{"id":28319,"date":"2025-12-08T10:00:00","date_gmt":"2025-12-08T10:00:00","guid":{"rendered":"https:\/\/spreecommerce.org\/uk-data-act-ecommerce-compliance\/"},"modified":"2026-04-17T17:59:48","modified_gmt":"2026-04-17T17:59:48","slug":"uk-data-act-ecommerce-compliance","status":"publish","type":"post","link":"https:\/\/spreecommerce.org\/uk-data-act-ecommerce-compliance\/","title":{"rendered":"UK Data (Use and Access) Act 2025: What Every eCommerce Business Needs to Know"},"content":{"rendered":"\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">What Does the UK Data Act 2025 Mean for eCommerce?<\/h2>\n\n\n\n<p>The <a href=\"https:\/\/www.legislation.gov.uk\/ukpga\/2025\/27\/contents\">UK Data (Use and Access) Act 2025<\/a> became law on June 19, 2025, with the most significant reforms taking effect on February 5, 2026. For ecommerce platforms processing UK customer data, this legislation changes how international data transfers work and expands the ICO&#8217;s enforcement authority.<\/p>\n\n\n\r\n  <section  class=\"highlight-box-wrap alignstandard text-align-left\" style=\" \">\r\n    <div class=\"highlight-box highlight-box-green\">\r\n      <div class=\"icon\">\r\n                  <img decoding=\"async\" loading=\"lazy\" width=\"24\" height=\"24\" src=\"https:\/\/spreecommerce.org\/wp-content\/themes\/spree\/images\/bulb.svg\" alt=\"\">\r\n              <\/div><!-- \/.icon -->\r\n      <div class=\"desc\">\r\n        <h3>Key Takeaways<\/h3>\n<p><strong>Last verified:<\/strong> March 2026<\/p>\n<p><strong>Regulation:<\/strong> The UK Data (Use and Access) Act 2025 tightens international transfer rules with a new &#8220;materially lower standards&#8221; test, expands ICO enforcement powers, and requires full audit trails for all data processing.<\/p>\n<p><strong>The SaaS problem:<\/strong> US-owned SaaS platforms (Shopify, BigCommerce, Salesforce, commercetools) create automatic CLOUD Act exposure. Even with UK datacenters, US law enforcement can compel data access without a UK court order.<\/p>\n<p><strong>The solution:<\/strong> Self-hosted, open source commerce deployed on UK infrastructure eliminates CLOUD Act exposure and gives you full control over data residency, retention, and audit trails.<\/p>\n<p><strong>Penalties:<\/strong> PECR fines up to \u00a317.5 million or 4% of global turnover. Data protection violations carry fines up to \u00a320 million or 4% of turnover.<\/p>\n      <\/div><!-- \/.desc -->\r\n    <\/div>\r\n  <\/section>\r\n\r\n\n\n\n\n\n<p>The core change is a new &#8220;data protection test&#8221; for international transfers. Under the previous framework, data could flow to countries with &#8220;adequate&#8221; protection levels. The 2026 reforms shift the burden: any country receiving UK personal data must now maintain protections that are not &#8220;materially lower&#8221; than UK standards. This directly impacts which ecommerce platforms you can safely use when your data flows through US-headquartered vendors.<\/p>\n\n\n\n<p>The ICO issued 36 enforcement actions in 2024 alone, with penalties totaling over \u00a315 million. The new Data Act gives the ICO expanded investigation authority with shorter response timelines for enforcement notices. Maximum PECR fines sit at \u00a317.5 million or 4% of global turnover, whichever is higher. Data protection violations carry separate penalties up to \u00a320 million or 4% of turnover.<\/p>\n\n\n\n<p>For ecommerce businesses, the pressure is clear: know where your customer data physically resides, understand which laws apply, and prove your platform architecture complies with both UK GDPR and the new Data Act.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">What Does the UK Data Act Require for eCommerce Platforms?<\/h2>\n\n\n\n<p><strong>The UK Data Act imposes six core compliance requirements on any platform processing UK personal data.<\/strong> These cover data residency control, approved international transfer mechanisms, CLOUD Act safeguards, data retention and deletion, full audit trails, and updated cookie consent rules.<\/p>\n\n\n\n<p>The ICO&#8217;s transfer guidance is explicit: &#8220;Organisations must ensure that UK personal data transferred internationally receives protection that is not materially lower than under UK data protection law.&#8221; That &#8220;materially lower&#8221; standard is what makes CLOUD Act exposure a compliance liability.<\/p>\n\n\n\n<figure class=\"wp-block-table\" style=\"margin:24px auto 0; overflow-x:auto\">\n<table style=\"border-collapse:collapse; width:100%; table-layout:fixed\">\n<thead><tr><th style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; font-weight:600; background-color:#f3f3f3; vertical-align:top; word-wrap:break-word\">Requirement<\/th><th style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; font-weight:600; background-color:#f3f3f3; vertical-align:top; word-wrap:break-word\">What It Means for Commerce<\/th><th style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; font-weight:600; background-color:#f3f3f3; vertical-align:top; word-wrap:break-word\">Technical Implementation<\/th><\/tr><\/thead>\n<tbody><tr><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\"><strong>Data Residency Control<\/strong><\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">UK personal data must reside in UK infrastructure unless a legal transfer mechanism is in place<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Deploy on AWS eu-west-2, Azure UK, or dedicated UK datacenter<\/td><\/tr><tr><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\"><strong>International Transfer Mechanism<\/strong><\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Data leaving the UK requires UK SCCs, adequacy decision, or binding corporate rules<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Document every cross-border data flow with approved legal basis<\/td><\/tr><tr><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\"><strong>CLOUD Act Safeguards<\/strong><\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">US vendors must document and mitigate US government data access risk<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Data Transfer Impact Assessment (DTIA) for every US-headquartered processor<\/td><\/tr><tr><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\"><strong>Data Retention &#038; Deletion<\/strong><\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Retain for regulatory windows (3-5 years for FCA\/MHRA), delete on demand<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Platform must support configurable retention policies and verified deletion<\/td><\/tr><tr><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\"><strong>Full Audit Trail<\/strong><\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Every transaction, API call, user access, and data modification logged<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Immutable, tamper-evident logging on your own infrastructure<\/td><\/tr><tr><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\"><strong>Cookie &#038; Consent Rules<\/strong><\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Low-privacy-risk cookies (analytics, session) no longer require explicit consent<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">High-privacy-risk cookies still require active consent<\/td><\/tr><\/tbody>\n<\/table>\n<\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">Industries Affected by the UK Data Act<\/h2>\n\n\n\n<p>The UK Data Act affects all industries processing UK personal data, but regulated sectors face the steepest compliance timelines and the most frequent audit requirements.<\/p>\n\n\n\n<p><strong>Financial Services<\/strong> face immediate obligations. The FCA&#8217;s PS21\/3 supervisory statement already expected UK data residency. The Data Act 2025 now legally mandates this with automatic ICO enforcement. Banks, fintech platforms, insurers, and payment processors must demonstrate compliance at every annual audit.<\/p>\n\n\n\n<p><strong>HealthTech and Medical Devices<\/strong> fall under both MHRA regulation and NHS data-sharing requirements. The MHRA requires manufacturers and distributors of medical devices to maintain UK or EEA data residency. The new Data Act closes loopholes that previously allowed US cloud storage for telemedicine platforms, patient data systems, and electronic prescription services.<\/p>\n\n\n\n<p><strong>Regulated Professional Services<\/strong> including law firms and legal services must comply with professional body data protection rules alongside the UK Data Act. See <a href=\"\/uk-legal-services-ecommerce\/\">UK Legal Services commerce<\/a> for professional services guidance.<\/p>\n\n\n\n<p><strong>eCommerce and Retail<\/strong> businesses processing payment card data (PCI-DSS) or customer health information at scale face scrutiny, particularly for high-value transactions. See <a href=\"\/public-sector-procurement-ecommerce\/\">Public sector procurement commerce<\/a> for government-specific guidance.<\/p>\n\n\n\n<p><strong>Marketplace and Multi-Seller Platforms<\/strong> carry special exposure: they process data on behalf of multiple vendors. Operating a marketplace on a US-hosted platform creates a cascading data transfer risk for every seller.<\/p>\n\n\n\n<p>For organizations handling EU data alongside UK data, <a href=\"\/gdpr-schrems-ii-ecommerce-compliance\/\">GDPR and Schrems II compliance<\/a> creates overlapping requirements that demand unified EU\/UK infrastructure strategies.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">Why Do US-Owned SaaS Platforms Create UK Data Risk?<\/h2>\n\n\n\n<p>US-headquartered SaaS platforms create automatic CLOUD Act exposure that the UK Data Act&#8217;s &#8220;materially lower standards&#8221; test now treats as a compliance liability. The issue is structural, not a matter of vendor intent.<\/p>\n\n\n\n<p>The US CLOUD Act (2018) allows US federal law enforcement to compel any US company to hand over data, regardless of where that data is physically stored. A Shopify server in Dublin, a BigCommerce instance in London, or a Salesforce deployment in Frankfurt can all be accessed by US authorities under US law.<\/p>\n\n\n\n<p><strong>The US Department of Justice processed over 130,000 data requests in 2023 alone.<\/strong> From a UK data protection perspective, this violates the &#8220;materially lower standards&#8221; test because US legal process does not require a UK court order.<\/p>\n\n\n\n<p>According to the ICO&#8217;s 2024 annual report, international data transfer complaints increased by 28% year-over-year, with CLOUD Act exposure cited as a growing concern in enforcement decisions. The trend is clear: the regulatory environment is tightening, not loosening.<\/p>\n\n\n\n<figure class=\"wp-block-table\" style=\"margin:24px auto 0; overflow-x:auto\">\n<table style=\"border-collapse:collapse; width:100%; table-layout:fixed\">\n<thead><tr><th style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; font-weight:600; background-color:#f3f3f3; vertical-align:top; word-wrap:break-word\">UK Data Capability<\/th><th style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; font-weight:600; background-color:#f3f3f3; vertical-align:top; word-wrap:break-word\">Shopify Plus<\/th><th style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; font-weight:600; background-color:#f3f3f3; vertical-align:top; word-wrap:break-word\">BigCommerce<\/th><th style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; font-weight:600; background-color:#f3f3f3; vertical-align:top; word-wrap:break-word\">Salesforce Commerce Cloud<\/th><th style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; font-weight:600; background-color:#f3f3f3; vertical-align:top; word-wrap:break-word\">commercetools<\/th><\/tr><\/thead>\n<tbody><tr><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\"><strong>Company HQ<\/strong><\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Canada (NYSE-listed, US jurisdiction)<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">US (Charleston, SC)<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">US (San Francisco)<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Germany (SAP\/US investor-backed)<\/td><\/tr><tr><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\"><strong>UK Data Residency<\/strong><\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">\u26a0\ufe0f EU datacenters, CLOUD Act exposure remains<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">\u26a0\ufe0f Limited UK options, primarily US\/EU<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">\u26a0\ufe0f US-hosted default, UK requires contract addendum<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">\u26a0\ufe0f EU residency possible, CLOUD Act still applies<\/td><\/tr><tr><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\"><strong>CLOUD Act Exposure<\/strong><\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">\u26a0\ufe0f US parent company subject to US warrants<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">\u26a0\ufe0f Direct US company, automatic exposure<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">\u26a0\ufe0f Direct US company, automatic exposure<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">\u26a0\ufe0f US-influenced governance via investors<\/td><\/tr><tr><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\"><strong>Data Retention Control<\/strong><\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">\u274c Vendor-controlled retention policies<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">\u274c Retention tied to plan level, no granular control<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">\u26a0\ufe0f Admin console retention, async deletion<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">\u26a0\ufe0f Possible via API, compliance burden on you<\/td><\/tr><tr><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\"><strong>Full Audit Trail<\/strong><\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">\u26a0\ufe0f Admin logs, gaps in API-level changes<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">\u26a0\ufe0f Basic logging, incomplete API audit trail<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">\u2705 Audit trail including API calls<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">\u26a0\ufe0f Event log requires custom implementation<\/td><\/tr><tr><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\"><strong>Self-Hosting (UK)<\/strong><\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">\u274c SaaS-only, no self-hosting<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">\u274c SaaS-only, no self-hosting<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">\u274c SaaS-only, no self-hosting<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">\u274c SaaS-only, no self-hosting<\/td><\/tr><\/tbody>\n<\/table>\n<\/figure>\n\n\n\n<p>Every US-owned SaaS platform inherits CLOUD Act exposure even when offering UK datacenters. No US company can contractually guarantee it will refuse to comply with a US warrant, making documented CLOUD Act mitigation effectively impossible on SaaS.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">How Self-Hosted Open Source Commerce Meets UK Data Act Requirements<\/h2>\n\n\n\n<p>Self-hosted commerce on UK infrastructure eliminates CLOUD Act exposure entirely. When you deploy on your own servers in the UK, you control the jurisdiction, the encryption keys, the retention policies, and the audit trail. The international transfer question becomes moot because data never leaves your infrastructure.<\/p>\n\n\n\n<figure class=\"wp-block-table\" style=\"margin:24px auto 0; overflow-x:auto\">\n<table style=\"border-collapse:collapse; width:100%; table-layout:fixed\">\n<thead><tr><th style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; font-weight:600; background-color:#f3f3f3; vertical-align:top; word-wrap:break-word\">UK Data Act Requirement<\/th><th style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; font-weight:600; background-color:#f3f3f3; vertical-align:top; word-wrap:break-word\">SaaS Risk<\/th><th style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; font-weight:600; background-color:#f3f3f3; vertical-align:top; word-wrap:break-word\">Self-Hosted Solution<\/th><th style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; font-weight:600; background-color:#f3f3f3; vertical-align:top; word-wrap:break-word\">Spree Implementation<\/th><\/tr><\/thead>\n<tbody><tr><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\"><strong>Data Residency<\/strong><\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">CLOUD Act exposure despite UK datacenter claims<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">You control the server location in AWS UK, Azure UK, or dedicated UK hosting<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Deploy on UK infrastructure, data never leaves your control<\/td><\/tr><tr><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\"><strong>Transfer Mechanism<\/strong><\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">CLOUD Act creates exposure not covered by SCCs<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">No outbound transfer, data stays on UK servers<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">All processing on your UK deployment, no third-party SaaS<\/td><\/tr><tr><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\"><strong>CLOUD Act Safeguards<\/strong><\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">US government can compel SaaS vendor access<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">You (a UK entity) are the data controller, US law does not apply<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Full control of backup locations, encryption keys, access logs<\/td><\/tr><tr><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\"><strong>Retention &#038; Deletion<\/strong><\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Vendor-controlled deletion, no verified erasure<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">You control live data and backups, delete and verify in your logs<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Configurable retention windows, verified deletion in audit logs<\/td><\/tr><tr><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\"><strong>Audit Trail<\/strong><\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Depends on SaaS vendor logging completeness<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Every API call, database change, and user access logged to your systems<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Every transaction and admin action logged to your infrastructure<\/td><\/tr><tr><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\"><strong>Cookie Control<\/strong><\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Inherit vendor&#8217;s cookie and analytics policies<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">You choose which cookies to set and which analytics to run<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Full control of cookie stack, no mandatory third-party cookies<\/td><\/tr><\/tbody>\n<\/table>\n<\/figure>\n\n\n\n<p>For UK businesses that must meet the Data Act while running commerce at scale, a self-hosted open source platform with built-in data sovereignty controls provides the strongest architectural fit.<\/p>\n\n\n\n<p>Spree&#8217;s BSD 3-Clause license means your security team can audit every line of code. No proprietary black boxes processing your customer data. Compliance capabilities like audit trails, configurable retention policies, and enterprise authentication (SSO\/SAML) are built into the platform, not added through third-party plugins that introduce their own data transfer risks.<\/p>\n\n\n\n<p>You own the infrastructure, the code, the data, and the compliance posture. Deploy on any UK cloud provider, any UK datacenter, or on-premises. Integrate any payment processor with UK residency commitments (Adyen, Stripe UK entity) without forced vendor dependencies.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">Architecture &#038; Deployment for UK Data Act-Compliant Commerce<\/h2>\n\n\n\n<p>A UK Data Act-compliant commerce architecture requires UK-based infrastructure at every layer, with documented data residency and no automatic replication to non-UK regions.<\/p>\n\n\n\n<p><strong>Data layer.<\/strong> Primary PostgreSQL database on AWS RDS in eu-west-2, Microsoft Azure UK, or a self-managed UK datacenter. Encrypt at rest with keys you control. Encrypted backups to UK S3 or Azure storage with defined retention windows (30-day rolling for operations, 3-5 years for FCA\/MHRA regulatory holds). No automatic backup replication to US regions.<\/p>\n\n\n\n<p><strong>Application layer.<\/strong> Deploy on Kubernetes in a UK region (AWS EKS eu-west-2, Azure AKS UK) or your own UK cluster. Isolate the application layer from third-party SaaS tools with US headquarters. Authentication via SSO\/SAML for enterprise customers, using UK-resident identity infrastructure rather than US-based providers without explicit residency contracts.<\/p>\n\n\n\n<p><strong>Payment layer.<\/strong> Use a UK-based payment processor (Adyen, Stripe with UK entity commitment) or a local acquiring bank. PCI-DSS compliance via tokenization ensures no raw card data touches your servers. Avoid routing payment data through US-headquartered intermediaries without documented transfer mechanisms.<\/p>\n\n\n\n<p><strong>Monitoring and compliance layer.<\/strong> Centralized, immutable logging on UK infrastructure (Elasticsearch or Splunk on UK servers). UK-based application performance monitoring. Define RTO\/RPO targets. Maintain encrypted, UK-based off-site backups. Test recovery quarterly. Audit every third-party integration to ensure customer data does not flow to US endpoints without approved transfer mechanisms.<\/p>\n\n\n\n<p>Self-hosted infrastructure in the UK runs roughly 10-20% more expensive than US-based hosting. For regulated industries (financial services, HealthTech), the compliance liability reduction and audit simplification justify the premium.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">UK Data Act Compliance by Industry<\/h2>\n\n\n\n<p>Different regulated sectors face different timelines, oversight bodies, and audit frequency under the UK Data Act.<\/p>\n\n\n\n<figure class=\"wp-block-table\" style=\"margin:24px auto 0; overflow-x:auto\">\n<table style=\"border-collapse:collapse; width:100%; table-layout:fixed\">\n<thead><tr><th style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; font-weight:600; background-color:#f3f3f3; vertical-align:top; word-wrap:break-word\">Industry<\/th><th style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; font-weight:600; background-color:#f3f3f3; vertical-align:top; word-wrap:break-word\">Regulatory Body<\/th><th style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; font-weight:600; background-color:#f3f3f3; vertical-align:top; word-wrap:break-word\">Compliance Deadline<\/th><th style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; font-weight:600; background-color:#f3f3f3; vertical-align:top; word-wrap:break-word\">Key Requirement<\/th><th style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; font-weight:600; background-color:#f3f3f3; vertical-align:top; word-wrap:break-word\">Audit Frequency<\/th><\/tr><\/thead>\n<tbody><tr><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\"><strong>Financial Services<\/strong><\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">FCA<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Immediate (PS21\/3 already expected UK residency)<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">UK data residency + full audit trail + segregated client data<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Annual<\/td><\/tr><tr><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\"><strong>HealthTech<\/strong><\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">MHRA<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Immediate<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">UK\/EEA residency + documented CLOUD Act mitigation<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Annual<\/td><\/tr><tr><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\"><strong>Insurance<\/strong><\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">FCA \/ PRA<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Immediate<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">UK residency + audit trail + cyber security standards<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Annual<\/td><\/tr><tr><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\"><strong>Payments &#038; E-Money<\/strong><\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">FCA<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Immediate<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">UK residency + segregated customer funds data<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Annual<\/td><\/tr><tr><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\"><strong>Digital Health<\/strong><\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">NHS DSPT<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Ongoing<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">UK residency + information governance standards<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Annual<\/td><\/tr><tr><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\"><strong>General Retail \/ B2C<\/strong><\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">ICO<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">February 5, 2026<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">UK residency recommended; GDPR + Data Act compliance<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">On complaint basis<\/td><\/tr><tr><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\"><strong>B2B eCommerce<\/strong><\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">ICO<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">February 5, 2026<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">GDPR + Data Act compliance<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">On complaint basis<\/td><\/tr><tr><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\"><strong>Multi-Seller Marketplaces<\/strong><\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">ICO<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">February 5, 2026<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Data controller responsibility per seller + audit trail<\/td><td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">On complaint basis<\/td><\/tr><\/tbody>\n<\/table>\n<\/figure>\n\n\n\n<p>For organizations also subject to EU regulations, the <a href=\"\/gdpr-schrems-ii-ecommerce-compliance\/\">GDPR and Schrems II eCommerce compliance<\/a> guide covers the overlapping EU requirements. Financial services platforms handling EU transactions should also review DORA compliance at <a href=\"\/dora-ecommerce-compliance\/\">DORA eCommerce compliance<\/a>.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">Build UK Data Act-Compliant Commerce with Spree<\/h2>\n\n\n\n<p>The UK Data Act 2025 draws a clear line: US-owned SaaS platforms create CLOUD Act liability that the &#8220;materially lower standards&#8221; test treats as a compliance gap. Self-hosted UK infrastructure eliminates that exposure entirely.<\/p>\n\n\n\n<p>Spree gives your team full control over data residency, retention, and audit trails. Deploy on AWS UK (eu-west-2), Azure UK, or a dedicated UK datacenter. Every transaction, API call, and admin action is logged to your infrastructure. Set your own retention windows for FCA, MHRA, or general ICO compliance. Audit every line of code under the BSD 3-Clause license.<\/p>\n\n\n\n<p>Whether you&#8217;re a fintech platform meeting FCA PS21\/3, a HealthTech company under MHRA oversight, or a retail brand moving off Shopify Plus to eliminate CLOUD Act exposure, the Spree team can help scope the right UK-compliant architecture.<\/p>\n\n\n\n<p><a href=\"https:\/\/spreecommerce.org\/get-started\/\"><strong>Talk to the Spree Team \u2192<\/strong><\/a><\/p>\n\n\n\n<p><a href=\"https:\/\/spreecommerce.org\/get-started\/\"><strong>Explore Spree Enterprise \u2192<\/strong><\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Frequently Asked Questions<\/h2>\n\n\n\n<div class=\"wp-block-wpseopress-faq-block-v2 is-layout-flow wp-block-wpseopress-faq-block-v2-is-layout-flow\">\n<details id=\"does-the-uk-data-act-apply-to-non-uk-businesses-serving-uk-customers\" class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>Does the UK Data Act apply to non-UK businesses serving UK customers?<\/strong><\/summary>\n<p>Yes. The UK Data Act applies to any business processing personal data of UK residents, regardless of where the business is registered. A US ecommerce company selling to UK customers must comply with the Data Act&#8217;s transfer and residency rules. The &#8220;materially lower standards&#8221; test applies to every international data flow involving UK personal data.<\/p>\n<\/details>\n\n\n<details id=\"is-gdpr-still-relevant-now-that-the-uk-data-act-is-in-force\" class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>Is GDPR still relevant now that the UK Data Act is in force?<\/strong><\/summary>\n<p>Both frameworks apply simultaneously. GDPR governs the lawfulness of data processing (consent, rights, purpose limitation). The UK Data Act focuses on data residency, international transfers, and ICO enforcement powers. You must comply with both. The Data Act strengthens GDPR by tightening rules around international transfers and expanding penalties.<\/p>\n<\/details>\n\n\n<details id=\"if-i-use-a-us-saas-platform-with-a-uk-datacenter-am-i-compliant\" class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>If I use a US SaaS platform with a UK datacenter, am I compliant?<\/strong><\/summary>\n<p>Likely not. The ICO&#8217;s interpretation of &#8220;materially lower standards&#8221; includes CLOUD Act exposure. Storing data in a UK datacenter does not eliminate the risk that US law enforcement can compel the vendor to hand over that data. No US company can contractually guarantee refusal to comply with a US warrant, making documented CLOUD Act mitigation effectively impossible on SaaS architectures.<\/p>\n<\/details>\n\n\n<details id=\"what-are-the-penalties-for-non-compliance-after-february-5-2026\" class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>What are the penalties for non-compliance after February 5, 2026?<\/strong><\/summary>\n<p>The ICO can issue enforcement notices requiring compliance within 30-90 days. PECR fines reach \u00a317.5 million or 4% of global turnover. Data protection violations carry separate penalties up to \u00a320 million or 4% of turnover. For FCA-regulated firms, non-compliance can trigger supervisory action, license review, or Skilled Person reports.<\/p>\n<\/details>\n\n\n<details id=\"can-i-use-a-us-based-backup-service-or-cdn-with-uk-primary-data\" class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>Can I use a US-based backup service or CDN with UK primary data?<\/strong><\/summary>\n<p>Any backup or copy of UK personal data stored outside the UK requires an approved transfer mechanism (UK SCCs, adequacy decision) or documented exemption. A US CDN caching personal data (customer records, session data) needs an approved mechanism. Static assets like images and CSS that contain no personal data are exempt.<\/p>\n<\/details>\n\n\n<details id=\"how-does-the-uk-data-act-relate-to-schrems-ii\" class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>How does the UK Data Act relate to Schrems II?<\/strong><\/summary>\n<p>Schrems II (2020) invalidated the Privacy Shield and tightened Standard Contractual Clauses for US transfers. The UK Data Act&#8217;s &#8220;materially lower standards&#8221; test effectively codifies and extends the Schrems II principles for UK data. If your platform was not compliant with Schrems II, it will not meet UK Data Act requirements either.<\/p>\n<\/details>\n\n<script type=\"application\/ld+json\">{\"@context\": \"https:\/\/schema.org\", \"@type\": \"FAQPage\", \"url\": \"https:\/\/spreecommerce.org\/uk-data-act-ecommerce-compliance\/\", \"@id\": \"https:\/\/spreecommerce.org\/uk-data-act-ecommerce-compliance\/\", \"mainEntity\": [{\"@type\": \"Question\", \"url\": \"https:\/\/spreecommerce.org\/uk-data-act-ecommerce-compliance\/#does-the-uk-data-act-apply-to-non-uk-businesses-serving-uk-customers\", \"name\": \"Does the UK Data Act apply to non-UK businesses serving UK customers?\", \"answerCount\": 1, \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"<p>Yes. The UK Data Act applies to any business processing personal data of UK residents, regardless of where the business is registered. A US ecommerce company selling to UK customers must comply with the Data Act's transfer and residency rules. The \\\"materially lower standards\\\" test applies to every international data flow involving UK personal data.<\/p>\"}}, {\"@type\": \"Question\", \"url\": \"https:\/\/spreecommerce.org\/uk-data-act-ecommerce-compliance\/#is-gdpr-still-relevant-now-that-the-uk-data-act-is-in-force\", \"name\": \"Is GDPR still relevant now that the UK Data Act is in force?\", \"answerCount\": 1, \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"<p>Both frameworks apply simultaneously. GDPR governs the lawfulness of data processing (consent, rights, purpose limitation). The UK Data Act focuses on data residency, international transfers, and ICO enforcement powers. You must comply with both. The Data Act strengthens GDPR by tightening rules around international transfers and expanding penalties.<\/p>\"}}, {\"@type\": \"Question\", \"url\": \"https:\/\/spreecommerce.org\/uk-data-act-ecommerce-compliance\/#if-i-use-a-us-saas-platform-with-a-uk-datacenter-am-i-compliant\", \"name\": \"If I use a US SaaS platform with a UK datacenter, am I compliant?\", \"answerCount\": 1, \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"<p>Likely not. The ICO's interpretation of \\\"materially lower standards\\\" includes CLOUD Act exposure. Storing data in a UK datacenter does not eliminate the risk that US law enforcement can compel the vendor to hand over that data. No US company can contractually guarantee refusal to comply with a US warrant, making documented CLOUD Act mitigation effectively impossible on SaaS architectures.<\/p>\"}}, {\"@type\": \"Question\", \"url\": \"https:\/\/spreecommerce.org\/uk-data-act-ecommerce-compliance\/#what-are-the-penalties-for-non-compliance-after-february-5-2026\", \"name\": \"What are the penalties for non-compliance after February 5, 2026?\", \"answerCount\": 1, \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"<p>The ICO can issue enforcement notices requiring compliance within 30-90 days. PECR fines reach \u00a317.5 million or 4% of global turnover. Data protection violations carry separate penalties up to \u00a320 million or 4% of turnover. For FCA-regulated firms, non-compliance can trigger supervisory action, license review, or Skilled Person reports.<\/p>\"}}, {\"@type\": \"Question\", \"url\": \"https:\/\/spreecommerce.org\/uk-data-act-ecommerce-compliance\/#can-i-use-a-us-based-backup-service-or-cdn-with-uk-primary-data\", \"name\": \"Can I use a US-based backup service or CDN with UK primary data?\", \"answerCount\": 1, \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"<p>Any backup or copy of UK personal data stored outside the UK requires an approved transfer mechanism (UK SCCs, adequacy decision) or documented exemption. A US CDN caching personal data (customer records, session data) needs an approved mechanism. Static assets like images and CSS that contain no personal data are exempt.<\/p>\"}}, {\"@type\": \"Question\", \"url\": \"https:\/\/spreecommerce.org\/uk-data-act-ecommerce-compliance\/#how-does-the-uk-data-act-relate-to-schrems-ii\", \"name\": \"How does the UK Data Act relate to Schrems II?\", \"answerCount\": 1, \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"<p>Schrems II (2020) invalidated the Privacy Shield and tightened Standard Contractual Clauses for US transfers. The UK Data Act's \\\"materially lower standards\\\" test effectively codifies and extends the Schrems II principles for UK data. If your platform was not compliant with Schrems II, it will not meet UK Data Act requirements either.<\/p>\"}}]}<\/script><\/div>\n","protected":false},"excerpt":{"rendered":"<p>What Does the UK Data Act 2025 Mean for eCommerce? The UK Data (Use and Access) Act 2025 became law on June 19, 2025, with the most significant reforms taking effect on February 5, 2026. For ecommerce platforms processing UK customer data, this legislation changes how international data transfers work and expands the ICO&#8217;s enforcement [&hellip;]<\/p>\n","protected":false},"author":87,"featured_media":28318,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_seopress_robots_primary_cat":"none","_seopress_titles_title":"UK Data Act eCommerce: Why SaaS Creates CLOUD Act Risk","_seopress_titles_desc":"The UK Data Act 2025 tightens data sovereignty rules for eCommerce. See CLOUD Act risks, ICO enforcement, and how self-hosted platforms protect UK data.","_seopress_robots_index":"","footnotes":""},"categories":[146],"tags":[1099,1098,1096,1079,1097,1100],"class_list":["post-28319","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-open-source-ecommerce","tag-cloud-act","tag-data-sovereignty","tag-open-source-compliance","tag-self-hosted-commerce","tag-uk-data-act","tag-uk-ecommerce"],"acf":[],"_links":{"self":[{"href":"https:\/\/spreecommerce.org\/wp-json\/wp\/v2\/posts\/28319","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/spreecommerce.org\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/spreecommerce.org\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/spreecommerce.org\/wp-json\/wp\/v2\/users\/87"}],"replies":[{"embeddable":true,"href":"https:\/\/spreecommerce.org\/wp-json\/wp\/v2\/comments?post=28319"}],"version-history":[{"count":0,"href":"https:\/\/spreecommerce.org\/wp-json\/wp\/v2\/posts\/28319\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/spreecommerce.org\/wp-json\/wp\/v2\/media\/28318"}],"wp:attachment":[{"href":"https:\/\/spreecommerce.org\/wp-json\/wp\/v2\/media?parent=28319"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/spreecommerce.org\/wp-json\/wp\/v2\/categories?post=28319"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/spreecommerce.org\/wp-json\/wp\/v2\/tags?post=28319"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}