If your Shopify store collects personal data from EU customers, Shopify's separate Data Processing Addendum governs how that data is handled; merchants must review that document separately to understand their GDPR obligations.
This analysis describes what Shopify's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The incorporation of the DPA establishes the contractual framework governing how Shopify handles personal data subject to GDPR regulations. This creates binding obligations regarding data processing activities, including roles, responsibilities, and compliance standards that apply to merchants processing EU personal data through Shopify's platform.
The updated terms clarify the legal identity of the Shopify entity you contract with and establish which courts have exclusive jurisdiction to resolve disputes, depending on your store's billing address. Previously, the terms specified exclusive jurisdiction by region (Ontario for US/Canada, Singapore for Asia Pacific, Ireland for EMEA and other areas). The revised structure presents this information in a table format and adds explicit language stating that disputes can only be brought in the courts listed for your region, with those courts having exclusive jurisdiction. Shopify Inc. may act as a billing agent for other Shopify entities to collect fees and remit taxes in some jurisdictions. You can review the contracting party and forum table in Section 13 to confirm which entity and courts apply to your store based on your billing address.
View change record →Merchants using Shopify to sell to EU customers are acting as data controllers and Shopify as a data processor under GDPR; the specific obligations and safeguards governing EU customer personal data are set out in a separate Data Processing Addendum that merchants must review and understand independently of these main terms.
How other platforms handle this
We use your personal information to comply with applicable legal and regulatory obligations and respond to legally valid requests and communications from law enforcement authorities to the extent required by applicable law.
We may infer certain information from your interactions with the Lyft Platform and other personal information available to us. For example, if you frequently ride to or from airports, we may infer you are a frequent traveler.
we may use this information to make it easier for you to find the people you want to send payments to, for account and identity verification and fraud prevention purposes, to reduce the risk you will send payments to the wrong person, or to provide other personalized services.
"To the extent that Shopify processes any Personal Data (as defined in the Shopify Data Processing Addendum) that is subject to the GDPR on your behalf, the terms of the Shopify Data Processing Addendum, which are hereby incorporated into this Agreement, shall apply. The Data Processing Addendum can be found at https://www.shopify.com/legal/dpa.Excerpt from Shopify's Terms of Service
REGULATORY LANDSCAPE: This provision engages GDPR Article 28, which requires a written contract between data controllers (merchants) and processors (Shopify) setting out the subject matter, duration, nature, and purpose of processing.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Search "[your state] attorney general consumer complaint" to find your state's direct complaint form
We read the privacy policies and terms of service of 38 AI platforms. Here is what they say about training, retention, arbitration, and liability.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
The incorporation of the DPA establishes the contractual framework governing how Shopify handles personal data subject to GDPR regulations. This creates binding obligations regarding data processing activities, including roles, responsibilities, and compliance standards that apply to merchants processing EU personal data through Shopify's platform.
Merchants using Shopify to sell to EU customers are acting as data controllers and Shopify as a data processor under GDPR; the specific obligations and safeguards governing EU customer personal data are set out in a separate Data Processing Addendum that merchants must review and understand independently of these main terms.
ConductAtlas has identified this type of provision across 279 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Shopify.