- checkout b2b, compliance shopify, cookie banner, customer privacy api, garante privacy, partita iva footer, velocita e-commerce
- Francesco Guiducci
Shopify Compliance in Italy: Technical Privacy, Cookie and Data Checklist

Direct answer: no Shopify configuration can be declared universally “compliant”. Compliance depends on the business, products, markets, data processing, installed tools and documentation. My work is to verify and implement the technical layer; privacy, tax and legal positions must remain aligned with the guidance of the relevant professionals.
Privacy and cookies
I check which cookies and tracking tools load, what happens before and after consent, how choices can be withdrawn or changed and whether the banner matches the tools actually present.
The Italian Data Protection Authority guidelines require non-technical tracking tools not to activate without consent and state that the banner should not be presented indefinitely. One of the situations in which a new request may be shown is after at least six months have passed.
Pixels, analytics and apps
An app can introduce tracking even if the theme is configured correctly. For that reason the check must be performed on the real output of the site, not only on the CMP settings. I verify pixels, scripts, app embeds and marketing integrations.
Data collected at checkout
I do not rename address fields to automatically turn them into tax fields if the workflow produces ambiguous or hard-to-validate data. For tax codes, VAT numbers, certified email addresses or other data, I first verify the actual requirement, what Shopify supports on the plan being used and the integration with the system that will consume that data.
Business information and documentation
Company details, terms of sale, privacy, cookies, shipping and returns need to match the merchant's real operations. I do not generate “certified” policies or promise that a standard template automatically covers every obligation.
Performance and consent management
I measure the real cost of the banner and scripts; I do not claim that a specific CMP is lighter by a percentage without a verifiable source. If a solution introduces an LCP or INP issue, I work on the cause while preserving the required consent behavior.
Privacy source
For cookies and tracking, the reference is the Italian Data Protection Authority measure of June 10, 2021 and the related official documentation.
I’m Francesco Guiducci, a freelance Shopify expert and Shopify app developer. I work technically on Basic, Shopify and Advanced; my implementation does not replace legal or tax advice.
Updated September 3, 2026.

