Skip to content

    Back to blog

    Shopify · 8 min read

    Running Shopify GDPR-Compliant: The Checklist for Your Store

    Shopify is a Canadian company, your customers are in Austria or Germany – and the party responsible for data protection in the store is you, not Shopify. How serious regulators are can be put in numbers: according to DLA Piper’s GDPR survey (January 2025), European authorities have issued €5.88 billion in GDPR fines since May 2018 – €1.2 billion of that in the twelve months to January 2025 alone. Most of it hits corporations like Meta, but the era of mere warnings is over. The good news: a GDPR-clean Shopify store is achievable, and the platform now ships usable tools for it. The bad news: none of it happens by itself. Here is the checklist we work through on every store project. One thing up front: we are developers, not lawyers – for the fine print, your legal texts belong with someone who holds a bar license.

    The data processing agreement with Shopify

    Shopify processes customer data on your behalf – and for that, the GDPR requires a data processing agreement. Shopify provides a Data Processing Addendum as part of its terms. You don’t have to negotiate it, but you should know it, file it, and record it in your processing register.

    The same applies to every other service in your store: payment provider, shipping carrier, newsletter tool. Anyone processing customer data for you needs such an agreement. At most stores, that list is longer than the owners believe.

    Data transfers outside the EU: document them honestly

    Shopify runs its infrastructure globally, and customer data may be processed outside the EU in the process. Shopify relies on the usual legal mechanisms for this, such as standard contractual clauses. For you, this means the transfer must be named and correctly justified in your privacy policy. It cannot be argued away – if you want a store that runs exclusively on EU servers, Shopify is the wrong platform, and you should know that before choosing it.

    In practice, a great many merchants in the DACH region run Shopify stores on this basis. What matters is that your privacy policy describes reality instead of hiding it.

    Cookie banner and consent: the most common trouble spot

    This is where we find the most mistakes in stores we take over. A banner that merely informs is not enough: tracking and marketing scripts may only load after the visitor has consented – and declining must be as easy as accepting. Many consent apps display a banner but fire the pixels from second one anyway. You can verify this in the browser’s network tab in two minutes, and that is exactly what we do at every handover.

    Shopify ships a foundation for this with its Customer Privacy API, which proper consent solutions and many apps hook into. Set up correctly, it means: without consent, only what is technically necessary runs. Analytics and advertising pixels start only after the visitor clicks accept.

    Apps are data recipients – every single one

    Every installed app can access store data, and many access customer data. That makes every app relevant under data protection law: who is behind it, where does it process data, is there a processing agreement, does it appear in your privacy policy? For a store with fifteen apps, this is real legwork – and one more argument for keeping the app list lean.

    Our rule of thumb when selecting apps: prefer vendors with clear privacy documentation and an EU connection. For apps with no traceable information about their data processing, the question becomes whether the feature is worth the risk.

    Mandatory legal texts: imprint, privacy policy, terms, withdrawal

    For stores in the DACH region, there is no way around four documents: the imprint (Impressum), privacy policy, terms and conditions, and the withdrawal instruction including the model withdrawal form. Shopify offers template texts – they are written for North American law and are unusable for Austria or Germany. Have these texts drawn up by a law firm or a reputable legal-text service, and link them so they are reachable from every page, including the checkout.

    A detail that often gets overlooked: the texts have to stay current. A new app, a new payment provider, new tracking – any of these changes can require an update to the privacy policy.

    Newsletters only with double opt-in

    An email address from an order is not newsletter consent. If you want to send marketing emails, you need an active sign-up with a confirmation link – double opt-in – and you must be able to prove the consent. Check that your newsletter tool implements this correctly and that the checkout checkbox is genuinely empty by default. Pre-ticked boxes are not consent.

    The checklist to tick off

    Everything at a glance. The average, by the way, is not a high bar: during the DLA Piper survey period (2025), European supervisory authorities received 363 data breach notifications per day on average. If you can tick every item with a clear conscience, your store is in considerably better shape:

    • Data processing agreement with Shopify on file, likewise with every other service provider
    • Data transfers outside the EU named in the privacy policy
    • Consent solution in place: tracking loads only after consent, declining is just as easy as accepting
    • Every installed app reviewed for its data processing and covered in the privacy policy
    • Imprint, privacy policy, terms, and withdrawal instruction from a qualified source, reachable everywhere
    • Newsletter strictly double opt-in, no pre-ticked checkboxes
    • A defined process for access and deletion requests – Shopify provides tools for this in the admin