GDPR and customer data in retail
Consent storage and secure handling of personal data in CRM
Almost all work in a trading company involves personal data: name, address, phone number, purchase history and often payment information. This makes the Personal Data Regulation – better known as GDPR – something you encounter in practice from your first day in customer service or sales, not just something the lawyers deal with.
§What counts as personal data in a trading company
Personal data is any information that can be attributed to an identifiable person — this applies to both private consumers and contact persons at business customers. Name, email, customer number, IP address and notes in the CRM system about a customer's preferences are all personal data that must be processed according to the rules.
§Legal basis — when are you allowed to process data
You must not just register and use data because it's convenient. There must be a legal basis, and in retail the most common are that processing is necessary to fulfill a customer agreement, that the business has a legitimate interest that outweighs the customer's, or that the customer has given consent.
- 01Agreement — e.g. to save delivery address to be able to send the goods
- 02Legitimate interest — e.g. basic sales statistics without direct marketing
- 03Consent — eg newsletters and targeted marketing
- 04Legal obligation — e.g. the requirements of the accounting act regarding the preservation of documents
§Consent to marketing
If the company sends newsletters or offers, it generally requires active consent from the customer — a pre-ticked box or tacit acceptance is not enough. The consent must be voluntary, specific and informed and the customer must be able to easily withdraw it again without it costing him anything.
§Storage, deletion and data security
Data should only be kept for as long as it is necessary for the purpose it was collected for — accounting documents have a legally mandated retention period, whereas an old quote to a customer that never went anywhere should not sit in the system for years. Access to the CRM system should be limited to employees who actually need it, and if the company uses external IT providers to run the systems, there should be a data processing agreement that regulates how the provider may use and store the data.
| Situation | Legal basis | Example |
|---|---|---|
| Process an order | Fulfillment of contract | Name and delivery address are registered |
| Send offer to existing customer | Legitimate interest | Follow-up offers after a purchase |
| Send newsletter | Consent | The customer has ticked off during registration |
| Store invoices | Legal obligation | Bookkeeping Act retention requirements |
If you are in doubt about a specific situation, there are public guidance — including the Data Protection Authority's guidance aimed at small businesses — that walks you through step by step what is required. It is far cheaper to look it up in advance than to clean up after a mistake when a customer asks to have their information deleted and the company has no idea where it is.