I believe the authorities are correct here. Shopify is sending all personal data to CloudFlare, CloudFront (Amazon) and Fastly, so 3 US companies. They could sign so-called "data processing agreements" where they promise to safeguard personal data. But the Shopify FAQ explicitly states that they are unwilling to do so. As the result, Shopify is legally considered to not be processing data under the instructions of th…
As I see it, Shopify's role in this situation is more likely to be considered a data fence: because of the lack of processing agreement, they're not allowed to process any data (more accurately, the shop owner is not allowed to give them access to any data). The data that they do have through services they provide is illegally obtained; that doesn't mean they suddenly own that data.