- Job title
- Administrative manager
- Sector
- Real estate
- Organization type
- 40-person manufacturing company
- Joined
- Feb 2023
- Message
- 37
We run a small London-based e-commerce shop. We sell custom-designed ceramics and home textiles within the UK and primarily to Germany and France. We have a core team of 4 people and process around 3,500 orders a year through our website. Aside from customer names, delivery addresses, emails, and newsletter signups, we don't collect anything overly complex.
Last week, we got a pretty detailed email from a customer in Germany asking about our data retention periods and cookie policy. Up until now, we’ve gotten by using ready-made templates we found online, but realizing how serious this is, we decided to launch a proper compliance process from scratch. The initial consultancy quote we received was around 2,500 GBP, but since our budget is tight, we want to handle the bulk of it in-house.
Realistically, what does a GDPR compliance timeline look like for a retail business of our size? Which steps end up taking longer than expected, and where should we start?