Privacy and data protection

E-commerce, online store and privacy

Lawyers and in-house counsel for a GDPR-compliant webshop

From international e-commerce giants to the baker with an order page: we make your webshop privacy-proof, from privacy statements and cookies to data processing agreements and data breaches.

  • We worked for, among others:
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner

What we do

For e-commerce organizations, the laws and regulations regarding privacy and data protection are complex. The legislature has established additional rules in connection with consumer protection, resulting in extra work. Examples include certain information obligations regarding websites or regulations concerning cookies. Compliance with these laws and regulations is mandatory, as otherwise enforcement action may be taken by a supervisory authority (for example, by means of a fine). Within our practice group, we have the knowledge and experience to provide organizations with legal advice in this regard.

Questions about e-commerce? Please contact us.

E-commerce and privacy within Privacy and data protection

An online store relies on personal data. From the first visit to the website through delivery, returns, and after-sales, you process names, addresses, email addresses, payment details, order history, and browsing behavior. Consequently, every webshop—from an international e-commerce group to the baker with an order page on the corner—falls under the General Data Protection Regulation (GDPR) and the GDPR Implementation Act. This page specifically examines e-commerce from the perspective of Privacy and Data Protection: not the general rules of consumer law, but rather the question of how you lawfully process, secure, and account for customer data. Our mixed teams of lawyers and in-house counsel translate these rules into workable agreements that suit the size and risk profile of your webshop.

Legal basis and purpose limitation in the processing of customer data

According to Article 6 of the General Data Protection Regulation, every processing of personal data requires a valid legal basis. In the case of a webshop, the data required to process, deliver, and pay for an order is typically based on the performance of the contract. For a newsletter, personalized offers, or non-functional cookies, consent is usually required. Furthermore, pursuant to Article 5 of the General Data Protection Regulation, purpose limitation and data minimization apply: you may only collect data that is necessary for a predetermined purpose and retain it no longer than necessary. A common mistake is ticking the marketing consent box by default or retaining complete order histories without a retention period. We determine the correct legal basis for each data stream and establish a sustainable retention policy.

Privacy statement, cookies and consent on your webshop

The GDPR requires you to clearly inform data subjects in advance (Articles 13 and 14 of the General Data Protection Regulation). A webshop therefore needs an accessible and understandable privacy statement that specifies which data you process, for what purpose, on what legal basis, how long you retain it, and with which parties you share it. In addition to the GDPR, Article 11.7a of the Telecommunications Act also applies to cookies: prior, active consent is required for tracking and analysis cookies that process personal data — a cookie banner without a genuine opt-out option is insufficient. The Dutch Data Protection Authority strictly enforces this. With our cookie scan , we map out which cookies your shop places and configure consent in a GDPR-compliant manner.

Processor agreements with payment services, fulfillment, and marketing

A webshop rarely operates in isolation. Payment service providers, hosting providers, fulfillment centers, email and marketing tools, and parcel carriers gain access to customer data. Pursuant to Article 28 of the General Data Protection Regulation, you are required to enter into a data processing agreement with every party processing data on your behalf, including agreements regarding security, data breaches, sub-processors, and the deletion of data after completion. If you use services outside the European Economic Area—such as US marketing or analytics platforms—additional transfer requirements under Chapter V of the General Data Protection Regulation apply. We review and negotiate these contracts and draft model agreements that you can use time and again.

Security, data breaches and the rights of your customers

Article 32 of the General Data Protection Regulation (GDPR) obliges you to implement appropriate technical and organizational measures, such as a secure (TLS) connection, strong access security, and authorization management in your webshop and POS systems. If things do go wrong, you must assess the data breach and, if necessary, report it to the Dutch Data Protection Authority within 72 hours and potentially to the customer (Articles 33 and 34 of the General Data Protection Regulation). In addition, your customers have rights: access, rectification, erasure, and objection (Articles 15 to 22 of the General Data Protection Regulation), and extra safeguards apply to profiling for personalized offers. Read more about our approach to data breaches . A DPIA may be mandatory for sensitive or large-scale processing .

Enforcement, fines, and how MKB Juristen unburdens you

The Dutch Data Protection Authority can impose fines of up to 20 million euros or 4% of global annual turnover (Article 83 of the General Data Protection Regulation), in addition to reputational damage and the shutdown of your sales channel. The standard is the same for both large e-commerce players and small business owners, but the practical approach differs. That is why we work with mixed teams of lawyers and in-house counsel: from a quick compliance check for a start-up webshop to a comprehensive privacy program for an international platform. If you would like to know where you stand first, we can conduct a privacy audit or appoint a Data Protection Officer (DPO) . Do you have questions about e-commerce and privacy? Please feel free to contact us.

Mr. Jaime Boogaers
Mr. Jaime Boogaers
Corporate Law · Lawyer

In specialized legal cases, it is not just about the legal rule. It is also about evidence, timing, negotiating position, and the business implications of every step.

What we do for your webshop

Our mixed teams of lawyers and in-house counsel support e-commerce across the full spectrum of privacy and data protection.

  • Drafting and reviewing privacy statement and cookie policy
  • Setting up GDPR-compliant cookie consent and cookie scan
  • Determining legal bases, purpose limitation, and retention periods
  • Drafting and negotiating data processing agreements
  • Advice on the transfer of data outside the EEA
  • Data breach assessment, notification and handling
  • Handling requests for access, removal, and objection

Risks in e-commerce and privacy

Webshops process a large amount of personal data and link numerous external services. Without a robust setup, entrepreneurs run the risk of legal and financial harm.

  • Fine from the Dutch Data Protection Authority for missing or incorrect consent
  • Unlawful cookies and trackers without valid consent
  • No or defective data processing agreement with service providers
  • Data breach that is not reported or is reported too late
  • Reputational damage and standstill of the sales channel

Our approach

We start with the data flows of your webshop and determine the legal basis, purpose, and retention period for each flow. Next, we set up the mandatory documents (privacy statement, cookie policy, processing register) and conclude the appropriate data processing agreements. For the baker around the corner, a compact compliance check often suffices; for an international platform, we build a complete privacy program with a data breach procedure and transfer agreements. This ensures the standard is the same for everyone, but the approach is always tailored.

This is how we work

From initial assessment to a demonstrably GDPR-compliant webshop in clear steps.

01

Intake and initial assessment

We will briefly discuss the situation, the available documents, and your primary interests.

02

Analysis of position and risks

We assess your legal position, supporting documents, deadlines, and possible next steps.

03

Strategic advice

You will receive concrete advice on the best course of action: responding, negotiating, settling, or litigating.

04

Execution

We assist with correspondence, negotiation, litigation strategy, or further legal assistance.

Specialists for entrepreneurs

We combine legal analysis with practical experience in cases for entrepreneurs, directors, and organizations.

Our team is engaged to provide legal and strategic support in the field of privacy and data protection. We offer this support to a wide variety of clients, ranging from companies to non-profit organizations. Our practice group's excellent knowledge of privacy law and data protection results in sound and pragmatic advice. In addition to outlining the legal framework, our lawyers and legal experts specialize in implementing this advice within the organization.

Frequently asked questions about e-commerce and privacy

The questions webshop owners ask us most often about privacy and data protection.

When is legal advice advisable?

Legal advice is wise as soon as pressure arises, deadlines are running, an opposing party takes a position, or when the financial or strategic interests are significant.

Can MKB Juristen also help if there is already a conflict?

Yes. We assess your legal position, advise on strategy, and can assist with correspondence, negotiation, defense, or further legal steps.

How much does specialist legal advice cost?

Specialist advice is provided on an hourly basis in principle. Where possible, we provide clarity in advance regarding the expected approach, costs, and next steps.

Can I have a no-obligation consultation first?

Yes. You can request a free consultation. We will briefly discuss your situation and indicate which course of action is likely the sensible one.

Making your webshop GDPR compliant?

Contact MKB Juristen. Our lawyers and in-house counsel help you quickly and practically with privacy and data protection for your e-commerce.

Contact us

Contact us

Leave your details. We will contact you to briefly discuss your situation.

Contact us

Jaime Boogaers

Want to know more about our services?
Then contact our specialists.

Newsletter for entrepreneurs

Receive practical legal tips in your mailbox

Register now

Enter your email address and receive our newsletter.

No spam. Only legal tips.
By registering, you agree to our privacy statement.
SME Lawyers at the Chamber of Commerce Source: Chamber of Commerce 2019
Free consultation