GDPR for stores: customer data, marketing and retention
How data protection applies to an online shop: what you hold, what you may do with it, how long to keep it and how to handle customer requests.
The short answer
An online store holds a great deal of personal data: names, delivery and billing addresses, contact details, order histories, payment metadata, browsing and cart behaviour, support conversations, reviews, returns, and whatever marketing profiles the connected apps have built. Each purpose needs a basis and a retention period, and the two main groups behave differently. Order and invoice data is processed to perform the contract and then retained because tax law requires it, which in the Netherlands generally means seven years for business administration; that obligation takes precedence over a deletion request for those records. Everything else, browsing behaviour, marketing profiles, support history, abandoned carts, has a shorter retention you set and apply. Marketing, including abandoned cart emails and audience building, is a separate purpose needing its own basis, usually consent, captured properly. And because a store’s data lives across the platform and a dozen apps, handling an access or deletion request means working through the whole app list, which is why that list is also your data map.
What a store holds and how to treat it
| Data | Purpose | Basis | Retention |
|---|---|---|---|
| Order and invoice records | Performing and evidencing the sale | Contract, then legal obligation | Statutory period, generally seven years |
| Delivery addresses | Fulfilment | Contract | With the order record |
| Payment metadata | Reconciliation and disputes | Contract; provider holds card data | Per provider and accounting rules |
| Customer account | Providing the account | Contract | While the account exists, plus a defined period |
| Abandoned carts | Marketing | Consent, or the customer exception where it applies | Short; days to weeks |
| Newsletter subscription | Marketing | Consent with records | Until withdrawn plus a margin |
| Browsing and analytics | Understanding the store | Consent where identifiers are used | Short |
| Advertising audiences | Marketing | Consent | Per platform; review regularly |
| Support conversations | Serving the customer | Contract or legitimate interest | Defined; often one to two years |
| Reviews | Publication with consent | Consent | Until withdrawn |
| Returns and claims | Handling the case | Contract, legal obligation | With the order or the claim period |
Running a store compliantly
- Map the data across every app, using the app list; each app is a processor with its own store of data.
- Collect processing agreements from the platform and every app.
- Set retention per category and apply it, including in the apps.
- Separate marketing from transactional in both consent and systems.
- Capture marketing consent properly at sign-up and at checkout, unticked and specific.
- Write the response procedure for access and deletion requests, covering every system.
- Check the abandoned cart flow’s basis and its wording.
- Publish an accurate privacy statement built from the map.
- Review the app list quarterly, removing apps you no longer use, which also removes their data.
Marketing without complaints
The complaints that reach supervisory authorities about shops are almost always about marketing: messages nobody remembers agreeing to, unsubscribes that do not work, and abandoned cart emails to people who only typed an address. The fixes are simple: capture consent explicitly with clear wording, keep the record, make unsubscribing one click and permanent, honour it across every system including the apps, and check that the abandoned cart flow has a basis. A store that does those four things rarely hears from a regulator.
What this means for you
A store’s data splits into records you must keep for tax and warranty purposes and everything else, which needs a purpose, a basis and a shorter retention you actually apply. Treat marketing as a separate purpose with real consent, map data across every app because each is a processor, keep the app list short, and have a procedure for access and deletion that covers every system. This is general information rather than legal advice.
Frequently asked questions
How long do we keep order data?
Order and invoice records fall under tax retention rules, which in the Netherlands are generally seven years for business administration. That is a legal obligation to retain, so it overrides a deletion request for those records. Data beyond what the tax and warranty purposes require, such as browsing history, marketing profiles and support chat, has its own shorter retention that you set and apply. Separating the two is the practical task.
Can we send abandoned cart emails?
It is a marketing communication to someone who has not completed a purchase, so it needs a basis. Where the person is an existing customer and the message concerns similar goods, the limited customer exception may apply with an easy objection route. Otherwise consent is the safe basis, captured at the point the email address is entered, with clear wording. Sending to anyone who typed an address into a checkout field without agreeing to be contacted is where complaints come from.
What happens when a customer asks us to delete their data?
You assess it across every system: the store platform, the email tool, the CRM, the support desk, the review app, the analytics, the accounting system and any exports. Records you must keep for tax purposes are retained with an explanation; the rest is deleted or anonymised. Respond within one month. The reason this is difficult for stores is the app sprawl, which is why the app list doubles as your data map.
Sources
- EUR-Lex: Regulation (EU) 2016/679 (accessed 2026-09-12)
- Belastingdienst: Hoe lang moet u uw administratie bewaren (accessed 2026-09-12)