Shopify · Shopify Privacy Policy

International Data Transfers via Standard Contractual Clauses

Medium severity
Share 𝕏 Share in Share 🔒 PDF

What it is

Shopify transfers personal data from the EU, UK, and Switzerland to other countries (including the US) using Standard Contractual Clauses, which are legal contracts meant to ensure your data is protected even outside the EU.

Consumer impact (what this means for users)

If you are an EU, UK, or Swiss user, your personal data is transferred to countries outside those regions — potentially including the US — using legal contracts (SCCs) whose adequacy has been actively contested by European regulators, meaning your data protections may not be fully equivalent to EU standards.

How other platforms handle this

Ledger Medium

Your information, including Personal Data, may be transferred to — and maintained on — computers located outside of your state, province, country or other governmental jurisdiction where the data protection laws may differ than those from your jurisdiction. If you are located outside France and choo...

Amazon Medium

When you use Amazon Services, third-party service providers and sellers may receive information about your interactions to the extent necessary for them to fulfill their services. Third-party sellers who sell on Amazon's platform receive customer information necessary to fulfill orders, including na...

Klarna Medium

Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA) or the United Kingdom. Where we transfer your data outside the EEA or UK, we ensure appropriate safeguards are in place, such as standard contractual clauses approved by the European Commissi...

See all platforms with this clause type →
Need full compliance memos? See Professional →

Why it matters (compliance & risk perspective)

Post-Schrems II, the adequacy of SCCs for US transfers depends on supplementary measures, and multiple EU DPAs have found SCC-based transfers to US ad tech companies non-compliant — creating ongoing legal uncertainty for EU users whose data is transferred.

View original clause language
When we transfer personal information from the European Economic Area, United Kingdom, or Switzerland to countries that have not received an adequacy decision, we rely on appropriate safeguards, including Standard Contractual Clauses approved by the European Commission, to protect your personal information. You can request a copy of our Standard Contractual Clauses by contacting us at privacy@shopify.com.

Institutional analysis (Compliance & legal intelligence)

REGULATORY FRAMEWORK: International transfers are governed by GDPR Chapter V, specifically Articles 44–49, and equivalent UK GDPR provisions (UK ICO's International Data Transfer Agreement). The EU-US Data Privacy Framework (DPF, July 2023) may apply if Shopify is DPF-certified, but SCCs remain the primary stated mechanism. CJEU's Schrems II judgment (C-311/18) invalidated Privacy Shield and required supplementary measures for SCC-based transfers. Enforced by EU DPAs and ICO.

🔒

Compliance intelligence locked

Regulatory citations, enforcement risk, and due diligence action items.

Watcher $9.99/mo Professional $149/mo

Watcher: regulatory citations. Professional: full compliance memo.

Applicable agencies

  • FTC
    The FTC co-enforces the EU-US Data Privacy Framework for US companies and has authority over misrepresentations about cross-border data transfer compliance.
    File a complaint →

Applicable regulations

BIPA
Illinois, USA
CCPA/CPRA
California, USA
COPPA
United States Federal
CAN-SPAM
United States Federal
DMA
European Union
FCRA
United States Federal
GDPR
European Union
GLBA
United States Federal
HIPAA
United States Federal
UK GDPR
United Kingdom

Provision details

Document information
Document
Shopify Privacy Policy
Entity
Shopify
Document last updated
April 29, 2026
Tracking information
First tracked
March 15, 2026
Last verified
April 10, 2026
Record ID
CA-P-002683
Document ID
CA-D-00122
Evidence Provenance
Source URL
Wayback Machine
SHA-256
929225abb20671960ed1f40a6325a4c72cf5ea341e79aa8378056b3b66ef5708
Verified
✓ Snapshot stored   ✓ Change verified
How to Cite
ConductAtlas Policy Archive
Entity: Shopify | Document: Shopify Privacy Policy | Record: CA-P-002683
Captured: 2026-03-15 11:22:02 UTC | SHA-256: 929225abb2067196…
URL: https://conductatlas.com/platform/shopify/shopify-privacy-policy/international-data-transfers-via-standard-contractual-clauses/
Accessed: April 29, 2026
Classification
Severity
Medium
Categories

Other provisions in this document

Related Analysis