Skip to content
Menu

Regulation explainer

GDPR for small importers and resellers: common questions answered

small importers and resellers shipping to European Union. Drafted with AI assistance from the regulation dataset and approved by a person before publication; see the editorial policy.

Guide

If you handle customer or supplier data from EU contacts, here are answers to the questions importers and resellers ask most about GDPR.

What is GDPR and who does it apply to?

GDPR (General Data Protection Regulation (EU) 2016/679) is the European Union's law on how personal data is collected, stored, and used. It applies to any business that processes personal data of people in the EU, regardless of where the business itself is based. If you import or resell goods to EU customers and hold their names, addresses, or payment details, GDPR applies to you.

Does GDPR apply if my company is outside the EU?

Yes. GDPR follows the data, not the company's location. If you ship to EU customers and collect their personal information for orders, invoicing, or marketing, you are subject to GDPR requirements in the same way an EU-based business would be.

What documents do I need for GDPR compliance?

The core documents are a GDPR-compliant privacy policy, a Data Processing Agreement (DPA) with any processors you use, and Records of Processing Activities (RoPA). Depending on your operations, you may also need a Data Protection Impact Assessment (DPIA) if your processing is high-risk, a Data Protection Officer (DPO) appointment, and a cookie consent mechanism on your website.

Do I need a Data Protection Officer?

Not every business needs a DPO. Whether a DPO appointment is required depends on the scale and nature of your data processing. It is worth checking this against your own operations rather than assuming either way.

What is a Data Processing Agreement, and when do I need one?

A DPA is a contract between you and any third party that processes personal data on your behalf, such as a logistics provider or email platform. It sets out each party's responsibilities for handling that data under GDPR. If you use outside processors for EU customer data, a DPA should be in place with each one.

Do I need cookie consent on my website?

If your website uses cookies to track visitors from the EU, a cookie consent mechanism is one of the standard GDPR requirements. This is separate from your privacy policy, though the two usually work together.

Where does GDPR fit alongside other compliance checks?

GDPR is one piece of a wider compliance picture that includes [supplier compliance](/supplier-compliance) checks for products entering the EU. Keeping data documentation alongside product and supplier records makes it easier to respond if a customer, partner, or regulator asks questions.

You can read more about the regulation itself on the [GDPR](/regulations/gdpr) page, or use Complyra to keep track of where your documentation stands.

Complyra checks product and supplier information against regulatory requirements to support procurement decisions. It does not issue certifications or guarantee legal compliance; final responsibility for compliance remains with the buyer and supplier.

Related