Disclaimer: The information on this page is for guidance only and does not constitute legal or professional advice. Always consult a qualified lawyer on any specific legal problem or matter. BigCommerce disclaims all liability with respect to the information in this document.

The EU General Data Protection Regulation (GDPR), places the responsibility on businesses to give individuals control over their personal data. And it's not limited to European businesses. You should consult a lawyer if you have any questions about how GDPR applies to your business, but, in general, any company offering goods or services to individuals in the EU must comply.
BigCommerce merchants achieve GDPR compliance with features and capabilities that allow them to:
If you transfer an individual's personal data to vendors, such as through integrations or third-party apps, verify that they are GDPR compliant.
Take steps to make sure your customers' data is secure, and report data breaches when required.
Be transparent about your data collection and processing practices and where required to gain consent for collecting personal data.

BigCommerce meets and exceeds the privacy standards required by GDPR. We agree to enter into a Data Processing Addendum (DPA) and we self certify under the Data Privacy Framework.
As a component of our ongoing commitment to data security, we hold the ISO 27001 certification, the highest level of information security.
We've worked hard to stay ahead of GDPR and go above and beyond to maintain compliance. Here's how you can count on BigCommerce to comply with these new data privacy rules:
BigCommerce has an appointed Data Protection Officer (DPO).
We continue to catalogue data processing activities to ensure that collection, processing, and dissemination stays GDPR compliant.
We have assessed vendors for our core platform with whom BigCommerce shares personal data and we bind them to data protection terms as our sub-processors.
BigCommerce has implemented GDPR-compliant policies and protocols, like data breach response policies and data processing requirements.