The GDPR, or General Data Protection Regulation, is the European Union law that protects personal data. It applies whenever a business collects or uses information about people in the EU: names, email addresses, delivery addresses, order histories, IP addresses. It has applied since May 2018 and covers businesses of every size, including a solo creator with a newsletter.

It concerns you if you sell to people in the EU or collect their emails, even if your business is based elsewhere. A course creator in Canada with 800 subscribers in France and Germany is in scope for those subscribers. This page gives general information to help you understand the rules. It is not legal advice. For your specific situation, check the official texts, your national data protection authority or a lawyer.

What is the GDPR?

The GDPR is a regulation that sets principles and obligations for anyone who processes personal data. Personal data is any information that identifies a person directly or indirectly. Processing is almost anything you do with it: collecting, storing, sending emails, analyzing, deleting.

The law distinguishes two roles. The controller decides why and how data is used. When you run a store or a newsletter, that is you. The processor handles data on the controller's behalf, such as your email tool, your hosting provider or your e-commerce platform. Controllers must choose processors that offer adequate guarantees and sign a data processing agreement with them.

The GDPR rests on a few principles: use data lawfully, fairly and transparently, only for stated purposes, collect only what you need, keep it accurate, keep it no longer than necessary, and protect it.

It is not only about email consent. Consent is one of six legal bases. Fulfilling an order relies on the contract with the buyer. Keeping invoices relies on a legal obligation. Some analytics can rely on legitimate interest. Newsletters and marketing emails to people who are not customers usually need consent through a clear opt-in.

In the EU, the GDPR works alongside the ePrivacy rules, which cover cookies and electronic marketing. Related terms: data subject (the person the data is about), privacy policy, data breach and data protection officer, a role required only for some organizations.

Why it matters

The GDPR matters for three reasons: trust, deliverability and risk.

Fines can reach 20 million euros or 4% of worldwide annual turnover, whichever is higher, for the most serious breaches. Small businesses rarely face amounts like that, but complaints, investigations and orders to delete data are real. Customers also care. People buy more readily from a store that explains clearly what it does with their information.

A worked example. A jewelry seller has an email list of 2,500 contacts. 600 of them were copied from past order forms without asking for marketing consent. She emails the whole list every week. The 600 unconsented contacts open at 8% and mark her emails as spam far more often, which drags her overall open rate down to 24% and pushes some emails into spam folders. She removes the 600, sends them nothing more, and invites future buyers to opt in at checkout. Her list drops to 1,900, but opens rise to 38%: 722 opens per send instead of 600. A smaller, lawful list reaches more people.

How it works

For a creator or a small store, applying the GDPR comes down to a handful of steps.

  • Map your data. List what you collect (name, email, address, phone, order history), where it lives (store, email tool, spreadsheets) and why you need it.
  • Choose a legal basis for each use. Contract for fulfilling orders, legal obligation for accounting records, consent for marketing emails to non-customers, legitimate interest for some limited uses, with a balancing test.
  • Collect consent properly. Unticked checkboxes, clear wording, a separate choice for marketing, and a record of when and how each person agreed.
  • Publish a privacy policy. Explain in plain words who you are, what you collect, why, how long you keep it, who you share it with and how people can exercise their rights. Link it from your forms and checkout.
  • Respect people's rights. People can ask to access, correct, delete or export their data, object to marketing and withdraw consent. You generally have one month to answer.
  • Make it easy to leave. Every marketing email needs a working unsubscribe link, and requests must be honored promptly.
  • Secure the data. Use strong passwords and multi-factor authentication, limit access, keep sites on HTTPS and avoid sending customer lists around by email.
  • Handle breaches. If personal data leaks, you may need to notify your data protection authority within 72 hours and sometimes the people affected.
  • Check your processors. Make sure your platform, email tool and payment providers have data processing terms and explain where data is stored.

Benchmarks and examples

There is no score for GDPR compliance, but a few reference points help.

Access and deletion requests must be answered within one month, extendable in some complex cases. Breach notifications to the authority are due within 72 hours of becoming aware of a breach that poses a risk. Retention periods depend on the data: accounting records often must be kept for several years under national law, while marketing data about someone who has not engaged for two or three years is often deleted or re-confirmed.

Typical situations:

  • A course creator collects emails for a free lesson with a clear checkbox for her newsletter, and keeps buyers' data to give access to the course they paid for.
  • A small clothing brand ships to five EU countries, keeps order data for accounting and deletes old marketing contacts who never opened an email in two years.
  • A coach receives a deletion request, removes the person from the email list and customer records, but keeps the invoice because tax law requires it.
  • A creator outside the EU with European buyers applies the same rules to them and appoints an EU representative if the law requires it for her situation.

Common mistakes

  • Pre-ticked consent boxes. Consent must be an active choice. A box ticked by default does not count.
  • Adding buyers to marketing without asking. Some countries allow limited emails to existing customers for similar products, with an easy opt-out. Adding everyone to a newsletter by default is risky.
  • A copied privacy policy. A policy taken from another site describes someone else's tools and data. Write one that matches what you actually do.
  • Collecting data you never use. Asking for a birth date or phone number "just in case" increases your risk without benefit.
  • Ignoring requests. An unanswered access or deletion request is one of the most common reasons for complaints.

Best practices

  • Keep a simple data register. A one-page document listing each type of data, its purpose, its legal basis, where it is stored and how long you keep it.
  • Collect less. Ask only for what you need to deliver the order or the content.
  • Separate transactional and marketing. Order confirmations go to everyone who buys. Newsletters go only to people who agreed.
  • Clean your list regularly. Remove or re-confirm contacts who have not opened in a long time.
  • Use tools with clear data terms. Choose platforms that explain their role, security measures and data locations.
  • Prepare a request routine. Know how you will find, export and delete someone's data before the first request arrives.
  • Get professional advice when it matters. If you process sensitive data, sell at scale or have unusual flows, speak with a lawyer or a privacy specialist.

In Roctify

Roctify gives you tools that help with good data practices, but compliance remains your responsibility as the seller, and this section is not legal advice. Your store and link-in-bio page are served over HTTPS. With the Creator plan and up, forms let you collect subscribers for email marketing with wording you control, and your customers, orders and subscribers live in one shared catalog instead of scattered spreadsheets, which makes it easier to find someone's data when they ask. On the Pro plan, exports help you gather data for an access request, and team members let you give each person their own login instead of sharing one account.

Write your own privacy policy that describes the tools you use, including Roctify and your payment providers (Stripe, PayPal), and link it from your forms and checkout. Review Roctify's own terms and data processing documents to understand its role and where data is hosted.

FAQ

Does the GDPR apply to a small creator?

Yes, if you process personal data of people in the EU in the course of a business activity. There is no minimum size. Some record-keeping duties are lighter for small organizations, but the core principles apply to everyone.

Generally no. Order confirmations, shipping updates and receipts are needed to perform the contract with the buyer. Marketing emails are a different matter and usually need consent or a narrow exception for existing customers.

I am not in Europe. Should I care?

If you sell to people in the EU or monitor their behavior online, the GDPR can apply to you for that data. Many other countries have similar laws, so following GDPR principles is a sound baseline wherever you are. Check the rules that apply to your case with a professional.