Cybersecurity and GDPR for e-commerce: fines of 4% of turnover
If you run an e-commerce store, you are holding your customers' personal data: names, addresses, emails, payment details. The General Data Protection Regulation (GDPR) requires you to protect them or face fines of up to 4% of your annual turnover.
What are my obligations as an online store?
- Record of processing activities (who accesses which data).
- A clear, accessible privacy policy.
- Explicit consent for marketing and newsletters.
- Breach protocol: if you detect a leak, you have 72 hours to notify the Spanish data protection authority (AEPD).
- Impact assessment if you process sensitive data or data at scale.
What happens if I get hacked?
You must notify the breach to the AEPD within 72 hours and, if there is a high risk for those affected, also to the users themselves. Fines for failing to notify can exceed 20 million euros.
At DPL Asesores we audit your store's security and prepare the breach protocol. Request an audit.
📚 Related articles
Do you run an online store? Shopify Partner: VAT registration and filings in more than 50 countries, plus EPR for packaging, electrical equipment and batteries. Services for e-commerce →