GDPR data processing only in EU

Topic summary

Goal: ensure patient/client data is processed only within the EU for GDPR compliance (EU data protection regulation).

Key points:

  • Current capability: Forcing data storage/processing in a single region is not a native Shopify feature.
  • Shopify docs state: EU-based stores have infrastructure configured to store the store within the EU. However, Shopify may still rely on international data transfers to process data and deliver services, even if EU storage is chosen.

Implications:

  • The EU storage option does not guarantee EU-only processing; some cross-border transfers may still occur.
  • There’s uncertainty whether true EU-only processing is possible on Shopify, especially for sensitive medical data.

Latest update and actions:

  • The documentation reference appears to be a recent update.
  • Recommended next step: contact Shopify Support for definitive, up-to-date guidance (support chat link was provided).

Status:

  • Unresolved. The central question—whether strict EU-only processing can be guaranteed on Shopify—remains open pending official confirmation.
Summarized with AI on January 13. AI used: gpt-5.

We are planning to launch a website for medical purpose. As it will process client/patient sata we need to make sure that data is only peocessed in EU.

is this possible?

Hi NordicV,

Unfortunately storing data specifically on servers in one particular region is not a native feature of Shopify.

Ok, this is what I find on support page, what does that mean then?

"Places for data hosting

Protecting your personal data and your customers’ data is important to us at Shopify. We are aware that prioritizing data protection helps you maintain the trust and confidence of your customers. To support this, if you are based in Europe, we have configured infrastructure to store your store within the European Union.

Even if you choose to store data in Europe, Shopify may need to rely on international data transfers to process that data and deliver services in compliance with relevant laws and regulations, such as GDPR."

Thanks for sharing this NordicV - this must be a recent update.

Maybe the best option would be to contact Shopify support about this specifically as they may have more info. You can start an interaction here: https://help.shopify.com/en/support/topic-select/login-issue/contact/chat