Skip to Content
08 July, 2026

Privacy Compliance for Shopify Stores: APP, GDPR and CCPA

Privacy Compliance for Shopify Stores: APP, GDPR and CCPA

Table of Content

An Adelaide based wellness brand sent us an email titled “urgent privacy thing” one morning. A customer in Germany had emailed asking for a copy of all the data the store held on her, and then a follow up requesting that everything be deleted within 30 days. The team had not heard of GDPR data subject access requests, had not realised they applied to an Australian store selling internationally, and had no process for finding all the places that customer’s data lived (Shopify, the email platform, the reviews app, the helpdesk, an old marketing CSV). What looked like a single email turned into a week of detective work and a slightly nervous response.

Privacy compliance for Shopify merchants now spans at least three frameworks: the Australian Privacy Principles, the European GDPR for any EU traffic, and the California Consumer Privacy Act for Californian customers. This article covers what each one actually requires of an Australian merchant, where they overlap, and the practical setup that satisfies all three at once.

The Australian Privacy Principles: the one merchants forget

The APPs sit under the Privacy Act 1988 and apply to any organisation with an annual turnover above $3 million, plus a handful of specific categories regardless of turnover (health information, credit reporting, contracted service providers for the Commonwealth, and so on). Even if your turnover is below the threshold, ASIC, the OAIC and many B2B customers will expect you to follow the spirit of the principles, and many merchants opt in voluntarily.

The thirteen principles in plain English:

  • Be open about how you handle personal information (privacy policy).
  • Let people deal with you anonymously where practical.
  • Only collect personal information you actually need.
  • Collect from the individual where you can, not from third parties.
  • Tell people at the point of collection what you are doing with their data.
  • Use and disclose information only for the purpose collected.
  • Don’t use government identifiers (like Medicare numbers) as your own.
  • Make sure data is accurate.
  • Store data securely.
  • Let people access their data.
  • Let people correct their data.
  • Don’t use data for direct marketing without consent.
  • Restrict cross border data flows unless the recipient is bound by similar protections.

The Notifiable Data Breaches scheme sits alongside the principles and requires you to notify the OAIC and affected individuals when a breach is likely to cause serious harm. Penalties for non compliance can be significant: maximum fines were raised dramatically in 2022 and apply to serious or repeated interferences with privacy.

GDPR: when an Australian store needs to care

The General Data Protection Regulation applies whenever you offer goods or services to people in the EU or monitor their behaviour there. Selling and shipping to the EU triggers it. Running marketing aimed at EU customers triggers it. Loading Google Analytics with EU visitors collects their data and triggers it.

The obligations are similar in spirit to the APPs but more prescriptive in detail. Key obligations for Shopify merchants:

  • Lawful basis for processing (usually consent or contract).
  • Clear consent for marketing and for non essential cookies.
  • Data subject rights: access, correction, deletion, portability, restriction, objection.
  • Privacy by design and by default.
  • Breach notification within 72 hours.
  • Data processing agreements with vendors that handle your customer data.

Penalties are large (up to 4% of global annual revenue or 20 million euros, whichever is greater), and the EU regulators do enforce against non EU companies.

CCPA and CPRA: California is special

The California Consumer Privacy Act (as updated by the California Privacy Rights Act) applies if you meet certain thresholds and process personal information of California residents. Most small Australian merchants are below the threshold, but if you sell at scale into the US, check whether you cross any of them: gross revenue over $25 million, buying or selling personal information of 100,000+ Californians, or deriving 50%+ of revenue from selling personal information.

The rights granted: access, deletion, correction, opt out of sale or sharing, opt out of targeted advertising. The do not sell or share link is the most visible obligation.

Where the three frameworks overlap

If you build your privacy program to the highest common denominator, you cover all three with the same work. The shared core looks like this:

  • A clear, plain language privacy policy that lists what you collect, why, who you share it with, and how long you keep it.
  • A cookie consent banner that genuinely controls non essential cookies (not just an “OK” button).
  • A documented process for handling data subject requests, with a known turnaround time.
  • A vendor list with data processing agreements for the ones who touch personal data.
  • An incident response plan that includes breach notification timelines.
  • Sensible data retention: do not keep what you do not need.

Cookie consent on Shopify

Shopify added a built in customer privacy API that integrates with cookie consent banners. Most reputable consent management platforms (Cookiebot, OneTrust, Iubenda) plug into it. The key is that the consent choice must actually block the cookies and pixels that the customer rejects. Many stores have a banner that looks compliant but does nothing functional behind it, which is worse than no banner because it implies a consent that does not exist.

For Australian merchants serving international traffic, geo target your banner. EU and UK visitors need explicit consent (opt in). Californian visitors need an opt out link. Australian visitors can usually be served a simpler notice unless your category triggers stricter rules.

Handling data requests

The Adelaide brand’s pain came from not having a process. Build one before you need it.

  • Receive: a clearly published email address (privacy@yourdomain) and a form on your contact page.
  • Verify: confirm the person making the request is who they say they are. For Shopify customers, an authenticated session through their account is the cleanest method.
  • Fulfil: Shopify provides export and delete actions in the admin. For data held in other systems (email platform, helpdesk, reviews app, marketing tools), have a checklist of where to look.
  • Respond: within 30 days for GDPR, within a reasonable time for APP, within 45 days for CCPA. Acknowledge receipt promptly.
  • Document: keep a log of requests, responses and timelines.

Most stores get a handful of requests a year. The cost of having a process is small. The cost of not having one is a week of detective work and possible regulatory exposure.

Vendor data processing agreements

Every app and platform that processes your customer data on your behalf should have a data processing agreement (DPA) in place. Shopify provides one by default. Most major apps publish theirs and accept yours through a click through process. For smaller vendors, request one. Without a DPA, GDPR considers you and the vendor to be jointly liable for any breach, which is not a position you want.

Keep a register of which vendors process which data and where the DPA lives. This becomes critical the first time you face a breach or a regulator question.

Common mistakes

  • Boilerplate privacy policies: generic templates that do not reflect what your store actually does. Regulators read these.
  • Consent banners that do nothing: cookies fire regardless of what the customer clicks.
  • No process for deletion requests: deleted from Shopify but still in the email platform and the helpdesk.
  • Indefinite retention: marketing lists from five years ago, customer exports on shared drives, ex employee mailboxes still receiving customer enquiries.
  • Failing to map vendors: nobody knows which apps have customer data, so a request takes a week.

A one week action plan

  • Day 1: list every system that holds customer data. Note the vendor and the type of data.
  • Day 2: refresh your privacy policy with what you actually do, not what a template said you did.
  • Day 3: review your cookie consent setup and confirm it functionally blocks rejected cookies.
  • Day 4: draft a data subject request handling process and put it on a wiki.
  • Day 5: chase DPAs from any vendor you do not have one with.

Where Defyn fits in

Privacy compliance crosses Shopify, your apps, your hosting and your operational processes. We help Australian Shopify merchants build a privacy posture that satisfies APP, GDPR and CCPA without bolting on a separate program for each. The work pairs with our broader Shopify reviews including app audits and access control work. Take a look at our Sydney web development services or start a project to scope a privacy and compliance review. Our audit and support retainer keeps your privacy program current as regulations and your vendor stack both change.

Would rather not untangle APP, GDPR and CCPA on your own? Our Shopify development team helps Australian merchants build compliance into their stores from day one.

Insights

The latest from our knowledge base