Shopify privacy law · Netherlands
Shopify cookie consent in Netherlands
The Dutch DPA (Autoriteit Persoonsgegevens) requires the first-layer banner to explicitly state what data is collected and whether it's shared with third parties. AP investigations of the top-100 Dutch sites found 70%+ non-compliant; the first major cookie-specific fine is expected in 2026.
Governing law: GDPR + Dutch Telecommunications Act (Article 11.7a — cookie provision)
Enforcement reality
The Autoriteit Persoonsgegevens (AP) received a €53.5M enforcement budget for 2025-2026, roughly doubling its capacity. Late-2025 guidance requires the first-layer cookie banner to state (a) what categories of data are collected, and (b) whether that data is shared with third parties — not just link to the privacy policy. Sweep of top-100 Dutch consumer sites found 70%+ non-compliant with either the Accept/Reject equivalence rule or the first-layer disclosure requirement. AP has stated it will begin issuing formal warnings in Q4 2026, escalating to fines by mid-2027. NOYB has filed several complaints against Dutch e-commerce operators; the AP has confirmed it treats these as priority.
Regulator: Autoriteit Persoonsgegevens (AP)
Recent enforcement actions
- Booking.com·2024·€475,000
Failure to notify the AP of a data breach within 72 hours
- Uber Netherlands·2024·€290M
Unlawful transfer of driver data to the US (not cookie-specific but signals AP's willingness to fine)
What Shopify merchants must do in Netherlands
- Opt-in consent before non-essential cookies (Article 11.7a Dutch Telecommunications Act)
- First-layer banner must state what data is collected and whether shared with third parties (AP 2025 guidance)
- Accept and Reject visually equivalent on the first layer
- Privacy policy in Dutch if you target Dutch customers
- Named third-party recipients — 'partners' is not sufficient, name them
- DSAR response within 30 days, free of charge
- Honour AVG (Dutch acronym for GDPR) right-to-object immediately
How Consentico handles Netherlands
Consentico's geo-targeting detects Netherlands visitors at the edge and applies the right banner — opt-in posture for EU/UK rules, with Google Consent Mode v2 signals and a per-decision audit log. The banner survives Shopify theme switches and uninstalls cleanly.
Related concepts
- GDPREU regulation governing how organisations process personal data of EU/EEA residents. Applies to any Shopify store with EU visitors.
- ePrivacy DirectiveEU directive (2002/58/EC, amended 2009) requiring opt-in consent for cookies and similar storage. Enforced together with GDPR.
- Consent (GDPR)Freely given, specific, informed, and unambiguous indication of agreement. No pre-checked boxes, no implied consent from continued browsing.
- DSARData Subject Access Request — when an EU/UK resident asks you for a copy of, or deletion of, their personal data.
Compliant in Netherlands — in five minutes.
Free for stores under 5,000 banner views per month. No code, no theme edits.