"GDPR-compliant" is a phrase found in almost every software brochure—but data protection compliance isn’t achieved simply by a label; it results from a combination of software features, hosting location, and well-defined processes. This guide explains exactly what retailers should look for when choosing an e-commerce platform.
At a Glance
- GDPR compliance is a characteristic of the business as a whole, not just the software—the e-commerce platform, hosting, and processes must all work together.
- The server location determines the legal implications of data transfers to third countries: Hosting in Germany or the EU significantly simplifies the legal situation.
- Mandatory features: opt-in cookie consent, tools for providing information and deletion, double opt-in, and data-minimizing default settings.
- “Privacy by Design” means: Data protection is the default setting—not an afterthought.
What makes a store system GDPR-compliant?
Strictly speaking, software alone cannot be “GDPR-compliant”—the merchant, as the operator, is always responsible. However, the e-commerce platform can either enable or prevent compliance. Three levels are interlinked: the software (does it provide the necessary tools?), the hosting (where is the data stored, who has access, is there a data processing agreement?), and the processes (are data subjects’ rights actually being upheld?). If you only look at the feature list, you’ll overlook the other two levels.
Why does the server location matter?
Personal data may only be transferred to third countries outside the EU under specific conditions—the European Court of Justice significantly tightened the requirements for transfers to the U.S. with the Schrems II ruling (C-311/18). For merchants, this means that every U.S. cloud component in their setup (hosting, CDN, analytics tools) creates additional verification and documentation requirements. Hosting in Germany or the EU with a European provider simplifies the situation structurally—the question of standard contractual clauses and transfer impact assessments doesn’t even arise for the core of the online store.
What features should the online store system have?
| Requirement | How to identify them |
|---|---|
| Cookie Consent (Opt-in) | Tracking only begins after active consent—pre-checked boxes have been prohibited since the ECJ’s Planet49 ruling (C-673/17). |
| Data Subject Rights | Access to information, data export, and deletion of customer data must be possible without manual database intervention. |
| Double opt-in | Newsletter subscriptions become active only after a confirmation email is received. |
| Data Minimization | IP masking in statistics, configurable retention periods, guest orders without requiring an account. |
| Data Processing | The hosting/software provider provides a data processing agreement in accordance with Article 28 of the GDPR. |
| Encryption & Access | TLS throughout, role- and permission-based system in the backend, logged admin access. |
Privacy by Design: What Does This Mean in Practice?
Article 25 of the GDPR requires data protection through technical design and privacy-friendly default settings. In practice, this means: By default, the store collects only what is necessary for the purchase—tracking is disabled until the customer consents; forms do not require any unnecessary mandatory fields; retention periods run automatically. A system in which data protection is achieved only by disabling features works against this principle.
What XONIC Offers
The XONIC Shop System is developed according to the principle of Privacy by Design: cookie consent as a true opt-in, double opt-in for newsletters, tools for data access and deletion, IP masking, and data-minimalist default settings are all standard features. Software and hosting come from the same German provider—data is stored on servers in Germany, and the data processing agreement is provided by a single source. As a Chemnitz-based developer, XONIC Solutions has also been keeping pace with ongoing legal changes since 2005, from the button solution to the EU opt-out button. Details about the operating model can be found on the hosting page and in the brief description.
Note: This post does not constitute legal advice. Binding information regarding data protection compliance for your specific setup is provided by data protection officers and specialized law firms.
