vafer.app / blog

GDPR vs CCPA for Shopify merchants: opt-in vs opt-out, in plain language

Europe asks permission first; California asks forgiveness never — it demands an exit. GDPR is an opt-in regime: non-essential tracking may not run until the visitor agrees. CCPA and its sibling state laws are opt-out: tracking may run, but saying no must be one easy click, and it must actually work.

The practical differences, side by side

GDPR (EEA + UK)CCPA-style (California + other US states)
ModelOpt-in — consent before trackingOpt-out — tracking until objection
Defaults before choiceEverything non-essential OFFMay be ON
Required UIBanner with equal Accept / Reject“Do Not Sell or Share My Personal Information” link
Automatic signalsGPC must be honoured, no click needed
Pre-ticked boxesInvalidN/A (nothing to tick)
Applies to you whenYou have EEA/UK visitors, regardless of your sizeThresholds on revenue / data volume, varies by state

What this means for a Shopify banner

One banner shown identically to the whole world gets at least one region wrong. Show an opt-out banner to Germans and you're tracking EU visitors without consent; show a strict opt-in wall to Texans and you're paying a conversion cost no law asked of you. The pattern that fits both: resolve the visitor's region first, then apply that region's rule — opt-in with everything held for the EEA and UK, opt-out with the required link for the US, and a deliberate choice everywhere else.

Two traps merchants hit

The symmetric-buttons rule

EU regulators have repeatedly faulted banners where accepting takes one click but rejecting takes three. Reject must be as easy as Accept — same screen, same prominence.

The opt-out that doesn't do anything

A “Do Not Sell” link that sets a flag nobody reads is worse than none: it documents that you knew. The click has to flow into something enforced — on Shopify, that means writing sale_of_data: false to the Customer Privacy API and stopping the marketing trackers.

This is a plain-language orientation, not legal advice. Which specific laws bind your store depends on where you sell, your volumes and your setup — a privacy lawyer can tell you; a blog post can't.

Frequently asked

Do US visitors need a cookie banner at all?

US state privacy laws are opt-out: tracking may run by default, but California and a growing list of states require an easy way to object — commonly the “Do Not Sell or Share My Personal Information” link — and the choice must actually be honoured.

Can I show one global banner to everyone?

You can, but you are then either under-protecting EU visitors or over-asking everyone else. The cleaner pattern is per-region rules: opt-in for the EEA/UK, opt-out with the required link for the US, and your own choice elsewhere.

Is Global Privacy Control legally binding?

In California and several other states, yes — a GPC browser signal must be treated as an opt-out without requiring any click.

When a shopper says no, it means no.

Vafer is a cookie consent app for Shopify that holds known trackers until consent, deletes cookies on reject, and shows you proof it's working. Free in early access.

Join the waitlist

Keep reading