Skip to content
Rechnungskit

Answer a GDPR request from Shopify

Updated

This task appears when Shopify forwards a data protection request from a customer or from your shop to Rechnungskit. Under Invoices in the "To review" tab it is called "GDPR erasure request", for all three kinds of request, including an access request. On the dashboard it shows as "Review task"; the task reminder by email, which is in German, lists it as "DSGVO-Anfrage".

GDPR erasure request
Anonymize customer data, keep the invoices
  1. TriggerShopify forwards a requestaccess, erasure of a customer or erasure of the shop
  2. You"Anonymize customer data"confirm with "Anonymize", or "Mark as done"
  3. ThenTask closedyou send the reply to the person yourself
Rechnungskit never changes or deletes archived invoices, not even at the customer's request.

What happened

Shopify sends data protection requests that reach your shop to every connected app. Rechnungskit creates a task from them when there is something to do:

  • For a request about a customer, only if Rechnungskit has orders stored for that person. Otherwise the request is acknowledged without a task.
  • For erasure of the whole shop, only while the Shopify connection still exists.
Kind of request Text starts with What you do
Access (Art. 15 GDPR) "Shopify GDPR request: customer data access" Compile the stored data and send it to the person
Erasure of a customer "Shopify GDPR request: customer data deletion" Anonymize the customer data and point out the retention duty for invoices
Erasure of the shop (shop/redact), after the shop removed the app "Shopify GDPR request: shop data deletion" Check retention duties, then mark as done

Why Rechnungskit stops here

Rechnungskit may not delete invoices, not even at the customer's request. They are subject to the statutory eight-year retention period (§ 14b(1) UStG, § 147(1) and (3) AO). The right to erasure does not apply where storage is needed to comply with a legal obligation (Art. 17(3)(b) GDPR).

As the controller, you decide what answer the person is entitled to. So nothing is deleted or anonymized automatically.

How to resolve it

  1. Open the "To review" tab under Invoices. The row names the kind of request, but neither the person nor the affected orders.
  2. For an erasure request, click "Anonymize customer data". The confirmation says how many orders are affected. With "Anonymize", Rechnungskit overwrites the email and the billing and shipping address on these orders. The archived invoices stay unchanged. This cannot be undone. Afterwards, shipping and sending invoices to this person are no longer possible.
  3. For an access request, compile the stored data from the affected orders and invoices.
  4. Reply to the person yourself, for an erasure with a note on the retention duty for invoices. Rechnungskit does not send a reply.
  5. Once everything is done and no anonymization is needed, click "Mark as done".

When the task closes on its own

Anonymizing closes the task. Otherwise you close it yourself with "Mark as done". Both need a role that may match payments; read-only access is not enough.

Related settings

  • Connections → Connect: Shopify connection
  • Data processing agreement (DPA, AVV), which you can conclude digitally in your account

Where to find it in the app

Rechnungskit is not a tax advisory or law firm. This article explains general principles and does not replace advice from a tax advisor (Steuerberater, § 5 StBerG) or a lawyer (§ 3 RDG). Rechnungskit is built for businesses based in Germany and prepares documents, tax rates and bookings automatically. How your specific case is treated remains your decision, ideally together with your tax advisor or a lawyer.

de en