GDPR Breach - Remove Billing Address for Free Items

Topic summary

Users are raising concerns about Shopify requiring billing and shipping addresses for free downloadable items, arguing this practice violates GDPR principles.

GDPR Compliance Issues Identified:

  • Data Minimization (Article 5(1)(c)): Collecting billing addresses for free digital items is unnecessary and potentially non-compliant
  • Lawfulness of Processing (Article 6): No valid legal basis exists for requesting this information when no payment occurs
  • Purpose Limitation (Article 5(1)(b)): Address collection lacks a legitimate purpose for free downloads

Key Concerns:

  • No payment processing or physical shipping occurs, making address collection irrelevant
  • Practice creates friction in the customer experience
  • Shop owners may face GDPR complaints or penalties
  • No apparent method exists to disable this requirement

Current Status:
Multiple users have requested this feature, but no solution or official response has been provided. The discussion remains open with participants seeking a way to remove mandatory address fields for free digital products.

Summarized with AI on October 28. AI used: claude-sonnet-4-5-20250929.

When offering free downloadable items, there is no valid reason to collect a billing or shipping address so surely there should be an option to disable this completely.

These details are irrelevant since no payment is processed, and no physical goods are being shipped.

Under the General Data Protection Regulation (GDPR), collecting unnecessary personal data may constitute a breach. Specifically:

  1. Data Minimization (Article 5(1)(c)): GDPR requires that personal data collected be adequate, relevant, and limited to what is necessary for the purpose. Billing addresses serve no purpose in the context of free digital items, making their collection non-compliant.

  2. Lawfulness of Processing (Article 6): There must be a lawful basis for processing personal data. Without a valid reason to request billing addresses, collecting them for free downloads could violate GDPR requirements.

  3. Purpose Limitation (Article 5(1)(b)): Personal data must be collected for specified, explicit, and legitimate purposes. Unless there is a specific legal or technical need to request billing addresses, their collection fails to meet this requirement.

This practice is not only a massive turn off and inconvenience for customers but could also expose shop owners to GDPR-related complaints or penalties.

There doesn’t appear to be a method to disable this?! There are many other posts asking for the same thing but no answer.

There really needs to be an option for this to be disabled.

2 Likes

I completely agree. Why does Shopify think it needs a billing address? No sale = no tax. A free download doesn’t require a physical address, so there is nothing to verify.