Industry Guide

ePrivacy for Retail & E-Commerce

Industry-specific guidance on ePrivacy compliance for retail & e-commerce organisations. Understand the requirements, risk level, and key obligations that apply to your sector.

Compliance Risk Level

Medium Risk

This industry has moderate regulatory obligations with sector-specific requirements.

About ePrivacy

The EU directive governing privacy in electronic communications, covering cookies, direct marketing, traffic data, and the confidentiality of communications — often called the "Cookie Law".

Effective: 31 July 2002Max penalty: Determined by national law (no harmonised maximum) or Varies by member state transposition
Full ePrivacy overview

ePrivacy Impact on Retail & E-Commerce

Retail and e-commerce businesses collect extensive personal data through online shopping, loyalty programmes, marketing databases, and payment processing. The ePrivacy Directive's cookie consent requirements directly affect every online retailer, while GDPR governs customer data management, profiling for personalised recommendations, and direct marketing communications. Retailers using AI for dynamic pricing, customer segmentation, product recommendations, and chatbots must assess these systems under the AI Act's risk framework. Large retailers operating physical stores must also manage employee data, CCTV surveillance, and in-store tracking technologies in compliance with data protection rules.

Key ePrivacy Requirements for Retail & E-Commerce

1Implement GDPR-compliant cookie consent for all online properties
2Manage customer loyalty programme data with clear legal basis and retention
3Ensure marketing and profiling activities have valid consent or legitimate interest
4Process payment card data securely (PCI DSS alongside GDPR)
5Assess AI recommendation engines and dynamic pricing under AI Act framework
6Manage CCTV and in-store tracking with clear legal basis and signage
7Handle data subject rights requests across online and offline channels
8Implement ePrivacy-compliant direct marketing with proper opt-in/opt-out

Key ePrivacy Articles for Retail & E-Commerce

Art. 5

Confidentiality of communications

Establishes the fundamental right to confidentiality of electronic communications, prohibiting interception and surveillance. Also contains the cookie consent requirement (paragraph 3).

Art. 5(3)

Cookie consent requirement

Requires prior informed consent for storing information (cookies, pixels, fingerprinting) on user devices. Exempts cookies strictly necessary for requested services and transmission.

Art. 6

Traffic data

Requires erasure or anonymisation of traffic data when no longer needed for communication transmission or billing. Further processing requires user consent.

Art. 9

Location data other than traffic data

Location data may only be processed with consent or after anonymisation. Users must be informed of data types, purposes, duration, and whether data is shared with third parties.

Art. 13

Unsolicited communications (spam)

Requires opt-in consent for electronic direct marketing. Permits soft opt-in for existing customers receiving marketing about similar products, with easy opt-out in every message.

Vérifiez votre statut de conformité

Faites notre évaluation gratuite pour analyser la situation de votre organisation en matière de conformité. Obtenez en quelques minutes un rapport personnalisé avec des recommandations concrètes — sans inscription.

Lancer l’évaluation gratuite

Avertissement : les informations de cette page sont fournies à titre d’information et ne constituent pas un conseil juridique. Pour une assistance conformité spécifique, consultez un professionnel du droit qualifié dans votre juridiction.

Other Regulations Affecting Retail & E-Commerce

ePrivacy for Other Industries

ePrivacy for Retail & E-Commerce — Compliance Guide | Viktoria Compliance | Viktoria Compliance