{"id":28354,"date":"2025-11-10T10:00:00","date_gmt":"2025-11-10T10:00:00","guid":{"rendered":"https:\/\/spreecommerce.org\/gdpr-schrems-ii-ecommerce-compliance\/"},"modified":"2026-03-27T17:36:27","modified_gmt":"2026-03-27T17:36:27","slug":"gdpr-schrems-ii-ecommerce-compliance","status":"publish","type":"post","link":"https:\/\/spreecommerce.org\/gdpr-schrems-ii-ecommerce-compliance\/","title":{"rendered":"GDPR, Schrems II &#038; the CLOUD Act: Why EU Businesses Are Leaving US-Hosted Commerce"},"content":{"rendered":"<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n<section class=\"highlight-box-wrap alignstandard text-align-left\" style=\" \">\n<div class=\"highlight-box highlight-box-green\">\n<div class=\"icon\">\n <img decoding=\"async\" loading=\"lazy\" width=\"24\" height=\"24\" src=\"https:\/\/spreecommerce.org\/wp-content\/themes\/spree\/images\/bulb.svg\" alt=\"\">\n <\/div>\n<p><!-- \/.icon --><\/p>\n<div class=\"desc\">\n<h3>Key Takeaways<\/h3>\n<p><strong>Last verified:<\/strong> March 2026<\/p>\n<p><strong>Regulation:<\/strong> GDPR requires lawful processing, data subject rights, breach notification within 72 hours, and privacy by design for any platform handling EU customer data. Schrems II adds mandatory supplementary measures for US data transfers.<\/p>\n<p><strong>The SaaS problem:<\/strong> Shopify Plus, BigCommerce, and Salesforce Commerce Cloud operate under US jurisdiction. The CLOUD Act lets US law enforcement compel them to hand over EU customer data, regardless of where it is stored.<\/p>\n<p><strong>The solution:<\/strong> Self-hosted, open source platforms deployed on EU infrastructure eliminate CLOUD Act exposure entirely. You control data location, encryption keys, and legal jurisdiction.<\/p>\n<p><strong>Penalties:<\/strong> GDPR fines reach 4% of global annual revenue or 20 million euros, whichever is higher.<\/p>\n<\/p><\/div>\n<p><!-- \/.desc -->\n <\/div>\n<\/section>\n<h2 class=\"wp-block-heading\">What Does GDPR Mean for eCommerce in 2026?<\/h2>\n<p><strong>If your eCommerce platform is US-hosted, your EU customer data is one subpoena away from US law enforcement.<\/strong> That&#8217;s not a hypothetical risk. It&#8217;s the legal reality of the CLOUD Act, and it&#8217;s the reason GDPR compliance now starts with hosting jurisdiction.<\/p>\n<p>The CJEU upheld the EU-US Data Privacy Framework in September 2025, signaling temporary relief for transatlantic data transfers. But the structural tension hasn&#8217;t gone away: the US CLOUD Act (18 U.S.C. SS 2713) lets US law enforcement compel US-headquartered companies to hand over customer data stored anywhere in the world. Shopify, BigCommerce, and Salesforce Commerce Cloud all face this legal duty. So does any US-investor-backed SaaS platform. See the European Commission&#8217;s <a href=\"https:\/\/commission.europa.eu\/law\/law-topic\/data-protection_en\">GDPR overview<\/a> for the full regulatory framework.<\/p>\n<p><strong>The enforcement environment has real teeth.<\/strong> In 2025, the Irish Data Protection Commission fined TikTok 530 million euros for failing to protect EEA user data (Irish DPC, September 2025). For a mid-market eCommerce operator generating 10 million euros in revenue, a single GDPR violation could mean a 400,000 euro fine (GDPR Article 83 sets the ceiling at 4% of global annual revenue or 20 million euros).<\/p>\n<p>The question EU businesses are asking has shifted. It&#8217;s no longer &#8220;Is our SaaS vendor GDPR compliant?&#8221; It&#8217;s &#8220;Do we own our infrastructure and eliminate foreign legal exposure entirely?&#8221;<\/p>\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n<h2 class=\"wp-block-heading\">What Does GDPR Require from Your eCommerce Platform?<\/h2>\n<p><strong>Eight obligations hit your eCommerce platform the moment it processes a single EU customer order.<\/strong> Lawful processing, data subject rights, breach notification, processor oversight, privacy by design, data retention controls, transfer safeguards, and impact assessments. Miss any one and you&#8217;re exposed.<\/p>\n<p>As Article 44 of the GDPR states: &#8220;Any transfer of personal data which are undergoing processing or are intended for processing after transfer to a third country&#8230; shall take place only if the conditions laid down in this Chapter are complied with&#8221; (Regulation (EU) 2016\/679, Chapter V).<\/p>\n<p><strong>That makes hosting jurisdiction a compliance requirement, not an operational preference.<\/strong><\/p>\n<figure class=\"wp-block-table\" style=\"margin:24px auto 0; overflow-x:auto\">\n<table style=\"border-collapse:collapse; width:100%; table-layout:fixed\">\n<thead>\n<tr>\n<th style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; font-weight:600; background-color:#f3f3f3; vertical-align:top; word-wrap:break-word\">Requirement<\/th>\n<th style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; font-weight:600; background-color:#f3f3f3; vertical-align:top; word-wrap:break-word\">What It Means for Commerce<\/th>\n<th style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; font-weight:600; background-color:#f3f3f3; vertical-align:top; word-wrap:break-word\">Technical Implementation<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\"><strong>Lawful Basis (Articles 5-6)<\/strong><\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">You must have a legal reason to collect and process customer data<\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Implement explicit consent mechanisms; document lawful basis for each data category<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\"><strong>Data Subject Rights (Articles 15-22)<\/strong><\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Customers must access, correct, erase, restrict, port, and object to processing of their data<\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Build data export, deletion, and access request functionality; respond within 30 days<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\"><strong>Breach Notification (Articles 33-34)<\/strong><\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Notify your Data Protection Authority within 72 hours of discovering a breach<\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Implement breach detection, incident response plans, and automated alerting<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\"><strong>Processor Obligations (Articles 28-32)<\/strong><\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Every third-party vendor handling customer data must sign a Data Processing Agreement<\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Maintain processor inventory; audit sub-processor compliance; specify data location controls<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\"><strong>Privacy by Design (Article 25)<\/strong><\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Data protection must be built into platform architecture from day one<\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Conduct threat modeling; encrypt sensitive data; implement least-privilege access<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\"><strong>Data Retention (Article 5c)<\/strong><\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Keep customer data only as long as necessary for the stated purpose<\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Document retention schedules; automate deletion of expired data<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\"><strong>Transfer Mechanisms (Chapters 4-5)<\/strong><\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Transfers outside EU\/EEA require SCCs, BCRs, or adequacy decisions; Schrems II mandates supplementary measures for US transfers<\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Vet all third-party vendors; implement encryption with EU-held keys; avoid US-jurisdiction processors<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\"><strong>Data Protection Impact Assessment (Article 35)<\/strong><\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">High-risk processing requires risk assessment before launch<\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Conduct DPIA; document risks and mitigation; maintain records for 3+ years<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n<h2 class=\"wp-block-heading\">Industries Affected by GDPR and Data Sovereignty Requirements<\/h2>\n<p><strong>GDPR applies to every industry, but Schrems II and the CLOUD Act hit hardest where data sensitivity and regulatory overlap compound.<\/strong> These are the sectors where US-hosted SaaS creates the most exposure:<\/p>\n<ul class=\"wp-block-list\">\n<li><strong>Financial services and banking:<\/strong> PSD2, MiFID II, and GDPR together require that transaction data stays within EU jurisdiction with full audit trails on every access<\/li>\n<li><strong>Healthcare and pharma:<\/strong> GDPR plus national health data laws, with medical device sellers facing EU MDR obligations layered on top. See the <a href=\"\/healthtech-ecommerce\/\">HealthTech eCommerce compliance<\/a> guide.<\/li>\n<li><strong>Public sector and municipal procurement:<\/strong> National data sovereignty mandates often require EU-only infrastructure by law<\/li>\n<li><strong>EU automotive:<\/strong> Connected vehicle data falls under GDPR, the Cyber Resilience Act, and NIS2 simultaneously<\/li>\n<li><strong>Agricultural technology:<\/strong> Farm data and supply chain records face increasing pressure to avoid US infrastructure entirely<\/li>\n<li><strong>Professional services (legal, accounting, consulting):<\/strong> Client-privileged data where a CLOUD Act subpoena would destroy client trust<\/li>\n<li><strong>Luxury goods:<\/strong> Exclusive customer lists where data breaches are existential brand threats<\/li>\n<li><strong>Education platforms:<\/strong> GDPR plus FERPA-equivalent national student data laws<\/li>\n<\/ul>\n<p>The pattern is consistent. Any industry where data sensitivity, regulatory overlap, or client trust matters is moving away from US-hosted SaaS.<\/p>\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n<h2 class=\"wp-block-heading\">Why Do SaaS Platforms Fail GDPR and Schrems II Compliance?<\/h2>\n<p><strong>The problem isn&#8217;t that SaaS vendors haven&#8217;t gotten around to GDPR. The problem is architectural.<\/strong> Three structural limitations make US-hosted SaaS incompatible with full Schrems II compliance, and no amount of DPA negotiation fixes them.<\/p>\n<p><strong>The jurisdiction problem.<\/strong> Every US-headquartered SaaS platform operates under CLOUD Act jurisdiction. The law compels US companies to disclose customer data to US law enforcement regardless of where it&#8217;s stored. Your DPA with Shopify or BigCommerce clarifies liability allocation. It does not block a CLOUD Act subpoena.<\/p>\n<p><strong>The shared tenancy problem.<\/strong> SaaS platforms run on shared infrastructure. For GDPR requirements like data isolation, controlled access logging, and jurisdiction-specific hosting, shared tenancy is a structural barrier. You rely on your vendor&#8217;s security controls, not your own.<\/p>\n<p><strong>The sub-processor chain problem.<\/strong> Cross-border data transfer complaints to EU regulators increased 38% year-over-year, with SaaS platform sub-processor chains cited as a recurring source of compliance gaps (Irish DPC Annual Report 2024). Every SaaS dependency introduces vendors you haven&#8217;t vetted, operating under jurisdictions you don&#8217;t control.<\/p>\n<p><strong>Your DPA protects you from your vendor. It does not protect you from their government.<\/strong><\/p>\n<figure class=\"wp-block-table\" style=\"margin:24px auto 0; overflow-x:auto\">\n<table style=\"border-collapse:collapse; width:100%; table-layout:fixed\">\n<thead>\n<tr>\n<th style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; font-weight:600; background-color:#f3f3f3; vertical-align:top; word-wrap:break-word\">Data Sovereignty Capability<\/th>\n<th style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; font-weight:600; background-color:#f3f3f3; vertical-align:top; word-wrap:break-word\">Shopify Plus<\/th>\n<th style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; font-weight:600; background-color:#f3f3f3; vertical-align:top; word-wrap:break-word\">BigCommerce<\/th>\n<th style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; font-weight:600; background-color:#f3f3f3; vertical-align:top; word-wrap:break-word\">Salesforce Commerce Cloud<\/th>\n<th style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; font-weight:600; background-color:#f3f3f3; vertical-align:top; word-wrap:break-word\">commercetools<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\"><strong>EU Data Residency<\/strong><\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Ireland data center, but US parent access<\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Limited EU availability; US parent access<\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Frankfurt region available; US parent access<\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">EU-hosted regions; but US-investor-backed<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\"><strong>CLOUD Act Exposure<\/strong><\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Subject to US subpoena via parent company<\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Direct US company; subject to US subpoena<\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Direct US company; subject to US subpoena<\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">US-investor-backed; potential US access<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\"><strong>Source Code Audit<\/strong><\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Proprietary, held in US<\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Proprietary, held in US<\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Proprietary, held in US<\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Proprietary, held by US-backed parent<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\"><strong>Self-Hosting Option<\/strong><\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">SaaS only<\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">SaaS only<\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">SaaS only<\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">SaaS only<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\"><strong>Encryption Key Control<\/strong><\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Vendor-managed<\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Vendor-managed<\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Vendor-managed<\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Vendor-managed<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\"><strong>Transfer Impact Control<\/strong><\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">No user control over supplementary measures<\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Limited DPA negotiation<\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">DPA available; US parent retains access<\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">DPA available; US investor network limits guarantees<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p><strong>EU data residency does not equal EU data sovereignty.<\/strong> These vendors offer EU data centers, but as long as the parent company falls under US jurisdiction, the CLOUD Act creates a legal pathway to your customer data that no DPA can block.<\/p>\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n<h2 class=\"wp-block-heading\">How Self-Hosted Open Source Commerce Meets GDPR Requirements<\/h2>\n<p><strong>Here&#8217;s what changes when you own your infrastructure: every Schrems II supplementary measure becomes a deployment decision instead of a vendor negotiation.<\/strong> Data location, encryption keys, access policies, legal jurisdiction \u2014 you control all of it. No third-party dependency gaps.<\/p>\n<figure class=\"wp-block-table\" style=\"margin:24px auto 0; overflow-x:auto\">\n<table style=\"border-collapse:collapse; width:100%; table-layout:fixed\">\n<thead>\n<tr>\n<th style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; font-weight:600; background-color:#f3f3f3; vertical-align:top; word-wrap:break-word\">GDPR Requirement<\/th>\n<th style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; font-weight:600; background-color:#f3f3f3; vertical-align:top; word-wrap:break-word\">How Self-Hosted Commerce Meets It<\/th>\n<th style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; font-weight:600; background-color:#f3f3f3; vertical-align:top; word-wrap:break-word\">Spree Enterprise Feature<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\"><strong>Data Sovereignty<\/strong><\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Deploy on your own EU infrastructure; control physical location and access logs<\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Run on AWS Ireland, GCP Frankfurt, Azure Germany, or on-premises servers<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\"><strong>CLOUD Act Mitigation<\/strong><\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">No US parent company holds your data or responds to US subpoenas<\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Spree is open source under BSD 3-Clause license; you own the instance entirely<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\"><strong>Encryption Control<\/strong><\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Manage your own encryption keys in EU jurisdiction<\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">AES-256 at rest, TLS 1.3+ in transit; keys held in your infrastructure<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\"><strong>Processor Transparency<\/strong><\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Choose only EU-based vendors; maintain your own processor inventory<\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Integrate any payment processor, CDN, or analytics tool you select<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\"><strong>Data Subject Rights<\/strong><\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Build export, deletion, and access request workflows into your platform<\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Full API access to all customer data; automated retention and deletion<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\"><strong>Breach Response<\/strong><\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Control your own detection, logging, and notification timelines<\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Admin action logging and API audit trails on your infrastructure<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\"><strong>Privacy by Design<\/strong><\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Architect data protection into your deployment from day one<\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Separate customer data, payment info, and admin logs at the application level<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\"><strong>Audit Readiness<\/strong><\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Maintain tamper-proof audit trails on infrastructure you control<\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Integration with ELK Stack, Splunk, or any centralized logging platform<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>For organizations that must achieve GDPR and Schrems II compliance while running commerce at scale, a self-hosted open source platform with built-in data sovereignty controls provides the strongest architectural fit. Spree Enterprise delivers these capabilities natively: deploy on any cloud or on-premises, audit every line of code under the BSD 3-Clause license, and integrate any payment processor without vendor lock-in.<\/p>\n<p><strong>When you self-host, you become the Data Controller with full authority over processing conditions.<\/strong> Your infrastructure, your encryption keys, your audit logs, your legal jurisdiction. No US parent company sits between you and your compliance posture.<\/p>\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n<h2 class=\"wp-block-heading\">Architecture and Deployment for GDPR-Compliant Commerce<\/h2>\n<p><strong>A production GDPR architecture starts with one question: where does your EU customer data physically live?<\/strong> The answer determines your hosting, your encryption strategy, and your legal exposure.<\/p>\n<p><strong>Hosting and data residency.<\/strong> Deploy on EU-sanctioned cloud providers with explicit data residency commitments:<\/p>\n<ul class=\"wp-block-list\">\n<li><strong>AWS:<\/strong> Ireland (eu-west-1) or Frankfurt (eu-central-1)<\/li>\n<li><strong>GCP:<\/strong> Frankfurt with Assured Workloads<\/li>\n<li><strong>Azure:<\/strong> Germany or Netherlands<\/li>\n<li><strong>On-premises:<\/strong> Your own data center for maximum sovereignty<\/li>\n<\/ul>\n<p>For strictest enforcement, prefer German-based infrastructure where local data protection authorities are most active.<\/p>\n<p><strong>Encryption and key management.<\/strong> AES-256 at rest, TLS 1.3+ in transit. Encryption keys must stay in EU jurisdiction using AWS KMS EU, Azure Key Vault EU, or a local Hardware Security Module. No cloud provider should hold your master keys. Segment data by sensitivity:<\/p>\n<ul class=\"wp-block-list\">\n<li><strong>Payment card data (PCI DSS scope):<\/strong> Separate encryption and restricted access<\/li>\n<li><strong>Customer PII:<\/strong> Role-based access controls with full audit logging<\/li>\n<li><strong>Product catalog and analytics:<\/strong> Standard controls<\/li>\n<\/ul>\n<p><strong>Network isolation.<\/strong> VPC segmentation keeps customer data servers in a private subnet, payment processing in a PCI-compliant zone, and analytics in a separate non-production network. All admin access goes through VPN with multi-factor authentication. Deploy intrusion detection and WAF rules against OWASP common vulnerabilities.<\/p>\n<p><strong>Breach response.<\/strong> Document your 72-hour notification procedure with designated DPA contacts and prepared communication templates before you need them.<\/p>\n<p>Spree&#8217;s provider-agnostic architecture means you choose any cloud, any region, any payment processor. Switch providers without touching your commerce application.<\/p>\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n<h2 class=\"wp-block-heading\">GDPR Compliance by Industry<\/h2>\n<p>For industry-specific compliance guidance on GDPR and data sovereignty, see:<\/p>\n<figure class=\"wp-block-table\" style=\"margin:24px auto 0; overflow-x:auto\">\n<table style=\"border-collapse:collapse; width:100%; table-layout:fixed\">\n<thead>\n<tr>\n<th style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; font-weight:600; background-color:#f3f3f3; vertical-align:top; word-wrap:break-word\">Industry<\/th>\n<th style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; font-weight:600; background-color:#f3f3f3; vertical-align:top; word-wrap:break-word\">Region<\/th>\n<th style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; font-weight:600; background-color:#f3f3f3; vertical-align:top; word-wrap:break-word\">Key Commerce Challenge<\/th>\n<th style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; font-weight:600; background-color:#f3f3f3; vertical-align:top; word-wrap:break-word\">Deep Dive<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">EU Automotive Manufacturing<\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">EU<\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Connected vehicle data under GDPR + Cyber Resilience Act + NIS2<\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">EU Automotive eCommerce Compliance (coming soon)<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">EU AgriTech<\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">EU<\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Farm data and supply chain records under GDPR + CAP digital rules<\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">EU AgriTech eCommerce Compliance (coming soon)<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Luxury Goods<\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">EU\/Global<\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Exclusive customer lists and brand protection under GDPR<\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Luxury eCommerce Compliance (coming soon)<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">HealthTech<\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">EU\/US<\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\">Patient data under GDPR + MDR + national health data laws<\/td>\n<td style=\"border:1px solid #d5d5d5; padding:10px 12px; text-align:left; vertical-align:top; word-wrap:break-word\"><a href=\"\/healthtech-ecommerce\/\">HealthTech eCommerce Compliance<\/a><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>Each sector faces a distinct combination of GDPR obligations layered on top of industry-specific regulation. The deep dive guides above cover platform architecture, data residency patterns, and vendor selection criteria tailored to each industry&#8217;s compliance stack.<\/p>\n<p>For UK-specific data protection requirements under the Data Protection Act 2018 and the Data (Use and Access) Act 2025, see the <a href=\"\/uk-data-act-ecommerce-compliance\/\">UK Data Act eCommerce compliance<\/a> guide.<\/p>\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n<h2 class=\"wp-block-heading\">Build Data-Sovereign Commerce with Spree<\/h2>\n<p>For EU and UK businesses that must guarantee GDPR compliance and eliminate CLOUD Act exposure, a self-hosted open source platform with full data sovereignty controls provides the most direct path to compliance.<\/p>\n<p>Spree Enterprise gives your team full control over infrastructure, data, security, and compliance. Deploy on your own EU infrastructure, audit every line of code under the BSD 3-Clause license, and integrate any payment processor without vendor lock-in. Your data, your jurisdiction, your rules.<\/p>\n<p><a href=\"https:\/\/spreecommerce.org\/get-started\/\"><strong>Talk to the Spree Team<\/strong><\/a> | <a href=\"https:\/\/spreecommerce.org\/get-started\/\"><strong>Explore Spree Enterprise<\/strong><\/a><\/p>\n<h2 class=\"wp-block-heading\">Frequently Asked Questions<\/h2>\n<div class=\"wp-block-wpseopress-faq-block-v2 is-layout-flow wp-block-wpseopress-faq-block-v2-is-layout-flow\">\n<details id=\"does-the-eu-us-data-privacy-framework-eliminate-cloud-act-concerns\" class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\">\n<summary><strong>Does the EU-US Data Privacy Framework eliminate CLOUD Act concerns?<\/strong><\/summary>\n<p>No. The CJEU upheld the DPF in September 2025, but the framework only covers companies that self-certify and demonstrate adequate safeguards. The CLOUD Act remains unresolved: it permits US law enforcement to compel US companies to disclose data stored anywhere, regardless of data protection laws. Any US-headquartered SaaS platform (Shopify, BigCommerce, Salesforce) still faces potential US government demands for EU customer data. Self-hosting on EU infrastructure with non-US platforms eliminates this exposure.<\/p>\n<\/details>\n<details id=\"is-shopify-gdpr-compliant-after-schrems-ii\" class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\">\n<summary><strong>Is Shopify GDPR compliant after Schrems II?<\/strong><\/summary>\n<p>Shopify offers a DPA and Ireland data centers, but Shopify Plus operates under US parent company control. US law enforcement can issue CLOUD Act subpoenas to Shopify&#8217;s US corporate entity, compelling disclosure of EU customer data regardless of where it is stored. Shopify&#8217;s DPA clarifies liability allocation between you and Shopify. It does not shield your customer data from a US subpoena. For full Schrems II compliance, use self-hosted infrastructure where no US entity holds your data.<\/p>\n<\/details>\n<details id=\"what-is-the-difference-between-a-dpa-and-standard-contractual-clauses\" class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\">\n<summary><strong>What is the difference between a DPA and Standard Contractual Clauses?<\/strong><\/summary>\n<p>A Data Processing Agreement (DPA) is a contract between you (the Data Controller) and your vendor (the Data Processor), specifying what data the processor accesses, how they use it, and their security obligations. Standard Contractual Clauses (SCCs) are EU-approved contract templates for international data transfers. Post-Schrems II, SCCs alone are insufficient for US processors. You must add supplementary measures like encryption with EU-held keys, access restrictions, and jurisdictional safeguards.<\/p>\n<\/details>\n<details id=\"what-happens-if-i-transfer-customer-data-to-a-us-saas-platform-without-proper-safeguards\" class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\">\n<summary><strong>What happens if I transfer customer data to a US SaaS platform without proper safeguards?<\/strong><\/summary>\n<p>Your Data Protection Authority can investigate, find a Chapter 5 GDPR violation, and issue a fine up to 20 million euros or 4% of global annual revenue. The DPA can also order data transfers to stop immediately, forcing an emergency platform migration. Customers can file complaints and claims for damages. For a 10 million euro revenue company, a single violation could result in a 400,000 euro fine plus the cost of unplanned migration.<\/p>\n<\/details>\n<details id=\"what-are-supplementary-measures-under-schrems-ii\" class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\">\n<summary><strong>What are supplementary measures under Schrems II?<\/strong><\/summary>\n<p>Supplementary measures are technical and organizational safeguards that prevent US authorities from accessing EU customer data even when a CLOUD Act subpoena is issued. Examples include encryption with keys held only in EU jurisdiction, data minimization (sending only necessary data to processors), split storage (sensitive data in EU, non-sensitive elsewhere), and contractual limitations on processor cooperation with foreign government demands. These measures do not prevent subpoenas, but they make the data technically inaccessible.<\/p>\n<\/details>\n<details id=\"if-i-self-host-am-i-fully-exempt-from-cloud-act-exposure\" class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\">\n<summary><strong>If I self-host, am I fully exempt from CLOUD Act exposure?<\/strong><\/summary>\n<p>For your core commerce data, yes. When you host on EU infrastructure with a non-US platform vendor like Spree (open source, BSD 3-Clause license), US authorities have no legal standing to compel disclosure. However, if you use US-based integrations for analytics, CDN, or payment processing, those specific vendors may still be subject to subpoenas for data they process. Minimize US vendor dependencies across your entire stack to minimize residual CLOUD Act exposure.<\/p>\n<\/details>\n<p><script type=\"application\/ld+json\">{\"@context\": \"https:\/\/schema.org\", \"@type\": \"FAQPage\", \"url\": \"https:\/\/spreecommerce.org\/gdpr-schrems-ii-ecommerce-compliance\/\", \"@id\": \"https:\/\/spreecommerce.org\/gdpr-schrems-ii-ecommerce-compliance\/\", \"mainEntity\": [{\"@type\": \"Question\", \"url\": \"https:\/\/spreecommerce.org\/gdpr-schrems-ii-ecommerce-compliance\/#does-the-eu-us-data-privacy-framework-eliminate-cloud-act-concerns\", \"name\": \"Does the EU-US Data Privacy Framework eliminate CLOUD Act concerns?\", \"answerCount\": 1, \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"<\/p>\n<p>No. The CJEU upheld the DPF in September 2025, but the framework only covers companies that self-certify and demonstrate adequate safeguards. The CLOUD Act remains unresolved: it permits US law enforcement to compel US companies to disclose data stored anywhere, regardless of data protection laws. Any US-headquartered SaaS platform (Shopify, BigCommerce, Salesforce) still faces potential US government demands for EU customer data. Self-hosting on EU infrastructure with non-US platforms eliminates this exposure.<\/p>\n<p>\"}}, {\"@type\": \"Question\", \"url\": \"https:\/\/spreecommerce.org\/gdpr-schrems-ii-ecommerce-compliance\/#is-shopify-gdpr-compliant-after-schrems-ii\", \"name\": \"Is Shopify GDPR compliant after Schrems II?\", \"answerCount\": 1, \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"<\/p>\n<p>Shopify offers a DPA and Ireland data centers, but Shopify Plus operates under US parent company control. US law enforcement can issue CLOUD Act subpoenas to Shopify's US corporate entity, compelling disclosure of EU customer data regardless of where it is stored. Shopify's DPA clarifies liability allocation between you and Shopify. It does not shield your customer data from a US subpoena. For full Schrems II compliance, use self-hosted infrastructure where no US entity holds your data.<\/p>\n<p>\"}}, {\"@type\": \"Question\", \"url\": \"https:\/\/spreecommerce.org\/gdpr-schrems-ii-ecommerce-compliance\/#what-is-the-difference-between-a-dpa-and-standard-contractual-clauses\", \"name\": \"What is the difference between a DPA and Standard Contractual Clauses?\", \"answerCount\": 1, \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"<\/p>\n<p>A Data Processing Agreement (DPA) is a contract between you (the Data Controller) and your vendor (the Data Processor), specifying what data the processor accesses, how they use it, and their security obligations. Standard Contractual Clauses (SCCs) are EU-approved contract templates for international data transfers. Post-Schrems II, SCCs alone are insufficient for US processors. You must add supplementary measures like encryption with EU-held keys, access restrictions, and jurisdictional safeguards.<\/p>\n<p>\"}}, {\"@type\": \"Question\", \"url\": \"https:\/\/spreecommerce.org\/gdpr-schrems-ii-ecommerce-compliance\/#what-happens-if-i-transfer-customer-data-to-a-us-saas-platform-without-proper-safeguards\", \"name\": \"What happens if I transfer customer data to a US SaaS platform without proper safeguards?\", \"answerCount\": 1, \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"<\/p>\n<p>Your Data Protection Authority can investigate, find a Chapter 5 GDPR violation, and issue a fine up to 20 million euros or 4% of global annual revenue. The DPA can also order data transfers to stop immediately, forcing an emergency platform migration. Customers can file complaints and claims for damages. For a 10 million euro revenue company, a single violation could result in a 400,000 euro fine plus the cost of unplanned migration.<\/p>\n<p>\"}}, {\"@type\": \"Question\", \"url\": \"https:\/\/spreecommerce.org\/gdpr-schrems-ii-ecommerce-compliance\/#what-are-supplementary-measures-under-schrems-ii\", \"name\": \"What are supplementary measures under Schrems II?\", \"answerCount\": 1, \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"<\/p>\n<p>Supplementary measures are technical and organizational safeguards that prevent US authorities from accessing EU customer data even when a CLOUD Act subpoena is issued. Examples include encryption with keys held only in EU jurisdiction, data minimization (sending only necessary data to processors), split storage (sensitive data in EU, non-sensitive elsewhere), and contractual limitations on processor cooperation with foreign government demands. These measures do not prevent subpoenas, but they make the data technically inaccessible.<\/p>\n<p>\"}}, {\"@type\": \"Question\", \"url\": \"https:\/\/spreecommerce.org\/gdpr-schrems-ii-ecommerce-compliance\/#if-i-self-host-am-i-fully-exempt-from-cloud-act-exposure\", \"name\": \"If I self-host, am I fully exempt from CLOUD Act exposure?\", \"answerCount\": 1, \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"<\/p>\n<p>For your core commerce data, yes. When you host on EU infrastructure with a non-US platform vendor like Spree (open source, BSD 3-Clause license), US authorities have no legal standing to compel disclosure. However, if you use US-based integrations for analytics, CDN, or payment processing, those specific vendors may still be subject to subpoenas for data they process. Minimize US vendor dependencies across your entire stack to minimize residual CLOUD Act exposure.<\/p>\n<p>\"}}]}<\/script><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Key Takeaways Last verified: March 2026 Regulation: GDPR requires lawful processing, data subject rights, breach notification within 72 hours, and privacy by design for any platform handling EU customer data. Schrems II adds mandatory supplementary measures for US data transfers. The SaaS problem: Shopify Plus, BigCommerce, and Salesforce Commerce Cloud operate under US jurisdiction. The [&hellip;]<\/p>\n","protected":false},"author":87,"featured_media":28353,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_seopress_robots_primary_cat":"none","_seopress_titles_title":"GDPR & Schrems II: Why EU Businesses Leave US Commerce","_seopress_titles_desc":"GDPR, Schrems II, and the CLOUD Act make US-hosted eCommerce a legal risk for EU businesses. Learn why self-hosted open source is the compliant path.","_seopress_robots_index":"","footnotes":""},"categories":[146],"tags":[1104,1103,1101,1102,1105],"class_list":["post-28354","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-open-source-ecommerce","tag-cloud-act-ecommerce","tag-eu-data-sovereignty-commerce","tag-gdpr-ecommerce","tag-schrems-ii-ecommerce-platform","tag-self-hosted-ecommerce"],"acf":[],"_links":{"self":[{"href":"https:\/\/spreecommerce.org\/wp-json\/wp\/v2\/posts\/28354","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/spreecommerce.org\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/spreecommerce.org\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/spreecommerce.org\/wp-json\/wp\/v2\/users\/87"}],"replies":[{"embeddable":true,"href":"https:\/\/spreecommerce.org\/wp-json\/wp\/v2\/comments?post=28354"}],"version-history":[{"count":0,"href":"https:\/\/spreecommerce.org\/wp-json\/wp\/v2\/posts\/28354\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/spreecommerce.org\/wp-json\/wp\/v2\/media\/28353"}],"wp:attachment":[{"href":"https:\/\/spreecommerce.org\/wp-json\/wp\/v2\/media?parent=28354"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/spreecommerce.org\/wp-json\/wp\/v2\/categories?post=28354"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/spreecommerce.org\/wp-json\/wp\/v2\/tags?post=28354"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}