Refrigerated Frozen Foods logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Refrigerated Frozen Foods logo
  • NEWS
  • PRODUCTS
  • COLD STORAGE
    • Cold Storage Trends
    • Farm to Frozen
    • Supply Chain & Logistics
  • PACKAGING
  • TOPICS
    • Food Safety
    • Product Development & Manufacturing
    • Sustainable Solutions for Cold Foods
  • MEDIA HUB
    • Play Our Word Game
    • Podcasts
    • Videos
    • Polls
    • Webinars
  • DIRECTORIES
    • Cold Storage Construction Guide
    • Warehouse Guide
    • Food Master
  • MORE
    • Cold Chain Perspectives
    • Case Studies
    • C-Suite Q&A
    • Top 150 Processors
    • Awards >
      • Best New Retail Products
      • Cold Storage Facility of the Year
      • Processor of the Year
    • Directory of Associations
    • R&FF Store
    • Calendar of Events
    • FA&M Conference & Expo
  • EMAG
    • eMagazine
    • Archive Issues
    • Contact
    • Advertise
  • SIGN UP!
Food SafetyCold Chain Perspectives

How GDPR affects the U.S. grocery industry

Several chains have displayed international influence with the presence of not only brick-and-mortar stores in several nations, but also through international marketing efforts.

By Greg Sparrow
ComplianceData Greg Sparrow
April 10, 2018

The General Data Protection Regulation (GDPR) continues to be an important topic of conversation for U.S. companies. Since its inception, the GDPR has raised a number of questions as to whether businesses are properly prepared to comply.

The GDPR was adopted on April 27, 2016 and allotted a 2-year post-adoption grace period for businesses to strategize and implement their compliant approach. With only three months left, it has been reported that an estimated 61% of U.S. businesses are not ready for the regulation, and that only 67% of European-based businesses have begun moving into the implementation phase of their GDPR compliance program, according to a study produced by TrustArc, San Francisco. The potential fines have many concerned about compliance as the May 25 date of enforcement approaches, but businesses struggle with fully understanding the regulation, thus failing to launch a comprehensive plan.

Turning our focus to the grocery industry, several chains have displayed international influence with the presence of not only brick-and-mortar stores in several nations, but also through international marketing efforts. For example, after Amazon, Seattle, Wash., acquired Whole Foods Market, Austin, Texas, in June 2017, the e-commerce giant became America’s fifth-largest grocery retailer. Outside of the benefit of concrete locations near its customers, the marketing data obtained through the acquisition provided Amazon valuable behavioral statistics on grocery-buying habits, patterns and product preferences.

The GDPR places Amazon’s acquired Whole Foods business unit under scope not only for its presence in the United Kingdom, but also due to its monitoring of European Union (EU) data subjects and attempt to offer them goods and/or services. Amazon’s practices most likely include the use of automated individual decision making against EU data subjects, requiring explicit consent under the GDPR. Processing is broadly defined in the regulation to include most actions that can be performed with data and can specifically refer to collection and storage, which in this case, would be under Amazon’s wheelhouse. The retailer must therefore have processes in place to honor nine distinct rights awarded to EU data subjects, and be able to operate under the guiding privacy principles defined within the GDPR. The regulation further dictates appropriate security efforts around the protection of personal data, establishes breach reporting requirements and increases risk associated with vendors processing this data. These expansive requirements make the process of marketing and vendor outsourcing more complex for anyone with a direct consumer relationship with EU data subjects.

Many smaller agencies may not be considering the new regulations as seriously as they should be, but past enforcement actions point to enforcement risk even with smaller agencies. The GDPR states that non-compliant companies posing a risk to EU citizens and their privacy can be fined up to $20 million or 4% of their global turnover for the previous fiscal year, whichever is greatest. It is important to note that this fine would be per violation. It can certainly be assumed that larger repercussions would be imposed in this hypothetical case, since case law suggests similar types of violations don’t stand alone and typically occur with others. 

There are several steps that companies must immediately embark on to mitigate their exposure to risk. A solid start begins with understanding GDPR regulation applicability to various parts of the business, and understanding each unit’s risk profile to establish priorities for the initiative. Once risk and priorities have been identified, it is critical for organizations to identify and establish their lawful basis for processing of this data.

Every industry has its own unique risk and operational challenges, and every business within has its own maturity relative to industry peers. Using the trusted counsel of a compliance firm helps to quickly identify both industry and organizational risk that, as a non-biased third-party, are often otherwise overlooked. A risk management and compliance consulting firm can help organizations quickly identify risk, formulate a plan to mitigate this risk and set up ongoing monitoring programs to maintain valuable records of compliance. 

Some have suggested the GDPR will set the global precedent for data privacy and security regulations.  Brazil and China have both showed interest in forming similar requirements to protect the privacy of its citizens’ personal information from businesses storing and transferring data across borders.

To adequately prepare for the GDPR and similar regulations, businesses must become educated on these regulations and determine how to conquer the requirements. Applicable processes and procedures can help minimize exposure to fines, but also provide an opportunity within the market to reassure customers and earn their trust.

 

KEYWORDS: data analytics data management General Data Protection Regulation risk management strategies

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Greg Sparrow is senior vice president and general manager of CompliancePoint, Duluth, Ga.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Best New Retail Products of 2026 badge with grocery store refrigerators in the background.

    Top of the Freezer: R&FF’s Best New Retail Products

    From BFY proteins to globally inspired treats, these...
    Product Development & Manufacturing
    By: Kelley Rodriguez
  • Pasco Exterior

    Reser’s Fine Foods: From Farmhouse Kitchen to ‘Good Times’ Everywhere

    A home-based potato salad company started 75 years ago...
    Product Development & Manufacturing
    By: Kelley Rodriguez
  • FromtheColdCorner-Anchor_1170x658.jpg

    EPR, Plastic Packaging for Cold Foods & More

    As consumer and regulatory pressure put plastic in the...
    Sustainable Solutions for Cold Foods
    By: Kelley Rodriguez
Manage My Account
  • eMagazine
  • What’s Hot in Cold Newsletter
  • Manage My Preferences
  • Online Registration
  • Customer Service

More Videos

Popular Stories

From the Cold Corner with Americold's Rob Chambers feature image

How Cold Chain Strategy Is Replacing Capacity

Best New Retail Products of 2026 badge with grocery store refrigerators in the background.

Top of the Freezer: R&FF’s Best New Retail Products

1170x658 of Cold Storage Podcast with Jennifer Jewers Bowlin and Craig Handy

ASRS, AI & Adaptability: What's Shaping the Future of Cold Storage

2026 Processor of the Year

 

Does your facility lead the industry? Nominate your cold storage facility today!

Events

June 17, 2025

Refrigerated & Frozen Foods’ State of the Cold Chain

On Demand Kelley Rodriguez, Editor in Chief of Refrigerated & Frozen Foods, will be joined in this 60-minute webinar by industry experts to help unpack the latest research.

January 1, 2030

Webinar Sponsorship Information

For webinar sponsorship information, visit www.bnpevents.com/webinars or email webinars@bnpmedia.com.

View All Submit An Event

Products

Water Activity in Foods: Fundamentals and Applications, 2nd Edition

Water Activity in Foods: Fundamentals and Applications, 2nd Edition

See More Products
New Retail Products

Explore the newest flavors, textures, and innovations in the frozen food aisle!


SEE WHAT'S NEW!
Play Refrigerated & Frozen Foods’ Cool Word of the Week! There's a new word every Wednesday.

Related Articles

  • DriverReach Steve Iskander

    How the driver shortage affects the food, beverage industry

    See More
  • Angela Fernandez

    The retail grocery industry’s to-do list for 2017

    See More
  • GS1 Angela Fernandez

    The drivers of e-commerce growth in the grocery industry

    See More

Related Products

See More Products
  • small-occ.jpg

    Occupational Health and Safety in the Food and Beverage Industry

  • statical.jpg

    Statistical Process Control for the Food Industry: A Guide for Practitioners and Managers

  • The 10 Principles of Food Industry Sustainability

See More Products
×

Elevate your expertise in refrigerated and frozen foods with unparalleled insights and connections.

Get the latest industry updates tailored your way.

JOIN TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Directories
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Service
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBLITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing