GDPR and UK GDPR: What Shopify Store Owners Need to Know

After Brexit, the UK retained its own version of GDPR (UK GDPR), which is functionally nearly identical to EU GDPR. If you sell to UK customers, UK GDPR applies. If you also sell to EU customers, EU GDPR applies independently. The core obligations are the same: lawful basis for processing personal data, transparency about data use, customer rights to access and delete their data, and appropriate security measures. Non-compliance can result in fines up to £17.5M or 4% of global annual turnover (whichever is higher) under UK GDPR.

Cookie Consent

Shopify’s built-in cookie consent banner (enabled in Online Store → Preferences) provides a basic consent mechanism. For full compliance, the banner must: appear before any non-essential cookies are set, allow customers to accept or decline (not just acknowledge), and remember the customer’s choice. Use the Shopify App Store cookie consent apps (Pandectes GDPR, Consentmo, Cookiebot) for more robust consent management that handles banner customisation, consent logging, and automatic blocking of third-party scripts pending consent.

Privacy Policy Requirements

Your Privacy Policy must cover: what personal data you collect (name, email, address, payment data, browsing behaviour), why you collect it (lawful bases: contract fulfilment, legitimate interest, consent), who you share it with (third-party apps, email providers, analytics, payment processors), how long you retain it, and customer rights (access, rectification, erasure, data portability, objection). Shopify provides a Privacy Policy generator in Settings → Legal — use it as a starting template but ensure it accurately reflects your actual data practices.

Marketing Permissions

You need explicit opt-in consent to send marketing emails to UK and EU customers (this is PECR — Privacy and Electronic Communications Regulations — not GDPR, but applies simultaneously). A pre-ticked marketing consent box is not valid consent. The consent must be freely given, specific, informed, and unambiguous. Shopify’s checkout includes an opt-in checkbox for email marketing — ensure it is unchecked by default. Document when and how each subscriber consented for compliance auditing.

Data Subject Rights

Customers have the right to: access a copy of their data (Subject Access Request), correct inaccurate data, delete their data (“right to be forgotten”), and portability of their data. Shopify provides tools to export customer data for SARs and delete customer records. For deletion requests, be aware that some data must be retained (financial records for HMRC compliance) even when you delete the customer account. Document your data retention schedule so you can explain why certain data is retained when processing deletion requests.

Shopify Experts · OneOnic

Ready to Grow Your Shopify Store?

Our Shopify experts at OneOnic have helped hundreds of store owners scale faster. Let us build, optimise, and grow your store.