I'll get you on the right track.Sorry, something went wrong — please try again. ⚓The connection was briefly interrupted — please try again. ⚓Forward the question to the teamYour email address or phone numberSendQuestion + message will go directly to our teamPrivacy PolicyHand over ⚓ The team has received your question and will get back to you by email or phone call — usually promptly on weekdays.That didn't work — please call us: 04122-4084792.Connection interrupted — 04122-4084792 will help immediately.
Enlarge the windowReduce window size againRestore default sizeDrag the header to move · Drag edges and corners to resize · Double-click for full screen · Drag to the right edge to dockDock as column on the rightSolve column again