Open the developer tools on most Shopify stores selling into Europe and you'll see the same thing. The cookie banner appears. Behind it, the analytics script, the Meta pixel and three app scripts have already fired.
That's the single most common compliance failure, and a banner doesn't fix it — it disguises it. Consent obtained after the tracking has started isn't consent. The banner exists to make the store look compliant, and in that specific sense it works, which is why nobody checks.
The broader issue is that the banner is one requirement among several, and the others are less visible. What data are you collecting and on what legal basis? What happens when a customer emails asking for everything you hold on them? Does every app touching your customer data have an agreement in place? Who finds out if there's a breach, and how quickly?
And it applies based on where your customers are, not where you are. A store in Melbourne selling to Berlin is in scope. That's the same reasoning that makes the European Accessibility Act your problem too, covered in accessibility and ADA compliance.
This is a practical guide, not legal advice. Data protection law varies by jurisdiction and continues to develop, and the consequences of getting it wrong are legal rather than technical. Use this to have a better conversation with a qualified adviser — not instead of one.




