11.1 Privacy Risks and Impacts of E-Commerce

Key Takeaways

  • E-commerce sites share data with payment processors, fraud vendors, analytics, advertising platforms, chat vendors, and carriers, so each integration needs a purpose, contract, and consent check.

  • Hashing an email before sending it to an advertising platform's conversion API pseudonymizes it but does not anonymize it; the platform can match it, so the transfer can still be a sale or sharing under the CCPA.

  • PCI DSS prohibits storing sensitive authentication data such as the card verification code after authorization, and limits displayed card numbers to at most the first six and last four digits.

  • PCI DSS v4.0.1 requirements 6.4.3 and 11.6.1, effective March 31, 2025, target payment-page script attacks by requiring script inventories and tamper detection.

  • Chatbots collect unpredictable free text, so they need disclosure that users are talking to a bot, redaction of card numbers and sensitive data, authentication before account access, and limited retention.

Last updated: October 2026

11.1 Privacy Risks and Impacts of E-Commerce

Quick Summary: The BoK lists e-commerce risks explicitly: behavioral advertising, cookies, chatbots, payments, and behavioral profiling. An online store is a dense network of third parties, and each page view can send data to a dozen vendors. Privacy technologists map those flows, keep payment data inside a small, well-defended zone, govern advertising and personalization with consent and opt-outs, and treat chat transcripts as sensitive data.


The E-Commerce Data Flow

Loading diagram...

Each arrow is a disclosure that needs a purpose, a legal basis, a contract, and an entry in the data inventory. The most common failures are tags that send more than intended (search terms, product names that reveal health conditions, or email addresses in URLs) and vendors added by marketing teams without review.


Cookies, Pixels, and Behavioral Advertising

Retailers use cookies and pixels for sessions and carts (strictly necessary), analytics, and advertising. Advertising tags enable retargeting (showing ads for products a person viewed) and conversion measurement.

  • Consent and opt-outs. In the EU, non-essential cookies and pixels require prior consent. Under the CCPA and other state laws, sending data to ad platforms for cross-context behavioral advertising is usually a sale or sharing that must stop when a consumer opts out, including by Global Privacy Control. California's 2022 settlement with Sephora ($1.2 million) centered on undisclosed sales through tracking and ignored GPC signals, and its 2025 settlement with Healthline Media ($1.55 million) added a purpose-limitation finding because article titles suggesting medical diagnoses were shared with advertisers.
  • Server-side tracking. Conversion APIs send events directly from the retailer's server to ad platforms, often with hashed email addresses or phone numbers. Hashing is pseudonymization, not anonymization: the platform hashes its own users' emails the same way and matches them. The data remains personal data, and the transfer must respect consent and opt-outs.
  • Sensitive products. Product and search data can reveal health, pregnancy, religion, or sexuality (a pregnancy test, a mobility aid, a prayer rug). Exclude these categories from advertising feeds.

Behavioral Profiling and Personalized Pricing

Recommendation engines, segment-based promotions, and dynamic pricing all rely on profiles. Risks include unanticipated revelation (Section 7.1), discrimination, and personalized pricing that charges people differently based on inferred willingness to pay. In January 2025, the U.S. Federal Trade Commission released preliminary findings from its study of "surveillance pricing," describing how intermediaries use data such as location, browsing, and demographics to set individualized prices.

Controls: limit profile inputs to shopping behavior on the site, exclude sensitive inferences, give customers a non-personalized option, explain personalization ("Recommended because you viewed..."), and test pricing models for disparate outcomes across groups.


Chatbots

Retail chatbots, increasingly powered by large language models, collect free text, so customers type whatever they like: card numbers, medical details, passwords, or complaints about family members. Risks and controls:

RiskControl
Users do not realize they are talking to a botClear disclosure. California's BOT Act (2019) prohibits using an undisclosed bot to mislead people in order to sell goods, and the EU AI Act requires disclosure of AI interaction from August 2, 2026
Card numbers and sensitive data in transcriptsReal-time redaction of payment card numbers and identifiers; send payments to a PCI-compliant payment flow instead of chat
Bot reveals account data to the wrong personRequire authentication before the bot accesses orders, addresses, or payment methods
Transcripts used to train modelsContract terms prohibiting vendor training on customer data, and retention limits
Wrong answers about orders or policiesGrounding in verified data; companies remain responsible for what their bots say (a Canadian tribunal held Air Canada liable for its chatbot's incorrect refund advice in 2024)
Session-replay style capture of chat widgetsDisclosure and consent; US wiretap-law class actions have targeted chat and replay vendors

Payments

Payment card data is governed by the Payment Card Industry Data Security Standard (PCI DSS). Version 4.0.1, published in June 2024, is current, and its "future-dated" requirements became mandatory on March 31, 2025.

Key rules that intersect with privacy:

  • Never store sensitive authentication data after authorization: the full magnetic-stripe or chip data, the card verification code (CVV2/CVC2), and PINs.
  • Mask card numbers when displayed: at most the first six (BIN) and last four digits, unless a person has a business need to see more.
  • Render stored card numbers unreadable using strong cryptography, truncation, tokenization, or one-way hashes.
  • Protect payment pages from script attacks. Requirement 6.4.3 requires an inventory and authorization of every script on payment pages, and 11.6.1 requires a mechanism to detect unauthorized changes to payment pages, countering "Magecart" skimming (Section 10.3).
  • Reduce scope: hosted payment pages or embedded payment fields from the processor keep card data off the merchant's servers entirely, and network or processor tokens replace card numbers for recurring payments.

3-D Secure (EMV 3DS) supports risk-based authentication by sending device and transaction data to the card issuer. It reduces fraud but shares more data, so merchants should send only the data elements the protocol requires and disclose the processing.

Fraud Prevention and Profiling

Fraud tools collect device fingerprints, IP addresses, and behavioral signals. Fraud prevention is a recognized legitimate interest under GDPR Recital 47, but the data must not drift into marketing (purpose limitation), retention should match chargeback windows, and automated declines may trigger rights related to automated decision-making.

Test Your Knowledge

A retailer sends purchase events to an advertising platform's conversion API, including SHA-256 hashes of customers' email addresses. The marketing team says no personal data leaves the company because the emails are hashed. What is the correct assessment?

A

Incorrect only in the EU; under US state laws hashed data is always deidentified.

B

Correct, because SHA-256 is a one-way function, so the advertising platform cannot learn anything about the retailer's customers.

C

Incorrect; the platform can match the hashes, so they remain personal data subject to consent and opt-outs.

D

Correct, provided the hashes are truncated to 16 characters.

Test Your Knowledge

Under PCI DSS, which data element may a merchant never store after a payment has been authorized, even if encrypted?

A

The cardholder's name

B

The last four digits of the card number

C

The card verification code (CVV2/CVC2)

D

The card expiration date

Test Your Knowledge

Customers of an online pharmacy often type card numbers and medication details into its AI support chatbot, and transcripts are kept indefinitely by the chat vendor. Which set of controls best reduces the privacy risk?

A

Allow the vendor to train its general-purpose model on the transcripts in exchange for a lower subscription price.

B

Disclose the bot, redact sensitive data in real time, route payments to checkout, authenticate lookups, and limit vendor use.

C

Disable the chatbot's disclosure notice so customers feel more comfortable sharing details.

D

Keep transcripts indefinitely for quality review, but encrypt them at rest with a key managed by the chat vendor.

Sections you finish are checked off in the contents.