CookieScan

Data transfers outside the EU: what does GDPR say?

Most advertising and analytics trackers installed on Shopify (Meta, Google, TikTok...) transfer data to servers located outside the EU/EEA, which is governed by a specific legal regime.

The principle

GDPR (Chapter V, Articles 44 to 49) strictly regulates transfers of personal data to countries outside the EU/EEA. A transfer is only lawful if based on a European Commission adequacy decision, standard contractual clauses, or another recognised safeguard.

The US case

Since the “EU-US Data Privacy Framework” adequacy decision (2023), transfers to US companies certified under this framework are facilitated. But not all US companies are certified, and the validity of this framework has already been challenged in European courts in the past for its predecessors (Safe Harbor, Privacy Shield) — a point worth watching over time.

What this means for a Shopify store

Installing Meta Pixel, Google Analytics or TikTok Pixel implies a data transfer to these companies. Checking their certification status, and documenting this legal basis, is part of the merchant’s obligations as data controller — independent of the question of consent to setting the cookie itself.

Does your store follow these rules?

Our free scanner technically checks what fires before consent on your Shopify store, in ~30 seconds.

Scan my store for free

Sources

Other articles

Independent informational content, not affiliated with Shopify. Not legal advice; for an assessment of your situation, consult a lawyer or your DPO.