Shopify updated its privacy policy on July 10, 2026 to revise how it describes cross-border data transfers for users in the EEA, UK, and Switzerland. The prior policy stated that Personal Data sent to Canada was protected under Canadian law, which the European Commission had found adequate. The updated policy replaces this with a framework based on Shopify's Binding Corporate Rules (BCRs) for transfers between Shopify entities, and Standard Contractual Clauses (SCCs) for transfers to third-party subprocessors. The practical effect is that data protection assurances now rest on different legal instruments (BCRs and SCCs) rather than adequacy decisions.
The updated policy changes the legal mechanism used to protect personal data when it crosses borders, but does not change where data is transferred or fundamentally alter protection levels. For EEA and Swiss users, data transfers between Shopify entities now rely on Shopify's Binding Corporate Rules (which have been approved by European data protection authorities), rather than adequacy decisions. For UK users, transfers use Standard Contractual Clauses and may rely on the adequacy decision for Canada. For transfers to third-party subprocessors, contractual commitments in the form of Standard Contractual Clauses now replace prior language referencing comparable protections. The policy states these mechanisms reflect Shopify's commitment to adequate protection, but the shift in legal instruments may have implications for how disputes or compliance issues would be evaluated under GDPR or UK data protection law.
Now protected under Shopify's Binding Corporate Rules (approved by European data protection authorities) rather than adequacy decisions.
Now use Standard Contractual Clauses between Shopify entities, with potential reliance on adequacy decision for Canada transfers.
Now explicitly protected by Standard Contractual Clauses rather than prior language referencing 'comparable' contractual commitments.
This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology
Shopify replaced its reliance on European Commission adequacy decisions with Binding Corporate Rules for intra-Shopify transfers and Standard Contractual Clauses for third-party transfers. This shift has compliance implications under GDPR Article 44-50 (international transfers) and …
Regulatory exposure, obligation change, escalation trigger, board-ready language, and recommended action for legal and compliance teams.
Unlock the full institutional analysis — InsightConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-003584.
Shopify restructured its contracting party and dispute resolution framework in an update detected on August 1, 2026. Previously, the terms …
Shopify updated its Terms of Service on May 11, 2026 to add new provisions regarding communications through additional channels like …
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
Get alerted when this policy changes again, including what changed and why it matters.