Skip to main content

Global Privacy Control on Shopify: what US stores actually have to do in 2026

Twelve states now require honoring universal opt-out signals, and Shopify honors GPC automatically — but only in the regions you configured. If you never opened that screen, nothing is being honored.

· 9 min read

Cover for the article on Global Privacy Control and Shopify, showing that twelve US states require honoring universal opt-out signals

Shopify honors the Global Privacy Control signal automatically. That sentence is true, and it is the reason a lot of US merchants believe they are done.

Read the rest of it. Shopify’s documentation says that when the GPC header is present, it activates opting out of data sale or sharing or targeted advertising “in regions using the data sharing opt-out page.” Regions you configured. If you never opened Settings › Customer privacy and set up the US regions, there is no configured region, and the signal arriving in your visitors’ browsers is not doing anything.

Automatic, once you turn it on, is not the same as automatic.

The map, briefly

As of August 2026, twenty US states have comprehensive consumer privacy laws in effect. Indiana, Kentucky and Rhode Island joined on January 1, 2026.

Twelve of those states require sites to honor universal opt-out signals like GPC: California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon and Texas.

The detail that catches small merchants off guard: Texas and Nebraska have no revenue or consumer-volume threshold. Most state laws only reach you above something like $25M in revenue or 35,000–100,000 consumers. Texas and Nebraska instead apply if you do business there or serve residents there and process or sell personal data — with a carve-out for businesses that meet the SBA’s small-business definition.

That carve-out matters and we are not going to wave it away: it is a real exclusion and it is fact-specific. But “we’re too small for privacy law” stopped being a safe assumption, and whether the carve-out covers you is a question for a lawyer, not for a blog post. This one included.

Most cure periods — the grace window to fix a violation after being notified — have expired. California’s is discretionary. Rhode Island never had one.

What Shopify actually does

Credit where due: Shopify built more of this than most platforms, and it is worth knowing exactly where the line falls.

The Customer Privacy API is a browser-side JavaScript API that applies consent decisions to Shopify-managed surfaces — pixels, audiences, and checkout. You read consent with four methods:

  • analyticsProcessingAllowed()
  • marketingAllowed()
  • preferencesProcessingAllowed()
  • saleOfDataAllowed()

You can also listen for the visitorConsentCollected event to react when a visitor changes their mind, and record decisions with setTrackingConsent().

The GPC signal is collected and honored automatically, and it cannot be adjusted through setTrackingConsent(). That last part is the most important sentence in the documentation and almost nobody quotes it. It means no banner, no “Accept all” button, and no clever app can override a visitor’s GPC signal. If someone arrives with GPC on, the opt-out stands. By design.

Where the line actually falls

Here is what the automation does not cover, and where we keep finding gaps when we look at real stores.

Your own scripts. Consent applies to Shopify-managed surfaces. A tracking script you or a previous developer pasted into theme.liquid is not a Shopify-managed surface. It fires when the page loads, consent or no consent, unless it was written to check the Customer Privacy API first. Most pasted snippets were not.

Apps that predate the API. An app installing its own tag is only compliant if it uses the API. Some do. Some do not. The only way to know is to load your storefront with GPC enabled and watch what actually fires.

The gap between “configured” and “correct.” Publishing a privacy policy is a prerequisite before Shopify will let you enable the banner or opt-out page at all. Having enabled it is not evidence that the regions you serve are the regions you configured.

This is the same lesson we learned on our own site and wrote into our internal notes: a privacy policy is not written by reading your code, it is written by reading what the browser actually downloads on the published page. Hosting platforms and apps inject things that are not in your repository. Open your live store and check.

The part that makes this a measurement problem

Now the consequence nobody puts in the compliance articles.

Every honored opt-out is a customer you cannot measure in the browser. As GPC adoption grows and twelve states make honoring it mandatory, a rising share of your US traffic becomes legitimately invisible to your pixel. Your Meta reports will show fewer conversions than your Shopify admin does, and the gap will widen over time.

That gap is not a bug. It is the system working. And it changes how you should read your own numbers: a declining browser-measured conversion count is not automatically a performance problem, and treating it as one leads people to “fix” campaigns that were never broken.

One thing we want to be unambiguous about, because we have heard it pitched the other way: the Conversions API is not a way around consent. Server-side events must respect the same opt-out signal as browser events. Anyone selling you server-side tracking as a method to recover opted-out users is describing something you should not buy.

What server-side measurement does fix is the other category of loss — ad blockers, browser tracking prevention, dropped requests from consenting users. Those are real and worth recovering. Conflating them with consent losses is how honest tooling gets sold dishonestly. We wrote the full guide to the pixel and the Conversions API in Spanish if you want the mechanics.

The checklist

  1. Open Settings › Customer privacy and look at which regions are configured. Not whether the feature is on — which regions.
  2. Load your live storefront with GPC enabled in your browser and watch the network tab. What still fires is your actual answer.
  3. Audit scripts in theme.liquid and anything a past developer pasted in. Each one either checks the Customer Privacy API or it does not.
  4. List your installed apps that set tags and check each one’s consent behavior. The ones that cannot tell you are the ones to worry about.
  5. Confirm your privacy policy is published and accurate, in the sense of describing what actually runs — not what you intended to run.
  6. Recalibrate expectations for your reports before the gap surprises you in a quarterly review.
  7. Ask a lawyer whether the states you sell into reach you, and whether the small-business carve-outs apply. That question is genuinely fact-specific.

What we are not telling you

We are not lawyers and this is not legal advice. Thresholds, carve-outs and enforcement priorities vary by state and change, and whether any of this applies to your business depends on facts we do not have.

What we can tell you with confidence is the technical half: what Shopify honors, what it does not, and where the scripts on your own storefront are quietly ignoring a signal you are supposed to be respecting. That part is checkable in twenty minutes, and it is usually where the actual gap is.

If you want us to look at what your storefront really fires, the first round of our technical audit is free. If you would rather have it built right, here is how we build Shopify stores and how we run Meta Ads on top of measurement we trust.


Verified August 27, 2026. State counts and requirements change; confirm current status before acting.

Sources: Shopify Help Center — Configuring customer privacy settings · Shopify — Customer Privacy API · Enzuzo — US State Privacy Laws 2026 tracker · Consenteo — US state privacy law tracker 2026

Free technical audit

Forty-eight hours, everything public about your brand, zero sales deck.

Leave your email and we will send you the report. We tell you what we find, whether or not it leads to hiring us.

The signup form needs marketing cookies, which you have not accepted yet. You can enable them from the cookie notice, or simply write to us:

← Back to the blog

Start here

Shall we start by finding out what is happening with your store?

The first round of the technical audit is free and commits you to nothing: we review everything public about your brand without asking for a single login, send you the report within 48 business hours and read it together in half an hour. If you don’t need to hire us yet, we will tell you.