Skip to content
RU

Personal data in an online store

Key idea:

A store has three distinct legal bases, and mixing them is the classic mistake. Processing order data (name, address, phone) is lawful without separate consent — it is contract performance. Marketing mail requires its own consent with an unchecked box. Passing data to a courier or payment service is delegated processing that the policy must describe. Most stores fail with a single "agree to everything" checkbox.

Check your site →

Three bases — three regimes

  • The order: name, phone, delivery address — processing for contract performance (Art. 6(1)(5) of 152-FZ), no separate consent, but the policy must describe it
  • Mailings: separate consent, a separate unchecked box; "bought = subscribed" violates both 152-FZ and the advertising law
  • The account: keeping order history beyond contract performance is its own purpose, reflected in the policy

Couriers, payments, CRM

Every external service receiving buyer data is either a delegated processor (courier, fulfilment, CRM) or an independent operator (payment service). The policy lists recipient categories and transfer purposes; delegated processors get a contract with data-protection clauses. A foreign service in this chain adds cross-border transfer with an RKN notification.

Checklist and verification

  1. The mailing checkbox is separate from checkout and unchecked
  2. The policy describes orders, delivery, payments and mailings as distinct purposes
  3. The policy link sits in the checkout form, not only in the footer
  4. Counters and pixels load with consent in mind

The compliance scanner checks the store's cart and forms across several pages: forms without consent, missing documents and foreign trackers, with fine-exposure estimates.

Related

Cookies Before ConsentWhat is written without permission
Consent BannerIs there an equal Reject option
PII FormsConsent and policy at the form
Projections152-FZ and GDPR grades

Why teams trust us

A–F
grade + 152-FZ/GDPR
3
browser sessions per page
PDF
integrity-signed report
Free
scan without signup

How it works

1

Enter your site URL

2

The scanner opens pages in a browser

3

Get a grade and a fix list

Why check your site for privacy compliance?

Regulators fine sites for processing personal data without consent — and a site starts processing earlier than it seems: analytics, pixels and widgets write cookies the moment the page loads. The scanner shows the auditor's view: what leaves for third parties before consent, whether the banner works, and whether forms collect data correctly.

Real Browser

Three sessions per page: no action, banner accepted, banner rejected.

Trackers and Jurisdiction

Service catalogue: who receives visitor data and in which country.

Policy at Collection Point

The policy link and consent element are checked next to the form, not in the footer.

Signed PDF

Report with an HMAC integrity stamp — hand it to your lawyer or contractor.

Who uses this

Business

preparing for an audit

Lawyers

technical facts for an opinion

Web Studios

client site handover

DevOps

consent regression monitoring

Common Mistakes

Loading analytics before consentA counter in writes cookies before any banner. This is exactly what an audit records.
Banner without a Reject buttonConsent is voluntary only when refusing is as easy as agreeing.
Policy only in the footerThe visitor must see who receives their data at the moment of submission — next to the form itself.
Checking once and forgettingA new widget or tag manager quietly adds trackers. Only a re-check catches the regression.

Best Practices

Delay trackers until consentInitialise analytics from the CMP accept callback, not on page load.
Offer an equal RejectAccept and Reject buttons — same size, same level.
Consent checkbox at every formUnchecked by default, with the processing policy linked right there.
Turn on monitoringA standing watch alerts you when the grade drops — before an auditor notices.

Monitor compliance automatically

Scheduled re-checks with an alert when pre-consent trackers appear on your site.

Sign up free

Learn more

Frequently Asked Questions

Is a consent checkbox needed in the checkout form?

For the order itself — no; the basis is contract performance, a policy link suffices. A checkbox is needed for extra purposes: mailings, partner transfers, profiling.

A buyer asks to delete their data. Must we?

Yes, on the subject's request — with a caveat: data required by law (accounting, taxes) is kept for the statutory periods, and the buyer gets a reasoned reply about it.

Are courier services my processors?

Yes — delivery on your instruction. The "delivery services" recipient category and the purpose belong in the policy, and the contract with them needs data-processing clauses.

Try the live tool that powered this guide

Free plan — 10 monitors, checks every 5 min, no card required. Upgrade for 1-minute interval and multi-region monitoring.