Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking & Finance Review®

Global Banking & Finance Review® - Subscribe to our newsletter

Company

    GBAF Logo
    • About Us
    • Advertising and Sponsorship
    • Profile & Readership
    • Contact Us
    • Latest News
    • Privacy & Cookies Policies
    • Terms of Use
    • Advertising Terms
    • Issue 81
    • Issue 80
    • Issue 79
    • Issue 78
    • Issue 77
    • Issue 76
    • Issue 75
    • Issue 74
    • Issue 73
    • Issue 72
    • Issue 71
    • Issue 70
    • View All
    • About the Awards
    • Awards Timetable
    • Awards Winners
    • Submit Nominations
    • Testimonials
    • Media Room
    • FAQ
    • Asset Management Awards
    • Brand of the Year Awards
    • Business Awards
    • Cash Management Banking Awards
    • Banking Technology Awards
    • CEO Awards
    • Customer Service Awards
    • CSR Awards
    • Deal of the Year Awards
    • Corporate Governance Awards
    • Corporate Banking Awards
    • Digital Transformation Awards
    • Fintech Awards
    • Education & Training Awards
    • ESG & Sustainability Awards
    • ESG Awards
    • Forex Banking Awards
    • Innovation Awards
    • Insurance & Takaful Awards
    • Investment Banking Awards
    • Investor Relations Awards
    • Leadership Awards
    • Islamic Banking Awards
    • Real Estate Awards
    • Project Finance Awards
    • Process & Product Awards
    • Telecommunication Awards
    • HR & Recruitment Awards
    • Trade Finance Awards
    • The Next 100 Global Awards
    • Wealth Management Awards
    • Travel Awards
    • Years of Excellence Awards
    • Publishing Principles
    • Ownership & Funding
    • Corrections Policy
    • Editorial Code of Ethics
    • Diversity & Inclusion Policy
    • Fact Checking Policy
    Original content: Global Banking and Finance Review - https://www.globalbankingandfinance.com

    A global financial intelligence and recognition platform delivering authoritative insights, data-driven analysis, and institutional benchmarking across Banking, Capital Markets, Investment, Technology, and Financial Infrastructure.

    Copyright © 2010-2026 - All Rights Reserved. | Sitemap | Tags

    Editorial & Advertiser disclosure

    Global Banking & Finance Review® is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    1. Home
    2. >Business
    3. >WHAT MERCHANTS NEED TO KNOW ABOUT PROTECTING CUSTOMERS AND NEW REGULATIONS
    Business

    What Merchants Need to Know About Protecting Customers and New Regulations

    Published by Gbaf News

    Posted on November 10, 2017

    19 min read

    Last updated: January 21, 2026

    Add as preferred source on Google
    Image of Northvolt's battery manufacturing facility, highlighting its ongoing efforts to secure bankruptcy financing for restructuring and continuing operations in the EV battery market.
    Battery production facility of Northvolt amid bankruptcy financing efforts - Global Banking & Finance Review
    Why waste money on news and opinion when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    A guide to understanding GDPR implications

    Millions of people work, shop and play online every day, leaving behind volumes of data that can include sensitive information. A study by IDC estimates that by 2020 there will be 5,200GB of data for every consumer on earth. In total, that works out at 40 zettabytes, or 57 times more than every grain of sand on every beach.[1]

    Catherine Moore

    Catherine Moore

    Regulators have increasingly become concerned with how companies capture, manage and protect the swathes of data they hold on their customers. Within the European Union (EU), these concerns have resulted in the General Data Protection Regulation (GDPR),a new regulation which aims to give consumers greater rights and security over how their data is used.

    GDPR is the most comprehensive framework of its kind in the world and will have profound implications not just for businesses operating in the EU,but any that hold data on EU citizens. Companies in breach of GDPR could face severe fines, and with an implementation date of 25 May 2018, time is running out to ensure compliance.

    Merchants, which frequently come into contact with sensitive customer information like payment details, will have to be especially ready.

    What is GDPR?

     GDPR will effectively replace the EU Data Directive, which was established in 1995, during the early days of the internet, but is now considered inadequate to deal with current challenges. This is understandable considering the average smartphone today has 10x more processing power than a PC in 1995,[2]while eCommerce sales are over €500billion a year in Europe alone.3

    The new legislation establishes guidelines on how companies should handle customer privacy, store data securely, and respond to security breaches. It also attempts to offer a unified standard of operating across Europe so that companies do not have to deal with several regulatory environments.

    For the first time, obligations will be placed on data controllers and data processors. In other words, GDPR will affect not just an organisation (the controller) but also its outsourcing provider (e.g., a cloud computing company, or a third-party payment provider). Previous legislation placed responsibility solely on the controller.

    GDPR also addresses the export of personal data outside the EU. The legislation makes it clear that it does not just apply for European companies, but any business processing the data of EU citizens, even if not based in the EU.

    GDPR at a glance

    •  GDPR was adopted in 2016 and will become effective on May 25, 2018
    •  Applies to businesses in the EU and any company worldwide that holds data on EU citizens
    • Applies to data controllers and data processors
    • Fines can be up to 4 percent of annual worldwide turnover or €20million, whichever is greater
    •  Claims can be made by individuals and organisations

    Data management, portability and customer rights

    At the heart of GDPR are a number of changes to the way that customer data is handled.Under the legislation, customers will have to give explicit permission for companies to hold data about them. But that’s not all, companies must also provide evidence that this consent has been given. One potential implication is that merchants may have to alter their auto-renewal and subscription payment processes.

    Companies can no longer store a customer’s personal data simply because it may prove useful in the future, or so they can pass it on to another provider. From now on, the responsibility will be on businesses to justify why they’re retaining customer information, otherwise it may have to beerased.

    There’s another important element too, one that has a historical precedent. In 2014, a Spanish property owner who’d had his house repossessed wanted this fact removed from Google searches. He took the case to the European Court of Justice (ECJ) which ruled that Google had to delete those references to him. 

    GDPR: Key implications for merchants

    Consent Companies will have to actively get consent to store a customer’s personal data
    Customer profiling New restrictions on using data for customer profiling
    Security and data breaches Data breaches have to be reported within 72 hours of discovery
    Data portability Consumer has right to request transfer of personal data in certain circumstances
    Data transfer Prohibitions on transferring data to non-EEA* countries without adequate safeguards

    *The EEA includes EU countries and also Iceland, Liechtenstein and Norway. It allows them to be part of the EU’s single market.

    Right to be forgotten A business must erase an individual’s personal data in certain circumstances
    Security Businesses must have security systems that are appropriate to the level of risk

    This quickly became known as the ‘right to be forgotten’ and, following the ECJ case, it has been included in GDPR.

    As such, businesses will need to implement new policies on data retention and deletion. According to Catherine Moore, President of J.P. Morgan Merchant Services in Europe, this will mean a new mindset for some firms: “In certain industries, data might be retained forever because a regulator might ask for it. In others, the erasing of data has not been high on the priority list as there’s been no reason for doing it.”

    The right to be forgotten is a particular challenge for organisations because of the rich web of information that’s held in databases. Whereas companies may have previously been concerned about how to store and archive information, now the focus is turning to what information is held and how they can access it. For example, a merchant may have to remove someone’s personal information from all of their payment transaction record histories; if they so request.

    It’s also important to realise that data does not just mean information held on a database. GDPR makes no distinction between physical and digital data: it could be customer details held on paper, or in old files at a warehouse, for example. This would now have to be made available in the event of a consumer request. Yet a recent survey in the UK by Compuware showed that 71 percent of retailers do not always know where their customer data is stored.

    Timescale

    Given that GDPR becomes law in May 2018, merchants should already be looking at how GDPR will have an impact on their procedures. According to William Long, a Partner at law firm Sidley Austin: “If they haven’t started already then it is imperative they begin, due to the volumes of work involved and the potential ramifications for being in breach.”

    Under the regulation, firms can face fines of €20million or 4 percent of global revenues, whichever is greater. And that’s just for ‘serious breaches’. Such things as failing to keep proper breach logs, or failing to report a breach within a set timescale, will carry fines of up to €10million or 2 percent of global revenue.

    GDPR also allows individuals to make a claim for damages for non-financial loss.Merchants, and third party payment providers, who may unknowingly store credit card details, are frequent targets for attacks by cyber-criminals so they will have to ensure especially tight protocols in this regard. Payment providers may also start offering value-added data protection services as a means of reducing the investment required by merchants, and helping them win more business.

    One area that will also be changing is the credit card authentication standard PCI DSS. Although this is unconnected to GDPR, a new standard, PCI DSS 3.2 is set to become operational in February 2018. Companies who implement this standard will be some way to becoming GDPR compliant, at least as far as payments are concerned.  For example, multi-factor authentication (MFA) becomes mandatory in PCI DSS 3.2, offering retailers a way of protecting customer personal details.

    The emergence of the DPO

    One of the ways in which businesses can manage the new regulatory landscape is by appointing a data protection officer (DPO)with company-wide responsibility for ensuring that protection guidelines are followed. Employing a DPO will be mandatory for publicly-owned bodies, companies that regularly and systematically monitor data subjects on a large scale (such as banks or web analytics companies), or firms that handle data of a highly sensitive nature. However, it is a best-practice approach that is relevant for all companies.

    Choosing such a person is a crucial part of the process. As Joel Cullin, Head of Legal for J.P. Morgan Merchant Services in Europe says:“The DPO should be an individual who has a significant amount of autonomy within the organisation and is the data protection champion.” This is because compliance with GDPR will depend on many different skills — legal, technical and financial.Appointing an effective DPO will be one way of helping an organisation keep the right side of its duties under GDPR.

    Company-wide involvement

    A key aspect of preparing for GDPR is understanding that it’s an issue for everyone within the company. Devising a response will require a coordinated approach across the organisation, because one change can have an effect on another department. For example, making changes to consent may entail customers filling in lengthy forms, which may have an effect on online purchases, leading to an increased amount of shopping cart abandonment. So, making changes is not just the responsibility of one department — there’s a need for firms to take a wider view. GDPR could entail huge volumes of work: from amending contracts to make them compliant, changing privacy policies and notices, and altering company procedures to deal with data subject rights. 

    Conclusion

    Merchants are going to have to radically rethink the way they do business. There are obvious ways in which organisations will have to change, e.g., in obtaining customer consent and shifting data retention policies. But there are more subtle changes too: there will need to be a shift in company thinking, to ensure that customer concerns are at the heart of company policy.

    GDPR shouldn’t just be thought of as a burden: the organisational changes will mean greater transparency and will also offer more security for customers. Restricting the effectiveness of cyber criminals, and reducing the threat of breach, will be especially advantageous for merchants, which are frequent targets for these attacks. Companies that act quickly and robustly in implementing these changes may also find they will benefit from a greater degree of trust from their customers. By prioritising data security, they are demonstrating a willingness to put customer concerns first, which could result in reputational benefits, especially if the provisions they implement are in advance of what is required by the letter of the law.

    In short, implementing GDPR may mean major changes but it should benefit businesses and customers alike. Don’t delay, however, the time for action is now: companies who haven’t started thinking about it, may find it’s already too late. 

     GDPR: Opportunities for merchants

    • Increased trust between companies and their customers
    • Protection of enterprise reputation
    • Standardisation of processes across the EU
    • Better data security and reduced threat of breach

    [1]International Data Corporation (IDC), ‘The Digital Universe in 2020: Big Data, Bigger Digital Shadows, and Biggest Growth in the Far East.’ Available at: https://www.emc.com/leadership/digital-universe/2012iview/executive-summary-a-universe-of.htm. Accessed March 2017.

    [2]Tech Advisor: “How technology has changed the world in 20 years.” Available at: http://www.techadvisor.co.uk/opinion/windows/how-technology-has-changed-world-in-20-years/. Accessed June 2017.

    3eCommerce Europe: “European B2C e-commerce turnover forecast to reach the €500 billion mark this year.”Available at https://www.ecommerce-europe.eu/press-item/european-b2c-e-commerce-turnover-forecast-to-reach-the-e500-billion-mark-this-year/.Accessed June 2017.

    A guide to understanding GDPR implications

    Millions of people work, shop and play online every day, leaving behind volumes of data that can include sensitive information. A study by IDC estimates that by 2020 there will be 5,200GB of data for every consumer on earth. In total, that works out at 40 zettabytes, or 57 times more than every grain of sand on every beach.[1]

    Catherine Moore

    Catherine Moore

    Regulators have increasingly become concerned with how companies capture, manage and protect the swathes of data they hold on their customers. Within the European Union (EU), these concerns have resulted in the General Data Protection Regulation (GDPR),a new regulation which aims to give consumers greater rights and security over how their data is used.

    GDPR is the most comprehensive framework of its kind in the world and will have profound implications not just for businesses operating in the EU,but any that hold data on EU citizens. Companies in breach of GDPR could face severe fines, and with an implementation date of 25 May 2018, time is running out to ensure compliance.

    Merchants, which frequently come into contact with sensitive customer information like payment details, will have to be especially ready.

    What is GDPR?

     GDPR will effectively replace the EU Data Directive, which was established in 1995, during the early days of the internet, but is now considered inadequate to deal with current challenges. This is understandable considering the average smartphone today has 10x more processing power than a PC in 1995,[2]while eCommerce sales are over €500billion a year in Europe alone.3

    The new legislation establishes guidelines on how companies should handle customer privacy, store data securely, and respond to security breaches. It also attempts to offer a unified standard of operating across Europe so that companies do not have to deal with several regulatory environments.

    For the first time, obligations will be placed on data controllers and data processors. In other words, GDPR will affect not just an organisation (the controller) but also its outsourcing provider (e.g., a cloud computing company, or a third-party payment provider). Previous legislation placed responsibility solely on the controller.

    GDPR also addresses the export of personal data outside the EU. The legislation makes it clear that it does not just apply for European companies, but any business processing the data of EU citizens, even if not based in the EU.

    GDPR at a glance

    •  GDPR was adopted in 2016 and will become effective on May 25, 2018
    •  Applies to businesses in the EU and any company worldwide that holds data on EU citizens
    • Applies to data controllers and data processors
    • Fines can be up to 4 percent of annual worldwide turnover or €20million, whichever is greater
    •  Claims can be made by individuals and organisations

    Data management, portability and customer rights

    At the heart of GDPR are a number of changes to the way that customer data is handled.Under the legislation, customers will have to give explicit permission for companies to hold data about them. But that’s not all, companies must also provide evidence that this consent has been given. One potential implication is that merchants may have to alter their auto-renewal and subscription payment processes.

    Companies can no longer store a customer’s personal data simply because it may prove useful in the future, or so they can pass it on to another provider. From now on, the responsibility will be on businesses to justify why they’re retaining customer information, otherwise it may have to beerased.

    There’s another important element too, one that has a historical precedent. In 2014, a Spanish property owner who’d had his house repossessed wanted this fact removed from Google searches. He took the case to the European Court of Justice (ECJ) which ruled that Google had to delete those references to him. 

    GDPR: Key implications for merchants

    ConsentCompanies will have to actively get consent to store a customer’s personal data
    Customer profilingNew restrictions on using data for customer profiling
    Security and data breachesData breaches have to be reported within 72 hours of discovery
    Data portabilityConsumer has right to request transfer of personal data in certain circumstances
    Data transferProhibitions on transferring data to non-EEA* countries without adequate safeguards

    *The EEA includes EU countries and also Iceland, Liechtenstein and Norway. It allows them to be part of the EU’s single market.

    Right to be forgottenA business must erase an individual’s personal data in certain circumstances
    SecurityBusinesses must have security systems that are appropriate to the level of risk

    This quickly became known as the ‘right to be forgotten’ and, following the ECJ case, it has been included in GDPR.

    As such, businesses will need to implement new policies on data retention and deletion. According to Catherine Moore, President of J.P. Morgan Merchant Services in Europe, this will mean a new mindset for some firms: “In certain industries, data might be retained forever because a regulator might ask for it. In others, the erasing of data has not been high on the priority list as there’s been no reason for doing it.”

    The right to be forgotten is a particular challenge for organisations because of the rich web of information that’s held in databases. Whereas companies may have previously been concerned about how to store and archive information, now the focus is turning to what information is held and how they can access it. For example, a merchant may have to remove someone’s personal information from all of their payment transaction record histories; if they so request.

    It’s also important to realise that data does not just mean information held on a database. GDPR makes no distinction between physical and digital data: it could be customer details held on paper, or in old files at a warehouse, for example. This would now have to be made available in the event of a consumer request. Yet a recent survey in the UK by Compuware showed that 71 percent of retailers do not always know where their customer data is stored.

    Timescale

    Given that GDPR becomes law in May 2018, merchants should already be looking at how GDPR will have an impact on their procedures. According to William Long, a Partner at law firm Sidley Austin: “If they haven’t started already then it is imperative they begin, due to the volumes of work involved and the potential ramifications for being in breach.”

    Under the regulation, firms can face fines of €20million or 4 percent of global revenues, whichever is greater. And that’s just for ‘serious breaches’. Such things as failing to keep proper breach logs, or failing to report a breach within a set timescale, will carry fines of up to €10million or 2 percent of global revenue.

    GDPR also allows individuals to make a claim for damages for non-financial loss.Merchants, and third party payment providers, who may unknowingly store credit card details, are frequent targets for attacks by cyber-criminals so they will have to ensure especially tight protocols in this regard. Payment providers may also start offering value-added data protection services as a means of reducing the investment required by merchants, and helping them win more business.

    One area that will also be changing is the credit card authentication standard PCI DSS. Although this is unconnected to GDPR, a new standard, PCI DSS 3.2 is set to become operational in February 2018. Companies who implement this standard will be some way to becoming GDPR compliant, at least as far as payments are concerned.  For example, multi-factor authentication (MFA) becomes mandatory in PCI DSS 3.2, offering retailers a way of protecting customer personal details.

    The emergence of the DPO

    One of the ways in which businesses can manage the new regulatory landscape is by appointing a data protection officer (DPO)with company-wide responsibility for ensuring that protection guidelines are followed. Employing a DPO will be mandatory for publicly-owned bodies, companies that regularly and systematically monitor data subjects on a large scale (such as banks or web analytics companies), or firms that handle data of a highly sensitive nature. However, it is a best-practice approach that is relevant for all companies.

    Choosing such a person is a crucial part of the process. As Joel Cullin, Head of Legal for J.P. Morgan Merchant Services in Europe says:“The DPO should be an individual who has a significant amount of autonomy within the organisation and is the data protection champion.” This is because compliance with GDPR will depend on many different skills — legal, technical and financial.Appointing an effective DPO will be one way of helping an organisation keep the right side of its duties under GDPR.

    Company-wide involvement

    A key aspect of preparing for GDPR is understanding that it’s an issue for everyone within the company. Devising a response will require a coordinated approach across the organisation, because one change can have an effect on another department. For example, making changes to consent may entail customers filling in lengthy forms, which may have an effect on online purchases, leading to an increased amount of shopping cart abandonment. So, making changes is not just the responsibility of one department — there’s a need for firms to take a wider view. GDPR could entail huge volumes of work: from amending contracts to make them compliant, changing privacy policies and notices, and altering company procedures to deal with data subject rights. 

    Conclusion

    Merchants are going to have to radically rethink the way they do business. There are obvious ways in which organisations will have to change, e.g., in obtaining customer consent and shifting data retention policies. But there are more subtle changes too: there will need to be a shift in company thinking, to ensure that customer concerns are at the heart of company policy.

    GDPR shouldn’t just be thought of as a burden: the organisational changes will mean greater transparency and will also offer more security for customers. Restricting the effectiveness of cyber criminals, and reducing the threat of breach, will be especially advantageous for merchants, which are frequent targets for these attacks. Companies that act quickly and robustly in implementing these changes may also find they will benefit from a greater degree of trust from their customers. By prioritising data security, they are demonstrating a willingness to put customer concerns first, which could result in reputational benefits, especially if the provisions they implement are in advance of what is required by the letter of the law.

    In short, implementing GDPR may mean major changes but it should benefit businesses and customers alike. Don’t delay, however, the time for action is now: companies who haven’t started thinking about it, may find it’s already too late. 

     GDPR: Opportunities for merchants

    • Increased trust between companies and their customers
    • Protection of enterprise reputation
    • Standardisation of processes across the EU
    • Better data security and reduced threat of breach

    [1]International Data Corporation (IDC), ‘The Digital Universe in 2020: Big Data, Bigger Digital Shadows, and Biggest Growth in the Far East.’ Available at: https://www.emc.com/leadership/digital-universe/2012iview/executive-summary-a-universe-of.htm. Accessed March 2017.

    [2]Tech Advisor: “How technology has changed the world in 20 years.” Available at: http://www.techadvisor.co.uk/opinion/windows/how-technology-has-changed-world-in-20-years/. Accessed June 2017.

    3eCommerce Europe: “European B2C e-commerce turnover forecast to reach the €500 billion mark this year.”Available at https://www.ecommerce-europe.eu/press-item/european-b2c-e-commerce-turnover-forecast-to-reach-the-e500-billion-mark-this-year/.Accessed June 2017.

    More from Business

    Explore more articles in the Business category

    Image for Submit Your Entry for Years of Excellence Awards 2026
    Submit Your Entry for Years of Excellence Awards 2026
    Image for Nominations Open for Travel & Hospitality Awards 2026
    Nominations Open for Travel & Hospitality Awards 2026
    Image for Submit Your Entry Today for Telecom Awards 2026
    Submit Your Entry Today for Telecom Awards 2026
    Image for Submit Your Entries for The Next 100 Global Awards 2026
    Submit Your Entries for the Next 100 Global Awards 2026
    Image for Submit Your Entry: Public Sector & Governance Excellence Awards 2026
    Submit Your Entry: Public Sector & Governance Excellence Awards 2026
    Image for Nominations Invited for Real Estate Development Awards 2026
    Nominations Invited for Real Estate Development Awards 2026
    Image for Submit Your Entry: Process & Product Awards 2026
    Submit Your Entry: Process & Product Awards 2026
    Image for Call for Entries: HR & Recruitment Awards 2026
    Call for Entries: HR & Recruitment Awards 2026
    Image for Submit Your Nominations Today for Education & Training Awards 2026
    Submit Your Nominations Today for Education & Training Awards 2026
    Image for Join the Corporate Governance Awards 2026: Showcase Your Organisation’s Leadership
    Join the Corporate Governance Awards 2026: Showcase Your Organisation’s Leadership
    Image for Submit Your Entry Today for Business Awards 2026
    Submit Your Entry Today for Business Awards 2026
    Image for Decentralized Masters’ ‘family culture’ building trust instead of hierarchy
    Decentralized Masters’ ‘family Culture’ Building Trust Instead of Hierarchy
    View All Business Posts
    Previous Business PostPre-Action Protocol: What You Need to Know
    Next Business PostWidespread Mismanagement of Privileged Accounts and Access Revealed in One Identity Global Survey