PrestaShop
Partially CompliantFrench open source ecommerce platform, self-hosted, whose own hosted services run on Google Cloud in the United States.
Subject to the US CLOUD Act: a US provider in this tool's processing chain can be compelled to disclose data it holds, including data stored in the EU. The vendor itself is European-owned.
Open Source
GDPR Compliance Data
Not independently verified| GDPR Status | Partially Compliant |
| HQ Country | France |
| Ownership | European-owned |
| Foreign Disclosure Exposure | US CLOUD Act / FISA 702 |
| Data Hosting Location | United StatesSub-processor annex: "GOOGLE CLOUD PLATFORM / Hosting of data related to the provision of our services / United States". Source: prestashop.com/en/privacy-policy (read 2026-08-24). This covers PrestaShop's own services. A self-hosted shop runs wherever the merchant installs it. |
| EU Servers Available | |
| Data Processing Agreement | Not verified |
| Sub-processor List | Not verified |
| Schrems II Risk | High Risk |
| SCCs in Place | |
| Last Verified | 24 August 2026 |
How we reached this
PrestaShop SA is French. The compliance fields here describe PrestaShop's own services rather than a merchant's shop, because a self-hosted PrestaShop installation never sends order or customer data to the vendor. The published sub-processor annex names GOOGLE CLOUD PLATFORM with headquarters in the United States as the host for data related to the provision of PrestaShop's services, alongside Atlassian and Zendesk Inc., both US. Hence dataHostingLocation US and exposure US_CLOUD_ACT for the vendor-side services, with Schrems II risk HIGH. euServerAvailable is true because the software itself installs on any European host, which is the recommended deployment. No standalone DPA was located at a public URL. Ownership above the French entity was not verified in this review.
About PrestaShop
The Small Merchant's Platform
PrestaShop has been the default self-hosted storefront for small European retailers for well over a decade, particularly in France, Spain and Italy. It installs on ordinary PHP hosting, has an enormous module marketplace and does not require a developer to get a shop live.
That accessibility is the whole proposition. It is not the platform to build a composable commerce architecture on, and it does not pretend to be.
Two Different Data Questions
This listing needs a distinction most directories skip.
Your shop runs on your hosting. Order and customer data lives wherever you install PrestaShop, which for a European merchant on a European host means the data never touches PrestaShop the company at all. That is the strongest possible position and it is the normal deployment.
PrestaShop's own services, the account, the marketplace, the hosted add-ons, are a different matter. Its privacy policy publishes a sub-processor annex, and the first entry reads: "GOOGLE CLOUD PLATFORM, Hosting of data related to the provision of our services, United States". Atlassian and Zendesk, both US, follow it.
So the compliance fields on this page describe PrestaShop's own services, which is the part the vendor controls. If you self-host and never use their hosted add-ons, the exposure recorded here does not reach your customer data.
Practical Advice
Install on a European host. Scaleway, Hetzner, IONOS and OVH all run PrestaShop without complaint, and doing so puts your order data outside any American company's reach. Then read the module list, because third-party PrestaShop modules are where merchant data quietly leaves the EU.
More in ecommerce platforms.
Key Features
Pros & Cons
Categories
PrestaShop GDPR & data protection: common questions
Is PrestaShop GDPR compliant?
Partly. PrestaShop meets some of the requirements, with caveats worth reading before you commit. PrestaShop is a European company headquartered in France, data is hosted in the United States.
Where does PrestaShop store data?
PrestaShop states: "Sub-processor annex: "GOOGLE CLOUD PLATFORM / Hosting of data related to the provision of our services / United States". Source: prestashop.com/en/privacy-policy (read 2026-08-24). This covers PrestaShop's own services. A self-hosted shop runs wherever the merchant installs it.". Data is hosted in the United States. An EU region is available.
Does PrestaShop offer a Data Processing Agreement (DPA)?
We could not locate a published DPA for PrestaShop. That does not mean one is unavailable. Many vendors provide it on request or inside the account area rather than publishing it. Ask before you sign.
What a DPA has to cover →Is PrestaShop a European company?
Yes. PrestaShop is headquartered in France and, as far as we can establish, European-owned.
Is PrestaShop subject to the US CLOUD Act?
Indirectly. PrestaShop itself is European-owned and headquartered in France, so the company is not subject to US jurisdiction. The exposure runs through a US provider in its processing chain, a host, CDN or other sub-processor, which can be compelled to disclose data it holds even when that data sits on EU servers. That is a narrower exposure than a US-owned vendor, and the compliance notes above say which provider it is.
Schrems II compliance checklist →Related Tools

Shopware
German commerce platform available self-hosted or as managed cloud, with an open source community edition.

Saleor
Polish open source headless commerce API with a managed cloud, a published DPA and EEA data storage stated in its terms.

Sylius
Polish open source ecommerce framework built on Symfony, self-hosted, aimed at custom B2B and B2C builds.
Spotted something wrong?
Martech moves fast. Vendors change hosting regions, get acquired, publish a new DPA or rewrite their pricing, and they rarely announce it. We check what we publish and date every compliance review, but some of what you see here will be out of date before we catch it.
If you work at PrestaShop and something on this page is wrong, tell us and we will fix it. Readers, same invitation. Pointing us at the page that proves it gets it changed fastest.