You're moving from WooCommerce, Magento or Lightspeed to Shopify. Everything is ready: the new store, the products, the integrations. Then the question comes up that surprises many store owners: can you simply take customer data with you? Names, addresses, order history and account details all fall under the GDPR. And that law is stricter than you might think.
In this article we explain exactly what applies legally when migrating customer data, which legal bases the GDPR offers, and how Syncer handles this safely and compliantly.
Which customer data is migrated?
In a platform migration you typically migrate the following categories of customer data:
| Data type |
Examples |
Personal data? |
| Contact details |
Name, email address, phone number |
✅ Yes |
| Addresses |
Billing address, shipping address |
✅ Yes |
| Order history |
Order numbers, products, payment status |
✅ Yes (indirect) |
| Customer accounts |
Username, login status |
✅ Yes |
| Passwords |
Hashed or plain text passwords |
❌ Don't migrate |
All of this falls under the GDPR's definition of personal data. That means you need a valid legal basis for every processing activity.
What does the GDPR say about migrating customer data?
The GDPR provides six legal bases for processing personal data (article 6). For a platform migration two of them are relevant:
1. Contractual necessity (article 6(1)(b))
When a customer has ordered something, a sales agreement is in place. To execute that agreement correctly and keep the order history available, you may process the associated data. Migrating order data and customer accounts to the new platform falls directly under this basis: without that data you can't process orders, handle returns or honor warranty claims.
2. Legitimate interest (article 6(1)(f))
As a store owner you have a legitimate interest in a smooth platform transition. Customer data is needed for that. The controller's interest outweighs the data subject's privacy interest here, provided you are transparent about the change and use the data only for the original purpose.
Conclusion: yes, you may bring customer data along during a platform migration. But you have to handle it carefully.
Syncer as a processor: the data processing agreement
When Syncer migrates your customer data to Shopify, Syncer acts as a processor in the sense of the GDPR. You remain the controller. That means you decide which data is migrated and for what purpose. Syncer carries that out according to your instructions.
The GDPR requires processor and controller to enter into a data processing agreement (article 28 GDPR). It captures arrangements about:
- The purpose and duration of the processing
- The nature of the data being processed
- Security measures
- Confidentiality obligations
- The ban on sub-processors without consent
- What happens to the data once the migration is complete
Syncer signs a data processing agreement with every customer before the migration starts. That way the legal foundation is watertight.
Migrating passwords? Not allowed
One of the most frequently asked questions is whether you can bring passwords across. The answer is clear: no.
Passwords are stored in modern systems as hashed values with a salt. That hash is platform-specific and won't work in another system. But there's a legal reason as well: exporting and moving (hashed) passwords significantly increases the security risk and conflicts with the principle of data minimization.
So what does work? Shopify automatically sends customers an email inviting them to set a new password. Customers keep their account including the full order history. Only the password is new. In practice this rarely causes issues, especially when you communicate the migration well.
Data minimization: only bring what's needed
The GDPR requires that you process no more data than is strictly necessary for the purpose (article 5(1)(c)). In a platform migration that means:
- Don't migrate marketing lists if they aren't needed for the store to function
- Outdated accounts from customers who have been inactive for years don't need to come along
- Sensitive data that is already outdated should be deleted before the migration
- Don't collect data from third parties who have no customer relationship with your store
Syncer helps determine which data is truly necessary and which is better left behind. This saves not only legal risk but also migration time and storage costs.
How Syncer migrates customer data safely via Live Sync®
The way you migrate data is at least as important as whether you may do so. Syncer uses Live Sync® for that: an in-house migration technology that works fully on the basis of API connections.
That is an important difference from many other migration tools. No CSV exports, no bulk downloads of customer data sitting on someone's laptop. Everything moves directly from platform to platform via secured API connections:
-
No intermediate storage: data isn't temporarily stored on external servers or local systems
-
Encrypted connections: all API communication runs over HTTPS
-
Logging and audit trail: every migration step is logged so you can demonstrate afterwards what was migrated and when
-
No data loss: Live Sync® migrates incrementally, so even the last orders placed before go-live come along
This approach is not only safer from a technical perspective, but also from a GDPR perspective: fewer copies of data, less risk of breaches, better demonstrability.
What you as a store owner still need to do
A platform migration doesn't mean that you, as the controller, no longer have to do anything. There are a few items that remain your responsibility:
Update your privacy statement
Shopify as a technical platform is a new sub-processor. You have to mention that in your privacy statement. Shopify maintains its own Data Processing Addendum (DPA) describing how they handle customer data. Add a reference to Shopify as the hosting party in your privacy policy.
Inform your customers
You don't need to obtain customer consent in advance for the migration (given the contractual basis), but transparency is wise. A short email letting customers know you're moving to a new platform and that they'll receive an invitation to set a new password works well. This prevents confusion and increases trust.
Check retention periods
Do you have customer data in your current platform that has been inactive for more than seven years? Check whether you're still allowed to keep it under your bookkeeping and retention obligations, or whether you should remove it before the migration.
Update your data breach procedure
After the move to Shopify your technical environment changes. Make sure your internal data breach procedure knows how incidents on the new platform are reported to the data protection authority.
Practical: GDPR checklist for your platform migration
| Action |
Responsible |
Timing |
| Sign data processing agreement with Syncer |
Syncer + you |
Before migration start |
| Perform data minimization (clean up inactive accounts) |
You |
Before migration start |
| Update privacy statement (Shopify as sub-processor) |
You |
At or after go-live |
| Inform customers about the platform change and password reset |
You |
At go-live |
| Check retention periods and remove outdated data |
You |
Before migration start |
| Update data breach procedure for the new platform |
You |
After go-live |
Conclusion: yes, it's allowed. But do it right.
Migrating customer data during a platform migration is legally allowed under the GDPR, as long as you use the right legal bases, sign a data processing agreement and stay transparent toward your customers. Passwords don't come along. Data is minimized where possible. And the way you migrate makes a world of difference.
Syncer ensures the technical part stays GDPR compliant via Live Sync®. The communication part is on you, but we'll help you with that too.
Curious what your migration looks like?
Request a free migration plan. We look at your data, your platform and the GDPR requirements that apply to your situation.
Request a free migration plan
Sources