💡 In short: This page explains how data protection law applies to merchants selling on our platform.
⚖️ Status of Merchant under Data Protection Law
As part of the Supplier Agreement between refurbed and the merchant, merchants have entered a Joint Controller Agreement. This means that both refurbed and the merchant are responsible for how personal data of customers is processed.
As a (joint) data controller, merchants must be in compliance with data protection law.
💽 Personal Data
Personal Data is all information that can be linked to a customer. For our merchants, this will typically be:
- Customer Basic Data (Name, Title)
- Contact Details (Telephone Number, e-mail address)
- Purchase Information (Purchased Product, Price)
- Communication Records (e-mail, chat)
☑️ Merchant Compliance Measures
In case of suspected breach of data protection law, the regulator authority may investigate refurbed or merchants and will demand proof that all processing operations are legally compliant. It is very important that merchants comply with all necesarry requirements under data protection law.
Under the GDPR, merchants must (among other things!) ensure the following:
-
identify a valid purpose for the data processing.
▶️ Merchant’s purpose for data processing will usually be Art. 6 (1) b, c, and f depending on the exact process. This means that merchants will process data to “perform a contract”, “comply with legal obligations”, or “due to legitimate interests”.
-
maintain a privacy notice
▶️ Merchants must provide information about their data processing operations to customer, both on their own website and make it available on the refurbed platform.
-
maintain a record of processing activities
▶️ Merchants must maintain an overview over their data processing operations, which data is used, and how it is transferred. In case of an investigation, this record will be the first thing an authority will request.
-
comply with data subject rights
▶️ under the GDPR, customers have wide-ranging rights and can request in particular a copy of their personal data and the deletion, restriction or correction of their personal data. Merchants should always contact refurbed if a customer exercises these rights. If a customer contacts refurbed directly, refurbed will forward this query to the merchant and the merchant must comply with the data subject rights immediately.
-
minimise data processing
▶️ wherever possible, merchants should minimise the personal data they receive and process; this includes deletion of personal data when no longer necessary
-
controll data processors
▶️ merchants are responsible for each other company or software provider they use to process data. Merchants must properly review and vet these companies (in particular if they transfer data to third countries!)
-
ensure adequate information security
▶️ Merchants must maintain a secure IT infrastructure and handle personal data with confidentiality both re. internal and external actors. Data breaches are the most common incidents that leads to fines and regulatory action. Merchants are liable for all damages to refurbed caused by a data breach, so adequate it security such as encryption, confidentiality, back-up operation, etc. are key. These measures should be documented in an overview over Technical and Organisational Measures (TOM).
-
notify breaches to refurbed immediately and to authorities and data subjects if necessary
▶️in case of a data breach, merchants should contact refurbed immediately. If the breach is substantial enough, merchants may also be obliged to notify the breach to their respective data protection authority and/or the data subject. merchants should document all (potential) breaches and their response wherever necessary.
❗If a merchant send a customer the wrong device or the device still has personal data on it, this is a data breach!
-
controll third country transfers
▶️ when merchants transfer personal data outside of the EEA, they can do so only on the basis of a so called adequacy decision or on the basis of additional safeguards. Adequacy decisions can be found here. If there is no adequacy decisions, merchants will usually rely on an addendum to their data processing agreements with their partner called Standard Contractual clauses. Merchants must conduct a Data Transfer Impact Assessment for these transfers, where they analyse the risk of the data transfer. It is the merchant’s responsibility to ensure that third country transfers are properly de-risked and legally sound!.
⏩As a result, each merchant should have at a minimum the following written up-to-date documents:
📜 privacy notice
📜 template for responding to data subject inquiries
📜 overview over Technical and Organisational Measures to ensure data security
📜 list of (potential) data breaches and measures taken
📜 data transfer impact assessments for data transfer in third countries without adequacy decision
📜 record of processing activities
📜 data retention / deletion concept
Depending on the merchant, additional GDPR measures may be necessary or appropriate.
📩 Point of Contact
Refurbed’s Privacy and Data Protection Competence Center is available at dataprotection@refurbed.com.
📜Legal Basis:
🇪🇺 European Union: General Data Protection Regulation (GDPR)
❗ Local Legislation may apply