By business type

GDPR Policy Generator for marketplaces

Written for two-sided platforms: joint controllership, seller data, DSA duties and payouts.

Generate your GDPR policy Read the GDPR policy guide

The GDPR question on a marketplace is not what you process but in which capacity. Getting the controller, joint controller and processor split right per data flow determines who answers a request, who notifies a breach and which contract you need with sellers.

Marketplaces have a role problem that single-sided businesses do not. For your own account and platform data you are a controller. For data flowing between buyer and seller you may be a joint controller, a processor, or an independent controller depending on the specific flow - and Article 26 requires joint controllers to have an arrangement and to make its essence available to individuals.

The Digital Services Act added a substantial layer for marketplaces serving the EU: trader traceability, notice-and-action, statements of reasons for removals, internal complaint handling, and a ban on dark patterns in interface design. These are platform obligations, not seller obligations, and they cannot be delegated.

Payouts introduce a third dimension. Splitting payments between platform and seller usually means identity verification on sellers, tax reporting obligations, and a payments partner who becomes a significant party in the data chain.

What a GDPR policy for an online marketplace has to cover

How an online marketplace actually moves personal data

Buyer data shared with sellers

Name, delivery address and order contents passed to a seller who then becomes a controller in their own right for fulfilment.

Seller onboarding and verification

Identity documents, bank details and tax identifiers collected for verification and reporting.

Messaging between users

On-platform messages are personal data you host, with moderation, retention and disclosure questions attached.

Reviews and ratings

Published personal data about identifiable sellers and buyers, with rights to object and correct.

Payouts and tax reporting

Seller earnings data reported to tax authorities under marketplace reporting rules.

Moderation and enforcement records

Evidence of removals and suspensions, retained to support the statements of reasons the DSA requires.

Third parties the draft will ask you about

Stripe Connect or Adyen for Platforms · identity verification vendors · AWS or Google Cloud · Zendesk · trust and safety tooling · tax reporting providers

The rules that apply

GDPR Article 26 joint controllership

Where you and sellers jointly determine purposes and means, you need an arrangement and must make its essence available to data subjects.

Digital Services Act

Trader traceability, notice-and-action, statements of reasons, internal complaints, and interface design rules for marketplaces serving the EU.

Seller identity and tax reporting

Marketplace reporting rules require collection and reporting of seller identity and income data in many jurisdictions.

Consumer law allocation

Who the consumer contracts with - platform or seller - determines who owes cancellation rights and remedies.

Payments and KYC on sellers

Split payments usually trigger identity verification duties through the payments partner.

What the generated GDPR policy contains

The marketplace document set

  1. Map each data flow to a role

    Controller, joint controller or processor - per flow, not per relationship.

  2. Put an Article 26 arrangement in the seller terms

    And publish its essence where buyers can find it.

  3. Build DSA notice-and-action

    Reporting route, statements of reasons, internal complaints, and record-keeping.

  4. Separate buyer terms from seller terms

    Two audiences, two sets of obligations, two documents.

  5. Minimise what sellers receive

    And say what they receive in the buyer-facing policy.

  6. Document the payouts and reporting chain

    Including the payments partner’s own role and the tax reporting obligation.

Where this usually goes wrong

No Article 26 arrangement with sellers

Where joint controllership genuinely exists, the arrangement is mandatory and its essence has to be available to users.

Treating sellers as processors when they are controllers

A seller fulfilling an order decides its own purposes. Calling them a processor misdescribes the relationship and the contract.

Missing DSA notice-and-action machinery

It is a platform obligation with its own procedural requirements, including statements of reasons and internal appeals.

Dark patterns in the interface

Explicitly prohibited by the DSA for marketplaces, and separately actionable under consumer law.

Buyer data over-shared with sellers

Sellers need what fulfilment requires, not the full customer record.

Unclear contracting party

If a consumer cannot tell whether they contracted with you or a seller, the cancellation and remedy obligations land on you.

Frequently asked questions

Is a marketplace a controller or a processor?

Usually a controller for platform data and, for some flows, a joint controller with sellers. Sellers are typically independent controllers for fulfilment. The right answer is per data flow rather than per relationship.

What does the DSA require of marketplaces?

Trader traceability, a notice-and-action mechanism, statements of reasons for moderation decisions, an internal complaint-handling system, and interface design free of dark patterns.

Do I need separate terms for buyers and sellers?

Yes. They have different obligations, different rights and different commercial terms, and merging them produces a document that is unclear to both.

How much buyer data should sellers receive?

What fulfilment requires and no more. Over-sharing is a minimisation failure and increases your exposure when a seller mishandles it.

Does GDPR apply to a business outside the EU?

Yes, where you offer goods or services to people in the EU or monitor their behaviour. Article 3(2) is about where the person is, not where you are - and Article 27 may also require you to appoint an EU representative.

What is the difference between EU GDPR and UK GDPR?

The text is nearly identical, but they are separate laws with separate regulators, separate fine ceilings in different currencies, and separate transfer regimes. A business serving both needs both named, not "GDPR" as shorthand.

Do I need a Data Protection Officer?

Only where your core activities involve large-scale regular monitoring or large-scale special-category data, or you are a public authority. Many businesses do not need one - but if you do not have one, say who is accountable instead.

Is a GDPR policy the same as a privacy policy?

No. The privacy policy is the outward-facing notice. The GDPR policy set is the internal machinery - lawful basis register, ROPA, rights procedure, breach plan - that lets you answer a regulator when they ask how the notice is honoured.

GDPR Policy Generator for marketplaces

Answer a short questionnaire and get a draft written for an online marketplace. Free to start, no card required.

Generate your GDPR policy

Other documents an online marketplace needs

Each one is written for the same context, not a generic template.

The same document, by business type

Go deeper

PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.