Does GDPR apply to your Shopify store?
GDPR applies to your Shopify store if you sell to, ship to, or otherwise process the personal data of EU residents — regardless of where your business is based. If your store ships to Germany, France, Italy, or any other EU country, or if EU residents can browse and purchase from your store, GDPR applies to you.
The scope of GDPR for your Shopify store covers:
- Customer email addresses, names, and shipping addresses collected at checkout
- Browsing behaviour tracked by analytics and marketing pixels
- Purchase history and order data
- Email marketing lists and abandoned cart data
- Any data collected via contact forms, reviews, or loyalty programs
What Shopify handles for you
Shopify acts as a data processor on your behalf — they process customer data according to your instructions and have signed Data Processing Agreements in place. This covers:
- Secure storage of customer order data and payment information
- PCI DSS compliance for payment processing
- Data Processing Agreement with you as the merchant (automatically in place)
- Shopify's own GDPR compliance as a platform (privacy policy, data security)
- Customer data deletion tools in the Shopify admin (for erasure requests)
- GDPR webhooks that notify your store when a customer requests data deletion or export
What you must do yourself
As the data controller, you are responsible for:
1. Cookie consent banner
Shopify stores load numerous tracking technologies by default — analytics, marketing pixels, retargeting scripts — all of which set cookies. Under GDPR, EU visitors must consent to these before they fire. Shopify's native cookie banner does not block cookies before consent, making it insufficient for GDPR compliance.
2. Privacy policy that meets GDPR standards
Shopify provides a privacy policy template, but it is a starting point, not a finished document. Your privacy policy must disclose every third party you share customer data with — including Meta, Google, Klaviyo, and any other marketing or analytics tools you use.
3. Consent for email marketing
Under GDPR, you need explicit opt-in consent before adding EU customers to marketing email lists. Pre-ticked "Subscribe to newsletter" checkboxes at checkout are not valid. The checkbox must be unticked by default and clearly labelled.
4. Third-party app data processing agreements
Every Shopify app that processes customer data (Klaviyo, Mailchimp, Gorgias, Yotpo, etc.) needs a Data Processing Agreement. Most provide these automatically — check each app's privacy documentation.
5. Customer data request process
EU customers can request a copy of their data, ask for corrections, or request deletion at any time. You need a process to handle these within 30 days. Shopify's admin provides export and deletion tools, but you need a way for customers to submit requests.
Meta Pixel, Google Ads & tracking pixels
This is where most Shopify stores are non-compliant. Marketing pixels are the biggest GDPR risk for e-commerce stores.
The problem
The Meta Pixel (and Google Ads tag, TikTok Pixel, Pinterest Tag, etc.) fires immediately when a visitor lands on your store, sending their IP address and browsing behaviour to the respective ad network. Under GDPR, this requires explicit prior consent — the pixel must not fire until the visitor has clicked "Accept" on your cookie banner.
What valid pixel consent looks like
- Visitor lands on your store
- Cookie banner appears — pixels are blocked
- Visitor clicks "Accept all" — pixels fire
- Visitor clicks "Decline" or closes banner — pixels never fire for that session
The impact on your ad performance
EU visitors who decline cookies (typically 30–50% of EU traffic) will not be tracked by your pixels. This reduces your retargeting audience size and affects attribution data. To partially recover this signal, use Meta's Conversions API (server-side) alongside consent mode — it sends some purchase data without relying on the browser pixel, and is GDPR-compliant for conversion events that are part of fulfilling a customer order.
Privacy policy requirements for Shopify stores
Your Shopify store's privacy policy must tell customers:
- What personal data you collect (name, email, address, payment details, browsing behaviour)
- Why you collect it (fulfilling orders, marketing, fraud prevention, analytics)
- The legal basis for each processing activity (contract, consent, legitimate interest)
- Who you share data with — and you must name them: Shopify, Meta, Google, Klaviyo, your shipping provider, your payment processor
- Whether data is transferred outside the EU (yes, to US-based services — you need to state the transfer mechanism)
- How long you retain data
- Customer rights: access, correction, deletion, portability, objection
- How to contact you to exercise those rights
Shopify's default privacy policy template covers some of this but frequently misses third-party disclosures for the apps merchants add. iubenda automatically generates a privacy policy that updates when you add new Shopify apps — a significant advantage over static templates.
CCPA requirements for Shopify stores
If you have California customers and your store meets CCPA thresholds (over $25M revenue, or processes data of 100,000+ California consumers, or derives 50%+ revenue from selling data), you also need:
- A "Do Not Sell or Share My Personal Information" link in your store footer
- A way for California customers to opt out of data sharing with ad networks
- A privacy policy that includes CCPA-specific disclosures
Most growing Shopify stores will eventually hit CCPA thresholds. Adding the Do Not Sell link proactively costs nothing and protects you as you scale. Enzuzo handles CCPA opt-out alongside GDPR consent in a single app.
Handling customer data requests
EU customers have the right to:
- Access — request a copy of all data you hold about them
- Rectification — correct inaccurate data
- Erasure — request deletion of their data ("right to be forgotten")
- Portability — receive their data in a machine-readable format
- Objection — object to processing for marketing purposes
You must respond within 30 days. Shopify provides built-in tools to export and delete customer data from your admin. For deletion requests, you also need to delete data from every third-party app that holds customer data — your email platform, CRM, review app, and loyalty program.
Add a privacy@yourdomain.com email address or a contact form dedicated to data requests, and link it from your privacy policy.
Best GDPR apps for Shopify
Enzuzo
Native Shopify app. Cookie consent, privacy policy, CCPA opt-out, and DSAR workflow in one place.
- Native Shopify app — installs in minutes with no code
- Automatic cookie scanning on your store
- Handles GDPR consent + CCPA Do Not Sell in one banner
- Built-in privacy policy generator
- DSAR (data request) workflow from $22/month
- 10 domains on one plan — ideal for merchants running multiple stores
- Free plan limited in features vs paid tiers
- Less widely known than CookieYes
CookieYes
The most widely used cookie consent tool, with a solid Shopify integration and a generous free tier.
- Free tier up to 25,000 visits/month
- Google Consent Mode v2 — keeps ad conversion data flowing
- Automatic cookie scanning
- Clean, customisable banner design
- Very quick to install on Shopify
- No built-in privacy policy generation
- CCPA handling less seamless than Enzuzo
- DSAR workflow not included
iubenda
Privacy policy generator, cookie banner, and terms — lawyer-vetted, automatically updated as you add apps.
- Lawyer-vetted privacy policy that auto-updates
- Covers GDPR, CCPA, LGPD, and more in one doc
- Cookie banner included in subscription
- Good Shopify integration
- More expensive than CookieYes for banner-only use
- Interface has a learning curve
Shopify GDPR compliance checklist
Cookie consent
Legal documents
Email marketing consent
CCPA (US stores with California customers)
Customer data rights
Third-party apps
Frequently asked questions
Does my Shopify store need a GDPR cookie banner?
Yes, if you have EU customers. Shopify stores almost always use tracking pixels (Meta, Google Ads, TikTok), analytics, and remarketing cookies — all of which require explicit consent from EU visitors before firing. Shopify's built-in cookie banner does not block cookies before consent and is not sufficient for GDPR compliance. Dedicated apps like Enzuzo or CookieYes provide proper consent management.
Is Shopify GDPR compliant by default?
Shopify as a platform is GDPR compliant and acts as a data processor under your privacy policy. However, your store is not automatically GDPR compliant — you are the data controller and are responsible for obtaining cookie consent, publishing a compliant privacy policy, handling customer data requests, and managing third-party marketing pixels.
Does Shopify have a built-in cookie banner?
Shopify has a basic cookie consent banner built into some themes, but it does not block cookies before consent, does not provide granular category controls, and does not handle the CCPA Do Not Sell requirement. For GDPR compliance, you need a dedicated consent management app.
What happens to my Meta Pixel under GDPR?
The Meta Pixel sets cookies and sends customer behaviour data to Facebook/Meta. Under GDPR, this requires explicit consent from EU visitors before the pixel fires. You need a cookie consent banner that blocks the pixel until consent is given. To recover some conversion signal from non-consenting visitors, implement Meta's Conversions API alongside consent mode.
What is the best GDPR app for Shopify?
Enzuzo is our top pick for Shopify — it has a native integration, handles GDPR consent and CCPA opt-out in one banner, includes a privacy policy generator, and offers a DSAR workflow. CookieYes is the better option if you want a free tier (up to 25,000 visits/month) and prioritise Google Consent Mode v2 support.
Does GDPR apply to a Shopify store based in the US?
Yes. GDPR applies based on where your customers are located, not where your business is based. If you ship to or accept orders from EU countries, GDPR applies to you. See our full guide: Does GDPR apply to US companies?