Skip to content

Marketplace Data in Business Central: Your Obligations as a Seller

Selling through Amazon, Otto, Kaufland or eBay means processing personal data of buyers. Two sets of rules apply at once: your contract with the marketplace, and the GDPR. The software helps — the obligations stay yours.

This article says in plain terms what that means and what merchantCENTRAL takes off your hands.


1. Who is responsible for what

You Controller under the GDPR for the buyer data in your Business Central. You decide on purposes and means, you answer access and erasure requests, you obtain consent.
The marketplace Gives you the data and tells you contractually what you may do with it. Amazon's Data Protection Policy is the strictest of them.
ALTENBRAND Supplies the software. We have no access to your tenant and receive no buyer data. No data processing agreement is therefore needed between us — see privacy statement extension.

2. The three rules it comes down to in practice

Only what is needed

Buyer data may only reach whoever needs it to fulfil the order. The carrier needs the delivery address. It does not need the buyer's mailbox to send notifications of its own — that is a service of the carrier, not part of your delivery.

Not longer than necessary

Once the order is done and the legal retention is secured, buyer data has no place in working records any more. Marketplace policies commonly name 30 days after completion.

Posted documents are exempt

Invoices, delivery notes and ledger entries are subject to statutory retention. Marketplace policies grant that exception explicitly. You must not — and need not — anonymize posted documents.


3. What merchantCENTRAL does for you

Without you doing anything, because these are the software's own working copies:

Data category What happens
Shipment labels Address, contact data and the label, return, customs and QR documents are cleared after delivery. Tracking number and history stay.
Marketplace order records Buyer data, raw payload and processing log are cleared after completion. Numbers, dates, amounts and status stay.
Logs Activity and notification logs expire on their own period.

A nightly job queue entry does both and writes a log entry. That is your evidence.


4. What you have to decide

a) Master data of your marketplace buyers

The order import creates a customer for every buyer. That master data is your business data — merchantCENTRAL counts it in the data protection cockpit and anonymizes it at the press of a button, but never on its own.

The backlog needs deciding too: customers from before the origin was tracked appear as unclear origin in the cockpit and stay untouched until you record on the customer card where they came from.

b) Passing data to carriers

Whether a carrier receives phone number and e-mail address is your decision, per carrier.

Case Recommendation
Parcel service, own notifications Only with recorded consent. German data protection authorities have considered the transfer without consent inadmissible since 2018.
Parcel shop, timed delivery, forwarder notification Only when the service requires it. Here the delivery depends on the value.
Marketplace orders The software decides: e-mail never, phone only when required.

If a carrier stands at Always, you carry the consent behind it. The cockpit counts how many do.

Where consent comes from

From your order process — in your own shop typically a checkbox at checkout. Where it exists, set Recipient Agreed to Carrier Notifications on the sales order or permanently on the ship-to address. Model wording is available from the relevant trade associations; we do not provide legal advice.

c) The periods

30 days is what marketplace policies ask for. Shorter is always allowed. Longer is your decision and your risk towards the marketplace.


5. Access and erasure requests

When a buyer asks for access or erasure:

  1. Find the customer by marketplace customer ID or name.
  2. Report from the customer, the contacts, the marketplace orders and the posted documents.
  3. Erasure here means anonymizing, not removing: posted documents have to stay. Use the Anonymize Marketplace Data action on the customer card.
  4. Open entries block the anonymization. That is correct — while a receivable is open, a purpose exists.

Tell the buyer that posted documents are kept for statutory reasons. That is a valid ground for refusal under Art. 17(3)(b) GDPR.


6. Do I need a data processing agreement?

With whom Answer
ALTENBRAND No. We have no access to your tenant and receive no buyer data.
Parcel service, forwarder (transport only) No. A carrier is a controller of its own for the delivery.
Warehouse or fulfilment provider Yes. Whoever stores or picks for you processes on your behalf.
Microsoft (Business Central) Yes — already covered by your BC agreement.

7. For your retention concept

You can take this table as it stands:

Data category Period Trigger How
Shipment label (recipient data, documents) 30 days delivery automatic, nightly job
Marketplace order record (buyer data, payload) 30 days order completed automatic, nightly job
Unfinished order 90 days order or import date automatic, nightly job
Customer and contacts from the import 30 days last order, no open documents action in the cockpit
Posted invoices, shipments, entries 10 years posting no deletion (statutory retention)

See also