
Every order leaves in the shop a name, an address, a phone number and an e-mail. That is personal data, and whoever keeps it has duties: say what it is used for, not keep it longer than needed and answer anyone who asks to see or delete it. The exact rules depend on where your customers are, so here is only what WordPress and WooCommerce already provide, and where to find it. This is not legal advice.
What the shop already has for this
| Tool | Where it is | What it is for |
| Export personal data | WordPress, Tools, Export Personal Data | Give a customer a copy of what the shop holds on them, on request. |
| Erase personal data | WordPress, Tools, Erase Personal Data | Delete or anonymise a customer's data, on request. |
| Accounts and privacy | WooCommerce, Settings, Accounts and Privacy | Policy text at checkout and registration; how long to keep orders and unused accounts. |
| Privacy page | WordPress, Settings, Privacy | Choose the page that the site and WooCommerce display. |
What to do, in order
|
|
|
|
|
|
|
| Deleting a customer does not delete the duty to keep the order. In many countries accounting law requires sales records to be kept for years. WooCommerce can anonymise personal data while keeping the amounts, which is what accountants usually advise. Do not delete orders in bulk without asking them. |
| Security is data protection too. A shop whose customer list is exposed through an out-of-date plugin is a leak. Keep everything updated and the backups working: see personal data protection on your website. |
|
Was there access you do not recognise, or do you suspect customer data got out? Tell us now, with the address and what you saw, and we will look at the logs. Open a support ticket |
|
SEE ALSO Personal data protection: what applies to your website |
RECOMMENDED PRODUCT Web hosting with cPanel Domain and SSL included, daily backups and the panel you already know. from $6.59/mo (3-year plan, with coupon) See plans |
- 0 Users Found This Useful











