Privacy notice for an e-commerce website

A privacy notice and cookie notice for an online shop, drafted for the business with guidance on consent, for a fixed fee of £595 in five working days.

Share

Privacy notice for an e-commerce website

Buy now, £595

An online shop collects more personal data than its owner thinks: names, addresses, payment details handled by a processor, order histories, marketing preferences, device data through cookies, and support correspondence, and it shares that data with the payment processor, the delivery company, the email platform, the analytics provider and the marketplace. The privacy notice has to tell customers what the shop does with each, on what lawful basis, who receives it, how long it is kept and what their rights are, and the cookie notice and consent mechanism have to do what the privacy notice cannot. I draft the privacy notice and the cookie notice for the business, with guidance on the consent mechanism, for a fixed fee of £595, delivered in five working days.

Who this is for

Online shops, direct-to-consumer brands and marketplace sellers in England and Wales selling to consumers in the UK and abroad, from a first store to an established retailer whose notice has not kept up with its stack.

What matters in an e-commerce privacy notice

What the notice must tell customers and where it goes

Article 13 of the UK GDPR requires the shop, as controller, to tell customers at the point of collection who it is, what it collects, why and on what lawful basis, who receives the data, whether it leaves the United Kingdom, how long it is kept, what rights the customer has, and how to complain to the Information Commissioner's Office, in concise and plain language; the notice should be linked from the footer, the checkout, the account registration and the newsletter sign-up, layered so that the checkout shows the short version with a link to the full one, and dated and versioned, because a notice nobody can find at the point of collection has not been given.

The data an online shop collects and the lawful basis for each use

The notice should set out the data by purpose and the lawful basis for each: order processing, delivery and payment on the basis that it is necessary for the contract under Article 6(1)(b); fraud prevention, security and the shop's own analytics on the basis of legitimate interests under Article 6(1)(f), with the interest stated; tax and accounting records on the basis of a legal obligation under Article 6(1)(c); marketing on the basis of consent or the legitimate interest the soft opt-in supports; and account data, reviews and support correspondence on the basis that fits each; a notice that lists 'consent' as the basis for everything has got the law wrong and has given customers a right to withdraw that the shop cannot honour for its orders.

Marketing emails, the soft opt-in and the unsubscribe

Electronic marketing to individuals requires consent under regulation 22 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 unless the soft opt-in applies: the shop obtained the details in the course of a sale or negotiations for one, markets only its own similar products, and gave the customer a clear means to refuse at the point of collection and in every message; the notice should explain which the shop relies on, the sign-up and the checkout should implement it (an unticked box for consent, a clear opt-out for the soft opt-in), and every email should carry an unsubscribe that works, because the fines under the 2003 Regulations are for marketing without the basis the notice claims.

Payment processors, delivery companies and the other recipients

The notice should name or describe the categories of recipient: the payment processor (which receives card details the shop never sees and acts as an independent controller for its own fraud and compliance purposes), the delivery companies (which receive names and addresses), the e-commerce platform, the email and marketing platforms, the analytics and advertising providers, the customer service tools, and any marketplace through which orders arrive, with the controller or processor role of each; the shop should have a processor agreement under Article 28 with each processor, and the data protection terms it accepts with its platform are the subject of a separate review.

Regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 requires consent before non-essential cookies and similar technologies are placed (analytics, advertising, personalisation), with only strictly necessary cookies (the basket, the session, security) exempt, and the consent must be given through a mechanism that lets the visitor accept or refuse before the cookies fire, which a privacy notice cannot do; the pack includes a cookie notice listing the cookies by category and purpose and guidance on the consent banner the shop needs (no pre-ticked boxes, refusal no harder than acceptance, analytics and advertising off until accepted), because the regulator's enforcement in this area is against the banner rather than the notice.

Retention, international transfers and customers' rights

The notice should state the retention periods (order records for the period tax law requires, account data while the account is active, marketing data until consent is withdrawn, support correspondence for a stated period), the international transfers the shop makes (to a platform or provider outside the United Kingdom, under the safeguards Article 46 of the UK GDPR requires, which the international data transfer agreement or an adequacy regulation provides), the customers' rights (access, rectification, erasure, restriction, portability, objection, withdrawal of consent), how to exercise them and the one-month time limit, and the right to complain to the Information Commissioner's Office; the shop should be registered with the Information Commissioner's Office under the Data Protection (Charges and Information) Regulations 2018, which the notice can say.

What it costs

Website privacy and cookies pack, £595. Privacy notice, cookie notice and consent guidance. Five working days.

DPA and privacy terms, £795. Data processing agreement plus privacy notice. Five working days.

Buying online forms the engagement on payment. The scope is what the data protection agreements and privacy terms page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.

What you get

  • A data processing agreement that meets the statutory requirements and can be used as a schedule to your main contract
  • A privacy notice written for people to read rather than to be scrolled past
  • Clear allocation of controller and processor roles, which is where most confusion starts
  • International transfer provisions where you use overseas suppliers
  • Sub-processor and security provisions proportionate to what you do
  • A note on the operational steps the documents assume you are taking

What is not included

  • Full compliance audits and data mapping exercises
  • ICO registration, which you do yourself
  • Breach response and regulatory correspondence
  • Cyber security certification such as Cyber Essentials
  • Advice on data protection law outside the UK and EU

Questions I am often asked

Can we email customers about new products without asking?

Under the soft opt-in, if the details came from a sale or negotiations for one, the products are similar and the customer could refuse at the point of collection and can unsubscribe from every email. Otherwise consent is needed. The notice explains which the shop relies on.

Does the privacy notice cover cookies?

The privacy notice explains cookies; the cookie notice lists them; and the consent banner is what the law requires before non-essential cookies fire. The pack includes the first two and guidance on the third.

We use a US email platform. Does that need to be in the notice?

It does, as an international transfer, with the safeguard the shop relies on stated. The notice describes the transfers and the safeguards.


✉️
Not sure which service fits, or want to ask something first? Email me a few lines about your business and what you need. I reply, usually the same working day.

This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: October 2026. Email geoffrey@caesar.co.uk.