11 minutes read

The Complete GDPR Compliance Checklist

The Complete GDPR Compliance Checklist - icon

Table of Contents

Introduction

The GDPR, formally Regulation (EU) 2016/679, took effect on 25 May 2018 with a clear goal: to strengthen data protection and individuals’ rights across the EU and EEA. The UK adopted its own mirror version, UK GDPR, which applies similarly. Together, these regulations govern how organizations collect, store, and process personal data of people in those regions.

GDPR applies if you offer goods or services to EU residents or monitor their behavior. That means any Shopify or e-commerce business worldwide must comply if it ships to, advertises to, or tracks visitors from the EU, EEA, or UK-even if no payment is taken.

Step 1: Map and Inventory All Personal Data

A Record of Processing Activities (ROPA) is required under Article 30 of GDPR and serves as the foundation of any compliance checklist. An ROPA is mandatory under Article 30 of the GDPR and serves as an accountability tool for data processing activities. Organizations with over 250 employees must maintain a ROPA, but even smaller stores should keep one because e-commerce routinely involves profiling, international transfers, and frequent data collection.

  • List every category of personal data collected in your Shopify store: customer account details; order information (products, prices, shipping addresses); payment tokens; IP addresses; cookies and tracking pixel data; support ticket content; and product reviews. Data mapping involves identifying all personal data collected, its sources, uses, and storage locations.
  • For each processing activity, document the purpose (order fulfillment, fraud prevention, marketing, analytics), the data subjects involved (customers, newsletter subscribers, guest checkout users), the lawful basis, the data categories, recipients (shipping carriers, payment processors, apps), storage locations, and retention periods. Organizations must categorize personal data and document retention periods. ROPA must document categories of data processed and retention periods.
  • Create a visual data flow map showing how data moves from your storefront to Shopify’s servers, then outward to apps, payment gateways, email tools, advertising pixels, review platforms, and logistics providers. Understanding these data flows is critical for identifying gaps.
  • Even stores below 250 employees should maintain a simplified ROPA. The Article 30(5) exemption is narrow; most e-commerce operations involve regular and systematic monitoring of visitors, which eliminates the exemption. ROPA must be updated whenever new processing activities are introduced, such as installing a new app or launching a campaign.

Step 2: Determine Lawful Bases for Processing and Document Them

Under GDPR Art. 6, every data processing activity must rest on one of six lawful bases. GDPR defines six lawful bases for data processing, and each processing activity requires its own lawful basis. You must document your chosen lawful basis for processing in both your ROPA and your privacy policy.

  • Use “contract” as the legal basis for processing needed to fulfill orders, manage customer accounts, and handle returns. Organizations must establish a lawful basis for processing personal data, such as consent or contractual necessity.
  • Use “legal obligation” to refer to issuing invoices, maintaining tax records, and complying with anti-fraud regulations. Legal obligation is a valid lawful basis for processing data required by law.
  • Use “legitimate interests” for fraud prevention, internal analytics, or basic customer segmentation-but only after conducting a legitimate interests assessment (LIA). A LIA balances the store’s interests against individuals’ rights, documents the reasoning, safeguards (such as data minimization and opt-out mechanisms), and proportionality.
  • Use “consent” for non-essential processing: email marketing, SMS campaigns, advertising cookies, and detailed analytics. Consent is one of the six lawful bases under GDPR, and it must be freely given, specific, informed, and unambiguous. No pre-ticked boxes. No bundled consent.
  • GDPR compliance requires maintaining comprehensive documentation of data processing activities and lawful bases for processing. Record all bases and retention periods in your ROPA, and summarize them in clear, plain language in your privacy policy.

GDPR Arts. 12–14 require that transparent information be provided at or before the point of personal data collection. Privacy notices must be clear, concise, transparent, and easily accessible for users. Organizations should provide clear privacy information that addresses what data is collected, why it is collected, and individuals’ rights.

  • Your privacy policy must include: the identity and contact details of the data controller, a data protection officer DPO or privacy contact (if appointed), processing purposes, lawful bases, categories of personal data, all recipients including data processors, details of any data transfer outside the EEA/UK, retention periods, and a full listing of data subject rights including the right to withdraw consent and lodge complaints with a data protection authority.
  • If your store uses automated decision making or automated processing (such as AI-driven product recommendations or fraud scoring), explain the logic involved and the rights data subjects have regarding those decisions.
  • Your cookie policy should list cookie categories-strictly necessary, functional, analytics, and advertising-along with purposes, providers (first-party vs. third-party), and retention times. Note that most analytics and advertising cookies require prior consent under ePrivacy rules.
  • Write all policies in plain language, make them mobile-friendly, and link them from the footer of every page. If your store targets multiple countries, offer policies in relevant languages. Creating a dedicated privacy policy page helps centralize this information.

The GDPR, together with the ePrivacy Directive, requires prior, informed, granular consent for non-essential cookies and similar tracking technologies. Consent must be obtained before placing third-party cookies on a visitor’s device. For any Shopify store running analytics or advertising pixels, this is non-negotiable.

  • A compliant cookie banner must offer clear options to accept all, reject all, or customize by category. No pre-ticked boxes and no dark patterns that nudge users toward “accept.” Organizations must document consent to demonstrate compliance with GDPR. Every consent event should be logged with a timestamp, source, categories selected, and the user’s response.
  • Explicit consent may require a signed document or verified process for special categories of data. For standard cookie consent, a clear affirmative action (clicking “accept” after reviewing options) suffices.
  • Cross-border Shopify stores need geo-targeting: show GDPR-compliant banners to EU/EEA and UK visitors while adapting for other jurisdictions (CCPA opt-out in California, LGPD in Brazil). A cookie consent banner that adapts by region is essential.
  • Google Consent Mode v2 has been required since March 2024 for EU/EEA traffic using Google Ads and Analytics. Consent signals must be passed to Google tags before they fire. A Google-certified CMP like Pandectes automates this handshake and maintains audit logs.
  • Users must be able to revisit and change consent at any time via a persistent “Cookie Settings” link in the footer. Scripts should only fire in accordance with the current consent state. If a user revokes consent, tracking must stop immediately.
phone open on store

Step 5: Enable and Operationalize Data Subject Rights

GDPR outlines eight key data subject rights under Articles 15–22. Users have the right to access, rectify, delete, or transfer their personal data. Data subjects can request data portability under the GDPR, object to processing, request restriction of processing, and exercise rights related to automated decision-making. Stores must have clear procedures to honor every request.

  • Provide self-service options: customer account areas where users can update their details, unsubscribe links in every marketing email, and clearly signposted forms or email addresses for Data Subject Access Requests (DSARs) and deletion requests. The right to erasure is also known as the “right to be forgotten.”
  • Individuals can request access to their personal data within one month. Organizations must respond to data subject requests promptly and efficiently. If a request is complex, you may extend it by up to two additional months, but you must inform the requester within the first month and explain why.
  • Before disclosing or deleting data, verify the requester’s identity. Then locate all instances of their personal data: Shopify admin (orders, customer profiles), email marketing tools, review platforms, helpdesk tickets, and any apps acting as data processors. Don’t forget to handle inaccurate data-rectification requests, which require correcting errors across all systems.
  • Document each request in a DSAR log, including the date received, request type, systems searched, actions taken, communications sent, and completion date. Maintaining detailed records demonstrates compliance and helps identify process improvements.

Step 6: Manage Third‑Party Processors, Apps, and Integrations

Under GDPR Art. 28, a data controller must only use data processors that provide sufficient guarantees of data security and compliance. Every relationship must be formalized in a data processing agreement (DPA). Third-party processors must comply with GDPR requirements, and documentation of compliance must be maintained.

  • Build and maintain a processor register listing every third party that processes personal data on your behalf. For each, record what data they receive, why, where they’re located, and whether they transfer data outside the EEA/UK. This register complements your ROPA.
  • Review key DPA clauses: processing scope and instructions, confidentiality obligations, technical and organizational measures, sub-processor approval procedures, assistance with data subject rights, data breach notification timelines, and obligations to delete or return data at the end of the contract.
  • For Shopify apps specifically, check each app’s privacy policy and data retention practices. Does the app support consent signals? Does it offer deletion APIs? Does it host data in the EU, or does it rely on US infrastructure? A practical guide to a GDPR-compliant Shopify Store can help you evaluate each integration.
  • Understand role distinctions: most apps act as data processors following your instructions. But some, particularly ad networks or analytics platforms that use your data for their own purposes, may act as joint controllers or independent controllers. Joint controllership requires a shared arrangement and shared liability. If an app collects personal information for its own purposes, that’s a red flag worth investigating.
Make Your Shopify Store GDPR & Cookie Compliant in Minutes
Automatically manage cookie consent, block tracking before user approval, and stay compliant with GDPR, CCPA, LGPD, UK GDPR and Google Consent Mode v2 β€” without coding.

Step 7: Assess High‑Risk Processing with DPIAs

A data protection impact assessment (DPIA), sometimes referred to as a protection impact assessment (PIA), is required for high-risk data processing activities. Article 35 of GDPR outlines DPIA requirements and processes. DPIAs help identify and mitigate privacy risks proactively, and DPIAs must be conducted before starting high-risk processing.

  • Common e-commerce DPIA triggers include: extensive behavior-based advertising and customer profiling; AI recommendation engines that combine browsing history with purchase data; large-scale, systematic monitoring of user actions across sessions; and processing special categories of data.
  • The DPIA process follows clear steps: describe the processing and its purposes; assess necessity and proportionality; identify risks (discrimination, re-identification, loss of confidentiality); evaluate likelihood and severity; and define mitigation measures such as pseudonymization, strict access controls, data minimization, or reduced retention periods.
  • Stores should consult their data protection officer or privacy lead when conducting DPIAs. DPIAs require consultation with supervisory authorities if residual risks remain high after mitigation. If a relevant supervisory authority must be consulted, this must happen before the processing begins.
  • Accurate data mapping from Step 1 and documented lawful bases from Step 2 feed directly into DPIAs. DPIA outcomes should be documented and revisited periodically, especially when processing changes or new tools are added. A public authority may also require DPIAs for certain types of processing in its jurisdiction.
A Google-Approved Consent Platform for Shopify
Pandectes is an official Google Certified Consent Management Platform and is fully compatible with Google Consent Mode v2 and global privacy regulations.

Step 8: Strengthen Data Security and Prepare a Data Breach Response Plan

A personal data breach, as defined in GDPR Art. 4(12), is any security incident leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data. Data security is a core data protection principle, and every store that processes personal data must implement appropriate organizational security measures and technical safeguards.

  • Organizations should implement technical safeguards like encryption and access controls to protect personal data. For Shopify stores, this means: TLS/HTTPS across the entire site, two-factor authentication for all admin accounts, role-based access controls limiting staff to least-privilege access, regular backups, encryption of sensitive data at rest where feasible, and secure configuration of all apps and integrations.
  • A data breach response plan is mandatory under GDPR. Organizations must document their data breach response procedures. The plan should cover detection (monitoring logs and alerts), containment (isolating compromised systems), investigation (determining scope and affected data subjects), notification responsibilities, and post-incident review.
  • Organizations must report data breaches to the supervisory authority within 72 hours when the breach is likely to pose a risk to individuals’ rights and freedoms. Breach notifications must include details on the nature of the breach, the categories of data affected, the approximate number of affected data subjects, the likely consequences, and the measures taken. Individuals who are at high risk to their rights and freedoms must be notified promptly.
  • Concrete e-commerce examples include credential stuffing attacks that expose customer accounts and order histories, misconfigured analytics tags that leak email addresses or IP addresses to third parties, or a payment processor incident that exposes payment identifiers. A rehearsed plan with clear internal responsibilities helps prevent data breaches from escalating and reduces response time.
privacy drawing

Step 9: Handle International Data Transfers Lawfully

GDPR Chapter V limits the transfer of personal data from the EU/EEA or UK to countries lacking an adequacy decision. Many Shopify stacks involve such transfers-US-based email services, CDNs, analytics providers, or cloud hosting. If personal data is transferred outside the EEA, organizations need to identify transfer mechanisms and document assessments.

  • The main tools for lawful data transfer include: adequacy decisions by the European Commission (e.g., Canada, UK), standard contractual clauses (SCCs) approved by the Commission, and Binding Corporate Rules (BCRs) for corporate groups. Shopify itself applies BCRs and SCCs to cover international data flows.
  • After the Schrems II ruling, organizations must conduct a transfer impact assessment (TIA) for each transfer to evaluate whether the recipient country’s laws, particularly surveillance and government access laws, could undermine data protection. If risks are identified, apply appropriate safeguards such as encryption, pseudonymization, or contractual restrictions.
  • For Shopify merchants using US-based email services or analytics providers, ensure that standard contractual clauses are in place, that TIAs are documented, and that security measures such as encryption and data minimization are implemented.
  • Privacy notices and cookie policies should clearly disclose if and where data is transferred outside the EEA/UK, and what safeguards apply. Transparency about data transfer builds customer trust and satisfies GDPR’s accountability requirements.

Step 10: Maintain Ongoing Compliance and Governance

GDPR compliance is an ongoing governance process, not a one-time project. Article 5(2) requires organizations to demonstrate compliance at any time-the accountability principle demands living documentation, not dusty binders.

  • Conduct at least annual audits of your data maps, lawful bases, retention schedules, processor lists, consent mechanisms, and security controls. Organizations must regularly review and audit their compliance program to identify and address any gaps. Update everything when new tools, campaigns, or markets are added. Organizations should regularly update privacy notices, contracts, and security controls in response to regulatory changes.
  • GDPR mandates regular training for staff on data privacy principles and handling personal information safely. Train customer service, marketing, and fulfillment teams on how to recognize and route DSARs, handle personal data responsibly, and report potential incidents. Document all training sessions.
  • A data protection officer DPO is mandatory for certain organizations, specifically those engaged in large-scale processing, systematic monitoring, or handling special categories of data. DPOs must have expert knowledge of data protection laws and report directly to the highest level of management. DPOs guide organizations on implementing privacy by design and can be internal employees or external consultants.
  • Pandectes GDPR Compliance app supports ongoing compliance with automatic cookie scans, consent logs, Google Consent Mode integration, and multi-jurisdiction support covering GDPR, CCPA, and LGPD. This helps keep your store aligned with evolving rules without constant manual effort.

Conclusion

In conclusion, the complete GDPR compliance checklist provides a comprehensive framework for Shopify stores and e-commerce businesses to navigate data protection requirements effectively. By systematically mapping data, establishing lawful bases, updating policies, managing consent, and preparing for data breaches, organizations can demonstrate GDPR compliance and build lasting customer trust.

Remember, GDPR compliance is an ongoing process that demands continuous monitoring, staff training, and adaptation to regulatory changes. Leveraging tools like Pandectes can simplify these tasks, ensuring your store remains secure and compliant in a dynamic privacy landscape.

Make Your Shopify Store Fully GDPR & CCPA Compliant Today
Pandectes GDPR Compliance App for Shopify
Share
Subscribe to learn more
pandectes