GDPR compliance for ecommerce: BigCommerce is ready

Disclaimer: The information on this page is for guidance only and does not constitute legal or professional advice. Always consult a qualified lawyer on any specific legal problem or matter. BigCommerce disclaims all liability with respect to the information in this document.

What you need to know about GDPR

The EU General Data Protection Regulation (GDPR), places the responsibility on businesses to give individuals control over their personal data. And it's not limited to European businesses. You should consult a lawyer if you have any questions about how GDPR applies to your business, but, in general, any company offering goods or services to individuals in the EU must comply.

GDPR is premised on the belief that all users have the right to:

  • Know how their data is being used
  • Correct inaccurate or incomplete personal data
  • Erase or remove their personal data
  • Restrict data processing
  • Obtain and reuse their own personal data
  • Decide if data may be processed

BigCommerce has your ecommerce platform GDPR compliance covered

BigCommerce merchants achieve GDPR compliance with features and capabilities that allow them to:



  • Correct data: Customers can correct or update their data when they log in to their account.
  • Erase data: Customer data deleted from the BigCommerce Control Panel will be removed within 14 days.
  • Make data portable: Customer data can be exported into the CSV format by the Bulk Import/Export tool.
  • Require consent to use data: You can easily add a checkbox to give your users the ability to view and agree to your privacy policy before registering for an account.
  • Protect data: The BigCommerce offers numerous security features available for review on our Platform Trust Center. Report breaches: In the event of a data breach BigCommerce, we will report the event to you.

Tips for ecommerce GDPR compliance

Make sure your vendors are GDPR compliant

If you transfer an individual's personal data to vendors, such as through integrations or third-party apps, verify that they are GDPR compliant.

Protect personal data and report breaches

Take steps to make sure your customers' data is secure, and report data breaches when required.

Update your data privacy notice

Be transparent about your data collection and processing practices and where required to gain consent for collecting personal data.

More GDPR peace of mind for your ecommerce platform

BigCommerce meets and exceeds the privacy standards required by GDPR. We agree to enter into a Data Processing Addendum (DPA) and we self certify under the Data Privacy Framework.

Protecting personal data

As a component of our ongoing commitment to data security, we hold the ISO 27001 certification, the highest level of information security.

How BigCommerce complies with GDPR

We've worked hard to stay ahead of GDPR and go above and beyond to maintain compliance. Here's how you can count on BigCommerce to comply with these new data privacy rules:

Data protection leader

BigCommerce has an appointed Data Protection Officer (DPO).

Data processing inventory

We continue to catalogue data processing activities to ensure that collection, processing, and dissemination stays GDPR compliant.

Vendor assessment

We have assessed vendors for our core platform with whom BigCommerce shares personal data and we bind them to data protection terms as our sub-processors.

Privacy protocols

BigCommerce has implemented GDPR-compliant policies and protocols, like data breach response policies and data processing requirements.

Get GDPR peace of mind from your ecommerce platform