GDPR Update

PrivacyPolicy

GDPR Update

Your XONIC web store is GDPR-compliant by default—just keep your privacy policy up to date, and the system will take care of the rest.

GDPR Update: XONIC Shop System

GDPR Update for Your XONIC Web Store

You’ve surely heard of the new European General Data Protection Regulation (GDPR), which will replace the German Data Protection Act as of May 25, 2018. Due to the new EU data protection guidelines, all online store operators will also face changes to their store systems.

To address this, we’re providing a brief interim update that includes the following changes.

First things first: Your XONIC package comes with technical GDPR compliance as standard—all you need to do is keep your privacy policy up to date.


Changes to the Store

1.) Declaration of consent via a notice or checkbox when collecting customer-related data

Users must be informed about the collection and processing of their data or must actively consent to it. This applies to every page in the store where the customer enters personal data. However, active consent is still a matter of debate; the period following May 25, 2018, will show whether this becomes mandatory.

Consent can be obtained via a notice or a checkbox. To be on the safe side, you should use the checkbox. Both options can be configured under “My Store” > “Privacy Consents…”.

Option with a checkbox:

GDPR Contact Request

Option without a checkbox, using only a notice:

GDPR Contact Request 2

The following pages in the store where personal data is collected have been modified to comply with the GDPR:

  • Contact Request
  • Ticket system
  • Product Inquiry
  • Price Quote
  • Price Inquiry
  • Customer Registration
  • Order Completion
  • Callback
  • Guestbook
  • Newsletter (Footer, Customer Account...)
  • Review platforms Ekomi and Trusted Shops (collection via customer registration or in the customer account)

The layout of the pages has also been changed, as the GDPR requires adherence to the principle of data minimization. This means that providing a name must be voluntary, and only one contact method may be a required field. Therefore, in the future, customers will only be required to provide either an email address or a phone number.

With us, you also don’t have to manually insert code snippets into forms, as you would with other providers.


2.) Declaration of consent via a checkbox for shipping methods, if the email address is to be shared with the shipper

If, in addition to the address information—which is, of course, absolutely necessary for order fulfillment—you also wish to share the customer’s email address or phone number, you must obtain the customer’s consent in advance. In this case, we will also (as in point 1) add a new configuration value in Configuration --> My Shop. You’ll find this under Configuration --> My Shop “Data Protection Consents…”. By default, no data (email/phone) will be shared via API or export file. Consent will then be obtained during checkout when selecting a shipping method, if enabled.


3.) Opt-out cookie for Google Analytics, etc.

In the future, you must clearly inform customers in the privacy policy exactly what data you collect. A new requirement is that you must give customers the option to opt out of this. To this end, we’ll integrate corresponding sliders on the privacy policy page, which customers can use to deactivate the relevant services. If a service is deactivated, an opt-out cookie is stored and no further scripts are executed. This primarily affects xoStats and Google Analytics.

If you have integrated custom tracking tools that collect and share data, you should implement individual sliders for each one.

If you use Google Analytics, you must enter into a data processing agreement (DPA) with Google. You can complete this electronically in your Google Analytics account at the very bottom of the left column under Admin --> Account Settings > “Data Processing Addendum.” In addition, you should configure the new “Data Retention” feature so that the data collected by Google is automatically deleted after a specified period of time. You can find this setting under “Admin” → “Property” → “Tracking Information” → “Data Retention.”


4.) SSL Encryption on All Pages

With the GDPR, starting May 25, 2018, it will be necessary to encrypt all pages that collect personal data using SSL. Furthermore, unencrypted websites are marked as “not secure” in browsers, and Google also prioritizes websites with encryption. A domain-validated SSL certificate is therefore mandatory for all online store operators as of May 25, 2018.

If you do not yet have your own certificate and host with us, you can order it on the following page:

If you use your own hosting provider, please contact them. Once you have ordered the certificate, it must be configured in your online store. To do this, you must order the following service:


5.) Logging of Consent Obtained

Every instance of data collection or consent (when a customer submits a contact form, subscribes to a newsletter, etc.) should be logged going forward. For this purpose, there will be a new page in the V3 Shops admin panel that provides this information. Later, this overview will also be linked to the customer’s account as soon as the customer creates one.

Data Protection Management


Changes to the Privacy Policy by Shop Operators

Starting May 25, 2018, you will also need a new GDPR-compliant privacy policy. You can have this created by Janalow and many other legal portals (TrustedShops, IT Rechtskanzlei, eRecht24, etc.) or by your attorney. The new privacy policy should also include a notice explaining the nature, scope, and purpose of data collection and use. Additionally, the privacy policy will be attached to the order confirmation.


GDPR Compliance – Standard in Every XONIC Package

Data protection is mandatory in e-commerce—and in many shop systems, it’s an expensive add-on. With XONIC, GDPR compliance is built right in: included in every package, at no extra charge, and without any code tweaking. The SSL certificate is also included in the hosting package and is set up automatically.

As a store operator, all you need to do is keep your privacy policy up to date—the system takes care of the rest. We’re also happy to answer any questions about the GDPR over the phone.