To make an online store GDPR compliant, map your customer data, block trackers until the shopper consents, and show a compliant cookie banner. Get separate opt-in for marketing email, publish a privacy and cookie policy, and sign DPAs with your processors. Then secure the data you hold and honor deletion requests. This applies whether your store is registered in the EU or simply sells to EU shoppers.
The steps below turn that checklist into an ordered project you can run in one sitting for the core setup, then maintain on a schedule.
Does GDPR Apply to My Online Store?
GDPR applies to any store that processes the personal data of people in the EU or UK. The store's own registration or hosting location does not matter. A US-based Shopify store selling to EU customers is in scope the same as a store based in Germany. For the full rules, principles, and rights behind the regulation, see a plain-English guide to the GDPR.
The regulation is extraterritorial by design. It follows the data subject's location, not the merchant's. A store with zero EU staff and zero EU bank accounts still falls under GDPR once it processes an EU resident's data. That includes checkout data, an email address, or browsing behavior. GDPR is one piece of a wider patchwork of privacy laws. See the wider map of privacy laws if your store also serves customers outside the EU and UK.
This guide focuses on the ecommerce-specific parts of the job: checkout data, payment processors, marketing pixels, and abandoned-cart email. For the full whole-site GDPR program beyond the store-specific pieces, see the full GDPR compliance walkthrough.
The "Targeting" Test for US and Non-EU Stores
The targeting test decides whether a non-EU store falls under GDPR. If you deliberately target EU or UK shoppers, GDPR applies even without an EU presence. The European Data Protection Board's Article 3(2) territorial-scope guidelines list the practical indicators regulators look for.
A store is treated as targeting the EU when it shows several of these signals together:
-
Displaying prices in EUR or GBP
-
Offering shipping to EU or UK addresses
-
Publishing site content in an EU language
-
Running ads aimed at EU audiences
-
Mentioning EU or UK customers in marketing copy
One signal alone rarely triggers GDPR. A US store that ships internationally as an afterthought, with USD-only pricing and no EU marketing, sits in a gray zone. A store that prices in euros and ships to Germany by default reads differently. Add French-language ad copy and that store is targeting the EU under any reasonable reading of the guidelines.
Do I Need an EU Representative?
Yes, Article 27 requires a non-EU store that falls under GDPR to appoint an EU representative, and there is no small-business exemption. The representative is a local contact point for supervisory authorities and data subjects, not a legal advisor.
In practice, this requirement is widely ignored by small, occasional-shipper stores. Regulators have limited enforcement bandwidth against merchants with a handful of EU orders a year. That gap does not remove the legal obligation. A strong EU sales channel also raises the real-world risk of an audit or complaint that surfaces the missing representative.
What Customer Data Does Your Store Collect (and Under What Lawful Basis)?
Every online store collects data across at least six categories, and each one needs its own lawful basis under GDPR Article 6. Order fulfillment data runs on contract necessity and needs no separate consent; analytics and marketing data need consent.
| Data type | Example data | Lawful basis | Needs a consent banner? |
|---|---|---|---|
| Checkout / order data | Name, address, payment details | Contract necessity, Art 6(1)(b) | No |
| Account data | Email, password, order history | Contract necessity | No |
| Analytics | Page views, session behavior | Consent | Yes |
| Marketing / newsletter | Email opt-in, purchase history for ads | Consent | Yes |
| Support / chat | Chat transcripts, support tickets | Legitimate interest or contract | Sometimes |
| Payment data | Card details processed by a gateway | Contract necessity (processor handles storage) | No |
The split most guides blur: fulfilling an order does not require consent. Sending a shopper a marketing email based on that order does. Treat every checkout field as contract-necessary and every marketing or tracking use of that same data as consent-gated.
What You Need Before You Start
The prerequisite most store owners miss is a full inventory of every third-party script their theme and apps load. That includes scripts they never installed on purpose. Themes and marketplace apps routinely inject their own trackers without a clear on-screen prompt.
Before Step 1, line up:
-
Roles:
-
Time:
-
Inputs:
-
Tools:
Step 1: Map Every Piece of Customer Data Your Store Collects
Mapping your data means listing every place customer information enters your systems and every processor that can see it. This step is the foundation every later step depends on.
Walk through each data source in order:
-
Storefront and app analytics (page views, add-to-cart events)
-
Checkout and payment processing (name, address, card token)
-
Shipping and fulfillment (address, phone number for delivery)
-
Email and SMS marketing (opt-in status, purchase history)
-
CRM and support tools (contact records, chat transcripts)
For each source, note who else can see the data. That means your payment gateway, your fulfillment partner, and your email platform. The cookie and tracker slice of this map gets automated in Step 2. The rest, your CRM fields and processor list, stays a manual audit only you can do.
Step 2: Find and Categorize the Cookies, Pixels, and Trackers on Your Store
You cannot block a tracker you have not found. This step starts with a full-site scan, including product and checkout pages. Ecommerce themes and apps routinely inject trackers beyond what the merchant configured. Common examples include the Meta Pixel, Google Analytics and Ads tags, TikTok, email-marketing scripts, live chat widgets, and payment-processor cookies.
Consently's automatic full-site scan detects cookies, trackers, scripts, and iframes across the entire store. It then auto-categorizes them into groups like essential, analytics, and advertising. Add any checkout or funnel pages that are not linked from your main navigation or sitemap to the manual URL scan list. That way the scan does not miss them. A weekly scheduled re-scan catches new trackers as you add apps.
Step 3: Block Marketing and Analytics Trackers Until the Shopper Consents
Non-essential trackers must not fire before the shopper consents, and loading a marketing pixel first, then asking, is the single most-fined mistake in ecommerce compliance. The Meta Pixel, Google Ads and GA4 tags, and third-party embeds all fall under this rule.
The enforcement risk is not theoretical. France's CNIL fined SHEIN 150 million euros on 3 September 2025, specifically for placing trackers in customers' browsers without their consent. CNIL fined Google 325 million euros that same day in a related cookie-compliance action. Both cases sit inside CNIL's ongoing cookie-enforcement plan, running since 2019.
Consently auto-blocks cookies, scripts, and iframes until the shopper actively consents. That includes the Meta Pixel, Google tags, and YouTube or Facebook embeds. It is explicit-consent-only by design, which is exactly what GDPR requires. For the pixel-specific mechanics, see how to block the Meta Pixel until consent. For the enforcement pattern behind this rule, see tracking-pixel lawsuits.
Step 4: Add a GDPR-Compliant Cookie Banner
A compliant banner offers accept, reject, and manage options, and it makes reject as easy as accept. It blocks trackers before any choice is made and lets shoppers withdraw consent later. For the full rule set behind these requirements, see what a compliant cookie banner must do.
The free banner that ships with Shopify or WooCommerce works as a starting point. It rarely blocks trackers automatically or keeps a consent record you can produce in an audit. That gap is why most stores add a dedicated consent tool on top of the platform's default.
Consently's banner is customizable, with a preference center and reject-as-easy-as-accept by default. A floating revisit button lets shoppers withdraw consent at any time. Banner content ships in 35 languages. Automatic geotargeting shows the EU opt-in model to EU visitors and the US opt-out model to US visitors from the same install.
To wire this up on your platform, see setting it up on your Shopify store or doing the same on WooCommerce.
If your store also needs CCPA or PECR coverage beyond GDPR, the full cookie-law action plan walks through every major regime at once.
Read also: Best Cookie Consent for Ecommerce.
Step 5: Get Separate Opt-In Consent for Marketing Email (and Handle Abandoned Carts Correctly)
Marketing email needs its own opt-in, separate from the purchase itself, and the newsletter checkbox at checkout must be un-ticked by default. A ticked or bundled marketing box is not valid consent under GDPR.
The distinction most stores get wrong: an order-confirmation email is transactional and needs no consent because it runs on contract necessity. A newsletter or promotional email is marketing and needs consent.
Abandoned-cart emails sit in a genuinely contested middle ground. They are marketing emails, not transactional ones, since they promote a purchase rather than confirm one. Adding an item to a cart is not consent on its own.
The UK's PECR "soft opt-in" rule can permit these emails to existing customers without a fresh opt-in. Two conditions must both hold. First, the recipient must have bought or negotiated to buy a similar product from you before. Second, you must have offered a clear opt-out both at collection and in every message since. That exception never extends to first-time visitors or purchased contact lists.
Consently logs cookie and tracking consent and can gate marketing tags, but it does not run your email tool or send your abandoned-cart sequence. For whether your email platform itself meets GDPR requirements, see whether your email tool is GDPR compliant.
Step 6: Sign Data Processing Agreements With Your Payment, Shipping, and Marketing Providers
You remain the data controller and stay liable for every processor you use. A signed data processing agreement with each one is required, covering your payment gateway, shipping partner, email or SMS platform, analytics tool, and chat widget.
The ecommerce-specific point most guides skip: your payment processor is a sub-processor of your customer data, not a neutral utility. That includes Stripe, PayPal, and Shopify Payments. PCI-DSS certification covers payment-card security, not GDPR consent, so passing a PCI audit does not substitute for a signed DPA. Check where each processor stores and transfers data, since transfers outside the EU need standard contractual clauses.
Article 32 also makes you responsible for securing the data you hold, not just the processors who touch it. Serve your whole store over HTTPS so checkout and account data are encrypted in transit. Limit admin and staff access to order data to the people who actually need it. Delete or anonymize customer records once you no longer have a lawful reason to keep them. Data you never stored cannot leak in a breach.
Consently provides its own customer-facing DPA for the relationship between your store and Consently. It covers hosting region, subprocessor list, and standard contractual clauses on request. It does not sign or manage the DPAs you need with your other vendors. That agreement stays a direct relationship between your store and each processor.
Step 7: Publish a Privacy Policy and a Cookie Policy
A store needs a plain-language privacy policy and a cookie policy. The privacy policy covers what data the store collects, why, and its lawful basis. It also names which processors see the data, how long it is retained, what rights shoppers have, and how it is secured. The cookie policy lists the cookies found in Step 2. Link both from the site footer and from the cookie banner itself.
Consently generates a Cookie Policy and a Privacy Policy, plus Terms and Conditions, from guided workflows. Output covers more than 10 languages and embeds directly on your site. These generators are compliance assistance, not a substitute for legal advice. They never make a store compliant on their own. For what a store's privacy policy specifically needs to cover, see what an online store's privacy policy must include.
Step 8: Let Customers Access, Export, and Delete Their Data
Shoppers can request access, correction, portability, or deletion of their data, and Article 12 gives you one month to respond. The ecommerce complication is that the data lives in several places at once: the store account, order history, email platform, and payment processor.
Build one repeatable process rather than handling each request as a one-off search. Consently does not fulfill data-subject requests or export store data on your behalf. That workflow runs through your store platform's built-in tools, your email vendor, and your payment processor instead. For the step-by-step process, see how to handle a data request step by step.
Step 9: Keep a Consent Record and Re-Scan on a Schedule
GDPR requires you to prove consent, not just collect it. A timestamped record of who consented to what, and when, is required evidence in an audit. Stores add new apps and marketing tools constantly, so a one-time scan goes stale within weeks.
Consently keeps audit-ready, timestamped, exportable consent logs and runs weekly scheduled scans plus on-demand scans whenever you add a new app. New trackers get caught and blocked automatically instead of running unnoticed until the next manual check.
Common Ecommerce GDPR Mistakes to Avoid
The single most damaging mistake is letting the Meta Pixel or Google Analytics fire before the shopper consents. That exact violation cost SHEIN 150 million euros in September 2025.
Five mistakes recur across store audits.
-
Trackers fire before consent
-
The marketing checkbox is pre-ticked or bundled with checkout
-
Adding an item to a cart is treated as consent for marketing email
-
No consent log exists
-
The store relies on the free platform banner alone
How Consently Handles the Website Side of Ecommerce GDPR
Consently covers the website side of ecommerce GDPR across the steps above. It scans your store for cookies and pixels, then blocks them before consent. It also shows a geotargeted banner, signals Google Consent Mode, keeps an audit-ready consent log, and generates your cookie and privacy policies.
It does not sign your other vendors' data processing agreements or fulfill data-subject requests. It also does not detect Global Privacy Control signals or run on a native mobile app. Those pieces stay outside a cookie consent platform's job. For the full ecommerce cookie-consent setup, see cookie consent built for online stores.
FAQs
Does GDPR apply to my online store if I am based in the US?
Yes, if your store processes the personal data of EU or UK residents and meets the Article 3(2) targeting test. Signals include pricing in euros or pounds, shipping to the EU or UK, and site content in an EU language.
Is my Shopify or WooCommerce store GDPR compliant by default?
No. The built-in cookie notice on most platforms displays a banner. It does not automatically block trackers before consent or keep an audit-ready consent record, and GDPR requires both.
Do I need consent to send abandoned-cart emails under GDPR?
Usually yes, since abandoned-cart emails are marketing, not transactional. The PECR soft opt-in can permit them to existing customers without fresh consent, if you offered an opt-out at collection and in every message. Adding an item to a cart alone is never consent.
What personal data does an ecommerce store collect under GDPR?
Order and checkout data, account details, analytics behavior, marketing and newsletter preferences, support chat records, and payment information passed through a processor. Each category needs its own lawful basis.
Do I need a cookie banner if I only use Google Analytics and the Meta Pixel?
Yes. Both are non-essential trackers under GDPR and ePrivacy rules. They require a banner that blocks them until the shopper consents, not just a notice that they exist.
Is my payment processor responsible for GDPR, or am I?
You are. Your payment processor is a sub-processor acting on your instructions, and you need a signed DPA with them. You remain the data controller and stay liable as the merchant.
What are the GDPR fines for an online store?
Fines can reach 20 million euros or 4 percent of global annual revenue, whichever is higher. CNIL's 150 million euro fine against SHEIN in September 2025 was specifically for trackers placed without consent.
How do I handle a customer's request to delete their data?
Verify the requester's identity, then locate their data across your store account, order history, email platform, and payment processor. Delete or anonymize what is not legally required for retention, and respond within one month under Article 12.
Do I need an EU representative for my online store?
Yes, if GDPR applies to your store and you have no EU establishment. Article 27 requires an EU representative with no small-business exemption, though this rule is widely under-enforced for stores with only occasional EU sales.
Ready to handle the website side of ecommerce GDPR? Consently scans your store for cookies and pixels, then blocks them before consent. It shows the right banner for each visitor's region, keeps an audit-ready consent log, and generates your cookie and privacy policies. Try Consently free to get started.
