CookieScan

Do you need consent before setting cookies?

Yes, for any non-essential cookie or tracker: the ePrivacy directive requires consent collected BEFORE the deposit, not after.

The rule

Article 5(3) of the ePrivacy directive (2002/58/EC) sets the principle: storing or reading information on a user’s device (cookies, pixels, SDKs) requires prior consent, except for trackers strictly necessary for the requested service. “Prior” means before the script runs at all — not just a banner displayed in parallel while trackers load.

What this means technically

In practice, advertising scripts (Meta Pixel, Google Ads, TikTok Pixel...) and most analytics tools should only run after an explicit click on “Accept”. If a script fires as soon as the page loads, before any interaction with the banner, the prior-consent requirement isn’t met — even if the banner exists and looks correct visually.

The Shopify case

On Shopify, trackers can be injected via the theme, a third-party app, Google Tag Manager, or the native Shopify Pixel. Each of these sources can fire independently of the installed consent banner. That’s why a store with a well-installed CMP (OneTrust, Axeptio, Didomi...) can still let trackers through before consent: technical blocking wasn’t configured to cover every source.

Does your store follow these rules?

Our free scanner technically checks what fires before consent on your Shopify store, in ~30 seconds.

Scan my store for free

Sources

Other articles

Independent informational content, not affiliated with Shopify. Not legal advice; for an assessment of your situation, consult a lawyer or your DPO.