Handling personal data in the EU/EEA

To complete an online purchase, you need information that identifies the buyer. Strict regulations govern how you handle this personal data.

Requirements

The EU/EEA has rules governing the processing of personal data, known as the General Data Protection Regulation (GDPR). The purpose of the regulation is to adapt the rules to a more digital society and strengthen citizens' rights.

Businesses that collect and/or store personal data must already have procedures in place to comply with data protection legislation. The reform introduces stricter requirements for handling personal data, which means that more companies will need to change their data processing procedures.

The company’s management is responsible for establishing these procedures, but everyone in the company must be familiar with them.

Data collection

When your business asks a customer to provide personal data and stores it in the online shop's systems, this legislation imposes certain obligations on those who collect the data (usually the owners and operators of the online shop) and gives the person concerned certain rights.

If you use a third party to operate parts of your online store (outsourcing), giving people other than your own employees access to or use of the personal data collected, certain rights and obligations will arise between those who process the personal data and you as the data controller. It is therefore important to have robust agreements in place between the data processor and the data controller.

New regulations

As mentioned, legislation governing these matters already existed in the EU, but on 14 April 2016, the European Parliament adopted a new data protection regulation. As a result, new data protection legislation came into force in Norway on 25 May 2018, at the same time as in the rest of the EU.

Understanding new regulations, developing new procedures and training employees all require resources. It is therefore important that your business has a plan for meeting the new obligations and allocates sufficient resources to this work.

In simple terms, the new rules introduce the following changes affecting the e-commerce sector:

More detailed regulation, greater harmonisation and tighter rules across member states. The regulation allows for some local adaptations, but to a much lesser extent than before. Even companies outside the EEA that sell goods or services online within the EEA must comply. More consistent rules also make cross-border trade easier and reduce bureaucracy for businesses. Individual rights have also been strengthened. The new rules make it easier for people to erase their digital footprint and give them the right to data portability. This means that citizens can request their digital identity data, such as personal information held by a bank, in a machine-readable format.

The new regulations impose stricter requirements for information and consent, as well as for demonstrating the necessity of processing personal data. If you need to provide personal data when making a purchase, such as your name and address, you must be informed of your right to access the data stored about you and the purpose for which it is collected.

The rules in the new legislation clarify what companies that handle personal data must do. Companies must meet stricter requirements for systems and internal controls when processing personal data. You must also consider data protection at every stage when developing or implementing new products, services and systems. Data protection must be the default setting. This approach requires you to consider information security and data protection from the very first stage of the process.

There is also a separate section designed to strengthen cooperation between the data protection authorities in the various member states. The aim is for businesses and individuals to deal with only one supervisory authority, making it simpler and less costly to do business in the EU.

Data protection authorities have the power to impose higher fines than before on anyone who fails to comply with the new GDPR rules. Companies that do not comply risk fines of up to EUR 20 million or 4% of their global annual turnover. Companies should therefore pay closer attention to internal controls and compliance requirements.

For more information about what the new data protection rules mean for your business in practice, visit the website of the Norwegian Data Protection Authority.

Published 3 Dec 2018Last updated 28 Sep 2023
This page is translated with the assistance of AI