What do I need for GDPR on a dropshipping store?
Short answer
Eight things: a privacy policy naming every processor you use, a lawful basis for each purpose, consent collected before any non-essential cookie loads, an answer to any data access or deletion request within one month, a processing agreement with each vendor, transfer safeguards for processors outside the EEA, opt-in email marketing with no pre-ticked boxes, and breach notification within 72 hours.
| Requirement | What it means in practice | Cost |
|---|---|---|
| Privacy policy | Names every processor: platform, payments, analytics, email, supplier. | An hour |
| Lawful basis | Contract for orders, consent for marketing. Stated per purpose. | An hour |
| Cookie consent | Nothing non-essential loads before the visitor agrees. The Meta pixel is not essential. | Free app |
| Data subject requests | Access, correction, deletion and portability, answered within one month. | A working inbox |
| Processor agreements | A DPA with each vendor. Shopify and Klaviyo publish theirs; you accept them. | Free |
| International transfers | Standard Contractual Clauses for processors outside the EEA. | Usually in the DPA |
| Email marketing | Opt-in only. Pre-ticked boxes and bundled consent are invalid. | A checkbox setting |
| Breach notification | Report a qualifying breach to the regulator within 72 hours. | Know the number now |
What the GDPR requires of a small store selling into the EU or UK, and what each item costs you to do properly. General information, not legal advice.
It applies to you if you sell into Europe
The GDPR follows the customer, not the company. A store in Texas or Sydney running ads into Germany is covered for those customers, and “we are not an EU business” is not a defence.
The good news is that most of it is a one-afternoon setup rather than an ongoing burden, and the vendors you already use publish the documents you need.
The three that actually get people
Consent before the tag loads. This is the one most stores fail. A cookie banner that fires the Meta pixel as the page loads and then asks permission is not consent — the tag has to be blocked until the visitor agrees. Shopify has free consent apps that do this properly; installing one and leaving it in “notify” mode does not.
A privacy policy that names real processors. Not a template with placeholders. Your platform, your payment provider, your analytics, your email tool and anyone else who touches customer data, listed by name. This is also what payment providers check.
Answering requests within one month. Access, correction, deletion and portability. One month is the deadline, and the practical requirement is simply a monitored inbox and knowing how to export and delete a customer record in your platform. Do that once as a dry run before someone asks.
What dropshipping adds
Your supplier receives your customer’s name and address in order to ship the parcel. That makes them a recipient of personal data, and your privacy policy has to say so.
State it plainly: orders are fulfilled by suppliers located outside the EEA, and the customer’s shipping details are shared with them for that purpose. Vague wording about “third parties” is what turns a routine complaint into a real one, and the same honesty rule applies here as everywhere else on this site.
The email rule
Opt-in, unbundled, unticked. A checkout box that is ticked by default is not consent under the GDPR, and neither is “by ordering you agree to receive marketing”.
Use a separate, empty checkbox. Your list will be smaller and it will convert better, because the people on it chose to be there.
The records nobody keeps
The requirement people discover only when a regulator asks is documentation. Three things, none of which take long if you do them at launch:
- A one-page record of processing: what data you hold, why, where it goes and how long you keep it
- Consent logs, which your email tool already stores if marketing consent is collected properly
- A note of what you did, each time you answer an access or deletion request
None of that requires software. It requires a document you write once and update twice a year, and it is the difference between a routine questionnaire and a problem.
Where it sits in the launch
The privacy policy, cookie consent and refund policy all go live before your first campaign, not after your first complaint. They are the same step of the 10-step launch roadmap as the refund policy — and processors check for them before releasing a first payout, which makes this the rare compliance task with an immediate commercial reason to do it.
The broader picture of what is and is not lawful inside this model is in is dropshipping legal, and the tax side for EU sales is in EU dropshipping VAT.
The honest limit of this page
The GDPR is interpreted by national regulators, and the details — EU representatives, retention periods, what counts as a qualifying breach — depend on your setup and your volume.
This page covers the eight things every small store needs. It does not replace an adviser, and if you are processing anything beyond names, addresses and order history, get one.
General information, not legal advice. Data protection law is enforced nationally and changes — see our terms.
Related questions
Does the GDPR apply if my business is not in the EU?
Do I really need a cookie banner?
What happens if I ignore it?
This is one question out of a much longer guide. The full breakdown lives onthe 10-step launch roadmap, and you can run your own numbers in thebreak-even calculator.