mir-n logomir-nFree audit
All guides
GDPRUpdated September 3, 2026·9 min read

The GDPR compliance checklist for e-commerce stores (2026)

Twenty-three checks that decide whether your store passes a GDPR review — grouped by consent, cookies, data rights, processors and retention.

Most online stores fail GDPR on the same handful of points: a cookie banner that loads trackers before anyone clicks it, a privacy policy that never names a single processor, and no working way for a customer to request their data. None of those take long to fix once you know exactly what is missing. This GDPR compliance checklist walks through every item a European regulator or a cautious enterprise buyer will actually look for.

Work through it top to bottom. Each section ends with the evidence you should be able to produce if someone asks.

1. Lawful basis and consent

  • You can name a lawful basis for every category of personal data you collect (contract for orders, consent for marketing, legitimate interest for fraud checks).
  • Marketing opt-in is a separate, unticked checkbox — never bundled into the terms acceptance at checkout.
  • Consent is as easy to withdraw as it was to give: an unsubscribe link in every email and a cookie preferences link in the footer.
  • You keep a record of when and how each consent was captured.
Pre-ticked boxes and 'by continuing you agree' banners are not consent under GDPR. They were explicitly ruled out in Planet49 (CJEU, C-673/17).

2. Cookies and trackers

This is where the majority of stores fail, and it is the easiest thing for a regulator to verify — they just load your homepage with developer tools open.

  • No analytics, advertising or session-replay script fires before the visitor accepts. That includes Google Analytics, Meta Pixel, TikTok Pixel, Hotjar and Klaviyo's onsite tracking.
  • The banner offers 'Reject' with the same prominence as 'Accept' — one click, same visual weight.
  • Granular categories: strictly necessary, analytics, marketing, preferences.
  • A cookie policy lists each cookie, its purpose, its provider and its lifetime.
  • The choice persists and can be reopened from the footer.

If you want the cookie table written for you, our free cookie policy generator produces a GDPR- and CCPA-ready document you can paste into your store.

3. Privacy policy content

Required elementWhat auditors look for
Controller identityLegal entity name, postal address and a monitored email address
Purposes and lawful basesEach purpose mapped to its basis, not a generic list
RecipientsNamed processors: Shopify, Stripe, Klaviyo, Meta, your 3PL
International transfersNamed mechanism — Standard Contractual Clauses or an adequacy decision
RetentionA period or the criteria used to set it, per data category
Data subject rightsAll eight rights plus how to exercise them
Supervisory authorityThe right to lodge a complaint, and with whom

4. Data subject requests

  1. 1Publish one route for requests — an email address or a form — and monitor it.
  2. 2Be able to respond within one calendar month.
  3. 3Know how to export a customer's data from Shopify or WooCommerce, your email tool and your helpdesk.
  4. 4Know how to delete it in the same places, and what you must keep for tax law.
  5. 5Verify identity before acting, without demanding excessive documentation.

5. Processors and contracts

  • A data processing agreement is in place with every vendor that touches customer data.
  • Your processor list is current — vendors you removed last year should not still be named.
  • Transfers outside the EEA rest on SCCs or an adequacy decision, and you can say which.

6. Security and breach readiness

  • HTTPS everywhere, with HSTS and no mixed content.
  • Admin accounts use multi-factor authentication and least-privilege roles.
  • You can notify your supervisory authority within 72 hours of becoming aware of a breach.
  • You keep an internal incident log, even for breaches you decide not to report.

7. Evidence you should be able to produce

Compliance is a documentation exercise as much as a technical one. Keep a short folder containing: your record of processing activities, your consent logs, your signed DPAs, your cookie inventory with dates, and a dated screenshot or scan report of your live site showing no pre-consent trackers.

That last item is the one most stores never produce. A scheduled scan gives you a timestamped record that your storefront was clean on a given date — which is exactly what you need when a complaint arrives six months later.

See where your own store stands in 60 seconds.

mir-n loads your storefront in a real browser, records every tracker and cookie fired before consent, checks your required documents and runs WCAG tests — then hands you the fix for each finding.

Run a free audit

Frequently asked

Does GDPR apply to a US store?

Yes, if you offer goods or services to people in the EU or UK, or monitor their behaviour — which includes advertising retargeting. Shipping to Europe or running EU-targeted ads is enough to bring you in scope.

How much is a GDPR fine for a small store?

The headline maximum is 20 million euros or 4% of global turnover, but small-business enforcement in practice tends to be warnings and corrective orders. The more common cost is a blocked enterprise deal or a payment processor review.

Do I need a Data Protection Officer?

Only if your core activity is large-scale monitoring or processing of special-category data. Most e-commerce stores do not need one, but you should still name a contact for privacy questions.

Keep reading