Guides  / Securite  · 05 Apr 2026  · 11 min read

GDPR e-commerce 2026: the complete checklist

GDPR is 8 years old and still poorly applied on most e-commerce sites. Here's the concrete checklist to be compliant, point by point.

GDPR applies to any site processing the data of EU residents, regardless of where the company is hosted. Fines can reach €20 million or 4% of annual global revenue, whichever is higher. Eight years after it came into force, most of the e-commerce sites I audit still have at least three or four significant compliance gaps. Here's the concrete, point-by-point checklist to be compliant without needing a law degree.

This is the most visible point, and the most often poorly implemented. The rule is simple: refusing non-essential cookies must be just as easy as accepting them, on the same screen, in a single click. No box should be pre-checked for non-essential cookies. There must be a clear distinction between cookies strictly necessary for the site to function (no consent required) and audience-measurement, marketing, or social-media cookies (consent required). Consent must be stored with a precise timestamp and technical proof (session identifier, version of the text shown), so it can be produced during an audit.

Two distinct documents, often wrongly conflated. The legal notice identifies the company (registered name, business ID, address, hosting provider). The privacy policy must specify the identity of the data controller, the precise purpose of each data processing activity, the retention period for each category of data, the recipients (including third-party subprocessors), and the details of user rights: access, rectification, erasure, portability, objection, and restriction of processing, along with the concrete steps to exercise them.

3. Data collection forms

Every form (contact, sign-up, reviews) must include a clear, non-pre-checked box for any optional consent, with an explicit, understandable statement of how the data will actually be used. Collect only the data strictly necessary for the stated purpose — the minimization principle, often ignored out of excessive commercial caution ("you never know, it might come in handy").

4. Newsletter and marketing emails

Double opt-in is mandatory in practice: a confirmation email must be sent after sign-up, with an explicit validation link. Every subsequent email must include a clear unsubscribe link, functional in a single click, without requiring account login. Processing an unsubscribe request must not take more than a few business days.

5. Subprocessors and third-party tools

Build an exhaustive list of every third-party tool processing personal data on your behalf: analytics solution, CRM, payment provider, hosting, emailing solution, chatbot, review module. For each one, a Data Processing Agreement (DPA) must be signed, specifying security guarantees and where the data is processed (particularly important if the provider is outside the EU).

6. Technical security

HTTPS is mandatory across the entire site, no exceptions. Stored passwords must be encrypted with a robust algorithm (bcrypt at minimum, never MD5 or SHA1 alone). In the event of a security incident involving personal data, notification to the relevant data protection authority is mandatory within 72 hours, and notification to affected individuals is required if the risk to their rights and freedoms is high.

7. Record of processing activities

Every business, including very small ones and freelancers, must keep a record of processing activities listing each type of data collected, its purpose, its retention period, and the associated security measures. This document, often overlooked by small businesses, is the first thing requested during a data protection authority audit.

Concrete consequences of non-compliance

Beyond the direct financial risk, a formal notice from a data protection authority is made public and damages a company's reputation. On the cases I handle, a full compliance remediation typically takes 2 to 4 weeks of work, split between the initial audit, updating legal documents, reconfiguring the cookie banner, and technically securing the site.

Was this guide useful?

Comments

No comments yet. Yours will be the first.

Leave a comment

Your comment will be published after review. Your email address will not be shown or shared; it is only used to reply to you.

10 characters minimum, 4000 at most.

← All guides Start my project →
Also read

Related guides

Securite

Securing WordPress in 2026: the complete guide

WordPress powers 43% of the web, making it a prime target. Here's how to protect your site against modern threats: 2FA, WAF, hardening, back…

Read guide → 10 min read
Performance

How to optimize your PrestaShop store performance in 2026

A slow e-commerce site loses up to 40% of customers. Here's the complete methodology to turn a slow PrestaShop store into a high-performance…

Read guide → 8 min read
Prestashop

PrestaShop 1.7 to 8 migration: proven methodology

Migrating to PrestaShop 8 brings significant gains but requires a methodical approach. Lessons learned from more than 30 successful migratio…

Read guide → 12 min read
E-commerce

Shopify vs WooCommerce in 2026: which to choose?

The choice between Shopify and WooCommerce depends on your profile, budget and ambitions. A detailed comparison to help you choose right.…

Read guide → 9 min read
Prestashop

Custom PrestaShop theme vs marketplace theme: what you're not told

Buy a €60 theme or get a custom one developed for €5000? The answer isn't that obvious. A complete analysis of both approaches.…

Read guide → 7 min read
Marketing

Cart abandonment: the recovery sequence that actually converts

70% of e-commerce carts are abandoned. The right recovery sequence can win back 15-25% of those sales. Here's mine, tested on 50+ stores.…

Read guide → 9 min read
Performance

E-commerce hosting: OVH, o2switch or dedicated host? My 2026 comparison

The right host can cut your load time by 3x. An honest comparison of hosts for PrestaShop, WordPress and WooCommerce.…

Read guide → 10 min read
Seo

Local SEO: the complete strategy to dominate Google Maps

Have a local business? Here's the complete local SEO strategy I use to get clients ranking #1 in their city — Google Business Profile, revie…

Read guide → 12 min read