DSGVO (E-Commerce) – Definition

The General Data Protection Regulation (GDPR, known in German as DSGVO) is the EU-wide data protection law that has applied since 2018 and governs the processing of personal data within the EU.

For e-commerce operators, GDPR brings concrete requirements: consent management (cookies, tracking), data minimization, data subject rights (access, erasure), and data processing agreements with every service provider — including CMS vendors. In a CMS context, particularly relevant points are: personalization features (what's the legal basis?), the CMS provider's hosting location, and whether the vendor offers a data processing agreement under Art. 28 GDPR. Violations can be penalized with fines of up to 4% of global annual revenue. A practical challenge specific to content platforms is that GDPR compliance isn't a one-time checkbox but an ongoing operational requirement: consent preferences change, data subject deletion requests need to be fulfilled within defined deadlines, and personalization rules need to respect current consent status in real time rather than relying on stale permission data. For SFCC implementations specifically, teams should verify where a CMS vendor's infrastructure and support staff are physically located, since data processed outside the EU can trigger additional cross-border transfer requirements.