shopifyÂô¼ÒÈκÎʹÓÃGDPRÈÎÃüÊý¾Ý±£»£»£»£»£»£»£»£»¤¹ÙºÍ´¦Öóͷ£Êý¾Ý
Òþ˽ÉùÃ÷
GDPR£¨ÓÈÆäÊÇµÚ 12 ÖÁ 14 Ìõ£©ÒªÇóÄúÏòÄú´¦Öóͷ£ÆäÊý¾ÝµÄСÎÒ˽¼ÒÌá¹©ÌØ¶¨ÐÅÏ¢£¬£¬£¬£¬£¬Í¨³£½ÓÄÉÒþ˽ÉùÃ÷»òÒþ˽Õþ²ßµÄÐÎʽ¡£¡£¡£¡£¡£¡£
Äú¿ÉʹÓà Shopify µÄÒþ˽Õþ²ßÌìÉúÆ÷À´×ÊÖúÄúÖÆ¶©Òþ˽Õþ²ß¡£¡£¡£¡£¡£¡£Äú¿ÉÔÚ¡°½áÕË¡±»òÔÚÏßϵÄÉèÖÃÖÐÕÒµ½Ëü¡£¡£¡£¡£¡£¡£
Çë˼Á¿ÒÔÏÂÎÊÌ⣺
ÄúµÄÍøÕ¾ÉÏÊÇ·ñÓÐÒþ˽Õþ²ß£¬£¬£¬£¬£¬ÆäÖаüÀ¨ÄúÐèҪƾ֤¹æÔòÌṩµÄËùÓÐÐÅÏ¢£¿£¿£¿£¿£¿ËüÊÇ·ñÖÁÉÙ°üÀ¨¿Í»§ÔõÑù¾ÍÒþ˽ÎÊÌâÓëÄúÁªÏµ£¬£¬£¬£¬£¬ÒÔ¼°¿Í»§ÔõÑùÐÐʹÆäȨÁ¦£¨ÀýÈçɾ³ý»ò¸üÕý£¨Ð޸Ļò¸üÕý£©ÆäÊý¾ÝµÄȨÁ¦ÒÔ¼°»á¼û¸ÃÊý¾ÝµÄȨÁ¦£©µÄÏà¹ØÐÅÏ¢£¿£¿£¿£¿£¿
ÄúµÄÒþ˽Õþ²ßÊÇ·ñ°üÀ¨ Shopify ÔõÑù½«Äú¿Í»§µÄСÎÒ˽¼ÒÊý¾ÝÓÃÓÚ×Ô¶¯µÄΣº¦ºÍÚ²ÆÆÀ·Ö£¿£¿£¿£¿£¿Äú£¨»òÄúµÄЧÀÍÌṩÉÌ£©½«¿Í»§ÐÅÏ¢ÓÃÓÚ×Ô¶¯¾öÒéʱ£¬£¬£¬£¬£¬GDPR ÒªÇóÄúÅû¶ÕâЩÐÅÏ¢¡£¡£¡£¡£¡£¡£Shopify ʹÓÃÄú¿Í»§µÄСÎÒ˽¼ÒÐÅÏ¢£¬£¬£¬£¬£¬Í¨¹ý×Ô¶¯¾öÒé×èֹijЩ¿´ËÆÓÐÚ²ÆÐÔ×ÓµÄÉúÒâ¡£¡£¡£¡£¡£¡£Shopify µÄÒþ˽Õþ²ßÌìÉúÆ÷°üÀ¨´ËÐÅÏ¢¡£¡£¡£¡£¡£¡£ÓйشËϵͳµÄÏêϸÐÅÏ¢£¬£¬£¬£¬£¬Çë²ÎÔÄ×Ô¶¯¾öÒé¡£¡£¡£¡£¡£¡£
ÈÎÃüÊý¾Ý±£»£»£»£»£»£»£»£»¤¹Ù
Êý¾Ý±£»£»£»£»£»£»£»£»¤¹Ù (DPO) ¼àÊÓ×éÖ¯ÍøÂçºÍ´¦Öóͷ£Ð¡ÎÒ˽¼ÒÊý¾ÝµÄ·½·¨¡£¡£¡£¡£¡£¡£ÈôÊǹ«Ë¾µÄ½¹µãÔ˶¯Éæ¼°´ó¹æÄ£µÄÔÚÏ߸ú×Ù£¬£¬£¬£¬£¬Ôò GDPR ÒªÇóÄúÈÎÃü DPO ²¢ÔÚÒþ˽Õþ²ßÖÐÌṩ DPO µÄÁªÏµÐÅÏ¢¡£¡£¡£¡£¡£¡£
GDPR °üÀ¨ DPO ÐèÒªÍê³ÉµÄÌØ¶¨Ê¹Ãü£¬£¬£¬£¬£¬ÀýÈ磬£¬£¬£¬£¬ÔÚÄúµÄ×éÖ¯¸ü¸ÄÆäÍøÂçºÍ´¦Öóͷ£Ð¡ÎÒ˽¼ÒÊý¾ÝµÄ·½·¨Ê±£¬£¬£¬£¬£¬¾ÙÐÐÊý¾Ý±£»£»£»£»£»£»£»£»¤Ó°ÏìÆÀ¹À¡£¡£¡£¡£¡£¡£DPO ¿ÉÒÔÓÉÔÚ GDPR ºÍÊý¾Ý±£»£»£»£»£»£»£»£»¤ÒªÇó·½Ãæ¾ßÓÐרҵ֪ʶµÄÄÚ²¿Ö°Ô±µ£µ±£¬£¬£¬£¬£¬µ«ÄúÒ²¿É˼Á¿ÓëÕÕÁÏ»ò¹«Ë¾ÏàÖú£¬£¬£¬£¬£¬ÓÉËûÃǵ£µ±Íⲿ DPO¡£¡£¡£¡£¡£¡£
˼Á¿ÒÔÏÂÎÊÌ⣺
Óм¸¶àÈËÊܵ½ÄúµêÃæ¸ú×ÙÊÖÒÕµÄÓ°Ï죿£¿£¿£¿£¿ÕâЩ¿ÉÄܰüÀ¨ÐÐΪ¹ã¸æÓ¦Ó㬣¬£¬£¬£¬ÉõÖÁÖØ¶¨ÏòÓ¦Óᣡ£¡£¡£¡£¡£ÊÜÓ°ÏìµÄÈËÊýÊÇ·ñΪ¡°´ó¹æÄ£¡±ÊÇÒ»ÏîÖ´·¨¾öÒ飬£¬£¬£¬£¬ÄúӦƾ֤ÄúµÄÏêϸÇéÐÎ×Éѯ״ʦ¡£¡£¡£¡£¡£¡£
ÄúÓ¦×Ô¶¯ÈÎÃü DPO Â𣿣¿£¿£¿£¿×ÝȻִ·¨Éϲ»ÒªÇóÄúÖ¸¶¨ DPO£¬£¬£¬£¬£¬ÈôÊÇÄúÔÚÅ·ÖÞÕ¼ÓоÙ×ãÇáÖØµÄְ룬£¬£¬£¬£¬Äú¿ÉÄÜÏ£Íû×Ô¶¯ÕâÑù×öÒÔÈ·±£Äú³ä·Ö±£»£»£»£»£»£»£»£»¤¿Í»§µÄÊý¾Ý¡£¡£¡£¡£¡£¡£
Êý¾Ý´¦Öóͷ£ÐÒé
×÷Ϊ GDPR ÊÊÓõÄÊý¾Ý¿ØÖÆ·½£¬£¬£¬£¬£¬µÚ 28 ÌõÒªÇóÄúÔÚͨ¹ýÊý¾Ý´¦Öóͷ£·½£¨Èç Shopify£©´¦Öóͷ£¿Í»§Êý¾Ýʱ£¬£¬£¬£¬£¬ÄúÓ¦¶ÔÆä¿ÉÄÜʹÓúʹ¦Öóͷ£¸ÃÊý¾ÝµÄ·½·¨»®¶¨ÑÏ¿áµÄÐÒéÒªÇ󡣡£¡£¡£¡£¡£Õâͨ³£Í¨¹ýÊý¾Ý´¦Öóͷ£¸½Â¼»ò (DPA) Íê³É¡£¡£¡£¡£¡£¡£
Shopify ÒÑ×Ô¶¯½«Êý¾Ý´¦Öóͷ£ÐÒé (https://www.shopify.com/legal/dpa) ÄÉÈëЧÀÍÌõ¿î£¬£¬£¬£¬£¬´Ó¶øÖª×ãµÚ 28 ÌõÒªÇ󡣡£¡£¡£¡£¡£
¹ØÓÚ Shopify Plus É̼ң¬£¬£¬£¬£¬ËûÃÇÓë Shopify Ö®¼äµÄ¹ØÏµ½«ÓÉËûÃǵÄÐÉÌÌõÔ¼¾öÒé¡£¡£¡£¡£¡£¡£Shopify Plus É̼ҿÉÇ©ÊðÊý¾Ý´¦Öóͷ£¸½Â¼ÒÔÖª×ãËûÃǵÄÐèÇ󡣡£¡£¡£¡£¡£Î´Ç©ÊðÊý¾Ý´¦Öóͷ£¸½Â¼µÄ Shopify Plus É̼ҽ«ÊÜ Shopify ÔÚÏßÊý¾Ý´¦Öóͷ£¸½Â¼µÄî¿Ïµ¡£¡£¡£¡£¡£¡£
˼Á¿ÒÔÏÂÎÊÌ⣺
ÄúÔÚ Shopify ÍⲿʹÓÃµÄÆäËûÊý¾Ý´¦Öóͷ£ÕßÊÇ·ñ×ñÕÕÐÒéÔÊÐí±£»£»£»£»£»£»£»£»¤Äú¿Í»§µÄÊý¾Ý£¿£¿£¿£¿£¿Ðí¶àµÚÈý·½Ó¦Óá¢ÇþµÀ¡¢Ö§¸¶Íø¹Ø»òÆäËûÊý¾Ý´¦Öóͷ£ÕßÒ²»á×Ô¶¯½«Êý¾Ý´¦Öóͷ£ÐÒéÄÉÈëËûÃǵÄÌõ¿îÖС£¡£¡£¡£¡£¡£ÄúÊÇ·ñ¾ÍÕâЩÊÂÒË×Éѯ¹ýÕâЩµÚÈý·½£¿£¿£¿£¿£¿
ÄúÊǾßÓÐÐÉÌÌõÔ¼µÄ Shopify Plus É̼ÒÂ𣿣¿£¿£¿£¿ÈôÊÇÄúÏëÇ©ÊðÊý¾Ý´¦Öóͷ£¸½Â¼£¬£¬£¬£¬£¬ÇëÁªÏµ Shopify Plus ¿Í·þ¡£¡£¡£¡£¡£¡£ËûÃÇ¿ÉÒÔΪÄúÌṩ Shopify µÄÄ£°å DPA ÒÔ¾ÙÐÐÇ©Ê𡣡£¡£¡£¡£¡£
ShopifyÉÌ»§¹ÙÍøÔÎÄÏêÇ飺
Privacy notice
The GDPR (and particularly Articles 12 to 14) requires that you provide specific information to individuals whose data you are processing, generally in the form of a privacy notice or privacy policy.
You can use Shopify's privacy policy generator to get you started. You can find it in your settings under Checkout or online.
Think about the following question:
Do you have a privacy policy on your site that includes all of the information that you are required to provide under the regulation? At minimum, does it include how customers can get in contact with you about privacy questions and how customers can exercise their rights, for example the rights to erasure (deletion) or rectification (modification or correction) of their data and the right to access it?
Does your privacy policy include how Shopify may use your customers' personal data for automated risk and fraud scoring? The GDPR requires you to disclose when you (or your service providers) use their information in connection with automated decision-making. Shopify uses your customers¡¯ personal information to block certain transactions that appear to be fraudulent through automated decision-making. Shopify's Privacy Policy Generator includes this information. For more information about this system, see Automated decision-making.
Appointing a Data Protection Officer
A Data Protection Officer (DPO) oversees how your organization collects and processes personal data. If your business¡¯s core activities include large scale online tracking, the GDPR requires that you appoint a DPO and provide contact information for the DPO in your Privacy Policy.
The GDPR includes specific tasks that a DPO needs to do, such as conducting data protection impact assessments when your organization changes how it collects and processes personal data. The DPO can be an internal person who has expertise in the GDPR and data protection requirements, but you can also consider working with an consultant or firm to serve as an external DPO.
Think about the following questions:
How many people are affected by tracking technologies on your storefront? These can include behavioral advertising apps, or even retargeting apps. Whether or not the number of people affected is ¡°large scale¡± is a legal decision, and you should consult with a lawyer depending on your circumstances.
Should you voluntarily appoint a DPO? Even if you are not legally required to appoint a DPO, if your presence in Europe is large enough, you may wish to do so voluntarily to make sure that you adequately protect your customers¡¯ data.
Data processing agreements
As a data controller under the GDPR, Article 28 requires that when you engage a data processor (like Shopify) to process your customers¡¯ data, you impose strict contractual requirements on how they may use and process that data. This is typically done through a Data Processing Addendum, or DPA.
Shopify has automatically incorporated a Data Processing Agreement (https://www.shopify.com/legal/dpa) into its terms of service, which is designed to address the requirements of Article 28.
For Shopify Plus merchants, their negotiated contracts will govern their relationship with Shopify. Plus Merchants can sign a Data Processing Addendum to address their needs. Shopify Plus merchants who do not sign a Data Processing Addendum will be governed by Shopify¡¯s online Data Processing Addendum.
Think about the following questions:
Are other data processors that you work with outside of Shopify contractually committed to protecting your customers¡¯ data? Many third-party apps, channels, payment gateways, or other data processors will also automatically incorporate a Data Processing Agreement into their terms. Have you consulted with each of these third-parties?
Are you a Shopify Plus merchant with a negotiated contract? If you want to sign a Data Processing Addendum, then reach out to Shopify Plus Support. They can provide you with Shopify's template DPA to sign.
ÎÄÕÂÄÚÈÝȪԴ£ºShopifyÉÌ»§¹Ù·½ÍøÕ¾
ÉÏһƪ£ºShopify¿ªµêÁ÷³Ì¼°ÕË»§×¢²áȫָÄÏ
ÏÂһƪ£ºshopifyÒþ˽±£»£»£»£»£»£»£»£»¤¡ª¡ªGDPRÉúЧʱ¼äÒÔ¼°Êý¾Ý
- 1ÏàʶÍâÑóÍË»õ³ÌÐò£¬£¬£¬£¬£¬ÍË»õ²»ÔÙÊÇÄÑÌâ
- 2ÑÇÂíѷƽ̨ÔËÓª±ØÄîÊé¼®
- 3wishµêËÁÉóºËÇ·ºà¹ýµÄÔµ¹ÊÔÓɼ°½â¾öÕ½ÂÔ
- 4ËÙÂôͨÐÂÊÖ¿ªµêÐèÒªÉÏ´«¼¸¶à²úÆ·
- 5Coupangƽ̨ÉϺ«¹ú»§ÍâѡƷƫÏòµÄ½¨Òé
- 6Lazadaƽ̨ÔõÑù±£»£»£»£»£»£»£»£»¤Âô¼ÒºÍÂò¼ÒµÄÉúÒâÇå¾²£¿£¿£¿£¿£¿
- 7¹ú¼ÊÎïÁ÷µÄÊÕÖ§¿Ú¹ØÎñ
- 8ÍâóÂô¼Ò±ØÖªµÄ¹È¸èËÑË÷ÒýÇæÊ¹Óü¼ÇÉ
- 9¿ç¾³µçÉÌÖ±·¢Ä£Ê½£ºÊµÏÖÓëÖ÷¹ËÐèÇóÎÞ·ì¶Ô½Ó
- 10shopifyÖÎÀíºǫ́²å¼þÓÐÄÄЩ£¿£¿£¿£¿£¿