Customer data and GDPR in platform migration: what can you bring along?

  • Published May 1, 2026
  • Written by Michelle Brouwers
  • Reading time 7 minutes

LinkedIn X Facebook WhatsApp Pin it Messenger Email

Can you migrate customer data to Shopify under the GDPR? A practical guide to legal bases, what's allowed and how to migrate compliantly from WooCommerce, Magento or Lightspeed.

Customer data and GDPR in platform migration pop art header

You're moving from WooCommerce, Magento or Lightspeed to Shopify. Everything is ready: the new store, the products, the integrations. Then the question comes up that surprises many store owners: can you simply take customer data with you? Names, addresses, order history and account details all fall under the GDPR. And that law is stricter than you might think.

In this article we explain exactly what applies legally when migrating customer data, which legal bases the GDPR offers, and how Syncer handles this safely and compliantly.

Which customer data is migrated?

In a platform migration you typically migrate the following categories of customer data:

Data type Examples Personal data?
Contact details Name, email address, phone number ✅ Yes
Addresses Billing address, shipping address ✅ Yes
Order history Order numbers, products, payment status ✅ Yes (indirect)
Customer accounts Username, login status ✅ Yes
Passwords Hashed or plain text passwords ❌ Don't migrate

All of this falls under the GDPR's definition of personal data. That means you need a valid legal basis for every processing activity.

What does the GDPR say about migrating customer data?

The GDPR provides six legal bases for processing personal data (article 6). For a platform migration two of them are relevant:

1. Contractual necessity (article 6(1)(b))

When a customer has ordered something, a sales agreement is in place. To execute that agreement correctly and keep the order history available, you may process the associated data. Migrating order data and customer accounts to the new platform falls directly under this basis: without that data you can't process orders, handle returns or honor warranty claims.

2. Legitimate interest (article 6(1)(f))

As a store owner you have a legitimate interest in a smooth platform transition. Customer data is needed for that. The controller's interest outweighs the data subject's privacy interest here, provided you are transparent about the change and use the data only for the original purpose.

Conclusion: yes, you may bring customer data along during a platform migration. But you have to handle it carefully.

GDPR compliance dashboard laptop customer data platform migration Shopify

Syncer as a processor: the data processing agreement

When Syncer migrates your customer data to Shopify, Syncer acts as a processor in the sense of the GDPR. You remain the controller. That means you decide which data is migrated and for what purpose. Syncer carries that out according to your instructions.

The GDPR requires processor and controller to enter into a data processing agreement (article 28 GDPR). It captures arrangements about:

  • The purpose and duration of the processing
  • The nature of the data being processed
  • Security measures
  • Confidentiality obligations
  • The ban on sub-processors without consent
  • What happens to the data once the migration is complete

Syncer signs a data processing agreement with every customer before the migration starts. That way the legal foundation is watertight.

Migrating passwords? Not allowed

One of the most frequently asked questions is whether you can bring passwords across. The answer is clear: no.

Passwords are stored in modern systems as hashed values with a salt. That hash is platform-specific and won't work in another system. But there's a legal reason as well: exporting and moving (hashed) passwords significantly increases the security risk and conflicts with the principle of data minimization.

So what does work? Shopify automatically sends customers an email inviting them to set a new password. Customers keep their account including the full order history. Only the password is new. In practice this rarely causes issues, especially when you communicate the migration well.

Data minimization: only bring what's needed

The GDPR requires that you process no more data than is strictly necessary for the purpose (article 5(1)(c)). In a platform migration that means:

  • Don't migrate marketing lists if they aren't needed for the store to function
  • Outdated accounts from customers who have been inactive for years don't need to come along
  • Sensitive data that is already outdated should be deleted before the migration
  • Don't collect data from third parties who have no customer relationship with your store

Syncer helps determine which data is truly necessary and which is better left behind. This saves not only legal risk but also migration time and storage costs.

Customer data and order history migration to Shopify safe and GDPR compliant

How Syncer migrates customer data safely via Live Sync®

The way you migrate data is at least as important as whether you may do so. Syncer uses Live Sync® for that: an in-house migration technology that works fully on the basis of API connections.

That is an important difference from many other migration tools. No CSV exports, no bulk downloads of customer data sitting on someone's laptop. Everything moves directly from platform to platform via secured API connections:

  • No intermediate storage: data isn't temporarily stored on external servers or local systems
  • Encrypted connections: all API communication runs over HTTPS
  • Logging and audit trail: every migration step is logged so you can demonstrate afterwards what was migrated and when
  • No data loss: Live Sync® migrates incrementally, so even the last orders placed before go-live come along

This approach is not only safer from a technical perspective, but also from a GDPR perspective: fewer copies of data, less risk of breaches, better demonstrability.

What you as a store owner still need to do

A platform migration doesn't mean that you, as the controller, no longer have to do anything. There are a few items that remain your responsibility:

Update your privacy statement

Shopify as a technical platform is a new sub-processor. You have to mention that in your privacy statement. Shopify maintains its own Data Processing Addendum (DPA) describing how they handle customer data. Add a reference to Shopify as the hosting party in your privacy policy.

Inform your customers

You don't need to obtain customer consent in advance for the migration (given the contractual basis), but transparency is wise. A short email letting customers know you're moving to a new platform and that they'll receive an invitation to set a new password works well. This prevents confusion and increases trust.

Check retention periods

Do you have customer data in your current platform that has been inactive for more than seven years? Check whether you're still allowed to keep it under your bookkeeping and retention obligations, or whether you should remove it before the migration.

Update your data breach procedure

After the move to Shopify your technical environment changes. Make sure your internal data breach procedure knows how incidents on the new platform are reported to the data protection authority.

Practical: GDPR checklist for your platform migration

Action Responsible Timing
Sign data processing agreement with Syncer Syncer + you Before migration start
Perform data minimization (clean up inactive accounts) You Before migration start
Update privacy statement (Shopify as sub-processor) You At or after go-live
Inform customers about the platform change and password reset You At go-live
Check retention periods and remove outdated data You Before migration start
Update data breach procedure for the new platform You After go-live

Conclusion: yes, it's allowed. But do it right.

Migrating customer data during a platform migration is legally allowed under the GDPR, as long as you use the right legal bases, sign a data processing agreement and stay transparent toward your customers. Passwords don't come along. Data is minimized where possible. And the way you migrate makes a world of difference.

Syncer ensures the technical part stays GDPR compliant via Live Sync®. The communication part is on you, but we'll help you with that too.

Curious what your migration looks like?

Request a free migration plan. We look at your data, your platform and the GDPR requirements that apply to your situation.

Request a free migration plan

Sources

Michelle Brouwers

About Michelle

Shopify backend- and frontend developer. Loves AI and builds apps. Blogs about migrations and tech.

More articles