Skip to content

GDPR and customer data in retail

Consent storage and secure handling of personal data in CRM

Almost all work in a trading company involves personal data: name, address, phone number, purchase history and often payment information. This makes the Personal Data Regulation – better known as GDPR – something you encounter in practice from your first day in customer service or sales, not just something the lawyers deal with.

§What counts as personal data in a trading company

Personal data is any information that can be attributed to an identifiable person — this applies to both private consumers and contact persons at business customers. Name, email, customer number, IP address and notes in the CRM system about a customer's preferences are all personal data that must be processed according to the rules.

§Legal basis — when are you allowed to process data

You must not just register and use data because it's convenient. There must be a legal basis, and in retail the most common are that processing is necessary to fulfill a customer agreement, that the business has a legitimate interest that outweighs the customer's, or that the customer has given consent.

  • 01Agreement — e.g. to save delivery address to be able to send the goods
  • 02Legitimate interest — e.g. basic sales statistics without direct marketing
  • 03Consent — eg newsletters and targeted marketing
  • 04Legal obligation — e.g. the requirements of the accounting act regarding the preservation of documents

§Consent to marketing

If the company sends newsletters or offers, it generally requires active consent from the customer — a pre-ticked box or tacit acceptance is not enough. The consent must be voluntary, specific and informed and the customer must be able to easily withdraw it again without it costing him anything.

§Storage, deletion and data security

Data should only be kept for as long as it is necessary for the purpose it was collected for — accounting documents have a legally mandated retention period, whereas an old quote to a customer that never went anywhere should not sit in the system for years. Access to the CRM system should be limited to employees who actually need it, and if the company uses external IT providers to run the systems, there should be a data processing agreement that regulates how the provider may use and store the data.

SituationLegal basisExample
Process an orderFulfillment of contractName and delivery address are registered
Send offer to existing customerLegitimate interestFollow-up offers after a purchase
Send newsletterConsentThe customer has ticked off during registration
Store invoicesLegal obligationBookkeeping Act retention requirements

If you are in doubt about a specific situation, there are public guidance — including the Data Protection Authority's guidance aimed at small businesses — that walks you through step by step what is required. It is far cheaper to look it up in advance than to clean up after a mistake when a customer asks to have their information deleted and the company has no idea where it is.