AuditXYZ
E-commerce businesses and online retailers processing payments and customer personal data

Compliance Guide for E-Commerce Companies

The complete compliance roadmap for e-commerce companies. Navigate PCI DSS, GDPR, CCPA, and SOC 2 with recommended tools, auditors, and realistic budgets.

Compliance Guide for E-Commerce Companies

E-commerce companies handle two of the most regulated data types in any industry: payment card information and customer personal data. Whether you are a direct-to-consumer brand, a marketplace, or a B2B wholesaler, compliance obligations are unavoidable — and the cost of getting them wrong is severe. PCI DSS is mandated by the card networks, privacy laws like GDPR and CCPA apply based on where your customers live, and enterprise partners increasingly require SOC 2 reports before they will integrate with your platform.

This guide provides a practical, framework-by-framework roadmap for e-commerce businesses of all sizes, from Shopify merchants to high-volume marketplace operators.

Why E-Commerce Needs Compliance

Payment card fraud costs the e-commerce industry billions annually, and the card networks hold merchants accountable through PCI DSS requirements. Non-compliant merchants face fines of $5,000 to $100,000 per month from their acquiring bank, and a data breach can result in losing the ability to accept credit cards entirely — a business-ending outcome for most online retailers.

Privacy regulations add another layer of obligation. GDPR fines can reach 4% of global annual revenue, and the UK GDPR post-Brexit carries equivalent penalties. CCPA grants California consumers the right to sue for statutory damages in data breach scenarios without needing to prove actual harm. With the CPRA amendments now in full effect and additional US state privacy laws enacted in Virginia (VCDPA), Connecticut (CTDPA), Colorado, Texas, and more than a dozen other states, e-commerce companies with a national customer base face a patchwork of obligations that requires systematic management rather than ad hoc responses.

Why Enterprise Partners Demand SOC 2

B2B e-commerce relationships — wholesale buyers, marketplace integrations, drop-shipping partners — increasingly require SOC 2 reports before connecting their systems to yours. A security incident at your platform can cascade to their inventory, customer data, and financial systems. Enterprise procurement teams treat SOC 2 reports as baseline evidence that you have mature security controls in place.

Framework-by-Framework Breakdown

PCI DSS v4.0.1 — Payment Card Security

PCI DSS version 4.0.1 is the current standard, with its new customized implementation approach and expanded authentication requirements now in full effect. Every e-commerce company that processes, stores, or transmits cardholder data must comply.

The scope of your PCI DSS obligation depends heavily on how you handle payment data:

  • SAQ A (simplest): You use fully outsourced payment pages hosted by your payment processor (e.g., Stripe Checkout, PayPal, Square). Your website never touches cardholder data directly. This covers roughly 80% of small e-commerce merchants.
  • SAQ A-EP: You use a payment page hosted on your own domain but use a JavaScript-based payment form from a third-party processor. Slightly broader scope.
  • SAQ D for merchants: You store, process, or transmit cardholder data in any way not covered by simpler SAQ types. Significantly more complex.
  • Report on Compliance (ROC): Required for merchants processing over 6 million Visa or Mastercard transactions annually (Level 1 merchants). Requires an on-site assessment by a Qualified Security Assessor (QSA).

The single most impactful decision for most e-commerce companies is to use hosted payment pages that keep cardholder data entirely off your systems. This reduces PCI DSS scope to SAQ A and dramatically lowers both compliance costs and breach risk.

Key new PCI DSS v4.0.1 requirements that e-commerce companies should note:

  • Multi-factor authentication is now required for all access to the cardholder data environment
  • Password requirements have been updated with longer minimums
  • E-commerce skimming (Magecart-style) protections are now explicitly required: you must implement controls to detect unauthorized script modification on payment pages

See the PCI DSS framework guide for a complete control list and SAQ selection guidance.

GDPR — EU Customer Data

GDPR applies to any e-commerce company that sells to EU residents, regardless of where the company is incorporated. The territorial scope is defined by the location of the data subject, not the business.

For e-commerce, the most critical GDPR obligations are:

  • Cookie consent: You must obtain freely given, specific, informed, and unambiguous consent before placing non-essential cookies. Pre-checked boxes and consent buried in terms do not meet the standard.
  • Data minimization: Collect only the personal data you actually need for each processing purpose. Many e-commerce platforms over-collect behavioral and marketing data.
  • Data subject rights: EU customers can request access to their data, request deletion, object to direct marketing, and port their data to another service. You need workflows to respond within 30 days.
  • Data processor agreements: Every vendor or SaaS tool that processes EU customer data on your behalf requires a Data Processing Agreement (DPA). This includes your email marketing platform, analytics tools, customer support software, and fulfillment systems.
  • Privacy notices: Must clearly describe what data you collect, why, how long you retain it, and who you share it with.

GDPR fines are tiered: up to 10 million euros or 2% of global revenue for procedural violations, and up to 20 million euros or 4% of global revenue for substantive violations. See the GDPR framework page for a complete requirements breakdown.

For consent management and privacy operations, TruePrivacy is purpose-built for e-commerce consent flows, cookie categorization, and data subject request management. It integrates with common e-commerce platforms including Shopify and WooCommerce.

CCPA and US State Privacy Laws

The California Consumer Privacy Act (CCPA) and its CPRA amendments give California consumers rights to know, delete, opt out of sale, and limit the use of sensitive personal information. The threshold for CCPA applicability is businesses with annual gross revenues over $25 million, or those processing data of 100,000-plus consumers annually, or those deriving 50% of revenue from selling personal data.

Most mid-size e-commerce companies with California customers meet at least one of these thresholds. See the CCPA framework page for a practical compliance checklist.

The broader US state privacy law landscape has expanded substantially. E-commerce companies should establish a privacy program that can satisfy requirements across multiple state laws simultaneously rather than building state-by-state. The VCDPA and CTDPA follow similar structures to CCPA and can largely be addressed with the same operational workflows.

SOC 2 — Enterprise and B2B Trust

SOC 2 is the primary compliance credential for B2B e-commerce relationships. Enterprise wholesale buyers, marketplace partners, and ERP integration partners frequently require a SOC 2 Type II report before proceeding with integration. See the SOC 2 framework page for the Trust Services Criteria breakdown.

Phased Compliance Roadmap

Phase 1: PCI DSS Foundation (Month 1)

Determine your PCI DSS scope by documenting your payment flow in detail. Answer the following:

  • Does your server ever receive cardholder data, even briefly?
  • Do you store any cardholder data (even temporarily in logs)?
  • Is your payment page hosted on your domain or your processor's domain?

This scoping exercise determines which SAQ type applies. For most e-commerce companies using modern payment providers, the answer points to SAQ A or SAQ A-EP. Confirm the classification with your acquiring bank.

Complete the applicable SAQ — it is a self-assessment questionnaire that documents your controls and attests compliance. If you are a Level 1 merchant (over 6 million transactions), engage a QSA for a full Report on Compliance.

Additionally, conduct a vulnerability scan of your e-commerce infrastructure using an Approved Scanning Vendor (ASV). PCI DSS requires quarterly external scans.

Phase 2: Privacy Compliance (Months 1-3)

Conduct a data mapping exercise: document every category of personal data you collect, its source, its purpose, how long you retain it, and every system or vendor it flows to. This data map is the foundation for all privacy compliance efforts.

Implement cookie consent management with a Consent Management Platform (CMP) that meets GDPR and CCPA requirements. Audit your current cookie banner — if it pre-checks analytics and marketing cookies or makes consent unavoidable, it does not comply with GDPR.

Update your privacy policy to accurately describe your data practices. Ensure it covers:

  • Categories of personal data collected
  • Purposes and legal bases for processing
  • Data retention periods
  • Third-party sharing and processor relationships
  • Data subject rights and how to exercise them
  • Contact information for privacy inquiries

Execute Data Processing Agreements with all vendors handling EU customer data. Most major SaaS vendors (Shopify, Klaviyo, Google Analytics) provide standard DPAs — request and sign them.

Establish a data subject request workflow. When a customer submits a deletion or access request, you need a documented process to respond within 30 days and the technical ability to locate and delete or export their data across all systems.

Phase 3: SOC 2 Preparation (Months 4-8)

If you have B2B customers, enterprise marketplace partnerships, or wholesale buyer relationships, SOC 2 Type I is the next priority. Begin by:

  • Selecting a compliance automation platform to streamline evidence collection
  • Writing information security policies covering access control, change management, incident response, and vendor management
  • Implementing technical controls: MFA on all production systems, encryption at rest and in transit, centralized logging, and automated vulnerability scanning

Engage an auditor for SOC 2 Type I. The Type I audit evaluates whether your controls are designed appropriately as of a point in time — it does not require an extended observation period.

Phase 4: SOC 2 Type II and Ongoing Maintenance (Months 8-18)

After completing Type I, begin the observation period for SOC 2 Type II. The Type II report covers a 6-12 month period and provides evidence that your controls operate consistently over time. This is the report that most enterprise buyers actually want.

Annual PCI DSS recertification is required. Maintain your ASV scanning, review and retest any controls that changed, and complete your SAQ or ROC on the annual cycle.

Expand privacy compliance to additional US state jurisdictions as you grow your customer base, and monitor for new state privacy laws — over a dozen additional states have legislation in various stages of passage.

Budget Expectations

For a mid-size e-commerce company (20-100 employees) with hosted payments:

ItemTypical Cost
Compliance platform (annual)$8,000-$15,000
PCI DSS SAQ assessment$2,000-$10,000
GDPR / privacy tooling and CMP$3,000-$10,000
SOC 2 Type II audit$15,000-$30,000
ASV vulnerability scanning (annual)$1,500-$5,000
Total first year$29,500-$70,000

Using hosted payment solutions like Stripe, Braintree, or Adyen is the single most effective way to reduce PCI DSS scope and cost. Avoid storing cardholder data directly whenever possible — tokenization eliminates the most expensive compliance obligations.

For growing e-commerce companies looking to manage PCI DSS, GDPR, and SOC 2 without a dedicated compliance team, LowerPlane provides AI-powered compliance automation rated 9.4/10 by AuditXYZ, supporting 50-plus frameworks at $4,000 per year entry pricing with a free tier. See the compliance automation comparison to evaluate platforms side by side.

Common Mistakes E-Commerce Companies Make

Using the wrong SAQ type. E-commerce companies often file SAQ A when they actually qualify for SAQ A-EP or SAQ D based on how their payment page works. Mis-scoping PCI DSS is a common finding that creates both compliance gaps and potential liability.

Not implementing Magecart protections. JavaScript skimming attacks on e-commerce checkout pages have become extremely common. PCI DSS v4.0.1 explicitly requires controls to detect unauthorized script modification. Many merchants have not implemented these yet.

Ignoring non-functional cookie consent. Regulatory scrutiny of cookie consent mechanisms has intensified significantly. Pre-checked boxes, "I agree" buttons that apply to everything, or consent banners that make rejecting cookies harder than accepting them all violate GDPR. Fines for cookie consent violations from EU data protection authorities have become routine.

Missing DPAs with SaaS vendors. Most e-commerce stacks use 20-plus SaaS tools that process customer data. Without signed DPAs with all of them, you are in violation of GDPR Article 28. Run an audit of all your tools and request DPAs from any that process EU personal data.

Delaying SOC 2 until a deal requires it. Enterprise buyers who need a SOC 2 report are not willing to wait 6-12 months for you to get one. Proactively pursuing SOC 2 before you need it means having the report ready when the deal arrives.

Inadequate data retention and deletion processes. Many e-commerce platforms accumulate customer data indefinitely. GDPR requires documented retention periods and actual deletion when those periods expire. Failure to delete data is a separate violation from failure to disclose.

How Compliance Automation Helps

Managing PCI DSS, GDPR, CCPA, and SOC 2 simultaneously is complex for any team. Compliance automation platforms centralize evidence collection, automate control monitoring, and generate audit-ready documentation — reducing both the time and cost of maintaining multiple frameworks.

LowerPlane (rated 9.4/10 by AuditXYZ) supports PCI DSS, SOC 2, GDPR, and over 50 additional frameworks in a single platform. Its AI-powered evidence collection integrates with AWS, Stripe, Shopify, and other common e-commerce infrastructure. Starting at $4,000 per year with a free tier for initial gap assessments, it is particularly well-suited for e-commerce companies managing multiple frameworks without a large compliance team.

For privacy-specific operations — cookie consent, data subject requests, privacy notices, and DPA management — TruePrivacy provides purpose-built workflows for GDPR and CCPA compliance that integrate with e-commerce platforms.

Frequently Asked Questions

Do I need PCI DSS compliance if I use Stripe or PayPal?

Yes, but your scope is dramatically reduced. Using Stripe Checkout or PayPal's hosted payment page means cardholder data never touches your systems, qualifying you for SAQ A — the simplest compliance level. You still need to complete the SAQ annually, maintain a vulnerability scan, and attest compliance to your acquiring bank.

When does GDPR apply to a US-based e-commerce company?

GDPR applies whenever you sell to EU residents, regardless of where your business is incorporated. If you ship products to EU addresses or run EU-targeted advertising, you have GDPR obligations. The threshold for applicability is not based on revenue or transaction volume — if you are intentionally targeting EU consumers, you are in scope.

How long does it take to get SOC 2 Type II?

SOC 2 Type II requires a minimum observation period of 6 months (some auditors accept 3 months for initial reports). Including preparation time, most e-commerce companies should plan for 12-14 months from kickoff to a completed Type II report. Starting with a Type I audit (2-4 months) lets you provide something to enterprise buyers while building toward Type II.

What is the CPRA and how does it differ from CCPA?

The CPRA (California Privacy Rights Act) amended CCPA with additional requirements including a new "sensitive personal information" category with additional opt-out rights, stricter data minimization requirements, and the creation of the California Privacy Protection Agency (CPPA) as an enforcement body. CPRA amendments have been in effect since January 2023. If you were already CCPA-compliant, review your sensitive personal information handling and automated decision-making disclosures.

What US states have privacy laws that apply to e-commerce?

As of mid-2026, states with comprehensive consumer privacy laws in effect include California, Virginia, Colorado, Connecticut, Texas, Montana, Oregon, Florida, Delaware, and New Hampshire, among others. Additional states have laws scheduled to take effect through 2027. A privacy program designed around CCPA and GDPR will satisfy most state requirements, but review state-specific thresholds and obligations for accuracy.

Next Steps

Start by confirming your PCI DSS SAQ level with your payment processor — this is the fastest way to scope your payment compliance obligation. Then conduct a data mapping exercise to understand what personal data you collect and where it flows.

Review the PCI DSS framework guide and the GDPR guide for detailed requirement breakdowns. If you are approaching B2B sales, read the SOC 2 guide to understand what enterprise buyers actually look for in a report.

Compare compliance automation platforms to find the right tooling for managing multiple frameworks efficiently, and see our startups comparison if you are a growing company managing compliance with a lean team.

Company size

By submitting, you agree to our privacy policy.

Get your compliance roadmap

By submitting, you agree to our privacy policy.