- The consent question is not about personalisation. It is about storing or reading something on the shopper's device, which is a separate legal test from whether you may use the data afterwards.
- The European Data Protection Board's 2023 guidelines put tracking pixels, tracking links, fingerprinting and some IP based tracking inside the same consent rule that covers cookies.
- Recommending from a customer's own past orders, on your own site, is a different and much easier case than following them across other people's sites.
- The CNIL's legitimate interest test has three parts, and its published examples show where the balancing usually fails for retail marketing.
- One brand reported a 31.89% click through rate and 766 attributed orders from recommendations placed on its order tracking page in Q1 2026. That is a surface you own, seen by a customer who is already yours.
- Most small shops are carrying consent risk for tracking that produces nothing, because the tags were installed by a plugin years ago and nobody has read the network tab since.
Open your shop in a private window, open the browser's network panel, and load a product page without accepting the banner. Then count the third party requests. For a typical small store the number is somewhere between four and twenty, and the owner can usually name two of them.
That is the actual state of personalisation for most independent merchants. Not a sophisticated recommendation engine, not a segmentation strategy, but a layer of tags nobody audits, producing data nobody reads, carrying a legal exposure nobody priced. Meanwhile the personalisation that would genuinely earn money sits unbuilt, because it looks like the same problem and it is not.
What actually triggers the consent requirement?
Touching the device, not using the data. This is the distinction that untangles the whole subject and it is the one most explanations skip. European law puts two separate rules on top of each other. One asks whether you may store or read anything on the shopper's equipment. The other asks whether you may process the resulting personal data. You have to satisfy both, and they have different answers.
The first rule is Article 5(3) of the ePrivacy Directive, and it says nothing about cookies specifically. It covers storing information on terminal equipment or gaining access to information already stored there. The European Data Protection Board adopted guidelines in November 2023 clarifying how wide that is, and the summary of the guidelines on the technical scope of Article 5(3) lists what falls inside: tracking pixels and tracking links, device fingerprinting, local processing where the result is later sent out, IoT reporting, and certain IP based tracking.
Read that list against your own site. A pixel that fires without a cookie is still in scope. A fingerprinting script that reads screen size and fonts is in scope precisely because it reads the device. The common workaround of moving a tracker server side does not exit the rule if the point is still to identify the same person's equipment.
What the rule does not cover is what you already know about a customer because they told you. Their order history is not stored on their device. It is stored on yours, because they bought something. That is a completely different legal question, and it is the one with the better answer.
Can you recommend from a customer's own purchase history?
Usually yes, and the reasoning is worth being able to state. There is no device access involved, so the consent rule does not bite. What remains is the ordinary data protection question of your legal basis, and for recommending your own products to your own customer on your own site, legitimate interest is the standard route.
The CNIL sets out a three part test in its published guidance on relying on legitimate interests. The interest has to be lawful, clearly defined and real rather than hypothetical. The processing has to be necessary, meaning no less intrusive route achieves the same thing. And the balance has to come out in your favour against the person's rights and reasonable expectations. Its list of interests that can qualify includes fraud prevention and improving product performance.
Two things fail that test reliably in a retail context. Profiling that a customer would not reasonably expect from the relationship they think they have with you fails the third limb, which is why buying a lamp does not license inferring a household income bracket. And anything aimed at children fails at the first limb: the CNIL states plainly that targeted advertising based on profiling to minors is prohibited under the Digital Services Act, so a system built to do it cannot be justified on any basis.
Legitimate interest is not a box you tick. It is an assessment you write down before you start, and the writing down is most of its value. Three paragraphs naming the interest, why there is no lighter alternative, and what the customer would expect, dated and filed, is what turns a defensible position into a documented one. Nobody has ever regretted having it.
Where does personalisation actually pay?
On surfaces the customer has already chosen to look at. The best documented recent example is not a homepage or a retargeting campaign. Digital Commerce 360 reported that the brand Dr. Squatch added product recommendations to its post purchase order tracking page and recorded a 31.89% click through rate, with 766 attributed orders and $32,978 of revenue in the first quarter of 2026.
Sit with both halves of that. A 31.89% click through rate is extraordinary by any advertising standard, because the person is checking where their parcel is and they are in a good mood about your brand. And $32,978 in a quarter is a modest number for a brand of that size, which is the useful correction to the idea that personalisation changes a business on its own.
The pattern generalises, and it is the practical argument of this whole piece. The surfaces where personalisation converts best are the ones you already own and the customer already visits: the tracking page, the order confirmation, the account page, the reorder screen. Every one of those is reached by an identified customer in an existing relationship, which means the tracking consent question does not arise at all. The hardest personalisation legally is also the weakest commercially for a small shop, and the easiest legally is where the money is.
| Surface | What it can use | Consent needed to store or read on device | Typical value to a small shop |
|---|---|---|---|
| Order tracking page | This order, past orders | No, the customer is identified by the order | High, documented click through |
| Reorder and account page | Full purchase history | No | High for consumables |
| Post purchase email | Purchase history, preferences given | No for the content, marketing consent rules still apply to sending | High |
| On site recently viewed | This session | Depends on how it is stored, strictly necessary storage is exempt | Moderate |
| Homepage blocks by segment | Logged in history, or nothing | No if logged in, yes if inferred from tracking | Low until you have volume |
| Cross site retargeting | Third party identifiers | Yes, unambiguously | Low and falling for small catalogues |
The last row is where most small shops have spent their compliance budget and most of their attention. The first two rows are where nobody has looked, and they need no banner, no vendor and no legal opinion.
How a small shop should actually build this
Start from the record you already have rather than from a vendor's feature list. Every shop knows four things about a returning customer without any tracking at all: what they bought, when they bought it, what they paid, and whether they returned it. Those four fields carry most of the useful personalisation available at small scale, and none of them involves the shopper's device.
From purchase dates alone you can work out replenishment timing for anything consumable, which is the highest value personalisation most shops never build. A customer who buys a 60 day supply on 3 March is worth an email on about 25 April, and getting that timing roughly right beats every clever inference about their lifestyle. It is arithmetic on your own order table.
From what they paid you get a price band, which is more reliable than any inferred affluence signal and does not require you to guess anything about the person. Recommending an item at three times what somebody has ever spent with you reads as a shop that does not know them, which is the opposite of what personalisation is for.
From returns you get the signal everyone ignores. A customer who returned two of three orders in a category should not be shown more of that category, and a shop that keeps recommending it is telling the customer nobody is paying attention. Suppressing recommendations is personalisation too, and it costs nothing.
What has to be written down before you start?
Three short documents, none of which needs a lawyer to draft, though one is worth having a lawyer read if your volumes are meaningful.
The first is the record of what data you hold and why, which is an obligation in its own right in Europe and a useful exercise everywhere. One page. Where each field came from, what it is used for, how long you keep it.
The second is the legitimate interest assessment for anything you are not doing on consent or contract. Name the interest, show you considered a lighter option, and state honestly what a customer would expect. If writing the third paragraph makes you uncomfortable, that discomfort is the assessment working.
The third is the retention rule, which is the one that quietly protects you. Order data you keep for accounting reasons is not the same as behavioural data you keep because deleting it felt wasteful. Setting an actual deletion date on the second category reduces both your exposure in a breach and the size of any future data request you have to answer. It also tends to improve the recommendations, because a shopper's preferences from four years ago are noise.
What should you switch off first?
Anything you cannot name. Go through the tags on your site one by one and answer three questions for each: who installed it, what report does anyone read from it, and what would break if it were removed. In most audits of a small shop, between a third and a half of the tags fail all three, and they are pure liability with no offsetting benefit. Removing them is the single highest return privacy action available and it costs an afternoon.
Then check what remains against what your banner claims. The mismatch that regulators find most often is not exotic. It is a tag that fires before consent, on a site whose banner says nothing loads until you accept. That is a factual statement about your site being false, which is a much worse position than having no banner at all.
There is a related exposure in the tools themselves. Analytics and personalisation vendors have been enabling AI features on existing accounts, and the data those features consume is your customer data under a new purpose. We went through how to audit that in the piece on AI features your tools switched on without asking, and the same list applies here. A vendor's new model training default can change what your existing consent covers without anyone telling you.
Does this apply if you only sell in the United States?
Differently, and it is converging rather than diverging. The device access rule described above is European. The American structure is built on notice, sale and sharing definitions, and opt outs, with state laws varying in detail but agreeing on the shape: a shopper can tell you to stop sharing their data for cross context behavioural advertising, and increasingly they can do it through a browser signal rather than your banner.
The practical convergence is that the same architecture satisfies both. Personalisation built on first party purchase history, on surfaces you own, is low risk in every regime that exists, because there is no sharing, no cross context anything, and no device fingerprint. Personalisation built on third party identifiers is the one that needs a different answer per jurisdiction, per year, and it is also the one whose foundations keep being removed by browser vendors regardless of law.
What about recommendation quality with almost no data?
It is a real constraint and it is not the one people think. A shop with 400 orders cannot train anything meaningful on behaviour, but it does not need to. Rules built from your own catalogue knowledge outperform statistical recommendations at that scale, because you know that this soap goes with that dish and no model can learn it from six co purchases. We set out what actually works below the data threshold in the article on product recommendations when you have barely any data.
The same applies to knowing what customers want in the first place. Most small shops have a richer source than any tracking pixel sitting unread in their reviews and support inbox, and the method for mining it is in the piece on what AI reads in customer reviews and what it misses. Neither of those routes touches a shopper's device.
The order to do this in
Audit the tags before you build anything, because you may find you are already paying for the risk of a system you are not using. Write the legitimate interest assessment for the recommendations you intend to run, in plain language, before switching them on. Build first on the tracking page and the reorder page, because that is where an identified customer with intent already is. Leave cross site retargeting until you have a catalogue and a margin that justify it, which for most independent shops is later than the tooling implies and sometimes never.
Then say what you do. A privacy page that describes your actual behaviour in short sentences is worth more than a generated policy covering practices you do not have, and it is the document a regulator reads first. Ours is a working example rather than a template, and the reasoning behind how we handle merchant and shopper data sits on our page about how the platform handles your data.
The uncomfortable conclusion for anyone who has spent a year on consent tooling is that the compliance problem and the revenue problem have almost no overlap. The tags that create the legal exposure produce, for a small shop, close to nothing. The personalisation that produces money runs on data the customer handed you at checkout, on a page they came to voluntarily, in a relationship they already agreed to. Doing less is not a compromise here. For a business at this size it is simply the better strategy, and the law happens to agree.
The personalisation with the worst consent position is usually the one earning the least. Start where the customer already is, on a page you already own.MaShop, 4 September 2026