Shopify Ecom

Does a CCPA deletion request work the same way in Shopify as a GDPR one?

Published September 2, 2026·Last verified September 2, 2026·
At a glance
Short answer
Same Shopify erasure tool either way — but a CCPA-covered business answers in 45 days, not GDPR's one month.
One tool
Shopify's admin route — More actions > Erase personal data — asks for no law, region or jurisdiction.
Shopify's own label
Its Manage customers page calls the mechanism a GDPR erasure request; the same request runs whatever law the customer cited.
California clock
A covered business gets 45 calendar days to respond, extendable once by 45 more with notice — 90 days maximum.
Confirm receipt first
A separate 10 business days to confirm receipt and say how the request will be processed.
Not the same ten
Shopify's 10 days is a window to cancel a request you already submitted, not a deadline to answer.
Who is covered
Does business in California, plus one statutory test: $26,625,000 revenue; 100,000 consumers' data traded; 50% of revenue from data sales.
Grounds to keep data
California lists eight, from completing the transaction to complying with a legal obligation.
If you cannot verify
California lets you deny a deletion request from a requester you cannot verify, and you must tell them so.
As of
Shopify Help Center, shopify.dev and privacy.shopify.com read September 2, 2026; California statute and CPPA regulations the same day.

Does Shopify have a separate CCPA deletion process?

Your admin has one erasure route, and it never asks which statute the request named. Shopify's page on processing customer data requests sends a store owner, or staff with the customer permissions, through More actions > Erase personal data, and makes complying with the privacy laws that apply to your business your own responsibility.

Across the Shopify surfaces we read on September 2, 2026 — that page, the GDPR and US state privacy law hubs, Manage customers, the app compliance docs and the privacy portal — none describes a separate route for a request citing CCPA rather than GDPR. Manage customers does call it a "GDPR erasure request", Shopify's own label for the universal mechanism. What that button actually removes is answered next door.

Among the pages we read, the one that names both laws in a single sentence is Shopify's documentation for public apps:

Data privacy rules and regulations, such as the General Data Protection Regulation (GDPR) and California Privacy Rights Act (CPRA), set requirements for parties that collect, store, or process personal data of individuals. However, Shopify takes a standardized approach and requires public apps to provide the same privacy rights for all personal data, regardless of where an individual is located.
Shopify — Shopify.dev — Privacy law compliance for apps ·

That paragraph binds public apps, not the button in your admin — evidence of how Shopify designs the surface it controls, not an obligation lifted off you.

Does CCPA even apply to your Shopify store?

Sitting outside California does not settle it. Section 1798.140 defines a covered business as an entity that does business in the State of California and handles the personal information of consumers — a term tied to California residents — then attaches thresholds, any one of which is enough:

  • Annual gross revenues above $26,625,000 in the preceding calendar year — the statutory $25,000,000 threshold of Cal. Civ. Code § 1798.140(d)(1)(A) as adjusted by the CPPA effective January 1, 2025.
  • Buying, selling or sharing, alone or in combination, the personal information of 100,000 or more consumers or households annually (§ 1798.140(d)(1)(B)).
  • Deriving 50% or more of annual revenues from selling or sharing consumers' personal information (§ 1798.140(d)(1)(C)).

Whether your figures cross any of those thresholds is a question for your records and your lawyer. Those three are only § 1798.140(d)(1); the definition also covers a commonly branded affiliate that shares consumers' data with such a business, and a qualifying joint venture.

What follows is what California asks of a covered business: a store outside all of that sits outside the deadlines below, while the same erasure route in the admin still answers the customer. Other US states have privacy statutes with triggers of their own; this page has not read them.

How long do you have to answer a CCPA deletion request?

This is where the two regimes genuinely part. California's Civil Code § 1798.130 gives a covered business 45 days from receipt of a verifiable consumer request, and says the steps taken to verify it do not extend that duty; the CPPA regulations in force since January 1, 2026 call the same period 45 calendar days from the day the request is received. GDPR runs on a calendar month instead.

Two clocks, three measurements

What the clock measuresCalifornia (CCPA/CPRA)EU (GDPR)
Confirming receipt10 business days, plus how it will be processedArticle 12(3) sets no separate acknowledgement period
Answering on the substance45 calendar days from receiptOne month from receipt
Extending itOne further 45 days, 90 at most, with notice and a reason in the first 45Two further months where necessary, with notice in the first month

Cal. Civ. Code § 1798.130; Cal. Code Regs. tit. 11, § 7021; Regulation (EU) 2016/679, Article 12(3). Read September 2, 2026.

Neither extension is automatic: California's stops at 90 calendar days in total, and GDPR's is available only where the complexity and number of requests make it necessary. The acknowledgement is a duty of its own: it buys no time on the 45.

Two ten-day counts that are not the same clock
California's ten is 10 business days to confirm you received the customer's request and to say how it will be processed. Shopify's ten is different: once you submit an erasure in your admin, you have 10 days to cancel it — a window to undo your own action, not a deadline to answer anyone.

Can you refuse a CCPA deletion request?

The first fork is not why the customer is asking — it is whether you can tell who is asking. Under Cal. Code Regs. tit. 11, § 7022(a), a business that cannot verify the requester's identity may deny a request to delete, and must inform them that their identity cannot be verified.

Section 7060(a) puts that work before a deletion request arrives: establish, document and follow a reasonable method for verifying that the person asking is the consumer whose information you hold. Section 7060(b) runs the other way, and its list does not include deletion: a business may not require verification for a request to opt-out of sale/sharing, a "request to limit", or a request to opt-out of ADMT.

A verified request can still be refused in part. Civil Code § 1798.105(d) lists eight grounds for keeping information despite a deletion request:

  • Completing the transaction, contract, warranty or product recall
  • Ensuring security and integrity
  • Debugging to repair errors in existing functionality
  • Free speech, another consumer's free speech, or another legal right
  • Complying with the California Electronic Communications Privacy Act
  • Public or peer-reviewed research with informed consent
  • Solely internal uses aligned with the consumer's expectations
  • Complying with a legal obligation

Each ground carries its own statutory conditions — reasonably necessary and proportionate, solely internal, with informed consent. And a refusal is still an answer: it belongs inside the same 45 days.


About This Article

This article was written entirely by AI under human editorial direction. The editor sets the topic and structure, runs multi-stage validation on facts, links, and interactive elements, and verifies the output is useful from a business perspective. All claims are checked against official Shopify sources. Details may change — always confirm critical data at shopify.com.

Editorial Policy

Related questions

Stay updated

Get notified about new articles

Subscribe to receive updates when we publish new Shopify guides and insights.