The policy states that EEA, UK, and Swiss Personal Data transferred to Canada is covered by the European Commission's adequacy finding for Canadian law, and that onward transfers from Canada to other locations including subprocessors are protected by contractual commitments described as comparable to Standard Contractual Clauses rather than by adopted SCCs themselves. The policy does not specify which version of SCCs or equivalent instruments are used.
This analysis describes what Shopify's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The description of onward transfer protections as commitments comparable to Standard Contractual Clauses, rather than Standard Contractual Clauses as adopted by the European Commission, creates an interpretive question regarding whether these mechanisms satisfy GDPR Chapter V transfer requirements as evaluated by EEA supervisory authorities.
Interpretive note: The description of transfer protections as comparable to Standard Contractual Clauses rather than adopted SCCs introduces interpretive uncertainty regarding whether these mechanisms fully satisfy GDPR Chapter V requirements as assessed by EEA supervisory authorities.
The updated policy changes the legal mechanism used to protect personal data when it crosses borders, but does not change where data is transferred or fundamentally alter protection levels. For EEA and Swiss users, data transfers between Shopify entities now rely on Shopify's Binding Corporate Rules (which have been approved by European data protection authorities), rather than adequacy decisions. For UK users, transfers use Standard Contractual Clauses and may rely on the adequacy decision for Canada. For transfers to third-party subprocessors, contractual commitments in the form of Standard Contractual Clauses now replace prior language referencing comparable protections. The policy states these mechanisms reflect Shopify's commitment to adequate protection, but the shift in legal instruments may have implications for how disputes or compliance issues would be evaluated under GDPR or UK data protection law.
View change record →Under these terms, EEA, UK, and Swiss users' Personal Data may be transferred to Canada and onward to subprocessors in other countries, with onward transfers governed by contractual commitments described as comparable to Standard Contractual Clauses. The policy does not specify which jurisdictions subprocessors are located in or which specific contractual instruments are applied.
Cross-platform context
See how other platforms handle Cross-Border Data Transfers and Standard Contractual Clauses and similar clauses.
Compare across platforms →"If you are in the EEA, the UK, or Switzerland, when we send your Personal Data to Canada it is protected under Canadian law, which the European Commission has found adequately protects your information. If we then send this Personal Data outside of Canada (for example, when we send this information to our Subprocessors), this information is protected by contractual commitments that are comparable to those provided in the Standard Contractual Clauses.Excerpt from Shopify's Privacy Policy
(1) REGULATORY LANDSCAPE: Cross-border data transfers from the EEA, UK, and Switzerland are governed by GDPR Chapter V (and UK GDPR equivalents), which require an adequacy decision, Standard Contractual Clauses as adopted by the European …
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
The description of onward transfer protections as commitments comparable to Standard Contractual Clauses, rather than Standard Contractual Clauses as adopted by the European Commission, creates an interpretive question regarding whether these mechanisms satisfy GDPR Chapter V transfer requirements as evaluated by EEA supervisory authorities.
Under these terms, EEA, UK, and Swiss users' Personal Data may be transferred to Canada and onward to subprocessors in other countries, with onward transfers governed by contractual commitments described as comparable to Standard Contractual Clauses. The policy does not specify which jurisdictions subprocessors are located in or which specific contractual instruments are applied.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Shopify.