GDPR for UK Shopify stores: what actually matters in 2026
On this page
- Does UK GDPR apply to my Shopify store?
- Who's who: you, Shopify, and your apps
- The obligations that actually apply (not just cookies)
- Where to start: effort vs exposure
- Why "we've got a cookie banner" is the trap
- How to check where you actually stand
- What getting this right actually buys you
- The bottom line
- Sources
Short answer: if you run a UK Shopify store, UK GDPR applies to you the moment you take a customer’s name and email — not when you hit some revenue threshold, and not only if you sell across borders. But it isn’t one big scary thing you buy your way out of with a banner. It’s a stack of specific, ownable obligations — and once you can see them laid out, each one is a task, not a threat.
Does UK GDPR apply to my Shopify store?
Yes. UK GDPR (the UK’s version of the EU regulation, retained after Brexit and sitting alongside the Data Protection Act 2018) applies to any organisation that processes personal data — information that can identify a living person. For a Shopify store that’s customer names, email addresses, delivery addresses, phone numbers, and order histories.
There’s no small-business exemption from the core principles. A sole trader shipping candles from a spare room is subject to the same data-protection principles as a large retailer. What changes with size is the scale of the obligation, not whether it exists.
Who’s who: you, Shopify, and your apps
Before the obligations, get the roles straight — because they decide who’s responsible for what.
You, Shopify, and your apps — three roles
The roles decide which paperwork you need. Get them straight before anything else.
You’re the controller: you decide why and how customer data is used, so the buck stops with you. Shopify is usually your processor for core store services, and most of your apps are processors acting on your instructions too — but a few (a payment provider running its own fraud checks, say, or certain add-on services) make their own decisions and are controllers in their own right. Getting that split right is what tells you which paperwork you actually need.
The obligations that actually apply (not just cookies)
Most store owners think “GDPR” and reach for a cookie banner. Cookies matter, but they’re one layer of a taller stack.
What actually applies to a UK Shopify store
Cookies are one layer. Each of these has a home elsewhere on this blog — this is the map.
UK GDPR Arts 13–14What you collect, why, who with, how long — matching realityPECR reg. 6Non-essential tags wait until the visitor agreesUK GDPR Art 28A DPA with every app that processes data on your behalfUK GDPR Art 5(1)(e)A reason to hold each type — and a point to deleteUK GDPR Art 15A copy of their data, usually within one calendar monthData protection feeRegister and pay the annual fee unless exemptEach layer has a home elsewhere on this blog — this guide is the map; the deep-dives are the territory: what a cookie banner does and doesn’t cover, why your privacy notice drifts out of date, which apps need an Article 28 DPA, and how to answer a subject access request in time.
Where to start: effort vs exposure
You can’t do everything at once, and you don’t need to. The trick is to spend your first hours where the risk is highest and the fix is cheapest — not on the thing that feels most visible.
Effort vs exposure — spend your first hours here
Do the high-exposure, low-effort fixes first. The visible thing (the banner) usually isn’t the highest-risk thing.
Honest note: this is general guidance to help a UK store owner get their bearings, not a verdict on your specific business or legal advice. Where a call is genuinely close — an unusual data flow, an international transfer, a contested processor role — check the ICO’s own guidance or a specialist. The point here is to make the invisible visible, not to replace advice on the hard cases.
Why “we’ve got a cookie banner” is the trap
A cookie banner is visible, cheap, and reassuring — which is exactly why it becomes the finish line in most people’s heads. But the parts that create real exposure are the invisible ones: the app you installed last quarter that now processes customer emails with no DPA on file; the privacy notice that hasn’t been updated since you changed payment providers; the marketing list you can’t prove people consented to.
This is the quiet problem for a growing store: compliance drifts. You add a tool, swap a courier, connect a new CRM — and the paperwork silently stops matching reality. Nobody warns you. It surfaces when a customer complains, a B2B buyer asks for your DPAs, or the ICO gets in touch — the point at which “we think we handled it” needs to become “here’s exactly how”.
How to check where you actually stand
You don’t need to read the regulation to find out whether your store has gaps.
Run these against your own store
You don't need to read the regulation to find the gaps — these six surface most of them.
Does it match what your store actually does today, not launch day?
Do non-essential tags really wait for consent on the live site?
Is there an Article 28 agreement for every app that processes data for you?
Do you have a reason to hold each data type, and a point to delete it?
Could you answer a subject access request within one month?
Are you registered and paying the data protection fee (unless exempt)?
The fastest first step is an outside-in check of the signals anyone — a customer, a partner, or a regulator — can already see from your public website: your privacy notice, cookie behaviour, security, and business identity. That’s exactly what GuardianStack’s free public check does, in about 30 seconds, with every finding shown in plain English and mapped to the rule it comes from. It’s read-only — it changes nothing on your store — and it’s the honest starting point before you spend money on tools or templates.
What getting this right actually buys you
The point isn’t optimising around fines — it’s that your business looks after its customers’ data and can prove it: you can answer a complaint calmly, hand a B2B buyer your data map, and treat a data request as a routine task. That readiness is the real return — not fear managed, but a business that runs on solid ground.
The bottom line
UK GDPR for a Shopify store isn’t one thing you can buy your way out of with a banner. It’s a handful of obligations — roles, notice, consent, processor contracts, retention, subject requests, registration — that have to keep matching a business that keeps changing. Get visibility first, fix the gaps that matter most, and keep an eye on the drift. That’s the whole game.
Sources
The primary sources behind this guide — check them yourself:
Frequently asked questions
Does UK GDPR apply to a small Shopify store?
Yes. UK GDPR applies to any business that handles personal data — names, emails, addresses, order history — regardless of size. A one-person Shopify store processing customer orders is in scope.
Is a cookie banner enough to be GDPR compliant?
No. A cookie banner addresses one obligation (consent for non-essential cookies under PECR). UK GDPR also covers your privacy notice, contracts with the apps that process your data on your behalf (Article 28 DPAs), data retention, and honouring data subject requests (usually within one calendar month).
Do I need to register with the ICO as a Shopify store?
Most UK businesses that process personal data must register with the ICO and pay the annual data protection fee, unless a specific exemption applies. The fee is tiered by size and turnover.
See where your store actually stands
Run a free outside-in compliance check of your website — no login required, results in about 30 seconds.
Run the free website check