GDPR for stores: customer data, marketing and retention

How data protection applies to an online shop: what you hold, what you may do with it, how long to keep it and how to handle customer requests.

4 minread 868words last updated

The short answer

An online store holds a great deal of personal data: names, delivery and billing addresses, contact details, order histories, payment metadata, browsing and cart behaviour, support conversations, reviews, returns, and whatever marketing profiles the connected apps have built. Each purpose needs a basis and a retention period, and the two main groups behave differently. Order and invoice data is processed to perform the contract and then retained because tax law requires it, which in the Netherlands generally means seven years for business administration; that obligation takes precedence over a deletion request for those records. Everything else, browsing behaviour, marketing profiles, support history, abandoned carts, has a shorter retention you set and apply. Marketing, including abandoned cart emails and audience building, is a separate purpose needing its own basis, usually consent, captured properly. And because a store’s data lives across the platform and a dozen apps, handling an access or deletion request means working through the whole app list, which is why that list is also your data map.

What a store holds and how to treat it

DataPurposeBasisRetention
Order and invoice recordsPerforming and evidencing the saleContract, then legal obligationStatutory period, generally seven years
Delivery addressesFulfilmentContractWith the order record
Payment metadataReconciliation and disputesContract; provider holds card dataPer provider and accounting rules
Customer accountProviding the accountContractWhile the account exists, plus a defined period
Abandoned cartsMarketingConsent, or the customer exception where it appliesShort; days to weeks
Newsletter subscriptionMarketingConsent with recordsUntil withdrawn plus a margin
Browsing and analyticsUnderstanding the storeConsent where identifiers are usedShort
Advertising audiencesMarketingConsentPer platform; review regularly
Support conversationsServing the customerContract or legitimate interestDefined; often one to two years
ReviewsPublication with consentConsentUntil withdrawn
Returns and claimsHandling the caseContract, legal obligationWith the order or the claim period

Running a store compliantly

  1. Map the data across every app, using the app list; each app is a processor with its own store of data.
  2. Collect processing agreements from the platform and every app.
  3. Set retention per category and apply it, including in the apps.
  4. Separate marketing from transactional in both consent and systems.
  5. Capture marketing consent properly at sign-up and at checkout, unticked and specific.
  6. Write the response procedure for access and deletion requests, covering every system.
  7. Check the abandoned cart flow’s basis and its wording.
  8. Publish an accurate privacy statement built from the map.
  9. Review the app list quarterly, removing apps you no longer use, which also removes their data.

Marketing without complaints

The complaints that reach supervisory authorities about shops are almost always about marketing: messages nobody remembers agreeing to, unsubscribes that do not work, and abandoned cart emails to people who only typed an address. The fixes are simple: capture consent explicitly with clear wording, keep the record, make unsubscribing one click and permanent, honour it across every system including the apps, and check that the abandoned cart flow has a basis. A store that does those four things rarely hears from a regulator.

What this means for you

A store’s data splits into records you must keep for tax and warranty purposes and everything else, which needs a purpose, a basis and a shorter retention you actually apply. Treat marketing as a separate purpose with real consent, map data across every app because each is a processor, keep the app list short, and have a procedure for access and deletion that covers every system. This is general information rather than legal advice.

Written by the CivSec S.M.A.R.T team

We build and run websites, software and AI systems for businesses. We write about what we see in that work, in plain language, and we update articles when things change.

Last checked . Spotted something outdated? Tell us.

Frequently asked questions

How long do we keep order data?

Order and invoice records fall under tax retention rules, which in the Netherlands are generally seven years for business administration. That is a legal obligation to retain, so it overrides a deletion request for those records. Data beyond what the tax and warranty purposes require, such as browsing history, marketing profiles and support chat, has its own shorter retention that you set and apply. Separating the two is the practical task.

Can we send abandoned cart emails?

It is a marketing communication to someone who has not completed a purchase, so it needs a basis. Where the person is an existing customer and the message concerns similar goods, the limited customer exception may apply with an easy objection route. Otherwise consent is the safe basis, captured at the point the email address is entered, with clear wording. Sending to anyone who typed an address into a checkout field without agreeing to be contacted is where complaints come from.

What happens when a customer asks us to delete their data?

You assess it across every system: the store platform, the email tool, the CRM, the support desk, the review app, the analytics, the accounting system and any exports. Records you must keep for tax purposes are retained with an explanation; the rest is deleted or anonymised. Respond within one month. The reason this is difficult for stores is the app sprawl, which is why the app list doubles as your data map.

Sources

  1. EUR-Lex: Regulation (EU) 2016/679 (accessed 2026-09-12)
  2. Belastingdienst: Hoe lang moet u uw administratie bewaren (accessed 2026-09-12)