Online store customer data flow.
This GDPR data flow diagram traces personal data through a typical online-store checkout. A customer interacts with the storefront, which passes the order to a service that stores customer and order records. The service also sends information to separate payment and fulfillment processors. Clear trust boundaries make those external disclosures visible, while the audit log shows a separate operational record of the order event. This layout is useful when preparing a DPIA, a vendor inventory or a data-processing map. Replace the generic systems and labels with the services actually used and record the purpose, lawful basis and retention period for each flow. The diagram is a documentation aid rather than a legal determination.
Open it in the AI editor with a prompt pre-filled — keep what works, change what doesn't.
Scenario
DPIA
Key decisions
- Separate processors: Payment and fulfillment services sit outside store systems.
- Purpose-specific stores: Customer, order and audit data use separate stores.
- Boundary crossings: Payment and shipping details leave the order service.
When to reuse this
Use this DFD to begin documenting customer data flows for an ecommerce privacy review.
Frequently asked questions
Why are payment and fulfillment shown separately?
What does the audit log represent?
Is this a complete DPIA?
Tweak it with chat, export PNG/SVG, or fork it for your own use case.