Back to Shop
Complico Basic GDPR Guidelines

Complico Basic GDPR Guidelines

Download File

If you are an international manufacturer, an e-commerce seller on platforms like Amazon FBA, eBay, or Etsy, or a B2B firm targeting the European market, data privacy is just as critical as product safety. The General Data Protection Regulation (GDPR) sets the global standard for data privacy, and failing to comply can result in severe financial penalties and account suspensions on major marketplaces.

Whether you are capturing customer emails for marketing, processing shipping addresses, or tracking website analytics, your business falls under the scope of the GDPR. Below are the basic guidelines and actionable steps every business needs to ensure compliance in 2026.

The 7 Core Principles of GDPR

Before diving into the operational checklist, it is essential to understand the foundational principles that govern how you must handle EU consumer data:

Lawfulness, Fairness, and Transparency: You must have a legal justification for collecting data, and you must be upfront with users about what you are doing.

Purpose Limitation: Only use data for the specific reason you claimed when you collected it.

Data Minimization: Do not collect more information than you strictly need.

Accuracy: Keep your customer data up-to-date and accurate.

Storage Limitation: Delete or anonymize data once it is no longer needed for its original purpose.

Integrity and Confidentiality: Protect data with robust, technical security measures (e.g., encryption).

Accountability: You must be able to document and actively prove your compliance.

The Complico Compliance Checklist

Translating those principles into daily business operations requires specific, documented actions. Here is the basic checklist for securing your digital operations.

1. Map Your Data (Maintain a RoPA)

You cannot protect what you do not know you have. Creating a Record of Processing Activities (RoPA) is a mandatory step for demonstrating accountability, as required under Article 30 of the GDPR. You need to document:

Exactly what personal data you collect (names, IP addresses, payment details).

Where that data is stored (your servers, third-party logistics providers, marketplace dashboards).

Who has access to it, internally and externally.

How long you intend to keep it.

2. Establish a Lawful Basis and Update Your Privacy Policy

You cannot simply harvest data; you need a stated "lawful basis" for every piece of information you process. For e-commerce, this is usually "contractual necessity" (e.g., needing an address to ship a product) or "explicit consent" (e.g., a user opting into a marketing newsletter).

Your privacy policy must be easily accessible, written in plain language, and explicitly state your lawful basis, what data you collect, and the rights of the consumer.

3. Implement Strict Consent Mechanisms

Pre-ticked boxes and buried opt-out clauses are strictly forbidden. If you use non-essential cookies on your website (like tracking pixels for ad retargeting), you must implement a compliant consent banner that allows users to explicitly opt-in before any tracking occurs. Furthermore, withdrawing consent must be as easy as giving it.

4. Prepare for Data Subject Rights (DSARs)

Under the GDPR, EU citizens have enforceable rights regarding their data, including the right to access it, correct it, or demand its complete erasure ("the right to be forgotten"). You must have a streamlined, internal process to respond to these Data Subject Access Requests (DSARs) within one month, in line with guidance from the European Data Protection Board.

5. Appoint an Article 27 EU Representative

If your company is based outside of the European Union (e.g., the US, UK, or Asia) but you sell goods or services to individuals within the EU, GDPR Article 27 requires you to appoint a representative located in an EU member state.

This representative acts as your local point of contact for data subjects and European supervisory authorities. Failure to appoint an Article 27 representative is a direct violation of the GDPR, as explained in our guide to Article 27 representation, and is a common pitfall for international e-commerce sellers scaling their operations into Europe with the help of an EU Authorised Representative.

6. Conduct a Data Protection Impact Assessment (DPIA)

If you are implementing new technologies or processing data in a way that poses a high risk to consumer privacy (such as large-scale automated profiling or processing sensitive health data), you are legally required to conduct a DPIA. This is a formal risk management process designed to identify and minimize privacy risks before a new project launches, and is summarized further in the European Commission's official GDPR summary.

Still unsure whether you need an EU Authorised Representative? Our 2026 guide to EU representation and our overview of authorised representatives break down exactly who needs one and why, alongside our complete representative services guide.

Need help building your GDPR compliance program? Explore our full range of EU compliance services, read more on our compliance blog, learn about Complico Consulting GmbH, or contact our team to schedule a consultation.

Book a 30-Minutes
Consultation

Speak directly with a compliance specialist. In this one-on-one call