This guide explains the technical setup. It is not legal advice: for your privacy policy and data processing, speak to a solicitor or data protection adviser.
The rules in plain terms
- Cookies that are strictly needed for the store to work, like the cart and checkout, do not need consent.
- Analytics, advertising and most marketing cookies do need consent, given before they load.
- Rejecting must be as easy as accepting. A big “Accept all” next to a hidden “Settings” link is not a fair choice.
- No pre-ticked boxes, and no “by continuing to browse you agree”.
- In Ireland, the Data Protection Commission’s cookie guidance also says consent should not be assumed to last forever; asking again after around six months is a sensible default.
1. Turn on Shopify’s own cookie banner
Shopify has a built-in cookie banner under Settings → Customer privacy. It connects to Shopify’s Customer Privacy API, which is what Shopify’s own analytics, the Google and YouTube app, the Facebook and Instagram app and many other apps listen to. Set it to show to visitors in the EU and UK, and include a clear reject button.
If you use a third-party consent app instead, check it passes the shopper’s choice to the Customer Privacy API. If it doesn’t, your apps cannot see the choice and keep tracking anyway.
2. Find tracking that ignores consent
The banner only controls the tags that ask it for permission. Code pasted straight into the theme usually doesn’t ask. Look for:
- Google Analytics or Google Ads tags hard-coded in
theme.liquid. - A Meta pixel added by hand on top of the Facebook and Instagram app, which also double-counts purchases.
- Old scripts in Settings → Checkout or in the order status page, left over from previous apps.
- Chat widgets, heatmaps and review apps that set their own cookies.
Move tracking into Shopify’s customer events (pixels) or the official apps, which respect consent, and delete the hard-coded copies.
3. Set up Google Consent Mode v2
Since March 2024, Google requires Consent Mode v2 for advertisers who want remarketing and conversion measurement for users in the European Economic Area. Without it, your Google Ads audiences shrink and conversions go missing. The Google and YouTube app on Shopify supports Consent Mode and reads the shopper’s choice from Shopify’s privacy settings, so with the built-in banner this is mostly a case of connecting the official app instead of pasting tags.
4. Test what actually loads
- Open the store in a private window from an EU location, or with a VPN set to Ireland.
- Before clicking the banner, open the browser’s developer tools and check the Network tab. No requests should go to Meta, Google Ads, TikTok or analytics tools.
- Click reject and browse a few pages. Still nothing should fire.
- Open a new private window, click accept, and check the tags now load and record a page view.
5. Email marketing consent is separate
- Cookie consent does not give you permission to send marketing emails.
- Use an unticked box at checkout or signup for marketing emails, and record who ticked it. Shopify stores this on the customer record.
- Existing customers can sometimes be emailed about similar products without a fresh opt-in, provided they had a clear chance to opt out, but check this with your adviser.
- When moving from another platform, only import customers who opted in as subscribed.
Common mistakes
- A banner with “Accept” and “Close”, where closing still loads every tag.
- A banner that only shows on the home page, while shoppers from Google land straight on product pages.
- A privacy policy that doesn’t list the apps and tools the store actually uses.