HOW TO COMPLY WITH UK GDPR, PECR AND COOKIE REQUIREMENT

YOUR WEBSITE COLLECTS MORE THAN ORDERS

An e-commerce website may collect customer names, addresses, telephone numbers, payment information, account details, browsing behaviour and marketing preferences. The problem is that businesses sometimes collect this information without first deciding why it is needed, how long it will be retained or who will be permitted to use it.

Imagine that an online retailer installs advertising cookies, automatically adds every customer to its marketing list and gives its delivery and marketing providers access to customer information. The website has a privacy notice, but it does not explain these activities. The business may be using the information to support sales, but its data practices may not match what customers were told. That gap can create complaints, security risks and regulatory liability.

This issue is important for your knowledge because customer data is commercially valuable, but it belongs to identifiable individuals who have legal rights over its use.

Under the UK GDPR framework, a business may become a controller where it decides why and how personal data will be processed. A third-party service that processes the information on the business’s instructions may be a processor.

The controller remains responsible from the point at which it begins dealing with identifiable personal information. Using a payment provider, email platform or cloud service does not automatically transfer that responsibility. A business must therefore understand the information moving through its systems. 

UK LEGAL PRINCIPLES

cookies, website, computer, accept, privacy, data, user, security, safety, gdpr, click, file, browser, laptop, privacy, gdpr, gdpr, gdpr, gdpr, gdpr, click

Under the UK GDPR principles, personal data must be processed lawfully and fairly, used for specified and legitimate purposes, limited to what is necessary, kept accurate, retained only for as long as required and protected securely.

In practical terms, a business should not collect information simply because its website allows it to do so. Each use of personal data should have an appropriate lawful basis. For example, a customer’s address may be processed because it is necessary to perform the sales contract and deliver the order. Other processing may be required to comply with a legal obligation or pursue a legitimate business interest. Where processing depends on consent, the business must be able to demonstrate that valid consent was obtained.

Consent must also be capable of being withdrawn. According to the manual, withdrawing consent should be as easy as giving it. Customers also have rights relating to their information. These include rights to be informed, access their data, correct inaccurate information, request erasure in appropriate circumstances, restrict certain processing, object to direct marketing and challenge some forms of automated decision-making.

How PECR affects cookies and marketing

The Privacy and Electronic Communications Regulations 2003, commonly known as PECR, apply specifically to areas including cookies and electronic direct marketing. Cookies are small files placed on a user’s device that can remember activity, preferences or browsing behaviour. Some support essential website functions, while others may be used for analytics, advertising or customer profiling.

Under PECR, users should be given clear information about the purpose of cookies and, where required, an opportunity to provide consent. A banner that only states “By continuing to use this website, you accept cookies” may not give the customer a genuine choice. PECR also regulates unsolicited electronic marketing. Businesses should not assume that purchasing a product automatically means that the customer agrees to receive every future promotion. Marketing communications should identify the sender and provide an effective way for the recipient to object or withdraw their permission.

To comply with those principles, business owners must understand the information their business actually collects. First, identify the personal data obtained through orders, enquiries, accounts, newsletters, cookies and third-party tools. Then record why each category is used, its lawful basis, who receives it and how long it will be retained.

Your privacy notice should accurately explain these activities in language customers can understand. It should not be copied from another website because another business may collect different information or use it for different purposes. Your cookie process should distinguish between cookies required for the website to operate and those used for analytics or advertising. Where consent is needed, the user should be able to accept or refuse those cookies.Businesses should also use processors that provide sufficient guarantees regarding data protection and security. Under Article 28 of the GDPR framework, a processor should act on the controller’s instructions and implement appropriate technical and organisational measures.

Finally, access to customer information should be restricted, systems should be protected and the business should maintain a procedure for responding to a personal-data breach. Where the breach is likely to create a high risk to affected individuals, those individuals may also need to be informed without undue delay. A business should therefore have a process for identifying the breach, limiting the damage, preserving evidence, assessing the risk and recording the response.

In conclusion, data protection should not be treated as a privacy notice added after a website has been built. It should form part of how the business collects orders, manages accounts, selects service providers and communicates with customers. By collecting only necessary information, explaining its use, respecting customer choices and protecting the data securely, an e-commerce business can reduce compliance risks while building greater customer confidence.

Learn more

topic covered in this Articles

READING OUTCOMES

More commercial Articles

UPCOMING FREE TRAINING

Checkbox

DISCOVER

LEARN

contact us today

Useful links

News

Projects

Join Us

Follow Us

About Us

Legal

Scroll to Top