CookieScan

Is Shopify GDPR-compliant by default?

No: Shopify provides tools (Customer Privacy API, consent settings), but actual compliance depends on how the merchant configures them.

What Shopify provides

Shopify offers a Customer Privacy API to manage consent and restrict some native trackers (Shopify Pixel, some checkout scripts) based on the visitor’s choice. For a few years now, the platform has also enforced a minimal banner for EU/EEA visitors on certain themes.

What Shopify doesn’t do

Shopify doesn’t control third-party apps installed by the merchant (analytics, marketing, reviews, upsell), nor code manually added to the theme or via Google Tag Manager. Each of these sources can set trackers independently of the consent banner and the native privacy API.

Responsibility stays with the merchant

As the data controller, the Shopify merchant remains responsible for their store’s compliance, including for trackers added by third-party apps. A correctly configured CMP (OneTrust, Axeptio, Didomi...) and regular technical checks remain necessary, whatever e-commerce platform is used.

Does your store follow these rules?

Our free scanner technically checks what fires before consent on your Shopify store, in ~30 seconds.

Scan my store for free

Sources

Other articles

Independent informational content, not affiliated with Shopify. Not legal advice; for an assessment of your situation, consult a lawyer or your DPO.