Guide
Wholesale applicant data under GDPR: why deletion beats anonymisation
Wholesale applications collect exactly the data that GDPR treats most carefully: names, business addresses, contact details, and sometimes a passport-adjacent identifier. Most stores handle the approvals well and the rejections badly — the applicant you turned down is the one whose data you have no lawful reason to keep, and "we anonymise it" is usually not the answer people think it is. This guide covers what to keep, for how long, and why deletion beats anonymisation for business applicants.
The rejected applicant is the hard case
An approved applicant becomes a customer: you have a contract, a company record, orders, and invoices you are legally required to retain. The lawful basis is clear and the retention period is set by tax law, not by preference.
A rejected applicant has none of that. There is no contract, no ongoing relationship, and after the decision is communicated there is usually no purpose left. GDPR's storage limitation principle (Art. 5(1)(e)) says data may be kept no longer than necessary for the purposes it was collected for — and once you have decided not to trade with someone, the application has served its purpose.
The usual objection is that you want a record in case they reapply, or in case of a dispute. Both can be legitimate, but both need to be stated as a purpose with a retention period attached, not left as a vague intention. A defensible position looks like: "rejected applications are deleted after 90 days; we retain the decision and its date for 12 months to handle reapplications and disputes." What is not defensible is keeping the full application indefinitely because nobody built the deletion path.
Why anonymisation usually fails here
Anonymisation is attractive because it removes the data from GDPR's scope entirely — anonymous data is not personal data. The catch is the standard: data is only anonymous if re-identification is not reasonably possible by anyone, using any means reasonably likely to be used.
Business applicant data rarely clears that bar. A company name plus a VAT number is a public registry lookup away from a named human — that is precisely what registries are for. For a sole trader, the company name frequently is the person's name. Strip the contact name and email, keep "Müller Handel, DE123456789, applied 4 March, rejected", and you have a record that identifies an individual to anyone with a browser.
So the pattern of "anonymise instead of delete" that works for web analytics does not transfer to B2B applications. Deletion is simpler, cheaper to explain, and actually achieves the goal. If you want to keep statistics, keep counts — applications per month, approval rate — not de-identified rows.
Who is the controller?
This gets muddled when an app is involved. The merchant decides to run a wholesale program, decides the questions on the form, and decides who gets approved: the merchant is the controller for applicant data. An app processing that data on the merchant's behalf is a processor, and needs an Art. 28 data processing agreement to be lawful.
Two practical consequences. First, the retention period is the merchant's decision, not the app's default — so it should be configurable, and the app should not quietly keep data longer than the merchant told it to. Second, when an applicant exercises their rights, the request lands with the merchant, and the app has to be able to answer it: find the record, export it, delete it. An app that cannot delete a single applicant on request is not usable by a controller who has to comply.
Registry lookups and data minimisation
Verification is a place where it is easy to send more than necessary. Checking a business against VIES, Zefix or Companies House requires a company identifier — a VAT number, a registry number. It does not require the applicant's name, email or address, and sending those to a third party would be processing without a purpose.
Keep the split clean: the registry receives the identifier and returns a status; the applicant's personal details never leave your systems. That is both minimisation in the Art. 5(1)(c) sense and a much shorter answer when someone asks what your subprocessors receive.
Do keep the evidence of the check. For intra-EU supplies the validity of the buyer's VAT ID is a substantive condition of zero-rating, so the VIES consultation ID and the date belong in your records — attached to the company, not floating in a log. That is a retention purpose with a real legal basis behind it, and it is worth distinguishing from the application itself.
What belongs in the privacy notice
The wholesale form is a collection point, so it needs its own paragraph rather than a link to a general policy. What applicants should be able to read before submitting:
- What is collected, and which fields are required versus optional.
- That the business details are checked against public registries, and which ones.
- How long an application is kept if approved, and if rejected — with actual numbers.
- Who processes it besides you, and where (hosting region matters to European buyers).
- How to request access or deletion, and that a decision is not made by automated means alone — or, if it is, say so, because Art. 22 attaches rights to that.
That last point is worth care. Auto-approval rules are convenient and defensible for low-risk cases, but "your application was rejected automatically" is a different legal position from "we reviewed it". If rejections are automated, applicants have a right to human intervention.
A retention model that holds up
A structure that covers the realistic cases:
- Approved and became a customer — retained under the customer relationship; invoices follow tax-law retention (in Germany, 8 years for invoices), not the application's schedule.
- Approved but never ordered — a company record with no transactions. Give it an expiry: if there is no order within, say, 24 months, it is a dormant record with no purpose.
- Rejected — delete the application on a short clock; keep the decision and date only as long as you have a stated reason.
- Withdrawn or abandoned — a half-finished form is data you never had a use for. Delete it soonest of all.
Whatever the numbers, the sweep has to actually run. A retention policy that exists only in a privacy notice is worse than none: you have published a promise you are breaking.
The short version
Applicant data is the liability in a wholesale program, and rejections are where it accumulates. Delete rather than anonymise, because a company name plus a VAT number re-identifies a sole trader. Send registries an identifier and nothing else, but keep the verification evidence with a legal basis of its own. Put real retention numbers in the privacy notice, make them configurable by the merchant who is the controller, and make sure something automated enforces them.
Plain-language summary, not legal advice — retention periods and the lawful basis for your specific program are worth a lawyer's half hour.
Verify your next wholesale application automatically
Anmelda checks every B2B application against VIES, Zefix and Companies House, then creates the native Shopify company for you.
Add to Shopify