Anyone setting up a Shopify store today receives more legal certainty under German law than most guides claim—and less than initial impressions might suggest. When setting up a new store, automated data protection settings are already enabled: there's a generated privacy policy, a cookie banner, and a page to disable data sharing, all without installing a single app. Shopify itself includes a statement that should be kept in mind: "Automated privacy settings are not a substitute for legal advice." The work discussed in this article lies precisely between these two extremes.
In August, we set up a German Shopify store from scratch, from the initial address to the legal texts, meticulously documenting what the platform handles and where manual intervention is required. The result was surprising: almost every field a German store needs is present. The gaps don't arise where a function is missing—but rather where an existing field remains empty or is populated with incorrect data.
To clarify: Our Shopify development services page answers questions about the costs of a Shopify project, the migration process, and when Shopify is the right choice compared to Shopware or WooCommerce ; a separate article on Shopware 6 and Shopify covers the technical system comparison from a developer's perspective. This article focuses exclusively on the legal setup of a German online store—what the platform offers, what you need to do yourself, and how you'll know you're doing it right.
What Shopify brings with it
A look at the settings of a newly created shop is more user-friendly than expected. Under the customer privacy section, three things are already set up: an automatically generated privacy policy in German, which names Shopify as the data controller and is kept synchronized with the shop settings; a cookie banner , which, according to Shopify, is automatically configured for visitors in the UK and the European Economic Area; and an opt-out page for data sharing. These automated settings are enabled by default for new shops.
The banner's design is remarkable. It displays "Accept" and "Decline" side-by-side, equally sized and prominent, along with a link to the settings—precisely the design that causes countless self-made and cheaply purchased banners to fail. Anyone familiar with the WordPress world knows the discussion: A banner with a pale and smaller "Decline" button than the "Accept" button is a classic recipe for legal trouble. The platform avoids this pitfall for you.
Shopify also offers more comprehensive legal texts than many expect. It maintains its own policy pages—for return policies, privacy statements, terms and conditions, shipping policies, subscription terms, and, explicitly, for the legal notice (Impressum ). The oft-repeated claim that "Shopify doesn't have a legal notice" is simply no longer true. The space is there. However, what it contains and whether it's accessible in your shop remains your responsibility—and that's precisely where the problems begin.
The gap is not the function, but the content.
The automatically generated privacy policy has one important characteristic to be aware of: it's compiled from your shop's master data. What you enter under shop address and contact details will then appear verbatim in the legal text. This is elegant as long as the master data is correct—and problematic if it isn't.
In the shop we set up in August, the contact section of the generated statement read something like this: “…please contact us by phone at , by email at …”. No phone number was provided, and the generator had dutifully inserted a comma at this point. Two lines later, a private email address was listed instead of the business address, and the street name contained a typo that was solely in the Shopify master data—the legal notice and legacy system had it correctly. Three errors in one paragraph, none caused by the platform, all made public by it.
This leads to a simple sequence that applies before every go-live: first, check the master data—company name, street, house number, city, telephone number, business email address—then proofread the generated texts, at least up to the contact section. Correct the source, not the text; the explanation will follow. Anyone who tries the other way around and corrects the text will have the error reappear the next time it's updated.
Legal notice: The field is there, Section 5 DDG decides on the rest.
The legal requirement for an imprint (Impressum) for online shops is now stipulated in Section 5 of the Digital Services Act (Digitale Dienstegesetz ) – the successor to the former Section 5 of the Telemedia Act (TMG). While the content itself has changed little, many imprints still refer to the old regulation; this is a small, cost-free point for modernization. Required information includes, among other things, the name and address, for legal entities the legal form and authorized representatives, an electronic contact option including an email address, the register number, for regulated professions the chamber and professional information, and the VAT identification number, if applicable.
The crucial clause, however, precedes this: This information must be "easily recognizable and directly accessible" at all times. This is precisely where Shopify stores regularly fail—not because of the content itself, but because of its accessibility. Shopify's policy pages are not automatically added to the menu. A completed legal notice that is only linked via the checkout footer, or not at all, does not meet the requirement. The solution takes two minutes: Open the footer menu, add the legal notice and privacy policy as menu items, then view the homepage and a product page while logged out and actually click the links.
A second, often overlooked point: The telephone number is not just a nice-to-have. It is not only a sign of trust, but also appears as mandatory information elsewhere – in distance selling regulations, in the very next section.
Cancellation policy: The template comes from the legislator, not the platform.
This is where the convenience ends. Shopify provides a space for return policies and even suggests a standard text—but a return policy is not the same as a cancellation policy . What a German online shop needs for distance selling is specified quite precisely in Article 246a § 1 of the Introductory Act to the German Civil Code (EGBGB) : the business must inform customers about "the conditions, time limits, and procedures for exercising the right of withdrawal" and also provide "the model cancellation form in Annex 2." They can fulfill this obligation by "transmitting the correctly completed model cancellation policy provided in Annex 1 in written form . "
Here's the good news: you don't have to invent anything. The official templates for the legal notice and form are available as appendices to the Introductory Act to the German Civil Code (EGBGB); they must be filled out correctly and uploaded to the online shop—as a separate page, linked in the footer, and also in text form with the order confirmation. Incidentally, the same regulation explicitly requires the inclusion of "your telephone number, your email address," and, if applicable, other online communication methods. Therefore, anyone who omits the telephone number from their online shop not only violates the legal notice requirements but also the information obligations for distance selling—and, incidentally, produces the legally generated text with the missing comma mentioned earlier.
In practical terms, this means that the cancellation policy, sample cancellation form, and terms and conditions are the parts where convenience doesn't pay off. We recommend having these three documents reviewed by a lawyer or using a well-maintained legal text service with regular updates—not because the templates themselves are complicated, but because their combination with your product range can be. Exceptions apply to digital content, custom-made items, and perishable goods, and these must also be clearly stated.
Base price: The field exists — however, only what someone enters is displayed.
Here too, the common claim is "it's not possible," and here too it's incorrect. Shopify supports base prices: You enter the total quantity and unit of measurement for each variant, and in every theme of the Online Store 2.0 generation, the base price then automatically appears on product and category pages, in the shopping cart, and at checkout . Only with older, vintage themes does the theme code need to be modified. The available units depend on the unit system in the general settings—for Germany, this is metric.
The obligation behind this is absolute. Section 4 of the Price Indication Ordinance is entitled "Obligation to Indicate the Unit Price" and requires that, for pre-packaged goods, the unit price must be indicated "unambiguously, clearly recognizably, and legibly" in addition to the total price ; for loose goods, the unit price alone is sufficient. Exceptions exist, for example, for quantities under ten grams or ten milliliters and for certain product categories—these are limited and do not replace a review of one's own product range.
The real stumbling block, therefore, isn't a technical one, but a problem of sheer volume: the field has to be filled for each variant. A shop with three hundred affected variants needs three hundred entries, and an empty line is a violation that no one notices—until someone does. Anyone migrating or importing should therefore include the two base price columns directly in the import file, instead of manually adding them later. It's precisely these kinds of details that explain why, in our ongoing Shopify project , we maintain the same product range once in WooCommerce and once in Shopify: the differences aren't in the feature lists, but in the required fields.
What no platform can do for you
Three things remain entirely your responsibility, regardless of the shop system . First, registration in the packaging register. Anyone shipping goods in packaging to private end consumers must register before the first shipment and report the quantities – including boxes and packing material. This isn't a shop setting, but rather a registration with a separate authority, and it's often overlooked because it's unrelated to the shop system.
Secondly, the data location. The hosting location for shop data can be viewed in the privacy settings; in the shop we set up, it was listed as the European Union. Actively check this setting instead of accepting it—and while you're at it, review the default data usage settings. In our case, a feature was enabled that uses customer data for product and advertising purposes within the Shopify network. It can be disabled; it just doesn't do so automatically.
And thirdly, the care you need with everything you add. Every app, every tracking script, and every embedded service expands the processing—and thus what must be included in the privacy policy and controllable in the consent banner. The automated policy knows Shopify and its standard features; it doesn't know about the chat widget you installed last week. We've described how to check your entire shop for compliance in a separate article about whether your shop is GDPR compliant.
The check before going live: one hour, eight steps
The following step typically uncovers most of the outstanding issues and takes about an hour for a typical online store. First: Open the master data and check the company name, address, phone number, and business email address character by character. Second: Read the generated privacy policy up to the contact section instead of just activating it. Third: Complete the legal notice according to Section 5 of the German Data Protection Act (DDG) – including the VAT identification number and registration details, if applicable. Fourth: Add the legal notice, privacy policy, terms and conditions, cancellation policy, and shipping information to the footer navigation and click on it while logged out.
Fifth: Insert the cancellation policy and sample cancellation form according to the official appendices and provide them in text form for the order confirmation. Sixth: Open the cookie banner in an incognito window from a German perspective and check whether "Reject" is displayed alongside "Accept"—and whether no tracking scripts actually load before consent is given. Seventh: Fill in the base prices for each variant and check on a category page whether they are displayed. Eighth: Place a real test order and read the confirmation email—the mandatory information must actually be received there.
Performing this process twice—once before going live and once four weeks later—also catches any changes that may have crept in through newly installed apps. This is the most common reason why a shop that was initially clean is no longer clean six months later.
Who wrote this post
Storetown Media is a Shopify agency based in Tornesch near Hamburg. We implement Shopify and Shopify Plus for German merchants and migrate them from WooCommerce, Shopware, or Magento. We're not an official Shopify partner – but we're someone who will also tell you when the platform isn't right for you.
Frequently asked questions about Shopify and German law
Do I need an additional app for the cookie banner in Shopify?
In most cases, no. Shopify provides its own cookie banner, which, according to the help center, is automatically configured for visitors in the European Economic Area and the UK and is active by default for new stores. It displays "Accept" and "Decline" options side by side. An app might be useful if you integrate many additional services, need more granular categorization of individual scripts, or want to comply with specific documentation requirements. In any case, always check in an incognito window to ensure that no tracking scripts are loaded before you give your consent.
Is the privacy policy generated by Shopify sufficient for a German online store?
It's a useful starting point, but not a viable final product. Shopify itself states that the automated privacy settings are not a substitute for legal advice and that you remain responsible for ensuring your privacy policy is correct. Two things are practically crucial: The text is generated from your master data, so any error there will be reflected verbatim in the legal text. And the policy only recognizes Shopify and its standard features—you have to manually add any additional apps or embedded third-party functions.
Where do I enter the legal notice in Shopify?
Shopify provides a dedicated policy page for this purpose; the legal notice is listed there alongside the return policy, privacy policy, terms and conditions, shipping policy, and subscription terms. The more important step comes next: the policy pages are not automatically included in the navigation. Section 5 of the German Data Protection Act (DDG) requires that the information be easily recognizable and directly accessible—so explicitly include the legal notice in the footer navigation and manually click the link while logged out.
How do I display the base price in a Shopify store?
Regarding the base price fields for each variant: You enter the total quantity and unit of measurement; the available units depend on the unit system in the general settings. In themes from the Online Store 2.0 generation, the base price then appears automatically on product and category pages, as well as in the shopping cart and checkout; older vintage themes require an adjustment in the theme code. The effort lies not in the technical aspects, but in the sheer number of entries: Each affected variant needs its own entry.
Does the phone number really need to be displayed in the shop.
Yes, from two directions. Article 246a § 1 of the Introductory Act to the German Civil Code (EGBGB) explicitly states that the telephone number and email address of the business must be provided as mandatory information for distance selling contracts, and § 5 of the German Data Protection Act (DDG) requires prompt electronic contact. Regardless of this, a reachable telephone number is one of the strongest signals of trust for first-time buyers, as consumer advice guides explicitly point this out. If it is missing from the basic information, gaps also arise in the automatically generated texts.
Is my shop's data stored in the EU?
This can be viewed in the shop's privacy settings—in the shop we set up, the European Union was listed as the hosting location. Don't rely on this assumption; actively check and, at the same time, review the default data usage settings: functions that use customer data for advertising and personalization purposes within the provider's network may be enabled by default and can be deactivated. For your own documentation, both should be included in the record of processing activities.
Conclusion: The platform provides fields, but not legal certainty.
Shopify has made significant strides regarding German law in recent years. Cookie banners, privacy policies, opt-out pages, an imprint slot, and base price fields are all available without requiring an app installation—this was different a few years ago, and it renders a good portion of older online guides obsolete. Anyone still claiming that Shopify can't handle an imprint or base price is describing a situation that no longer exists.
What the platform can't do is take responsibility. It doesn't fill in master data, it doesn't insert legal texts into the navigation, it doesn't write the cancellation policy, it doesn't enter base prices, and it doesn't register you anywhere. This isn't a weakness of the system, but rather the normal division of labor: The fields belong to the platform, the content belongs to you. And because all the fields are now available, a legally compliant German Shopify store is no longer a question of apps or budget —but of a careful hour before going live.
If you don't want to invest this hour yourself, or if you would like to have an existing shop reviewed, we will take care of it as part of our Shopify support — including migration from an old system, if that's what it comes down to.
What was the last problem you encountered?
Which of these points cost you the most time when setting up or moving a shop—the legal texts, the base prices, or the consent issue? We are particularly interested in cases where something only came to light months later.
And to everyone who has switched from another system: What legal aspects of the migration did you underestimate? Write them in the comments—the less spectacular answers are the most helpful here. For a specific project, you can reach us via the contact page.






















{% endif %} {% if title and title != "" %}
{{ title }}
{% endif %} {% if excerpt and excerpt != "" %}