Skip to content

What do I need for GDPR on a dropshipping store?

legalUpdated 2026-08-18

Short answer

Eight things: a privacy policy naming every processor you use, a lawful basis for each purpose, consent collected before any non-essential cookie loads, an answer to any data access or deletion request within one month, a processing agreement with each vendor, transfer safeguards for processors outside the EEA, opt-in email marketing with no pre-ticked boxes, and breach notification within 72 hours.

What the GDPR requires of a small store selling into the EU or UK, and what each item costs you to do properly. General information, not legal advice.
RequirementWhat it means in practiceCost
Privacy policyNames every processor: platform, payments, analytics, email, supplier.An hour
Lawful basisContract for orders, consent for marketing. Stated per purpose.An hour
Cookie consentNothing non-essential loads before the visitor agrees. The Meta pixel is not essential.Free app
Data subject requestsAccess, correction, deletion and portability, answered within one month.A working inbox
Processor agreementsA DPA with each vendor. Shopify and Klaviyo publish theirs; you accept them.Free
International transfersStandard Contractual Clauses for processors outside the EEA.Usually in the DPA
Email marketingOpt-in only. Pre-ticked boxes and bundled consent are invalid.A checkbox setting
Breach notificationReport a qualifying breach to the regulator within 72 hours.Know the number now

What the GDPR requires of a small store selling into the EU or UK, and what each item costs you to do properly. General information, not legal advice.

It applies to you if you sell into Europe

The GDPR follows the customer, not the company. A store in Texas or Sydney running ads into Germany is covered for those customers, and “we are not an EU business” is not a defence.

The good news is that most of it is a one-afternoon setup rather than an ongoing burden, and the vendors you already use publish the documents you need.

The three that actually get people

Consent before the tag loads. This is the one most stores fail. A cookie banner that fires the Meta pixel as the page loads and then asks permission is not consent — the tag has to be blocked until the visitor agrees. Shopify has free consent apps that do this properly; installing one and leaving it in “notify” mode does not.

A privacy policy that names real processors. Not a template with placeholders. Your platform, your payment provider, your analytics, your email tool and anyone else who touches customer data, listed by name. This is also what payment providers check.

Answering requests within one month. Access, correction, deletion and portability. One month is the deadline, and the practical requirement is simply a monitored inbox and knowing how to export and delete a customer record in your platform. Do that once as a dry run before someone asks.

What dropshipping adds

Your supplier receives your customer’s name and address in order to ship the parcel. That makes them a recipient of personal data, and your privacy policy has to say so.

State it plainly: orders are fulfilled by suppliers located outside the EEA, and the customer’s shipping details are shared with them for that purpose. Vague wording about “third parties” is what turns a routine complaint into a real one, and the same honesty rule applies here as everywhere else on this site.

The email rule

Opt-in, unbundled, unticked. A checkout box that is ticked by default is not consent under the GDPR, and neither is “by ordering you agree to receive marketing”.

Use a separate, empty checkbox. Your list will be smaller and it will convert better, because the people on it chose to be there.

The records nobody keeps

The requirement people discover only when a regulator asks is documentation. Three things, none of which take long if you do them at launch:

  • A one-page record of processing: what data you hold, why, where it goes and how long you keep it
  • Consent logs, which your email tool already stores if marketing consent is collected properly
  • A note of what you did, each time you answer an access or deletion request

None of that requires software. It requires a document you write once and update twice a year, and it is the difference between a routine questionnaire and a problem.

Where it sits in the launch

The privacy policy, cookie consent and refund policy all go live before your first campaign, not after your first complaint. They are the same step of the 10-step launch roadmap as the refund policy — and processors check for them before releasing a first payout, which makes this the rare compliance task with an immediate commercial reason to do it.

The broader picture of what is and is not lawful inside this model is in is dropshipping legal, and the tax side for EU sales is in EU dropshipping VAT.

The honest limit of this page

The GDPR is interpreted by national regulators, and the details — EU representatives, retention periods, what counts as a qualifying breach — depend on your setup and your volume.

This page covers the eight things every small store needs. It does not replace an adviser, and if you are processing anything beyond names, addresses and order history, get one.


General information, not legal advice. Data protection law is enforced nationally and changes — see our terms.

Related questions

Does the GDPR apply if my business is not in the EU?

Yes, if you offer goods to people in the EU. The regulation follows the customer, not the company, so a US or Australian store running ads into Germany is covered for those customers. Non-EU controllers may also need an EU representative depending on the scale and nature of the processing, which is a question worth putting to an adviser rather than a forum.

Do I really need a cookie banner?

If you load the Meta pixel, GA4 or any advertising tag for EU visitors, yes — and it has to block those tags until consent is given, not just announce them. A banner that sets cookies as the page loads and then asks is worse than no banner, because it documents the violation. Shopify has free consent apps that do the blocking properly.

What happens if I ignore it?

For a small store, the realistic first consequence is not a fine. It is a complaint to a regulator, a questionnaire you have to answer, and the discovery that you cannot produce records you never kept. Fines exist and scale with turnover, but the practical cost is the disruption and the fact that fixing it retroactively is much harder than doing it at launch.

This is one question out of a much longer guide. The full breakdown lives onthe 10-step launch roadmap, and you can run your own numbers in thebreak-even calculator.

Keep reading