Links on this page may be affiliate links — the price stays the same for you. How affiliate links work

Ireland / Guides / Shopping and your rights / Data Protection When Shopping Online: What Actually Applies to You

27 June 2026 · 5 min read · Shopping and your rights

Data Protection When Shopping Online: What Actually Applies to You

The gap between the EU and UK approach and the US approach

Few areas show a bigger difference between the three regions covered in this series than data protection. The EU and the UK each have a single, comprehensive law that applies to almost any company processing personal data about their residents, including a foreign online shop. The US has no equivalent nationwide law; protection instead comes from a mix of an enforcement agency acting against unfair practices, a handful of sector-specific federal laws, and separate state laws that only apply if you happen to live in a state that has passed one.

EU: the GDPR follows the shop, not just the shopper's country

The EU's General Data Protection Regulation applies to any company that offers goods or services to people in the EU and processes their personal data, regardless of where that company is legally based. This matters for online shopping specifically, because it means an EU resident's data protection rights do not disappear just because they bought from a shop outside the EU, as long as that shop was targeting EU customers. Core rights under the GDPR include the right to access a copy of your personal data, the right to have inaccurate data corrected, and the right to have data erased in certain circumstances. A company receiving such a request should generally respond within one month; if the request is complex, that period can be extended, but the company has to inform the person and explain why. If a request is not properly handled, a complaint can be made to the relevant national data protection authority.

UK: the same framework, running in parallel after Brexit

The UK retained the substance of the GDPR after leaving the EU, now known as the UK GDPR, sitting alongside the Data Protection Act 2018 and enforced by the Information Commissioner's Office. The individual rights are essentially the same set found in the EU version: access, rectification, erasure, restriction of processing, data portability and the right to object to certain processing, with organisations generally expected to respond within one month. The two frameworks were near-identical at the point of separation and have stayed close since, but they are legally distinct and can, in principle, diverge as each side amends its own rules over time, which is worth remembering rather than assuming they will always match exactly.

US: no single law, a patchwork instead

The US has no comprehensive federal privacy law covering how an online shop can collect and use your data. Instead, the Federal Trade Commission enforces against unfair or deceptive practices under its general authority, including cases where a company breaks its own stated privacy promises, and a small number of federal laws cover specific sectors, such as health information or communications aimed at children, without providing a general right over personal data collected by an ordinary retailer. Where broader rights exist, they typically come from state law rather than federal law. California is the most developed example: the California Consumer Privacy Act, as expanded by the California Privacy Rights Act, gives California residents rights including knowing what personal information a business has collected about them, requesting its deletion, and opting out of the sale or sharing of that information, along with a right, added in 2023, to correct inaccurate data. These rights apply because of residence in California, not because of where a shop is based, and a shopper outside California generally cannot rely on them even when buying from a California-based retailer.

What this means for an ordinary online order

  • In the EU and the UK, you can generally ask any shop targeting your market what data it holds about you, correct it, or ask for it to be deleted, with a roughly one-month response expectation.
  • In the US, whether you have a similar right depends heavily on which state you live in; a resident of a state without a comprehensive privacy law has fewer formal rights than a California resident shopping at the same site.
  • Cookie and tracking consent requirements are strongest in the EU and the UK; a US shopper is more likely to see tracking happen by default, subject to any applicable state opt-out right.
  • None of this depends on whether a purchase used a voucher code or coupon code; data protection rights attach to the data collected, not to the price paid or the discount used.

On daily-coupons.info, we list codes across 527 shops in 22 countries without asking shoppers to create an account or accepting cookies to track visits, which is described in more detail on our about us page and our FAQ page.

This article is general information, not legal advice. Data protection rights depend on where you live, where the company operates, and which specific law applies; check the relevant privacy notice and, if needed, your national or state data protection authority for a specific situation.

Frequently asked questions

Does the GDPR protect a UK resident buying from an EU shop?

Generally, protection now comes from the UK GDPR when the UK resident is the one whose data is processed, rather than the EU GDPR, though an EU-based shop targeting UK customers would also need to consider UK rules separately from its EU obligations.

Can I ask a US shop to delete my data if I do not live in a state with a privacy law?

You can always ask, and some companies will comply voluntarily or apply their broadest policy to all customers, but there may be no legal requirement forcing the company to do so if your state has not passed a law creating that right.

Do cookie banners mean the same thing everywhere?

No. In the EU and the UK, rules derived from data protection and e-privacy law generally require clear consent before non-essential cookies are set. In much of the US, there is no equivalent general requirement, though some state laws add specific opt-out rights around the sale or sharing of data.

What should I do if a shop ignores my data request?

In the EU or the UK, you can escalate a complaint to the relevant national data protection authority, such as the Information Commissioner's Office in the UK, after giving the company a reasonable chance to respond. In the US, options depend on the state and any applicable law, with the state Attorney General's office often the relevant contact where a state privacy law exists.

← Back to all guides