Retail & E-commerce
Data Protection for Jamaican Retailers & E-commerce Businesses
How Jamaican retailers and online stores should manage customer, payment, marketing, delivery and website data under the Data Protection Act.
What you will learn
- How retailers collect data across the customer journey
- What to know about payment and marketing data
- The processors an online store relies on
- How to be ready for a customer-data breach
A modern retailer may collect information across the whole customer journey:
Website → Checkout → Payment → Delivery → Customer service → Returns → Marketing → Loyalty programme.
This creates multiple processing activities, which are easiest to manage in a Personal Data Register.
Typical personal data
Customer name, telephone, email, billing address, delivery address, transaction history, account information, marketing preferences, IP and device information, and customer-service communications. Most of this is ordinary personal data, but the volume and the payment element raise the stakes.
Payment data
Understand what your payment provider processes and what your own systems actually store. Avoid collecting or storing payment information simply because the technology allows it.
Marketing
A purchase does not mean businesses should assume unrestricted permission to use customer information for every future marketing activity. Document what marketing information is collected and why, how preferences and consent are managed where applicable, opt-out and withdrawal mechanisms, and the marketing providers involved.
E-commerce processors
Potential processors include web hosting, your e-commerce platform, email provider, payment gateway, CRM, delivery platform, analytics provider, marketing automation and cloud storage. Some may involve processing outside Jamaica, so review your international transfers.
A common breach scenario
A malicious party gains access to an administrator account and downloads customer information. Your organisation should already know which data was exposed, how many customers, which processor or system, whether sensitive data was involved, and who is responsible for responding. That is exactly what a prepared breach response gives you.
Put this into practice
Generate a privacy notice tuned to online and in-store retail.
Create My Retail Privacy NoticeFrequently asked questions
Key takeaways
- Retailers create many processing activities across the customer journey.
- Understand what your payment provider processes versus what you store.
- A purchase is not unlimited permission for all future marketing.
- Know in advance which data, systems and customers a breach would affect.
Continue learning
Getting Started
What is Personal Data?
Running a Compliant Business
Do I Need Consent?
Data Management
How to Build a Personal Data Register for Your Business
Third-Party Management
Data Processors, When Another Company Handles Personal Data for You
Incidents & Security
What to Do When Your Business Has a Data Breach
