Dealing with personal data during sales
When you are selling products or services you will be In relation to data protection, processing data covers any action taken in respect of the data, including: collecting, storing, using, disclosing and erasing or destroying it. Any information about an identifiable, living person. Information which cannot be used to identify someone on its own will still be personal data if it can be used in combination with other information to identify that individual. about your customers. This section deals with your The area of law which deals with the way in which data can be handled. obligations in this context, including when and how you can collect Any information about an identifiable, living person. Information which cannot be used to identify someone on its own will still be personal data if it can be used in combination with other information to identify that individual. and how you can use it. It provides guidance about your particular obligations when selling from your business premises, by phone or via a website, app or mail-order. It also covers the use of CCTV, e-receipts, bookings, getting customer feedback and running competitions.
Collecting personal data
Collecting personal data when selling from a website or app
Collecting personal data when selling over the telephone
Collecting personal data when selling by mail-order
Collecting personal data when selling from a shop
- 12.What are my data protection obligations when selling from a shop or other business premises?
- 13.Can I use CCTV or other video surveillance on my business premises?
- 14.Do I have to tell people that I am using video surveillance?
- 15.Are there any limitations on what I can use video surveillance for?
- 16.Can I share footage captured by my video surveillance with anyone outside my business?
- 17.Are there restrictions on how I can use personal data I have collected from CCTV?
- 18.Can I collect customer information when taking bookings or appointments?
- 19.What privacy information do I have to give customers about how I will use the personal data that I have collected when taking bookings or appointments?
- 20.Do my data protection obligations end when I have taken the booking or made the appointment?
- 21.Can I send e-receipts to customers?
- 22.What privacy information do I have to give customers when taking email addresses to send e-receipts?
- 23.Do my data protection obligations end once I have sent the e-receipt?
- 24.Can I collect customer information for the purpose of getting feedback on my goods or services?
- 25.What privacy information do I have to give to customers when collecting customer data in the context of service feedback?
- 26.Do my data protection obligations end once I have collected the customer's information?
- 27.Can I collect customer information to run in-store competitions or prize draws?
- 28.What privacy information do I have to give customers when collecting customer information in the context of in-store competitions?
- 29.Do my data protection obligations end once I have collected the customer's information?
Collecting data for NHS Test and Trace
- 30.Do I need to collect data from visitors and customers for NHS Test and Trace?
- 31.Can I refuse entry to my premises to individuals who do not provide me with their personal information for contact tracing?
- 32.How do I comply with the UK GDPR when collecting customers' details for NHS Test and Trace?
- 33.How long do I need to keep information collected for NHS Test and Trace?
- 34.Who can I share personal data with that I have collected for NHS Test and Trace?
- 35.Can I check my visitors' or customers' COVID status?
Using and storing sales data
- 36.Can I use the personal data I have collected from my customers during a sale for other purposes?
- 37.How can I decide whether the new purpose is compatible with the old purpose?
- 38.Can I use personal data I have collected from my customers during a sale for direct marketing purposes?
- 39.Can I share personal data I have collected from my customers during a sale?
- 40.Can I store personal data I have collected from my customers during a sale?
- 41.Can I use a customer's personal data as part of a loyalty scheme?
- 42.What privacy information do I have to provide customers who are taking part in my loyalty scheme?
- 43.Do I need customer consent to process their data as part of my loyalty scheme?
- 44.Do I need separate customer consent if I want to use their data for profiling?
- 45.Do I need to carry out a data protection impact assessment for data profiling?
- 46.Can I share customer data collected as part of a loyalty scheme?