Photo: free stock photography (Unsplash licence) — see imprint
Know where personal data actually lives
Not just the customer table. The order export on someone's laptop, the backup from 2021, the support inbox, the analytics tool, the newsletter provider. You cannot protect or delete data you have not located.
Deletion must be a function, not a favour
When a customer asks to be deleted, that must be a button someone can press — including in the systems the shop syncs into. If deletion means 'a developer writes a SQL statement', it will not happen reliably.
Consent before the script runs
A cookie banner that loads the tracking script before the click is decoration. Load nothing until consent exists — this is a technical implementation detail that decides whether the banner means anything at all.
Keep the boring paperwork with the boring systems
Every external service that touches customer data needs a processor agreement, and you should be able to list them in one minute. If nobody can name all of them, that is the finding — not the paperwork.
- Locate every copy of personal data, including exports.
- Deletion has to be a button, not a favour.
- No script loads before consent exists.
Frequently asked questions
We are engineers, not lawyers, so we will not answer yes or no for your company. The question is decided by law — it depends on how many people process personal data, and on the nature and scope of that processing — and the edge cases genuinely need a lawyer or a specialist. What we can do is give that person accurate answers about your systems, which is usually the missing part.
Whether it is legally sufficient is a lawyer's call, not ours. What we can tell you is whether it does what it claims: open the network tab and reload the page. If the tracking script loads before anyone has clicked anything, the banner is decoration regardless of its wording. Fix that first — a legal review of a banner that lies is wasted money.
Technically, it has to be something a person can press — in every system the shop syncs into: CRM, newsletter tool, support inbox, the export sitting on someone's laptop. If deletion means a developer writes a SQL statement when they find time, it will not happen reliably, and the forgotten request is the one that becomes a problem. Which data you may keep, and how long, is a legal question. Build the button either way.
With a map, not a policy. List every place personal data actually lives: the customer table, the backup from 2021, the analytics tool, the newsletter provider, the order export somebody emailed to themselves. Every external service on that list needs a processor agreement. If nobody can name them all inside a minute, that is the finding — and that is where the work starts.
We do this for a living — Shopware, Node.js, React, ERP integration and automation for B2B.
Talk to an engineer