Guides

GDPR for UK Shopify stores: what actually matters in 2026

21 May 2026 5 min read GuardianStack
On this page

Short answer: if you run a UK Shopify store, UK GDPR applies to you the moment you take a customer’s name and email — not when you hit some revenue threshold, and not only if you sell across borders. But it isn’t one big scary thing you buy your way out of with a banner. It’s a stack of specific, ownable obligations — and once you can see them laid out, each one is a task, not a threat.

Does UK GDPR apply to my Shopify store?

Yes. UK GDPR (the UK’s version of the EU regulation, retained after Brexit and sitting alongside the Data Protection Act 2018) applies to any organisation that processes personal data — information that can identify a living person. For a Shopify store that’s customer names, email addresses, delivery addresses, phone numbers, and order histories.

There’s no small-business exemption from the core principles. A sole trader shipping candles from a spare room is subject to the same data-protection principles as a large retailer. What changes with size is the scale of the obligation, not whether it exists.

Who’s who: you, Shopify, and your apps

Before the obligations, get the roles straight — because they decide who’s responsible for what.

Concept · Who's responsible for what

You, Shopify, and your apps — three roles

The roles decide which paperwork you need. Get them straight before anything else.

controllerYou (the store)

You decide why and how customer data is used.

The buck stops here — accountability is yours.
processorShopify & most apps

Usually handle your core data on your instructions.

Need an Article 28 DPA with each.
controller?A few apps & services

Some apps — and some Shopify services — decide their own purposes.

Controllers in their own right — a different arrangement.
Source: ICO — Controllers and processors · UK GDPR Arts 4, 24, 28

You’re the controller: you decide why and how customer data is used, so the buck stops with you. Shopify is usually your processor for core store services, and most of your apps are processors acting on your instructions too — but a few (a payment provider running its own fraud checks, say, or certain add-on services) make their own decisions and are controllers in their own right. Getting that split right is what tells you which paperwork you actually need.

The obligations that actually apply (not just cookies)

Most store owners think “GDPR” and reach for a cookie banner. Cookies matter, but they’re one layer of a taller stack.

Framework · The obligation stack

What actually applies to a UK Shopify store

Cookies are one layer. Each of these has a home elsewhere on this blog — this is the map.

1A truthful privacy noticeUK GDPR Arts 13–14What you collect, why, who with, how long — matching reality
2Cookie consent before trackingPECR reg. 6Non-essential tags wait until the visitor agrees
3Processor contracts (DPAs)UK GDPR Art 28A DPA with every app that processes data on your behalf
4Data retentionUK GDPR Art 5(1)(e)A reason to hold each type — and a point to delete
5Subject access requestsUK GDPR Art 15A copy of their data, usually within one calendar month
6ICO registrationData protection feeRegister and pay the annual fee unless exempt
ONE STACK, SIX LAYERS Privacy notice Cookie consent Processor DPAs Data retention Subject access ICO registration a banner is one layer
Source: UK GDPR Arts 5, 13–15, 28 · PECR · ICO data protection fee

Each layer has a home elsewhere on this blog — this guide is the map; the deep-dives are the territory: what a cookie banner does and doesn’t cover, why your privacy notice drifts out of date, which apps need an Article 28 DPA, and how to answer a subject access request in time.

Where to start: effort vs exposure

You can’t do everything at once, and you don’t need to. The trick is to spend your first hours where the risk is highest and the fix is cheapest — not on the thing that feels most visible.

Analysis · Where to start

Effort vs exposure — spend your first hours here

Do the high-exposure, low-effort fixes first. The visible thing (the banner) usually isn’t the highest-risk thing.

Do first · high exposure, low effortMissing DPAs · stale privacy notice · marketing consent you can’t prove
Plan · high exposure, higher effortA real retention schedule · a data map across the whole stack
Quick win · low exposure, low effortICO registration · a findable privacy contact route
Later · low exposure, higher effortPolishing wording the average visitor never reads
Source: GuardianStack methodology · illustrative prioritisation

Honest note: this is general guidance to help a UK store owner get their bearings, not a verdict on your specific business or legal advice. Where a call is genuinely close — an unusual data flow, an international transfer, a contested processor role — check the ICO’s own guidance or a specialist. The point here is to make the invisible visible, not to replace advice on the hard cases.

A cookie banner is visible, cheap, and reassuring — which is exactly why it becomes the finish line in most people’s heads. But the parts that create real exposure are the invisible ones: the app you installed last quarter that now processes customer emails with no DPA on file; the privacy notice that hasn’t been updated since you changed payment providers; the marketing list you can’t prove people consented to.

This is the quiet problem for a growing store: compliance drifts. You add a tool, swap a courier, connect a new CRM — and the paperwork silently stops matching reality. Nobody warns you. It surfaces when a customer complains, a B2B buyer asks for your DPAs, or the ICO gets in touch — the point at which “we think we handled it” needs to become “here’s exactly how”.

How to check where you actually stand

You don’t need to read the regulation to find out whether your store has gaps.

Diagnostic · The highest-signal checks

Run these against your own store

You don't need to read the regulation to find the gaps — these six surface most of them.

1
Privacy notice

Does it match what your store actually does today, not launch day?

2
Cookie behaviour

Do non-essential tags really wait for consent on the live site?

3
App DPAs

Is there an Article 28 agreement for every app that processes data for you?

4
Retention

Do you have a reason to hold each data type, and a point to delete it?

5
Data requests

Could you answer a subject access request within one month?

6
ICO registration

Are you registered and paying the data protection fee (unless exempt)?

Source: UK GDPR · PECR · ICO — Guide to UK GDPR

The fastest first step is an outside-in check of the signals anyone — a customer, a partner, or a regulator — can already see from your public website: your privacy notice, cookie behaviour, security, and business identity. That’s exactly what GuardianStack’s free public check does, in about 30 seconds, with every finding shown in plain English and mapped to the rule it comes from. It’s read-only — it changes nothing on your store — and it’s the honest starting point before you spend money on tools or templates.

What getting this right actually buys you

The point isn’t optimising around fines — it’s that your business looks after its customers’ data and can prove it: you can answer a complaint calmly, hand a B2B buyer your data map, and treat a data request as a routine task. That readiness is the real return — not fear managed, but a business that runs on solid ground.

The bottom line

UK GDPR for a Shopify store isn’t one thing you can buy your way out of with a banner. It’s a handful of obligations — roles, notice, consent, processor contracts, retention, subject requests, registration — that have to keep matching a business that keeps changing. Get visibility first, fix the gaps that matter most, and keep an eye on the drift. That’s the whole game.

Sources

The primary sources behind this guide — check them yourself:

Frequently asked questions

Does UK GDPR apply to a small Shopify store?

Yes. UK GDPR applies to any business that handles personal data — names, emails, addresses, order history — regardless of size. A one-person Shopify store processing customer orders is in scope.

Is a cookie banner enough to be GDPR compliant?

No. A cookie banner addresses one obligation (consent for non-essential cookies under PECR). UK GDPR also covers your privacy notice, contracts with the apps that process your data on your behalf (Article 28 DPAs), data retention, and honouring data subject requests (usually within one calendar month).

Do I need to register with the ICO as a Shopify store?

Most UK businesses that process personal data must register with the ICO and pay the annual data protection fee, unless a specific exemption applies. The fee is tiered by size and turnover.

See where your store actually stands

Run a free outside-in compliance check of your website — no login required, results in about 30 seconds.

Run the free website check
← Back to all articles