Shopify privacy law · Germany
Shopify cookie consent in Germany
Germany applies GDPR with the strictest enforcement in the EU, plus its own TDDDG — Section 25 explicitly requires opt-in consent before any non-essential cookie. As of June 19, 2026, online stores selling to German consumers must also expose a persistent withdrawal button.
Governing law: GDPR + TDDDG (2024 successor to TTDSG)
- Free forever under 5k views/mo
- No credit card
- 5-minute install
Enforcement reality
Germany has 16 state-level Data Protection Authorities (one per Bundesland) plus a federal regulator (BfDI). The Bavarian DPA (BayLDA) and the Berlin DPA (BlnBDI) have been the most active against ecommerce. Enforcement is complaint-driven — once a complaint is filed (often by NOYB or vzbv), DPAs respond within weeks. Accept and Reject must have visually equal weight; consent logs must be verifiable and exportable. Effective June 19, 2026, a persistent 'withdraw consent' button is required on every page of any online store selling to German consumers — a change many Shopify merchants are still catching up to.
Regulator: Bundesbeauftragter für den Datenschutz und die Informationsfreiheit (BfDI)
Recent enforcement actions
- Notebooksbilliger.de·2021·€10.4M
Non-compliant employee surveillance + cookie consent issues
- Vodafone DE·2021·€9.5M
Inadequate verification for customer data access
What Shopify merchants must do in Germany
- Opt-in consent before any non-essential cookie or storage write — TDDDG Section 25 explicit
- Accept and Reject buttons of visually equal weight on the first layer (BfDI 2024 guidance)
- Persistent withdrawal button on every page — mandatory from June 19, 2026
- Verifiable, exportable consent log — required as evidence in DPA investigations
- Granular per-category consent (essential / functional / analytics / marketing)
- Imprint (Impressum) on every page including privacy contact details
- Double opt-in for email marketing (de-facto standard, defends against UWG claims)
- Privacy policy in German, listing every processor and the lawful basis
- Honour Art. 22 GDPR — no fully-automated decision-making (e.g., dynamic pricing) without explicit consent
How Consentico handles Germany
Consentico's geo-targeting detects Germany visitors at the edge and applies the right banner — opt-in posture for EU/UK rules, with Google Consent Mode v2 signals and a per-decision audit log. The banner survives Shopify theme switches and uninstalls cleanly.
Related concepts
- GDPREU regulation governing how organisations process personal data of EU/EEA residents. Applies to any Shopify store with EU visitors.
- ePrivacy DirectiveEU directive (2002/58/EC, amended 2009) requiring opt-in consent for cookies and similar storage. Enforced together with GDPR.
- Consent (GDPR)Freely given, specific, informed, and unambiguous indication of agreement. No pre-checked boxes, no implied consent from continued browsing.
- Lawful basisUnder GDPR, you must have one of six legal grounds to process personal data. For ecommerce: contract, legitimate interest, or consent.