Non-compliant cookies: what sanctions under GDPR?
GDPR sets a legal ceiling for the most serious breaches; in practice, supervisory authorities generally use progressive corrective powers — reprimands and compliance orders — before any fine.
The GDPR legal ceiling
Article 83 of GDPR sets, for the most serious breaches, an administrative fine ceiling of up to €20 million or 4% of worldwide annual turnover, whichever is higher. Breaches of consent rules (including cookies) fall into this most severe category of the text.
Progressive enforcement powers
Before any financial sanction, Article 58 of GDPR gives supervisory authorities a range of corrective powers: issuing warnings and reprimands, ordering compliance within a set deadline, and carrying out investigations, including automated online checks. A formal warning alone, while not a fine, can become public and carry a reputational cost.
What this means for a Shopify store
A store's size doesn't guarantee it won't be checked: supervisory authorities can run large-scale automated verification campaigns on cookie banners, regardless of a site's revenue. A regular technical audit (like the one this scanner offers) helps catch gaps before an external check reveals them.
Does your store follow these rules?
Our free scanner technically checks what fires before consent on your Shopify store, in ~30 seconds.
Scan my store for freeSources
Independent informational content, not affiliated with Shopify. Not legal advice; for an assessment of your situation, consult a lawyer or your DPO.