Appoint us
Online store team reviewing European data protection obligations

REP27 · Ecommerce · Shopify

Article 3(2) · Article 27 · Shopify stores

EU representative for a Shopify store.

Shopify makes selling into Europe a settings change, which is exactly why so many stores are inside Article 3(2) without anyone deciding to be. Accepting euros, shipping to Germany, running a marketing app and a pixel is enough. This page is the practical version: what in a Shopify store triggers the obligation, what has to appear in the storefront, and what a designation actually gives you.

CheckoutCustomer accountsEmail appsPixelsAnalyticsReviews

See the plans   Ask a question

It is the apps, not the products

Merchants expect the trigger to be what they sell. In practice it is what is installed: a marketing app builds profiles, a pixel shares identifiers, a heat-map app watches sessions. Each of those is processing you decided on.

Which Shopify apps bring a store inside Article 27 GDPR and where each must be declared
Which Shopify apps bring a store inside Article 27 GDPR and where each must be declared
If you cannot list your installed apps from memory, that list is the first deliverable of this exercise, not the designation.

Five steps, about a working day

The five steps to appoint an EU representative for a Shopify store
The five steps to appoint an EU representative for a Shopify store
  1. Inventory the store

    Checkout fields, customer accounts, abandoned-cart flows, newsletter, pixels, reviews, chat. This becomes your Article 30 record.

  2. Confirm you are caught

    Euro pricing, EU shipping zones, a European language or ads targeted at the Union are the indicators used in practice.

  3. Sign the designation

    One mandate, countersigned, valid for data subjects in all 27 Member States.

  4. Publish it

    Privacy policy page and the checkout footer. Article 13(1)(a) requires the identity of the representative to reach the customer.

  5. Route the requests

    Anything arriving at the representative is logged and forwarded to whoever answers deletion and access requests in your team.

What Shopify does and does not do for you

FunctionShopify providesStill yours
Data processing agreementYes, as your processorYour role as controller
Customer data requests APIYes, a mechanismThe decision on each request
Cookie bannerAvailable, configurableWhether consent is actually valid
Article 27 representativeNoA designation you buy separately
Privacy policy contentA generator, no moreAccuracy, including naming the representative

The platform gives you tools and a processor contract. It never becomes your representative, and no app in the store does either, whatever the listing implies.

What the designation gives a merchant

The paragraph for the policy

The exact Article 13(1)(a) wording, translated, ready to paste into the privacy page linked from the footer.

An address in the Union

Answered in eight languages, so a German customer's deletion request does not turn into a complaint about being ignored.

The Article 30 record

Kept and made available to authorities, which is the part almost no store has prepared.

A verifiable certificate

Useful the day a wholesale buyer or a payment provider asks how you handle EU data.

The three documents a European buyer asks for

Once a store starts selling wholesale into Europe, or applies to a European payment provider, the questions stop being about the products. These three come up every time, and none of them is generated by an app.

  1. The privacy notice naming a representative

    Reviewed first, because it is public and takes thirty seconds to check. A notice generated in 2021 with no representative named is a visible gap.

  2. The record of processing activities

    Article 30. It lists what you collect, why, on what basis, for how long and who else touches it. Most merchants have never written one; we assemble it from onboarding.

  3. The processor list

    Every app with access to customer data, plus Shopify itself. Buyers compare it against your notice, and inconsistencies are what slow deals down.

These are also the documents a supervisory authority requests first, which is convenient: preparing for a wholesale buyer prepares you for an authority.

Two mistakes specific to Shopify stores

The generated privacy policy

Shopify's generator produces a serviceable skeleton that names no representative, lists no apps and states no retention periods. It is a starting point being used as a finished document across thousands of stores.

The abandoned app

Apps uninstalled from the admin do not always lose the data they already exported. Before publishing a processor list, check which apps still hold customer records and ask for deletion in writing.

Duplicate storefronts

Merchants running a second store for another market often copy the theme and forget the notice, leaving one storefront naming a representative and the other naming nobody.

Consent that is not consent

A banner that loads pixels before the choice is made undoes the rest. This is the most common finding in European enforcement against online stores.

One question that settles most cases

Merchants ask us to review their store before deciding. In practice a single question resolves it: can a customer in the Union complete a purchase without you turning anything on? If the answer is yes, Article 3(2) is engaged and the designation is due. Shipping zones, currencies and language switchers are evidence; the ability to buy is the fact.

Consultation on appointing an Article 27 representative for an online store
Consultation on appointing an Article 27 representative for an online store
Contact point handling a customer request arriving from the European Union

Questions we are actually asked

Does Shopify act as my EU representative?

No. Shopify is your processor and gives you a data processing agreement. Article 27 requires a separately designated representative established in the Union, and no platform provides that.

We only ship to a few EU countries. Does it still apply?

Yes. There is no threshold of countries or orders. Offering goods to people in the Union brings Article 3(2) into play from the first order.

Our store is in USD only. Are we outside?

Currency is one indicator among several. EU shipping zones, a European language, EU-targeted ads or a local domain can each point the other way.

What about a store that only takes pre-orders?

Collecting an email address and an intention to buy from someone in the Union is processing. The absence of a completed sale changes nothing.

Does the representative answer my customers?

It is the contact point that customers and authorities may address. Requests are logged and forwarded to you; the substantive answer stays with you as controller.

Where exactly do we publish the representative?

In the privacy policy reachable from the storefront footer and from checkout. Some merchants also add it to the contact page, which is sensible but not required.

We already have a DPO. Is that enough?

No. A DPO advises and monitors under Article 37. A representative is a point of contact inside the Union under Article 27. They are different roles and can both apply.

Does using Shopify Payments change anything?

No. Payment routing does not create or remove an establishment, and it does not affect who is controller for the customer data.

What is the exposure for not designating?

Article 83(4)(a) puts infringements of Article 27 in the tier up to €10 million or 2% of worldwide annual turnover, and the absence is regularly treated as an aggravating factor.

Can we designate after we get a complaint?

You can, and you should, but the gap remains dated from when the obligation arose. Designating early is cheap; designating under pressure is not.

Do we also need a GPSR responsible person?

If you ship physical consumer goods to the Union, yes. That is Article 16 of a different regulation and it is what gets listings and consignments blocked.

Does a Shopify app that claims GDPR compliance cover this?

No app can accept the role of representative on your behalf. Compliance apps handle banners, requests and documentation; the designation is a legal appointment of a company.

How long does it take?

The designation is signed within 24 hours of a completed form. Updating the policy takes minutes once you have the wording.

Related: the wider ecommerce picture · the exact privacy notice wording

Designated before your next campaign

One form, a signed designation within 24 hours, the privacy policy paragraph ready to paste, and a request desk that answers in the language your customers write in.

See the plans