The General Data Protection Regulation (GDPR) and marketplaces: Platform operator obligations in France

Connect

The world’s most successful platforms and marketplaces, including Shopify and DoorDash, use Stripe Connect to embed payments into their products.

Learn more 
  1. Introduction
  2. Key takeaways
  3. Overview of the GDPR
  4. General GDPR obligations for marketplaces
    1. Informing customers and vendors
    2. Obtaining consent
    3. Protecting data
    4. Maintaining processing records
    5. Respecting individual rights
  5. Marketplace obligations for customers under the GDPR
  6. Marketplace obligations for vendors under the GDPR
  7. How Stripe Connect can help
  8. FAQs about the GDPR and marketplaces

As intermediaries, marketplaces collect, store, and process personal data from two target audiences: customers and vendors. As such, marketplaces are subject to strict transparency rules imposed by the General Data Protection Regulation (GDPR), a law that governs the collection and use of personal data in the EU.

It is important for marketplaces to know what the GDPR requires of platforms and who is responsible for personal data. Marketplaces also need to understand how to follow the law. In this article, we explain how the GDPR impacts marketplaces and their obligations to customers and vendors.

Key takeaways

  • The General Data Protection Regulation (GDPR) is the governing legal framework for the management and security of personal data in Europe. Similar to other businesses that process the personal data of EU residents, marketplaces are required to comply with the GDPR.
  • Under the GDPR, marketplaces must provide certain information to customers and vendors and obtain their consent. They must secure personal data, maintain records of processing activities, and make it easy for individuals to exercise their rights.
  • Marketplaces must define their involvement in data processing, establish joint controller contracts if necessary, and conduct rigorous Know Your Customer (KYC) checks to verify their customers.

Overview of the GDPR

The GDPR is a European law that governs the online protection and security of personal data in the EU. It strengthens user rights and helps create a more secure digital environment. The GDPR affects all European businesses – including marketplaces – as well as international platforms that process the personal data of EU residents.

According to the GDPR, data is considered personal if it can be used directly or indirectly to identify an individual. This includes first and last names, email addresses, physical and Internet Protocol (IP) addresses, bank details, phone numbers, identification numbers, and internet behaviour.

For marketplaces, GDPR compliance is mandatory. It can also help build trust with customers and vendors and enhance brand image.

General GDPR obligations for marketplaces

According to Article 13 and Article 14 of the GDPR, platforms must inform customers and vendors that their personal data is subject to processing. For specific types of processing, including targeted advertising and email marketing, vendors and customers must be allowed to consent to the collection and use of their data.

Marketplaces must also ensure adequate data security, maintain records of data processing activities, and allow individuals to exercise their rights.

Informing customers and vendors

Customers and vendors on a platform are entitled to know if their personal data is collected, stored, used, or sent to third parties. At the time data is collected, marketplaces must display privacy policies that state in clear and simple terms the type of data collected, storage period, and purpose of the collection. They must also have a legal basis to justify collection.

Article 6 of the GDPR lists the legal bases for collecting and processing personal data:

  • Execution of a contract
  • Express consent from the individual
  • Compliance with a legal obligation
  • Protection of vital interests
  • Performance of a task conducted in the public interest
  • Pursuit of a legitimate interest (e.g., website security, fraud prevention, internal administration, marketing)

Marketplaces must also inform customers and vendors if their data is shared with third parties (e.g., subcontractors or payment-service providers (PSPs)) and name data recipients. For GDPR compliance, it is important to ensure that privacy policies are easily accessible. For instance, they can be displayed when customers and vendors create accounts or on each webpage.

In certain cases, marketplaces must obtain informed consent from individuals to use their data, particularly when the processing is not based on one of the legal grounds (e.g., the performance of a contract or a legitimate interest).

Specifically, consent is required for email marketing, non-essential cookies, data collection that could lead to discrimination (e.g., by ethnicity or sexuality), and reuse of data for other purposes.

Customers and vendors must be able to consent freely and unequivocally prior to processing. The language used must be clear, simple, and easy to understand. Marketplaces cannot use pre-checked boxes.

Protecting data

A necessary part of GDPR compliance is protecting personal data. Platforms must take reliable security measures and anticipate fraudulent activity. They must encrypt saved data and follow Transport Layer Security (TLS) protocol. This prevents intercepted, leaked, or stolen data from being read. Marketplaces must also comply with Payment Card Industry Data Security Standard (PCI DSS) requirements to protect payment information.

For an extra layer of security, marketplaces can also require Strong Customer Authentication (SCA) when logging into accounts and restrict employee access rights.

Most platforms appoint a data protection officer (DPO) to oversee GDPR compliance. DPOs are useful when processing sensitive data on a large scale. They can provide an impartial assessment of current data management practices and offer advice. Marketplaces must report data breaches to the proper authorities – the Commission for Information Technology and Civil Liberties (Commission nationale de l'informatique et des libertés, or CNIL) – within 72 hours.

Note: Marketplaces with subcontractors (e.g., PSPs or email providers) must ensure that the subcontractors also comply with the GDPR and maintain an appropriate level of security. Article 28 of the GDPR requires signing data processing agreements (DPAs) to govern the use of subcontractors.

Maintaining processing records

According to Article 30 of the GDPR, marketplaces that process personal data online and have more than 250 employees must keep processing records. Records must include detailed descriptions of processing that provide an overview of operations performed. This includes information about involved parties (e.g., controllers, DPOs, and subcontractors), data categories, data use, data recipients, length of storage, and security measures.

Platforms with fewer than 250 employees only need to keep records for certain types of processing.

Respecting individual rights

Any entity subject to the GDPR must respect data protection rights and make it easy for individuals to exercise their rights. These include the right to access, rectify, object to, and restrict processing and the rights to erasure and data portability.

Marketplace obligations for customers under the GDPR

Under the GDPR, marketplaces must follow the rule of minimisation, meaning they must only collect personal data that is strictly necessary for the stated purpose. This principle applies to both customers and vendors.

This means platforms can only collect the minimum amount of information needed for ordering, and platforms are prohibited from collecting data for undefined purposes.

Marketplace obligations for vendors under the GDPR

Marketplaces must define their involvement in data processing. Typically, they are considered controllers of data related to platform operations. This includes creating accounts and categorising products. Meanwhile, vendors are considered controllers of data related to orders placed.

However, marketplaces can be considered joint data controllers if they play an active part in determining the purposes and methods of processing. For example, some marketplaces go beyond connecting customers to vendors and use customer data for targeted advertising or loyalty programmes. In these cases, the parties must sign a joint controllers contract.

This makes strict Know Your Customer (KYC) processes even more important. Marketplaces must verify their commercial partners' identities before doing business with them. KYC helps authenticate vendors and ensure secure, reliable, transparent environments for customers.

Stripe Connect is designed specifically for marketplaces. It handles the KYC process by verifying vendor identities when they register for the platform.

How Stripe Connect can help

Stripe Connect orchestrates money movement across multiple parties for software platforms and marketplaces. It offers quick onboarding, embedded components, global payouts and more.

Connect can help you:

  • Launch in weeks: Use Stripe-hosted or embedded functionality to go live faster and avoid the up-front costs and development time usually required for payment facilitation.

  • Manage payments at scale: Use tooling and services from Stripe so you don't have to dedicate extra resources to margin reporting, tax forms, risk, global payment methods or onboarding compliance.

  • Grow globally: Help your users reach more customers worldwide with local payment methods and the ability to easily calculate sales tax, VAT and GST.

  • Build new lines of revenue: Optimise payment revenue by collecting fees on each transaction. Monetise Stripe's capabilities by enabling in-person payments, instant payouts, sales tax collection, financing, expense cards and more on your platform.

Learn more about Stripe Connect or get started today.

FAQs about the GDPR and marketplaces

The content in this article is for general information and education purposes only and should not be construed as legal or tax advice. Stripe does not warrant or guarantee the accuracy, completeness, adequacy, or currency of the information in the article. You should seek the advice of a competent lawyer or accountant licensed to practise in your jurisdiction for advice on your particular situation.

More articles

  • Something went wrong. Please try again or contact support.

Ready to get started?

Create an account and start accepting payments – no contracts or banking details required. Or, contact us to design a custom package for your business.
Connect

Connect

Go live in weeks instead of quarters, build a profitable payment business, and scale with ease.

Connect docs

Learn how to route payments between multiple parties.