You may process customer personal data only with a valid legal basis, most commonly contract performance, a legal obligation, legitimate interests or consent. Core duties include informing individuals, enabling them to exercise their rights, securing the data appropriately and notifying the supervisory authority of serious breaches without undue delay. The scope depends on what you process and why.
What legal basis do I need for processing?
Personal data processing is governed by the directly applicable GDPR (Regulation (EU) 2016/679) and Act No. 18/2018 Coll. on Personal Data Protection. The first question is what legal basis supports the processing, rather than what consent to request. Article 6(1) GDPR recognises six bases:
- The individual’s consent.
- Performance of a contract, or steps before entering into it at the customer’s request.
- A legal obligation.
- Protection of the vital interests of the individual concerned or another natural person.
- A task in the public interest.
- The legitimate interests of the controller or a third party, unless overridden by the individual’s interests and rights.
Protection of property is not in itself a vital interest. Depending on the circumstances, it may support a legitimate interest after assessing the applicable conditions and the rights of the individuals concerned.
For an ordinary online shop, order fulfilment relies on contract performance, retention of accounting documents on a legal obligation, and debt recovery on legitimate interests. Consent is unnecessary, and requesting it “just in case” is a mistake. Consent belongs where another basis is absent, typically newsletters and marketing.
When is consent valid?
If you rely on consent, it must be freely given, distinguishable from other text, understandable and withdrawable at any time in the same way it was given (Section 14 of Act No. 18/2018 Coll.). You cannot force consent by withholding a service for which it is not actually necessary.
Other GDPR duties
Beyond establishing a legal basis, you must meet other GDPR requirements:
- Transparency: clear processing notices explaining who processes what, why, for how long and to whom data is disclosed.
- Respect for individual rights, including access, rectification, erasure, restriction, portability and objection.
- Appropriate data security.
- Data processing agreements with suppliers processing data for you, such as hosting, email services and external accounting.
- Notification of personal data breaches to the supervisory authority without undue delay and, where the risk is higher, communication to affected individuals.
- For large-scale or high-risk processing, an impact assessment and, where applicable, appointment of a data protection officer.
We prepare processing activity audits, privacy notices and data processing agreements through our GDPR and personal data protection service. For online shops, we combine this with terms and conditions in our e-commerce legal services package.
This answer provides general information on the law as at 10 September 2026. It does not constitute legal services or replace an assessment of an individual case. The details of your situation may differ. Book a consultation to discuss them.