PrivacyProof · Shopify
GDPR + the cookie rules require a clear privacy policy, lawful opt-in for non-essential cookies, and a way for people to exercise their data rights. Check yours in 60 seconds.
Shopify gives you the storefront and checkout, but legal compliance is on you, the merchant — Shopify's own terms make that explicit. The platform ships some tools (a cookie-banner and customer-privacy API, a hosted PCI-compliant checkout), but switching them on and configuring them correctly is your job, not Shopify's.
📦 On Shopify: Selling into the EU from a Shopify store triggers EU rules no matter where you're based — the test is your customer's location, not yours. What Shopify handles: Shopify offers a cookie-banner and customer-privacy API, but you have to enable and configure them — out of the box a store is not consent-compliant.
This rule applies to Shopify sellers who collect personal data from visitors in the EU or UK. Collect data from EU/UK visitors? Check your privacy policy, cookie consent, and data-rights handling. Not sure? The free checker tells you in about a minute — no signup.
Whatever the platform handles, you still need to be able to answer "yes" to each of these — these are the points Shopify sellers most often get caught on:
⚠️ Exposure: up to €20M or 4% of global turnover (Art. 83) · Status: In force. On Shopify, that's on top of any account suspension for breaking platform policy.
Compare the penalty for every rule →
Shopify offers a cookie-banner and customer-privacy API, but you have to enable and configure them — out of the box a store is not consent-compliant.
If you serve EU/UK visitors and use any non-essential cookies (analytics, advertising), yes — they must load only after the visitor opts in, with a Reject option as easy as Accept.
What data you collect, why, the lawful basis, who you share it with, how long you keep it, international transfers, and how to exercise data rights — in plain language, available at collection.
Up to €20 million or 4% of global annual turnover, whichever is higher — plus regulator orders and reputational damage.
RuleGoose checks this against the EU GDPR (Reg. (EU) 2016/679), UK GDPR + ePrivacy/cookie rules. Read it yourself: EUR-Lex — Regulation (EU) 2016/679 →
or get one RuleGoose Score across every rule your Shopify store has to meet.
GDPR privacy & cookie consent is one of several rules a Shopify store has to meet. See the full Shopify compliance checklist →, or read the platform-neutral GDPR privacy & cookie consent guide.
Informational only, not legal advice, and not affiliated with the EU or Shopify. Last reviewed 2026-06-30.