ePrivacy Directive

The ePrivacy Directive is a set of rules for data protection and privacy in the European Union (EU). The directive is separate from the General Data Protection Regulation (GDPR), and contains additional requirements for European privacy protection. It regulates the storing and accessing of information on devices, such as cookies, email marketing, and other aspects of privacy.

The ePrivacy Directive requires that a website asks for the users' consent before storing cookies that are not strictly necessary for the basic functioning of the website in their browser. The directive also requires that users are told the general purpose of a cookie before they are asked to provide consent. This applies to both first-party cookies that are generated by your website and typically used for analytics, and third-party cookies that are typically generated by advertisers and used for marketing purposes. Both first- and third-party cookies can be used for analytics and advertising.

If you're a Shopify merchant operating in or with customers from the EU, EEA (European Economic Area, which consists of EU countries plus Iceland, Liechtenstein, and Norway), UK, or Switzerland, then you must ask visitors to your website for their permission to use cookies that are not strictly necessary for the basic functioning of the website. This can be done through a banner that loads when a visitor enters your online store. You can install Shopify's Customer Privacy Banner app, or browse the Shopify App Store for third-party privacy banners.

Merchants must choose between three options for how Shopify uses cookies to collect and store your visitors' data: Collected before consent, Partially collected before consent, and Collected after consent.

Options for online store data collection
Option Definition Impact
Collected before consent Data is collected before a customer gives consent. This may not meet applicable data protection and privacy laws, but has no impact on analytics and ad campaigns. No impacts to analytics or marketing data collection.
Partially collected before consent Analytics data collection is limited to the duration of a user session, and marketing data collection is blocked prior to customer consent. This option may impact analytics and marketing data, and analytics data collection can be reduced.

Selecting this option prompts you to install a privacy banner app.

Collected after consent (Recommended) Data is not collected until a customer gives consent. This may be required by applicable data protection and privacy protection laws, but may impact analytics and ad campaigns. Due to the potential of users declining to give permission to data collection, this option may impact analytics and marketing data. There can be a drop in the number of overall sessions. Other metrics that depend on accurate session counts for their calculation can also be affected, for example, conversion rate.

Selecting this option prompts you to install a privacy banner app.

Ready to start selling with Shopify?

Try it free