Data is the asset. Mishandling it costs more than a fine.
A fashion or beauty brand lives on relationships: newsletters, loyalty, CRM, retargeting.
Every relationship is personal data.
And every piece of personal data comes with rules: GDPR, ePrivacy, the regulators’ guidance on cookies.
Data protection is not a legal chore to delegate. It is how you decide how much your customer can trust you.
First: know where the data lives
The map we draw with every brand is always the same, and it always surprises.
- eCommerce platform. Customer records, orders, addresses, purchase history. On Shopify you are the controller, Shopify is the processor.
- Marketing automation and CRM. Klaviyo, HubSpot, loyalty platforms: enriched profiles, behaviours, segments. Every tool is a processor you need a signed DPA with.
- Tracking. GA4, Meta Pixel, Google Ads, Clarity: the most sensitive and least visible data flows through here. Without consent, they must not fire.
- Retail and customer care. POS, loyalty cards, tickets, chat: channels often outside the digital perimeter, but inside the GDPR.
Legal bases, plainly
- Contract for everything needed to sell and deliver: order, payment, shipping, returns.
- Consent for newsletters, profiling and personalised marketing. Free, specific, documented, revocable in one click.
- Legitimate interest only where it genuinely holds (anti-fraud, security), with a written assessment.
- Cookies and pixels: prior consent for anything that isn’t strictly technical. A banner where “reject” sits at the same level as “accept”, editable preferences, a consent log.
What we implement in our projects
- Consent Mode v2 in Google Tag Manager: marketing and analytics tags fire only with the matching consent, and the consent is recorded.
- Server-side tracking gated by consent: less data exposed to the browser, more control over what leaves the perimeter.
- A central consent log: who said yes to what, when, and under which version of the privacy notice. It is the evidence you need in an audit.
- Minimisation and retention. Fields collected only when needed, automatic deletion at the end of the retention period, no profiles inactive for years kept in the CRM “just in case”.
- Data subject rights handled as a process: access, erasure and portability within fixed timeframes, using Shopify’s native GDPR requests towards every connected app.
The mistakes we see most often
- Pixels firing before the banner.
- Newsletter consent pre-ticked or buried in the checkout.
- Transfers outside the EU without standard contractual clauses (many US tools).
- A privacy notice copied from another site, describing processing you don’t do and omitting what you do.
- No data breach procedure: you find out what to do while it is happening.
This is the direction
Less data, more useful.
Real consent, not extracted.
Vendors chosen for how they handle data, not only for their features.
A brand with its data in order converts better, because the customer can feel it.