
Article 3(2) · Article 27 · Shopify stores
Shopify makes selling into Europe a settings change, which is exactly why so many stores are inside Article 3(2) without anyone deciding to be. Accepting euros, shipping to Germany, running a marketing app and a pixel is enough. This page is the practical version: what in a Shopify store triggers the obligation, what has to appear in the storefront, and what a designation actually gives you.
CheckoutCustomer accountsEmail appsPixelsAnalyticsReviews
Merchants expect the trigger to be what they sell. In practice it is what is installed: a marketing app builds profiles, a pixel shares identifiers, a heat-map app watches sessions. Each of those is processing you decided on.


Checkout fields, customer accounts, abandoned-cart flows, newsletter, pixels, reviews, chat. This becomes your Article 30 record.
Euro pricing, EU shipping zones, a European language or ads targeted at the Union are the indicators used in practice.
One mandate, countersigned, valid for data subjects in all 27 Member States.
Privacy policy page and the checkout footer. Article 13(1)(a) requires the identity of the representative to reach the customer.
Anything arriving at the representative is logged and forwarded to whoever answers deletion and access requests in your team.
| Function | Shopify provides | Still yours |
|---|---|---|
| Data processing agreement | Yes, as your processor | Your role as controller |
| Customer data requests API | Yes, a mechanism | The decision on each request |
| Cookie banner | Available, configurable | Whether consent is actually valid |
| Article 27 representative | No | A designation you buy separately |
| Privacy policy content | A generator, no more | Accuracy, including naming the representative |
The platform gives you tools and a processor contract. It never becomes your representative, and no app in the store does either, whatever the listing implies.
The exact Article 13(1)(a) wording, translated, ready to paste into the privacy page linked from the footer.
Answered in eight languages, so a German customer's deletion request does not turn into a complaint about being ignored.
Kept and made available to authorities, which is the part almost no store has prepared.
Useful the day a wholesale buyer or a payment provider asks how you handle EU data.
Once a store starts selling wholesale into Europe, or applies to a European payment provider, the questions stop being about the products. These three come up every time, and none of them is generated by an app.
Reviewed first, because it is public and takes thirty seconds to check. A notice generated in 2021 with no representative named is a visible gap.
Article 30. It lists what you collect, why, on what basis, for how long and who else touches it. Most merchants have never written one; we assemble it from onboarding.
Every app with access to customer data, plus Shopify itself. Buyers compare it against your notice, and inconsistencies are what slow deals down.
Shopify's generator produces a serviceable skeleton that names no representative, lists no apps and states no retention periods. It is a starting point being used as a finished document across thousands of stores.
Apps uninstalled from the admin do not always lose the data they already exported. Before publishing a processor list, check which apps still hold customer records and ask for deletion in writing.
Merchants running a second store for another market often copy the theme and forget the notice, leaving one storefront naming a representative and the other naming nobody.
A banner that loads pixels before the choice is made undoes the rest. This is the most common finding in European enforcement against online stores.
Merchants ask us to review their store before deciding. In practice a single question resolves it: can a customer in the Union complete a purchase without you turning anything on? If the answer is yes, Article 3(2) is engaged and the designation is due. Shipping zones, currencies and language switchers are evidence; the ability to buy is the fact.


No. Shopify is your processor and gives you a data processing agreement. Article 27 requires a separately designated representative established in the Union, and no platform provides that.
Yes. There is no threshold of countries or orders. Offering goods to people in the Union brings Article 3(2) into play from the first order.
Currency is one indicator among several. EU shipping zones, a European language, EU-targeted ads or a local domain can each point the other way.
Collecting an email address and an intention to buy from someone in the Union is processing. The absence of a completed sale changes nothing.
It is the contact point that customers and authorities may address. Requests are logged and forwarded to you; the substantive answer stays with you as controller.
In the privacy policy reachable from the storefront footer and from checkout. Some merchants also add it to the contact page, which is sensible but not required.
No. A DPO advises and monitors under Article 37. A representative is a point of contact inside the Union under Article 27. They are different roles and can both apply.
No. Payment routing does not create or remove an establishment, and it does not affect who is controller for the customer data.
Article 83(4)(a) puts infringements of Article 27 in the tier up to €10 million or 2% of worldwide annual turnover, and the absence is regularly treated as an aggravating factor.
You can, and you should, but the gap remains dated from when the obligation arose. Designating early is cheap; designating under pressure is not.
If you ship physical consumer goods to the Union, yes. That is Article 16 of a different regulation and it is what gets listings and consignments blocked.
No app can accept the role of representative on your behalf. Compliance apps handle banners, requests and documentation; the designation is a legal appointment of a company.
The designation is signed within 24 hours of a completed form. Updating the policy takes minutes once you have the wording.
Related: the wider ecommerce picture · the exact privacy notice wording
One form, a signed designation within 24 hours, the privacy policy paragraph ready to paste, and a request desk that answers in the language your customers write in.
See the plans