The policy establishes that when consumers interact with merchant-operated Shopify-powered stores, Shopify acts as a data processor rather than a controller, meaning data subject requests must be directed to the individual merchant rather than to Shopify. Shopify states it may offer tools and assistance to merchants to help fulfill such requests but does not commit to a specific mechanism or timeline for doing so.
This analysis describes what Shopify's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision determines which entity bears direct regulatory obligations for consumer data subject requests in the merchant storefront context, establishing that Shopify's direct compliance obligations to consumers are limited when acting as processor. The practical effect is that consumer access, correction, and deletion rights are dependent on the individual merchant's response capacity and compliance posture.
The updated policy changes the legal mechanism used to protect personal data when it crosses borders, but does not change where data is transferred or fundamentally alter protection levels. For EEA and Swiss users, data transfers between Shopify entities now rely on Shopify's Binding Corporate Rules (which have been approved by European data protection authorities), rather than adequacy decisions. For UK users, transfers use Standard Contractual Clauses and may rely on the adequacy decision for Canada. For transfers to third-party subprocessors, contractual commitments in the form of Standard Contractual Clauses now replace prior language referencing comparable protections. The policy states these mechanisms reflect Shopify's commitment to adequate protection, but the shift in legal instruments may have implications for how disputes or compliance issues would be evaluated under GDPR or UK data protection law.
View change record →The provision shifts focus from explaining Shopify's dual role to directing users to contact merchants directly and emphasizing merchant accountability, while removing explicit mention of Shopify's independent controller status for Shop App and fraud prevention.
View full change record →Under these terms, consumers who have visited or purchased from a Shopify-powered merchant store must contact that merchant directly to exercise data subject rights, as Shopify acts as processor in those contexts and directs such requests to the merchant. Shopify's policy does not specify a timeline within which merchants must respond to forwarded requests.
Cross-platform context
See how other platforms handle Controller-Processor Allocation Between Shopify and Merchants and similar clauses.
Compare across platforms →"Where Shopify acts as processor or service provider of your Personal Data on behalf of Shopify merchants, you need to directly contact the merchant you interacted with. For more information about how merchants collect and use your data when you visit and make purchases in their stores, review the specific merchant's terms and privacy policy. In some cases, we may offer tools and assistance to merchants to help fulfill these requests.Excerpt from Shopify's Privacy Policy
(1) REGULATORY LANDSCAPE: The controller-processor designation engages GDPR Articles 4(7), 4(8), 28, and 29, which establish the respective obligations of controllers and processors and require a data processing agreement between them.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Search "[your state] attorney general consumer complaint" to find your state's direct complaint form
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision determines which entity bears direct regulatory obligations for consumer data subject requests in the merchant storefront context, establishing that Shopify's direct compliance obligations to consumers are limited when acting as processor. The practical effect is that consumer access, correction, and deletion rights are dependent on the individual merchant's response capacity and compliance posture.
Under these terms, consumers who have visited or purchased from a Shopify-powered merchant store must contact that merchant directly to exercise data subject rights, as Shopify acts as processor in those contexts and directs such requests to the merchant. Shopify's policy does not specify a timeline within which merchants must respond to forwarded requests.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Shopify.