GDPR for eCommerce: Cookies, Checkout Data and Marketing Emails
Three areas account for the majority of GDPR fines issued to eCommerce businesses: cookie consent failures, misuse of checkout data for marketing, and unlawful email campaigns. Here is the exact compliance framework for all three.

The Three GDPR Traps That Catch eCommerce Businesses
GDPR enforcement against eCommerce businesses follows predictable patterns. Regulators across Europe — the CNIL in France, the ICO in the UK, the DPC in Ireland, and the Commissioner in Cyprus — consistently target the same three areas:
Each area has a clear compliance framework. Each area is routinely ignored. Each area carries significant fine risk.
---
Part 1: Cookies and Tracking on eCommerce Sites
The Problem
A typical eCommerce site uses 15-40 third-party trackers: analytics (Google Analytics, Hotjar), advertising (Meta Pixel, Google Ads, TikTok Pixel), retargeting, affiliate tracking, live chat, and more. Every one of these that sets cookies or collects data requires prior, informed, and freely given consent under the EU ePrivacy Directive before it activates.
The reality on most eCommerce sites: these trackers fire immediately on page load — before the user has clicked anything on the cookie banner. This is a direct violation, regardless of how prominent or well-designed your cookie banner appears.
What Valid Cookie Consent Requires
Under the EDPB (European Data Protection Board) guidelines and national DPA guidance, valid cookie consent must be:
Freely given:
Specific:
Informed:
Unambiguous:
Withdrawable:
The Technical Requirements
Cookie banner must load before any non-essential scripts.
Implement your Consent Management Platform (CMP) as the first script that loads — before Google Analytics, Meta Pixel, or any other tracker. All other scripts must be conditional on the consent status returned by the CMP.
Consent logging is mandatory.
You must be able to demonstrate consent: store the timestamp of consent, the version of the cookie banner shown, the categories consented to, the user's IP address, and the method by which consent was given. Regulators ask for this evidence during investigations.
Cookie list must be current and complete.
Your Cookie Policy must list every cookie by name, provider, category, and duration. Every time you add a new tool or pixel, update your Cookie Policy and re-trigger consent if the new tool falls into a category the user has not yet consented to.
The Meta Pixel Problem
The Meta Pixel is one of the most heavily scrutinised tracking tools in European GDPR enforcement. Key compliance requirements:
---
Part 2: Checkout Data and What You Can Do With It
The Problem
A customer places an order on your store. They provide their name, email address, delivery address, and payment details to complete the purchase. The lawful basis for processing this data is contract — you need it to fulfil the order.
Many eCommerce businesses then use this data for marketing: adding the customer to their newsletter list, sending promotional emails, retargeting them with ads. Unless you have a separate, valid lawful basis for each of these marketing activities, this is unlawful.
The data collected for contract performance cannot automatically be repurposed for marketing.
What You CAN Do With Checkout Data
Transactional emails — lawful under contract:
All of these are necessary to perform the contract. No separate consent is needed.
Post-purchase review requests — generally lawful under legitimate interests:
A single post-delivery email asking for a review is generally accepted under legitimate interests, provided it is not excessive and you have conducted a Legitimate Interests Assessment (LIA).
Soft opt-in marketing — lawful under ePrivacy Article 13(2) conditions:
You can send marketing emails to existing customers about similar products without fresh consent if ALL of the following conditions are met:
If any of these conditions are not met, soft opt-in does not apply and you need explicit consent.
Advertising retargeting — requires marketing consent:
Using a customer's email address to create a Custom Audience on Meta or Google for retargeting requires marketing consent — soft opt-in does not extend to sharing data with third-party advertising platforms.
The Checkout Consent Mechanism
At checkout, best practice is to include an unticked checkbox below the email field (separate from the order confirmation checkbox) with text such as:
*"I would like to receive marketing emails about products and offers from [Store Name]. You can unsubscribe at any time."*
This creates a documented opt-in for marketing emails, separate from the transactional relationship. Store the consent record (timestamp, IP, form version) in your CRM or email platform.
---
Part 3: GDPR-Compliant Email Marketing
What Lawful Basis Are You Using?
Email marketing can rely on:
You cannot rely on contract as a basis for marketing emails. GDPR is clear: processing that is necessary to perform a contract is limited to what is genuinely necessary for that performance. Marketing is not necessary to fulfil an order.
Consent Record Requirements
If you rely on consent for email marketing, you must maintain a consent record for every subscriber that captures:
This record must be available for regulatory review. "They ticked a box" is not sufficient — you need the evidence.
Double Opt-In: Best Practice
Double opt-in (requiring subscribers to confirm their subscription by clicking a link in a confirmation email) is not mandatory under GDPR, but it is the gold standard for consent evidence. Benefits:
For any business building a marketing list from scratch in 2026, double opt-in is the recommended standard.
Unsubscribe Mechanism Requirements
Every marketing email must include:
Suppression Lists
Maintain a suppression list of everyone who has unsubscribed. Never re-add a suppressed contact to a marketing list — even if they make a new purchase and soft opt-in would technically apply. If they have previously unsubscribed from marketing, that negative signal must be respected.
The eCommerce GDPR Audit Checklist
Cookies:
Checkout data:
Email marketing:
Need a full eCommerce GDPR compliance review, cookie compliance setup, or email marketing consent framework? Our legal team provides complete eCommerce compliance packages — covering all three areas above — tailored to your specific store, platforms, and marketing stack.
Need Legal Documents?
Get expert-drafted legal documents customized for your business. From NDAs to GDPR policies, we've got you covered.

