EXPLOREINDUSTRIESGUIDESLEARNGLOSSARYBOOKSWHITEPAPERTOOLSRESOURCESPIONEERMARKETSCOUNTRIESFEESMISSION FUNDPASSPORT
SUPPORTLOGINJOIN THE PROTOCOL →
GETREADYANDJUMP.COM · BUILT IN DETROIT

DATA PRIVACY
ON PROTOCOL.

Data Privacy on the GRAJ protocol. One fee. 195 countries. Join the protocol.

JOIN THE PROTOCOL →
Guide

DATA PRIVACY
FOR SELLERS.

Reference

The moment you sell to a consumer you are processing personal data, and the rules follow the person rather than your address. A brand in one country selling to a customer in another is subject to the customer's law, which is the part that surprises people.

The obligations that apply almost everywhere

The details differ by jurisdiction; the shape does not. Collect what you need, say what you are doing with it, keep it safe, and let people see and delete it.

  • A lawful basis for processing, decided before you collect
  • A privacy notice that says what you actually do
  • Access and deletion requests answered within a deadline
  • Breach notification, often within 72 hours

Transfers across borders

Moving personal data out of the EU or the UK needs a specific legal mechanism. Using a US-hosted tool for European customer data is a transfer, whether or not it feels like one.

Wholesale is not exempt

Business contacts are still people. A buyer's name, work email and phone number are personal data in most regimes, and a marketing list built without a basis is the most common enforcement case.

The practical minimum

Know what you hold and why, do not collect what you will not use, and be able to find everything about one person when they ask. Most of the cost of compliance is retrofitting it onto data you never mapped.

Where to go next
/privacy/compliance/coppa/compliance
JOIN THE PROTOCOL