Does GDPR apply to your Shopify store?

GDPR applies to your Shopify store if you sell to, ship to, or otherwise process the personal data of EU residents — regardless of where your business is based. If your store ships to Germany, France, Italy, or any other EU country, or if EU residents can browse and purchase from your store, GDPR applies to you.

The common misconception: Many US-based Shopify merchants assume GDPR only applies to European businesses. It doesn't. GDPR follows your customers, not your business address. A store in Texas that ships to the Netherlands is subject to GDPR for those Dutch customers.

The scope of GDPR for your Shopify store covers:

What Shopify handles for you

Shopify acts as a data processor on your behalf — they process customer data according to your instructions and have signed Data Processing Agreements in place. This covers:

Important distinction: Shopify being GDPR compliant does not make your store GDPR compliant. You are the data controller — the party legally responsible for how customer data is collected and used. Shopify provides the tools; you are responsible for using them correctly and for everything outside Shopify's platform (pixels, analytics, email marketing).

What you must do yourself

As the data controller, you are responsible for:

1. Cookie consent banner

Shopify stores load numerous tracking technologies by default — analytics, marketing pixels, retargeting scripts — all of which set cookies. Under GDPR, EU visitors must consent to these before they fire. Shopify's native cookie banner does not block cookies before consent, making it insufficient for GDPR compliance.

2. Privacy policy that meets GDPR standards

Shopify provides a privacy policy template, but it is a starting point, not a finished document. Your privacy policy must disclose every third party you share customer data with — including Meta, Google, Klaviyo, and any other marketing or analytics tools you use.

3. Consent for email marketing

Under GDPR, you need explicit opt-in consent before adding EU customers to marketing email lists. Pre-ticked "Subscribe to newsletter" checkboxes at checkout are not valid. The checkbox must be unticked by default and clearly labelled.

4. Third-party app data processing agreements

Every Shopify app that processes customer data (Klaviyo, Mailchimp, Gorgias, Yotpo, etc.) needs a Data Processing Agreement. Most provide these automatically — check each app's privacy documentation.

5. Customer data request process

EU customers can request a copy of their data, ask for corrections, or request deletion at any time. You need a process to handle these within 30 days. Shopify's admin provides export and deletion tools, but you need a way for customers to submit requests.

Meta Pixel, Google Ads & tracking pixels

This is where most Shopify stores are non-compliant. Marketing pixels are the biggest GDPR risk for e-commerce stores.

The problem

The Meta Pixel (and Google Ads tag, TikTok Pixel, Pinterest Tag, etc.) fires immediately when a visitor lands on your store, sending their IP address and browsing behaviour to the respective ad network. Under GDPR, this requires explicit prior consent — the pixel must not fire until the visitor has clicked "Accept" on your cookie banner.

What valid pixel consent looks like

The impact on your ad performance

EU visitors who decline cookies (typically 30–50% of EU traffic) will not be tracked by your pixels. This reduces your retargeting audience size and affects attribution data. To partially recover this signal, use Meta's Conversions API (server-side) alongside consent mode — it sends some purchase data without relying on the browser pixel, and is GDPR-compliant for conversion events that are part of fulfilling a customer order.

Shopify Markets and pixels: If you use Shopify Markets or Shopify's native pixel manager, consent mode must be configured separately. Installing a GDPR consent app handles this automatically for most setups.

Privacy policy requirements for Shopify stores

Your Shopify store's privacy policy must tell customers:

Shopify's default privacy policy template covers some of this but frequently misses third-party disclosures for the apps merchants add. iubenda automatically generates a privacy policy that updates when you add new Shopify apps — a significant advantage over static templates.

CCPA requirements for Shopify stores

If you have California customers and your store meets CCPA thresholds (over $25M revenue, or processes data of 100,000+ California consumers, or derives 50%+ revenue from selling data), you also need:

Most growing Shopify stores will eventually hit CCPA thresholds. Adding the Do Not Sell link proactively costs nothing and protects you as you scale. Enzuzo handles CCPA opt-out alongside GDPR consent in a single app.

Handling customer data requests

EU customers have the right to:

You must respond within 30 days. Shopify provides built-in tools to export and delete customer data from your admin. For deletion requests, you also need to delete data from every third-party app that holds customer data — your email platform, CRM, review app, and loyalty program.

Add a privacy@yourdomain.com email address or a contact form dedicated to data requests, and link it from your privacy policy.

Best GDPR apps for Shopify

#1
Editor's Pick — Best for Shopify

Enzuzo

Native Shopify app. Cookie consent, privacy policy, CCPA opt-out, and DSAR workflow in one place.

Score 4.5 / 5 From $7/mo
✓ Why it wins for Shopify
  • Native Shopify app — installs in minutes with no code
  • Automatic cookie scanning on your store
  • Handles GDPR consent + CCPA Do Not Sell in one banner
  • Built-in privacy policy generator
  • DSAR (data request) workflow from $22/month
  • 10 domains on one plan — ideal for merchants running multiple stores
✗ Limitations
  • Free plan limited in features vs paid tiers
  • Less widely known than CookieYes
#2
Runner-Up

CookieYes

The most widely used cookie consent tool, with a solid Shopify integration and a generous free tier.

Score 4.8 / 5 From Free
✓ Pros
  • Free tier up to 25,000 visits/month
  • Google Consent Mode v2 — keeps ad conversion data flowing
  • Automatic cookie scanning
  • Clean, customisable banner design
  • Very quick to install on Shopify
✗ Cons
  • No built-in privacy policy generation
  • CCPA handling less seamless than Enzuzo
  • DSAR workflow not included
#3
Best All-in-One Docs

iubenda

Privacy policy generator, cookie banner, and terms — lawyer-vetted, automatically updated as you add apps.

Score 4.6 / 5 From €4.99/mo
✓ Pros
  • Lawyer-vetted privacy policy that auto-updates
  • Covers GDPR, CCPA, LGPD, and more in one doc
  • Cookie banner included in subscription
  • Good Shopify integration
✗ Cons
  • More expensive than CookieYes for banner-only use
  • Interface has a learning curve

Shopify GDPR compliance checklist

Cookie consent

Legal documents

Email marketing consent

CCPA (US stores with California customers)

Customer data rights

Third-party apps

Frequently asked questions

Does my Shopify store need a GDPR cookie banner?

Yes, if you have EU customers. Shopify stores almost always use tracking pixels (Meta, Google Ads, TikTok), analytics, and remarketing cookies — all of which require explicit consent from EU visitors before firing. Shopify's built-in cookie banner does not block cookies before consent and is not sufficient for GDPR compliance. Dedicated apps like Enzuzo or CookieYes provide proper consent management.

Is Shopify GDPR compliant by default?

Shopify as a platform is GDPR compliant and acts as a data processor under your privacy policy. However, your store is not automatically GDPR compliant — you are the data controller and are responsible for obtaining cookie consent, publishing a compliant privacy policy, handling customer data requests, and managing third-party marketing pixels.

Does Shopify have a built-in cookie banner?

Shopify has a basic cookie consent banner built into some themes, but it does not block cookies before consent, does not provide granular category controls, and does not handle the CCPA Do Not Sell requirement. For GDPR compliance, you need a dedicated consent management app.

What happens to my Meta Pixel under GDPR?

The Meta Pixel sets cookies and sends customer behaviour data to Facebook/Meta. Under GDPR, this requires explicit consent from EU visitors before the pixel fires. You need a cookie consent banner that blocks the pixel until consent is given. To recover some conversion signal from non-consenting visitors, implement Meta's Conversions API alongside consent mode.

What is the best GDPR app for Shopify?

Enzuzo is our top pick for Shopify — it has a native integration, handles GDPR consent and CCPA opt-out in one banner, includes a privacy policy generator, and offers a DSAR workflow. CookieYes is the better option if you want a free tier (up to 25,000 visits/month) and prioritise Google Consent Mode v2 support.

Does GDPR apply to a Shopify store based in the US?

Yes. GDPR applies based on where your customers are located, not where your business is based. If you ship to or accept orders from EU countries, GDPR applies to you. See our full guide: Does GDPR apply to US companies?