RoPA Pilot

Shopify and GDPR: hosting, non-EU transfer and DPA

Shopify is published by Shopify International Ltd. If your teams use it, it is a processor within the meaning of Article 28 GDPR and it must appear in your record of processing activities.

Vendor (processor)
Shopify International Ltd
Headquarters
Canada
EU hosting
EU optional (plan/config)
Non-EU transfer
Yes
Transfer mechanism
Adequate country
Category
E-commerce / Sites
Typical personal data
identity, contact details, financial data, usage data
Detected domains
admin.shopify.com, myshopify.com

Does using Shopify mean a non-EU transfer?

Yes, but to a country covered by an adequacy decision (Canada): no additional safeguard is required, the destination country must still be named in your register.

What to write in your Article 30 record

Purpose: E-commerce / Sites. Categories of personal data: identity, contact details, financial data, usage data. Recipient: Shopify International Ltd. Transfer: Adequate country. Retention: aligned with the contract or the account lifetime, whichever is shorter.

How RoPA Pilot handles it

RoPA Pilot detects Shopify from the domain name of the tab — never from page content — and pre-fills the record above in one click. The extension flags the record if the transfer mechanism is missing or unverified.

Indicative information from public sources. The transfer mechanism actually applicable to you is the one written in your contract.