Contents

GDPR for Ecommerce Sellers: Your 2026 Compliance Checklist

GDPR for Ecommerce Sellers: Your 2026 Compliance Checklist

TL;DR: GDPR became law on 25 May 2018, and enforcement has only intensified since. Regulators have issued more than €5.88 billion in fines cumulatively. As a marketplace seller on Amazon or eBay, you are almost certainly a data controller for at least some of the personal data that flows through your business. That means real obligations around consent, subject access requests, third-party processors, and breach reporting. UK sellers also need to account for the Data (Use and Access) Act 2025, which has introduced meaningful differences between UK GDPR and EU GDPR.

GDPR for Ecommerce Sellers: Your 2026 Compliance Checklist

By the time you finish reading this, a data protection authority somewhere in the EU or UK is reviewing a complaint about a marketplace seller. GDPR has not faded into background noise. Cumulative fines passed €5.88 billion by January 2025, according to the Data Privacy Manager enforcement tracker, and regulators have made clear that business size is not a shield. Small sellers get fined too.

If you sell on Amazon or eBay, here is what compliance looks like for your business right now.

What Does GDPR Cover for Marketplace Sellers?

GDPR applies to any business that collects, stores, or processes personal data from individuals in the EU or UK, regardless of where the business itself is based. Selling from the US on Amazon.co.uk? GDPR applies. Running an FBA operation from Australia with EU shoppers in your customer list? GDPR applies.

The regulation is built on six core principles: data must be processed lawfully and transparently, collected for a specific purpose, limited to what is necessary, kept accurate, not stored longer than needed, and protected with appropriate security. Those six principles run through every obligation below.

If you sell across multiple marketplaces, the scope question is straightforward: any order from a UK or EU buyer brings GDPR into play.

What Counts as Personal Data When You’re a Seller?

Personal data under GDPR is any information that identifies or can identify a living individual. For a marketplace seller, the category is broader than most people expect.

It includes customer names, email addresses, delivery addresses, phone numbers, payment details, order history, and account data from any storefront you operate directly. IP addresses are personal data. So are cookies that track browsing behavior on your own site. The test is identifiability, not obvious sensitivity.

Genuinely anonymized data, where re-identification is truly impossible, falls outside scope. An aggregated order report with no individual identifiers is fine. An export of raw customer records is not.

The practical point: if you run your own Shopify storefront alongside your marketplace listings, you are collecting more personal data than a seller who operates exclusively through Amazon, and your obligations reflect that.

Are You a Data Controller, a Processor, or Both?

You are a data controller when you decide why and how personal data is collected. You are a processor when you handle data on someone else’s instruction.

As an Amazon or eBay seller, you are almost certainly a data controller for the data flowing through your own channels: your email list, your off-marketplace storefront, your customer service inbox. You hold that data, you decide what to do with it, and GDPR holds you responsible for it.

Amazon’s position is more layered. Amazon controls the customer relationship on its own platform, and its Business Solutions Agreement requires sellers to comply with applicable data protection laws. But when Amazon shares customer shipping information with you to fulfill an order, you receive personal data that you are responsible for handling correctly. The marketplace origin does not transfer your obligations to Amazon.

Amazon FBA sellers should note: Amazon handles physical fulfillment and processes the related data as part of that service. You still receive customer information for returns, refunds, and dispute resolution. You remain responsible for how you use it.

Your Core Obligations Under GDPR

Have a lawful basis for each type of processing. Order fulfillment is typically covered by contractual necessity. Marketing emails require explicit opt-in consent. Behavioral analytics need either consent or a documented legitimate interest assessment. The lawful basis must be identified before the processing starts, not after.

Respond to Subject Access Requests within 30 days. Any individual in the EU or UK can ask what data you hold about them. You have one calendar month to respond. Both EU GDPR and UK GDPR set the same deadline. You can extend by one further month if the request is complex or you receive a high volume simultaneously, but you must tell the individual within the original 30-day window that you are extending and why.

Honor deletion requests. If a customer asks you to erase their data and there is no overriding legal obligation to retain it (tax records, for instance, have their own retention rules), you are required to delete and confirm.

Maintain an up-to-date privacy policy. It needs to name what data you collect, the lawful basis for collecting it, who you share it with, how long you retain each category, and how individuals can exercise their rights. If your privacy policy has not been reviewed since 2020, it needs updating before anything else.

Get consent right. Pre-ticked boxes, bundled consent, and vague “I agree to the terms” language do not meet GDPR’s consent standard. Consent must be specific, freely given, clearly understood, and revocable. A customer who opts out of marketing emails should stop receiving them immediately.

UK GDPR vs EU GDPR: What Has Changed and Why It Matters

For most of the post-Brexit period, UK GDPR and EU GDPR were functionally identical. That is no longer quite accurate.

The UK data law changes introduced by the Data (Use and Access) Act 2025 (DUAA), which received Royal Assent on June 19, 2025 and came into force in phases through early 2026, created the first material divergences between the two regimes. For eCommerce operators, the most relevant changes are: the UK now permits certain analytics cookies without consent (EU GDPR still requires it), UK GDPR has introduced a “stop the clock” mechanism for Subject Access Requests in some circumstances (the EU has no equivalent), and automated decision-making rules have been relaxed under UK GDPR.

What has not changed: if you have customers in both the UK and EU, you need to satisfy both regimes. The EU Commission renewed the UK’s adequacy decision in June 2025, which keeps EU-to-UK data flows free of additional safeguards for the next four years. Adequate does not mean identical, and the gap is growing.

Practical read: if you are UK-based and sell on EU Amazon marketplaces, apply EU GDPR as your baseline. It is the stricter standard, and UK businesses with EU customers are required to appoint a representative in the EU under Article 27 EU GDPR if they have no EU establishment.

Third-Party Tools and Data Processing Agreements

Every third-party tool that handles your customers’ personal data on your behalf is a data processor under GDPR. That includes your repricing software, your shipping integrations, your email marketing platform, and your customer feedback tool. For each one, you need a Data Processing Agreement (DPA) in place before any personal data is shared.

A DPA sets out what data is processed, the purpose, the security measures in place, and that the processor acts only on your instruction. Reputable SaaS vendors will have a standard DPA available on request or in their terms documentation. Responsible providers whose tools connect to Amazon seller accounts are themselves required to maintain data processing terms compliant with GDPR. If a tool cannot produce a DPA, that is a genuine compliance risk.

Check and keep a record of the DPA status for every third-party tool in your stack. This is the area most smaller sellers neglect, and it is consistently what data protection authorities look at when investigating complaints.

What to Do If There’s a Data Breach

A data breach is any incident where personal data is accidentally or unlawfully accessed, disclosed, altered, or destroyed. If the breach is likely to create a risk to individuals’ rights and freedoms, you must notify your supervisory authority (the ICO in the UK, the relevant EU data protection authority if EU customers are affected) within 72 hours of becoming aware of it.

If the breach is likely to result in high risk to individuals, such as exposure of payment data, you must also notify the affected individuals directly and without undue delay.

72 hours is a short window. Have a process mapped before it happens: who gets notified internally, who contacts the regulator, what documentation is created. Discovering a breach on a Friday evening and spending the weekend figuring out your legal obligations is not a position you want to be in.

Key Compliance Checklist

  • Audit your data flows. Map exactly what personal data you collect, where it originates, where it goes, and how long you retain it. This is the foundation of every other obligation.
  • Review your privacy policy. It should state your lawful basis for each processing activity, name your third-party processors, and explain how individuals can exercise their rights.
  • Confirm DPAs are in place for every third-party tool handling personal data on your behalf.
  • Test your SAR process. Could you locate and produce all data held on a specific customer within 30 days? Run a mock request against your systems to find out.
  • Check your consent flows. If you collect email addresses for marketing, opt-in must be explicit, unchecked by default, and easy to withdraw.
  • UK sellers: review the DUAA changes. Analytics cookies, SAR handling, and automated decision-making rules have all shifted under UK GDPR since June 2025.
  • Sellers with EU customers: verify you have an EU representative if you are based outside the EU but serve EU marketplace buyers.


The ICO’s getting started guide for small businesses is the clearest plain-English reference for UK sellers working through these steps.

FAQ

Does GDPR apply to Amazon sellers based outside the EU and UK? Yes. GDPR applies to any business that offers goods or services to individuals in the EU or UK, or monitors their behavior, regardless of where the business itself operates. If your listings appear on Amazon.co.uk, Amazon.de, Amazon.fr, or any other UK or EU marketplace, the relevant GDPR regime applies to how you handle personal data from those orders.

What personal data does a typical marketplace seller actually hold? At minimum, most marketplace sellers hold customer shipping names and addresses, email addresses used in order communications, and order history. Sellers who run their own storefronts also typically hold IP addresses, cookie data, and marketing consent records. The full inventory is often larger than sellers realize until they run a data audit.

Do I need a Data Processing Agreement with Amazon and eBay? Amazon and eBay both set out their data processing terms in their seller agreements and supplementary data processing addenda. Review and retain those documents. For third-party tools you independently select, including repricing software and customer feedback platforms, securing a DPA with each provider is your responsibility.

How long should I keep customer data? GDPR does not set a universal retention period. Keep data for as long as it is necessary for the purpose you collected it, or as long as a separate legal obligation requires (UK tax records, for example, must be retained for six years). Beyond that, delete or anonymize it. Your privacy policy should state your retention period for each data category.

What is the maximum fine under GDPR? The upper tier is €20 million or 4% of annual global turnover, whichever is greater. Not every breach results in the maximum, but enforcement is serious and cumulative: total GDPR fines exceeded €5.88 billion by January 2025. Amazon was fined €746 million by Luxembourg’s National Commission for Data Protection in 2021 for violations related to advertising data use.

Regulatory guidance verified as of August 2026. UK GDPR information reflects the Data (Use and Access) Act 2025 provisions in force as of August 2026. This article is for general informational purposes and does not constitute legal advice.

Book a Demo

Author

Want monthly repricing tips, trends and news direct to your inbox?

See our Privacy Notice for details as to how we use your personal data and about your rights