Retail & E-Commerce
PCI, consumer privacy, and omnichannel security
Retail and e-commerce companies process payment data and consumer information across physical and digital channels. Thalorin provides unified compliance infrastructure addressing PCI DSS, consumer privacy regulations, and the security requirements of modern omnichannel retail operations.
California's privacy regulator now sets dates rather than principles. The California Privacy Protection Agency's regulations on cybersecurity audits, risk assessments and automated decisionmaking technology were approved by the Office of Administrative Law on 23 September 2025 and took effect on 1 January 2026. Section 7121 fixes the first cybersecurity audit report at 1 April 2028 for a business whose 2026 gross revenue exceeded $100 million, 1 April 2029 between $50 million and $100 million, and 1 April 2030 below that. Section 7200 requires ADMT compliance by 1 January 2027. Retailers are in scope on volume alone.
The card regime and the privacy regime answer to different masters and meet in the same customer record. PCI DSS v4.0.1 is enforced by acquirers and the card brands against a defined cardholder data environment; state privacy law is enforced by attorneys general and, in California, by an agency with its own rulemaking. Washington's My Health My Data Act, RCW 19.373, attaches to consumer health data rather than to company size, and routes violations through the state Consumer Protection Act. A supplement purchase can pull an ordinary retailer into it.
What gets underestimated is the identity graph. Omnichannel operations join point-of-sale, storefront, app and loyalty into one profile, and that join is what makes a deletion or opt-out request expensive to satisfy honestly. It is also where the sale-and-share question lives: the regulations treat selling or sharing personal information as an activity requiring a risk assessment under section 7150, and they treat inferring a consumer's interests from their presence in a sensitive location the same way. Marketing tags deployed without a data processing agreement quietly decide that question for you.
One customer record, three regimes, is the problem Thalorin is shaped around. The cardholder data environment, the privacy obligations and the contractual classification of every downstream recipient are held against the same asset and the same data flow, so a tag added to a checkout page raises the card-scope question and the sale-or-share question together, and a new state statute becomes a projection of control state that already exists rather than a fresh assessment programme.
Organizations face significant compliance challenges
Opt-out signals against loyalty enrolment
A business that sells or shares personal information must process a valid opt-out preference signal. Where honouring it would withdraw a consumer from a financial incentive programme, section 7025 allows one confirming question and no more — a branch few loyalty stacks implement.
An audit period that starts before the audit
The first cybersecurity audit report is due 1 April 2028 for the largest tier, covering 1 January 2027 through 1 January 2028. Evidence for that period has to already exist by the time anyone selects an auditor.
Scope crosses the lane and the storefront
The cardholder data environment spans store lanes, back office, e-commerce and whatever shares a network with them. Segmenting stores while leaving a common back office in the path is the pattern that expands an assessment after it has begun.
Tags contracted as third parties
Whether an advertising recipient is a service provider or a third party is settled by the contract terms in sections 7051 and 7053, not by intent. Get it wrong and an ordinary page load is a share, disclosed nowhere.
How Thalorin helps
PCI DSS compliance
Model the cardholder data environment across the store estate and the web estate as one boundary, with evidence bound to the lane, store or service that produced it. The PCI DSS capability page carries the standard's own requirements in detail.
Consumer privacy compliance
Track each state statute against the processing activities that trigger it, and carry the California deadlines — ADMT by 1 January 2027, risk assessments for pre-existing processing by 31 December 2027, submission by 1 April 2028 — as dated obligations.
E-commerce security
Hold the checkout page's script inventory as controlled state: what loads, who authorised it, what changed since the last assessment. The same inventory answers a card-scope question and a sale-or-share question.
Point-of-sale security
Carry terminals and lanes as assets with their own firmware, configuration and key state, so a store running an exception is a recorded deviation rather than something discovered during an assessment walkthrough.
Omnichannel data protection
Map the identity graph that joins point-of-sale, app, storefront and loyalty, so a deletion or opt-out request resolves to every system holding the profile rather than the ones the marketing team remembers.
Loyalty program security
Treat the loyalty programme as the financial incentive the CCPA calls it, carrying the Notice of Financial Incentive, the opt-out conflict handling and the enrolment record together with the programme itself.
Retail & E-Commerce: common questions
When is our first CCPA cybersecurity audit report due?
It depends on revenue. Under section 7121, a business whose 2026 annual gross revenue exceeded $100 million must complete its first cybersecurity audit report by 1 April 2028, covering 1 January 2027 to 1 January 2028. Between $50 million and $100 million for 2027, the first report is due 1 April 2029. Below $50 million for 2028, it is due 1 April 2030. After that the audit runs annually, with the report due the following 1 April.
Do we have to honour Global Privacy Control if the shopper is in our loyalty programme?
Yes, with one permitted step in between. A business that sells or shares personal information must process a conforming opt-out preference signal as a valid opt-out request. Where honouring it would withdraw the consumer from a financial incentive programme that requires consent to sale or sharing, you may notify them and ask them to affirm the withdrawal. If they affirm, or if you do not ask, the opt-out must be processed. Ignoring the signal because a loyalty account exists is not an option.
Does using purchase history for advertising require a risk assessment?
If it involves selling or sharing personal information, yes. Section 7150 lists the activities that require a risk assessment before processing begins: selling or sharing personal information, processing sensitive personal information, using automated decisionmaking technology for a significant decision, and certain inferences drawn from systematic observation or from a consumer's presence in a sensitive location. For processing already running before the regulations took effect, the assessment is due by 31 December 2027, with submission to the Agency by 1 April 2028.
Is our analytics vendor a service provider or a third party?
The contract decides, and the two are held to different terms — service providers and contractors under section 7051, third parties under section 7053. A recipient permitted to use the data for its own purposes, including building its own audiences, is not a service provider, and transfers to it are likely to be a sale or a share requiring disclosure and an opt-out. Reviewing which tags run on the checkout path against their contract terms is where most programmes find surprises.
Which state privacy laws apply if we ship nationwide?
Applicability is computed per state, not once. Each comprehensive state statute sets its own thresholds — residents processed, revenue, share of revenue derived from selling personal data — so a retailer can be in scope in some states and out in others with the same operations. Some obligations attach to a data category rather than to company size: Washington's My Health My Data Act governs consumer health data and routes violations through the state Consumer Protection Act.
Regulatory state described as of August 2026. Requirements change; verify against the current rule before relying on any date above.
Talk to us about Retail & E-Commerce.
See how one evidence artifact satisfies Retail & E-Commerce requirements alongside every other framework you carry.