GDPR and Your Online Store — What Does the Law Require?
Since May 25, 2018, the GDPR has set the framework for how all businesses in the EU must process personal data. For you as an online store owner, this means you have a legal responsibility for the personal information your customers provide—name, address, email, payment information, and more.
Violations can result in fines of up to 20 million euros or 4% of the company’s global annual revenue. However, the vast majority of these requirements can be met with the right platform and well-designed processes.
Cookie Consent and Consent Mode v2
The EU’s ePrivacy Directive requires you to obtain active consent from visitors before setting cookies other than those that are strictly necessary. Your online store must have a cookie consent banner that clearly explains the types of cookies you use and allows visitors to opt in or out of them. Consent must be voluntary, informed, and specific.
With Consent Mode v2, Google has introduced a standard that adapts the behavior of Google services based on consent. When a visitor rejects marketing cookies, Consent Mode v2 still sends anonymized pings—but without personally identifiable data.
In Shoporama, cookie consent using Consent Mode v2 is included by default. No third-party plugins, no configuration.
Privacy Policy
Every online store must have a privacy policy that describes how you collect, process, and store personal data. At a minimum, it must include:
- Who is the data controller (company name, business registration number, contact information)
- What types of personal data you collect
- The purpose of the data processing
- The legal basis (consent, contract, legitimate interest)
- Who you share data with
- How long you retain the data
- Customer rights (access, rectification, erasure, portability)
- Contact information for the Danish Data Protection Agency
Data Processing Agreements
When you use third-party services to process customer data—such as a payment gateway, shipping company, or email system—you are required to enter into a data processing agreement with each provider (GDPR Article 28).
On platforms with many third-party apps, you must, in principle, have an agreement with each app provider. In Shoporama, the data processing agreement is available directly in the admin panel. Because Shoporama is an integrated platform without third-party apps that handle data independently, you only need one data processing agreement. See how this differs from Shopify.
Server-Side Tracking and the GDPR
Traditional client-side tracking is vulnerable to ad blockers and cookie restrictions—you could lose 30–40% of your conversion data. Server-side tracking moves data processing to your server, giving you full control over which data is shared.
From a GDPR perspective, server-side tracking is an advantage: it provides better control over the data flow, data is shared only with consent, and the risk of unintended sharing is minimized.
Shoporama offers server-side tracking as an add-on for 89 DKK/month.
Customer Data: Access, Deletion, and Portability
The GDPR grants your customers the following rights:
- Right of access — the customer can request to view all recorded data. Response within 30 days.
- Right to rectification — errors in the information must be corrected without delay.
- Right to erasure — “the right to be forgotten” (with exceptions, such as accounting requirements).
- Right to data portability — data in a structured, machine-readable format.
- Right to object — to direct marketing.
In Shoporama, all customer data is centralized in the admin panel, making it easy to comply with requests.
GDPR Checklist for Online Store Owners
- Cookie consent — Do you have a banner that actively obtains consent? Is Consent Mode v2 implemented?
- Privacy Policy — Is it up to date and accessible from all pages?
- Data Processing Agreements — Signed with all vendors that process personal data?
- Newsletter consent — Explicit consent with double opt-in?
- SSL certificate — HTTPS on all pages?
- Data storage — Is data stored within the EU?
- Access Requests — Procedure for handling them within 30 days?
- Record of processing activities — Documented?
- Data breach — Plan to notify the Danish Data Protection Agency within 72 hours?
- Checkout — Only necessary personal data?
- Tracking — Do scripts respect the user’s consent?
- Employees — Trained in proper data handling?
How Shoporama Helps You with GDPR
- Cookie consent with Consent Mode v2 — included, automatically integrated
- Data hosted in the EU — no international transfers
- Data processing agreement directly in the admin panel — electronic signature
- No third-party apps with independent data processing — only one data processor
- Server-side tracking — add-on for 89 DKK/month, fully GDPR-compliant
- SSL certificate — included on all online stores
- Centralized customer data management — all data in one place in the admin panel
See all features and prices.
Conclusion
GDPR compliance is a legal requirement, but it doesn’t have to be complicated. Ensure you have cookie consent, a privacy policy, data processing agreements, and respect for your customers’ rights. Use the checklist above as a starting point.
Shoporama is designed to make GDPR compliance simple. With built-in cookie consent, EU hosting, electronic DPAs, and the option for server-side tracking, you have a solid foundation to build on.
GDPR Checklist: Shoporama vs. Your Task
| Requirements | Status with Shoporama | Your Task |
|---|---|---|
| Cookie consent | Included with Consent Mode v2 | Enable in admin |
| SSL Certificate | Included on all online stores | None — automatic |
| Data Processing Agreement | Ready in the admin panel for electronic signature | Sign the agreement |
| Privacy Policy | You must write it yourself | Create a page with your policy |
| Data hosted in the EU | Yes — Danish servers | None |
| Server-side tracking | Add-on (89 DKK/month) | Enable if desired |
| Right to access/deletion | Customer data collected in the admin panel | Process requests within 30 days |
| Consent for newsletters | Double opt-in available | Set up the correct consent flow |
| Record of processing | Not automatic | Document it yourself |
| Data breach plan | Shoporama handles platform security | Have a plan to notify affected parties within 72 hours |
Read more about online stores with no transaction fees or find the best online store platform.
Frequently Asked Questions
What does the GDPR require of my online store?
You must have cookie consent, a privacy policy, data processing agreements with all vendors, and be able to handle customers’ rights to access, rectification, and erasure within 30 days.
Does Shoporama have built-in GDPR compliance?
Yes, partially. Cookie consent with Consent Mode v2 is included. Data processing agreements can be signed electronically in the admin panel. Data is hosted in the EU. Server-side tracking is an add-on (89 DKK/month).
What is Consent Mode v2?
Google’s standard for customizing tracking based on user consent. When a visitor rejects cookies, anonymized data is sent to Google—without any personally identifiable information. Included in Shoporama.
Try Shoporama free for 30 days and experience GDPR compliance right out of the box. No credit card, no commitment.