Will the General Data Protection Regulation apply to you?

July 12, 2017 by
Jeroen Leenders

The General Data Protection Regulation (GDPR) will come into effect on the 25th of May 2018. The Brittish government has confirmed that the UK’s decision to leave the EU will not affect the commencement of the GDPR. Most of the European countries have passed the GDPR into their law and will be enforced from May next year.

The EU General Data Protection Regulation (GDPR) replaces the Data Protection Directive 95/46/EC and was designed to harmonize data privacy laws across Europe, to protect and empower all EU citizens data privacy and to reshape the way organizations across the region approach data privacy. The aim is to enable information to be freely shared internally across borders for companies that operate across the EU, but at the same time aims to make it clearer and give more control to individuals as to what companies can do with the data they hold on you.

Many small marketplace traders need not be overly concerned about the implications of the GDPR. However, entrepreneurs still need to be aware of its reach. Comply if necessary, fines can get up to 4% of your (global) turnover. The full impact of the GDPR is only applicable for data controllers and/or processors, i.e. when organizations store information on your customers. If you purely trade on marketplaces and take payment through services such as PayPal, then the impact of the GDPR may be minimal. It’ll be down to the marketplace and payment provider to keep the customer’s data safe and secure. However, if you download customer data and store it on your local hard drive or on a web server then the GDPR definitely applies to you.

The same situation arises if you have your own website/ web shop. If it is a hosted service then you won’t be storing customer data yourself. Again, download your customer data and you need to take a lot more notice of the GDPR. Ultimately, organizations should familiarise themselves with the GDPR requirements which classify more identifiers as ‘personal data’. Under the GDPR even an IP address can be construed as a personal identifier.

If you’re unsure as to how to proceed, the Information Commissioners Office has a data protection self assessment survey to help you get ready for the GDPR. Find key changes of the GDPR here.

Tagged with: , ,
Shein falls into the red ahead of its Hong Kong IPO
Shein has reported a quarterly net loss as the fast-fashion e-commerce giant prepares for its long-awaited initial public offering in Hong Kong. The Singapore-headquartered retailer recorded a net loss of...
July 27, 2026
Notino reaches €1.76 billion as European cross-border growth accelerates
Czech beauty retailer Notino generated €1.76 billion in revenue during its latest financial year, reinforcing its position as one of Europe’s most successful cross-border e-commerce businesses. The Brno-based company closed...
July 24, 2026
Kord raises £6.4 million to unify onboarding, compliance and payments
UK fintech company Kord has raised £6.4 million in Series A funding to expand its platform for customer onboarding, regulatory compliance and payment processing. The round was led by Guinness...
July 21, 2026
Top crossmenu