Rules and ethics
Part of UK compliance for marketplace sellers, from the factual trigger to the device map
Mapping marketplace seller data flows and device access before switching a service on
Map marketplace seller data flows, device access, roles, recipients, retention, security, incidents and deletion safely before enabling a service.
Marketplace seller software data protection begins with an exact flow map. For one England merchant, name the authorised seller, marketplace account, software service, managed provider and bounded product-to-order journey. Do not assume that a contract label settles controller or processor status.
Research closed on 6 September 2026. All data-protection provisions of the Data (Use and Access) Act 2025 were in force by 19 June 2026, according to the ICO's organisational summary. Some detailed ICO pages remain under review, so qualified publication-day checks are required.
Draw each processing operation
Create one row for each purpose rather than one box called "order data". Include account-user administration, catalogue contacts, customer order and delivery details, messages, cancellations, return reasons, fraud indicators, support records, logs and analytics. Record:
- purpose, affected people and lawful-basis decision;
- source, exact fields, identity unit and collection time;
- seller, marketplace, supplier and managed-provider actions;
- recipients, remote access, location and transfer evidence;
- retention, rights handling, correction, export and deletion; and
- owner, evidence version and recheck trigger.
The ICO groups lawfulness, fairness, transparency, purpose limitation, minimisation, accuracy, storage limitation, security and accountability in its guide to the data-protection principles. A privacy solicitor must apply those principles to the actual flow.
Determine roles from facts
Ask who decides each purpose and essential means, who acts on instructions and who uses data for an independent purpose. A supplier can have different roles for delivery, security telemetry or its own records. The ICO's controller and processor guidance explains the role distinction.
For any processor relationship, record subject, duration, nature, purpose, data types, people, instructions, confidentiality, security, subprocessors, rights assistance, audit and end-of-contract handling. The ICO's detailed contracts guidance is marked under review after DUAA changes. Treat that status as a recheck requirement, not an invitation to omit the contract review.
Inspect storage and access technologies
List every cookie, pixel, SDK, local-storage item, device identifier or similar operation, including those introduced by a marketplace widget or support service. State the purpose, duration, third party and whether the operation occurs before a user choice.
The final version of the ICO's storage and access technologies guidance is dated 29 April 2026. It explains PECR and relevant UK GDPR questions. The privacy and PECR reviewers must assess the exact technology and any claimed exception. Payment or marketplace permission does not become consent for unrelated tracking.
Test access, incidents and deletion
Use synthetic records to test minimum permissions, support access, logs, correction, rights routing, export, account removal and deletion. NCSC SaaS security guidance addresses privileged access, monitoring and recovery. It does not certify a configuration.
Record an incident owner, containment route and evidence preservation. ICO breach-reporting guidance is under DUAA review; a qualified adviser must decide notification duties from the actual risk and facts.
Keep production disabled if a role, purpose, transfer, access path, retention period or deletion outcome is unknown. A completed map supports review, but it is not a compliance guarantee.