If you sell to customers in the European Union or California (CCPA), you've likely received automated GDPR webhooks from Shopify regarding Customer Data Request or Customer Redact.
Failing to comply with data privacy regulations can result in steep fines. However, many merchants struggle to understand how GDPR requirements interact with their cloud data backups.
Here is what you actually need to know about exporting and redacting customer data on Shopify.
Shopify requires all installed apps to process three key privacy webhooks:
1. customers/data_request: A customer requests a copy of all personal data held by your store.
2. customers/redact: A customer requests permanent deletion of their personal data.
3. shop/redact: Sent 48 hours after a store uninstalls an app to request store data deletion.
A common compliance concern is: If a customer requests data deletion, does that break my automated backups?
Under GDPR guidelines, backup archives maintained for legal, financial, and disaster recovery purposes are permitted provided that:
Woonic Backup & Staging is engineered with privacy by design:
Keep your store safe from data loss and privacy fines with Woonic Backup & Staging!
Join top-performing Shopify brands using Woonic for automated AWS S3 daily backups, sandbox store staging, and instant 1-click file restores.