Key Takeaways
- The question is not how many languages you can afford. It is whom you target. The Article 29 Working Party's transparency guidelines put it in a single parenthesis: "(A translation in one or more other languages should be provided where the controller targets data subjects speaking those languages.)"
- Those guidelines define targeting with three signals a merchant switches on deliberately: operating "a website in the language in question", offering "specific country options", or facilitating "the payment for goods or services in the currency of a particular member state".
- The Dutch DPA fined TikTok Inc. €750,000 by decision of 9 April 2021 on this point alone: its privacy policy was served to Dutch users in English only between 25 May 2018 and 28 July 2020, contrary to Article 12(1) GDPR.
- TikTok argued that Dutch users read English well, citing the Netherlands' top-three placing in the EF English Proficiency Index since 2011. The regulator's answer was that this "does not change" the position.
- The EDPB has a name for the failure — Language Discontinuity — and its analysis is blunt: where the service speaks the country's language but the data-protection information does not, the Article 13 and 14 information "cannot be considered to have been given to data subjects."
Introduction
Your store sells into Estonia. The market is switched on, prices render in euros, the theme is translated, and checkout speaks Estonian. Then the cookie banner loads — in English — and so does the privacy policy sitting behind it.
Nobody decided that. It is what the defaults produce. It is also the moment a carefully localised store stops being localised, in the one place where being understood is a legal requirement rather than a conversion tactic.
The uncomfortable symmetry is this: the same settings that made your shop reach Estonian shoppers are the settings a regulator reads as evidence that you targeted them. This article works through the actual test for when a translation is owed, what Europe's clearest decision on the point held, and exactly where platform auto-translation stops. It is informational content, not legal advice.
Does Your Cookie Banner Have to Be in the Shopper's Language?
If you target shoppers who speak that language, yes. The Article 29 Working Party's transparency guidelines say a translation "should be provided where the controller targets data subjects speaking those languages", and the test for targeting is commercial: the language you sell in, the country options you offer, and the currency you take.
The test is targeting, not translation budget
The guidance sits in paragraph 13 of the transparency guidelines (WP260 rev.01), endorsed by the EDPB, and most of the paragraph is about writing plainly. The language obligation arrives almost as an aside: "(A translation in one or more other languages should be provided where the controller targets data subjects speaking those languages.)"
The word doing the work is targets, and the guidelines footnote it: "For example, where the controller operates a website in the language in question and/or offers specific country options and/or facilitates the payment for goods or services in the currency of a particular member state then these may be indicative of a data controller targeting data subjects of a particular member state."
Read that as a merchant rather than a lawyer and it stops being abstract. A translated storefront, a country selector, local-currency pricing — that is a market configuration, and every eCommerce platform ships it as a feature.
Recital 23 GDPR uses the same signals to decide whether the Regulation applies to a non-EU controller at all: "the use of a language or a currency generally used in one or more Member States with the possibility of ordering goods and services in that other language, or the mentioning of customers or users who are in the Union, may make it apparent that the controller envisages offering goods or services to data subjects in the Union."
Our position: if you have opened a market, you have already answered the targeting question. A store that translates its product pages into Italian and prices in euros to sell in Italy cannot coherently argue it does not target Italian speakers when the subject turns to its privacy notice. The trade-off is genuine — translation costs money and creates versions to maintain — but the decision was made upstream, when someone in marketing enabled the market.
What "intelligible" demands of a consent banner
A cookie banner is doing two legal jobs at once, and both are drafted in the same words. Article 12(1) requires the controller to provide Article 13 and 14 information "in a concise, transparent, intelligible and easily accessible form, using clear and plain language, in particular for any information addressed specifically to a child". Article 7(2) requires a consent request to be "presented in a manner which is clearly distinguishable from the other matters, in an intelligible and easily accessible form, using clear and plain language".
The EDPB's consent guidelines set the standard for that language at paragraph 67: "When seeking consent, controllers should ensure that they use clear and plain language in all cases. This means a message should be easily understandable for the average person and not only for lawyers."
And paragraph 70 tells you who "the average person" is: "A controller must assess what kind of audience it is that provides personal data to their organisation... After identifying their audience, controllers must determine what information they should provide and, subsequently how they will present the information to data subjects."
That is the whole argument in miniature. Intelligibility is measured against your audience, not against your drafting effort. A banner can be a model of plain English and still fail Article 12(1) for a shopper who does not read English — the same way a banner that buries its vendor list fails the informed-consent test even when every word is grammatical. We have looked at that second failure mode in detail in our analysis of what a cookie banner's vendor list does to informed consent.
What the €750,000 TikTok Fine Actually Decided
In a decision dated 9 April 2021, the Dutch data protection authority fined TikTok Inc. €750,000. The finding was narrow and unusually clean: between 25 May 2018 and 28 July 2020, TikTok provided its privacy policy to Dutch users — including children — in English only. The regulator held that this breached Article 12(1) GDPR. TikTok moved its Dutch policy into Dutch from 29 July 2020, and added a separate document written for Dutch-speaking children. The lesson for a store is not about video apps: it is that a regulator has already treated "we published it, just not in their language" as a standalone infringement.
The "everyone speaks English" defence, and why it failed
TikTok made the argument every merchant makes in the meeting where this comes up. Dutch users, it said, have a good command of English — noting that the Netherlands has ranked in the global top three of the EF English Proficiency Index since 2011.
The regulator's rejection is the passage worth keeping. In the decision's own words, at paragraph 98: "Het vereiste van begrijpelijkheid vergt ten minste dat wanneer de verwerkingsverantwoordelijke zich richt tot betrokkenen die een andere taal spreken, zij een vertaling in die taal aan die betrokkenen verstrekt." Working translation: the requirement of intelligibility demands, at a minimum, that where the controller addresses itself to data subjects who speak another language, it provides them with a translation into that language.
On the proficiency statistics: "De omstandigheid dat een relatief grote groep Nederlanders het Engels goed beheerst maakt dit niet anders" — the fact that a relatively large group of Dutch people command English well does not change the position — "zeker niet nu TikTok wordt gebruikt door veel personen onder de 16 jaar", since TikTok is used by many people under 16, for whom good English "is niet vanzelfsprekend", is not self-evident.
Why TikTok's other measures did not save it
TikTok pointed to in-app pop-up notifications, its Help Centre and Safety Centre, and a Dutch-language summary of its policy rolled out in July 2020. None of it worked, and the reasoning transfers directly to a storefront.
The pop-ups, the regulator accepted, genuinely improved transparency — but they "zijn geen vervanging van haar privacybeleid", are no substitute for the privacy policy, because they did not carry all the information Article 13 requires. The Help and Safety Centre failed for a different reason: users are only informed there "als ze zelf actief naar informatie gaan zoeken", once they actively go looking, which risks their not being informed in time.
Translate that to a shop and two common fixes lose their shine. A translated FAQ page is the Help Centre problem. A short localised blurb on the banner with the full policy left in English is the pop-up problem.
How far this travels to an online shop
Honesty about the limits matters more than a scarier headline. This decision is anchored in a child audience, and the regulator leans on that: it reached its finding via the transparency guidelines' know-your-audience rule, and its reasoning on English proficiency turns specifically on users under 16. An adult-facing homeware store is not identically placed, and any consultant who tells you the €750,000 transfers one-to-one is selling something.
What does transfer is the second sentence of paragraph 98, which states the intelligibility rule in general terms — after an opening sentence framing the breach around Dutch-speaking children under 16, and before a third that applies the rule "in particular" to children. Our read: the child-audience facts affect how severely a regulator treats the failure, not whether an untranslated notice is capable of being one. No European authority has yet fined a merchant over the language of a cookie banner specifically — we looked, and found commentary rather than decisions. That is a real gap in the enforcement record, and it is the honest reason to treat this as a risk to manage rather than a fire to put out.
Language Discontinuity: The EDPB's Name for an English-Only Banner
The EDPB catalogued this exact failure as a deceptive design pattern. In Guidelines 03/2022 on deceptive design patterns, Annex I checklist item 4.5.4 is called Language Discontinuity, and it opens with the rule: "When online services are offered and addressed to residents of certain Member States, the data protection notices should also be offered in these languages."
The trigger the EDPB describes will be familiar: "Users will face this deceptive design pattern when data protection information is not provided in the official languages of the country where they live, whereas the service is provided in that language."
Its worked example splits into two variations, and both have storefront equivalents.
Variation A is a service available in Croatian while all or some data-protection information is available only in English. The EDPB's analysis: "Information cannot be considered intelligible as required in Article 12 (1) GDPR. Due to the lack of data protection information in the understandable language, the information required under Article 13 respectively 14 GDPR cannot be considered to have been given to data subjects." Not "given badly" — not given.
Variation B is subtler and, on a multi-market storefront, easier to ship by accident: pages that automatically switch to the language of the country the user is in, overriding a language they explicitly chose, so they must reset the preference every time they open a data-protection page. The EDPB says this "can be considered as an unfair practice towards data subjects and could contribute to a breach of the principle of fairness of Article 5 (1) (a) GDPR." Geo-detection that outranks a shopper's own selection is a common storefront default.
One scope caveat, stated fully because leaving it out would be exactly the overreach this article is arguing against. These Guidelines address social media, and say so: they "focus solely on deceptive design patterns in social media platforms." The EDPB also says, in the same document, that "deceptive design patterns are not unique to social media platforms" and that interfaces raising the same issues "may include websites and cookie banners, online shops, video games, mobile applications and micropayments etc." So this is highly persuasive reasoning about what Article 12(1) intelligibility means, applied to an interface type the EDPB expressly names — not a rule written for your shop.
What Your Platform Translates, and What It Leaves You
Platform coverage is the part merchants get wrong, because partial automation feels like completion. Shopify's own documentation is specific enough to check yourself.
On 16 May 2024, Shopify's changelog announced: "When customers visit your store, the Shopify cookie banner will now be shown in their native language. These translations can be customized at any time by a translation app, such as the Shopify Translate & Adapt app. To help you get started, we have provided translations of our default banner text in 32 languages."
The Help Center now states: "The following languages have professional translations available for checkout, cookie banner, privacy policy, data sales opt-out page, and default content for themes built by Shopify", followed by a list of 33 languages.
Count that list against the EU's own and a gap appears.
| Fact | Number |
|---|---|
| Languages with Shopify professional translations | 33 |
| Official EU languages | 24 |
| Official EU languages on Shopify's list | 20 |
| Official EU languages absent from it | 4 — Estonian, Irish, Latvian, Maltese |
That arithmetic is just the two published lists compared: Shopify's 33 languages include Bulgarian, Croatian, Czech, Danish, Dutch, English, Finnish, French, German, Greek, Hungarian, Italian, Lithuanian, Polish, Portuguese, Romanian, Slovak, Slovenian, Spanish and Swedish — and not Estonian, Irish, Latvian or Maltese. A store with an active Estonian, Latvian or Maltese market gets no professional banner translation from the platform at all.
Our position: automatic banner translation is the most dangerous kind of partial fix, because it removes the visible symptom. The banner is the surface a merchant checks. Once it renders in Estonian, nobody scrolls to the preference centre, the withdrawal path, the DSAR form, or the marketing-consent line at checkout. Shopify's documentation says what it translates; it does not say what happens to policy text a merchant wrote themselves, so treat your own edits as uncovered until you have opened the store in that locale and looked. If you run a third-party consent app rather than the native banner, the whole question moves to that app, and its language list is the one that matters.
How to Decide Which Languages You Owe
- List your live markets. Not aspirations — the markets, currencies and storefront languages actually enabled today. This is the same list your finance team already has.
- Apply the three targeting signals to each. Storefront in that language, country options offered, payment accepted in that Member State's currency. One is indicative; all three together are hard to argue with.
- Inventory the surfaces, not the pages. Cookie banner, preference or settings centre, withdrawal path, privacy policy, DSAR intake form, marketing consent text at checkout and signup, and the transactional emails that carry privacy wording.
- Check what the platform covers, per surface, in the store itself. Open the storefront in that locale and read what a shopper sees. Documentation tells you what should happen; the rendered page tells you what does.
- Translate the load-bearing sentences first if you cannot do everything at once: controller identity, the purposes, what data is collected, and how to withdraw. Those are elements EDPB guidance (Guidelines 05/2020, paragraph 64) treats as the floor for informed consent, and they are a small fraction of a policy's word count.
- Record which language version was shown. A consent record that cannot say what the shopper was actually asked, in which language, on which date, is hard to defend two years later — which is the whole point of keeping proof-of-consent records.
Common Mistakes
Translating the banner and stopping. This is the worst one, and the most common, precisely because platforms have automated the visible half. The banner is a doorway; the obligations live behind it in the preference centre and the policy.
Letting geo-detection override an explicit language choice. The EDPB's Variation B addresses this directly, and it is usually an accident of storefront configuration rather than a decision anyone made.
Machine-translating a policy and shipping it unread. The transparency guidelines are explicit that where information is translated, the controller "should ensure that all the translations are accurate and that the phraseology and syntax makes sense in the second language(s) so that the translated text does not have to be deciphered or re-interpreted". A machine-translated legal notice that reads like one has swapped a language problem for a clarity problem, and Article 12(1) covers both.
Arguing from proficiency statistics. A regulator has heard that argument, from a party with better statistics than yours, and rejected it.
Assuming a short localised summary discharges the duty. TikTok's Dutch summary and its pop-ups did not compensate for the untranslated policy — the pop-ups specifically because they did not carry everything Article 13 requires. Summaries are a good addition and a poor substitute.
How PrivacyForge Helps
Most of the work above is inventory rather than law: which surfaces exist, which markets are live, and which combination a given shopper actually saw.
PrivacyForge's consent management keeps a timestamped record of each consent, including the purposes presented and the banner version in force, so an audit two years later can establish what a shopper was asked rather than what today's configuration implies. Region-aware banner text means the version shown can follow the visitor's region rather than a single global default. The data mapping module holds each processing activity with its purposes and recipients, which is the source text you translate once and reuse across surfaces instead of maintaining five drifting copies. Compliance scoring then surfaces the mismatch that matters here: markets that are live without the corresponding privacy surfaces being in place.
None of that writes your Estonian privacy policy. It tells you that you owe one, and records which version each shopper was shown.
Frequently Asked Questions
Does my cookie banner need to be in the local language?
If you target shoppers who speak that language, yes. The Article 29 Working Party's transparency guidelines say a translation "should be provided where the controller targets data subjects speaking those languages", and identify targeting through the website's language, country options offered, and payment in a Member State's currency. Running a localised storefront in that market answers the targeting question.
Is an English-only privacy policy legal in the EU?
Not where you target speakers of another language. The Dutch DPA fined TikTok Inc. €750,000 by decision of 9 April 2021 because its privacy policy was provided to Dutch users in English only between 25 May 2018 and 28 July 2020, breaching Article 12(1) GDPR — a finding anchored in its under-16 audience, though the rule it states is general. English-only remains fine for an audience you genuinely only address in English.
Has a regulator rejected the "everyone here speaks English" argument?
Yes. TikTok argued Dutch users command English well, citing the Netherlands' top-three placing in the EF English Proficiency Index since 2011. The Dutch DPA held that a relatively large group of Dutch people commanding English well "does not change" the position, particularly given the many users under 16 for whom good English is not self-evident.
Does Shopify translate the cookie banner automatically?
Shopify announced on 16 May 2024 that the cookie banner "will now be shown in their native language", with default banner text supplied in 32 languages. Its Help Center lists 33 languages with professional translations covering checkout, cookie banner, privacy policy and the data sales opt-out page. Four EU official languages are absent: Estonian, Irish, Latvian and Maltese.
Is machine translation good enough for a privacy notice?
Only if a competent speaker reviews it. The transparency guidelines require the controller to ensure translations are accurate and that "the phraseology and syntax makes sense in the second language(s) so that the translated text does not have to be deciphered or re-interpreted". Unreviewed machine output frequently fails that test, and Article 12(1) requires clear and plain language in every version.
Conclusion
The language question has a cleaner answer than most GDPR questions, and it is not the one merchants expect. There is no threshold of visitors, no proficiency percentage, and no exemption for small stores. There is a targeting test, and your market settings already answered it.
Start with the inventory rather than the translation budget: open your storefront in each live market's locale, click through the banner to the preference centre and the policy, and write down what language each surface actually rendered in. Most stores find the gap in ten minutes, and it is rarely where they expected — a full guide to the surrounding obligations sits in our complete guide to GDPR compliance.
This is informational content, not legal advice. Where a market is commercially significant, have the translated notices reviewed by someone qualified in that jurisdiction.
Sources
- GDPR Article 12 — Transparent information, communication and modalities (legislation.gov.uk)
- GDPR Article 7 — Conditions for consent (legislation.gov.uk)
- GDPR Recital 23 — Applicable to processors not established in the Union
- Article 29 Working Party, Guidelines on Transparency under Regulation 2016/679 (WP260 rev.01)
- EDPB Guidelines 03/2022 on deceptive design patterns in social media platform interfaces, v2.0
- EDPB Guidelines 05/2020 on consent under Regulation 2016/679, v1.1
- Autoriteit Persoonsgegevens, boetebesluit TikTok Inc., 9 April 2021 (PDF, Dutch)
- Shopify Help Center — Localization and translation
- Shopify changelog — The Shopify cookie banner is now shown in the customer's native language (16 May 2024)
- European Union — Languages