Key Takeaways
- On 13 August 2026 Shopify began offering eligible stores "personalized recommendations for customer information settings" that, in its own words, "help you collect more complete customer details at checkout so you can reconnect with past shoppers more effectively and personalize your marketing." New stores already use those settings by default.
- A marketing purpose cannot make a checkout field mandatory. EDPB Guidelines 2/2019 state that Article 6(1)(b) "will not cover processing which is useful but not objectively necessary for performing the contractual service ... even if it is necessary for the controller's other business purposes."
- The Court of Justice has already ruled on a mandatory checkout field. In Case C-394/23, decided 9 January 2025, collecting customers' title to personalise commercial communication was held "neither objectively indispensable nor essential" to performing the contract.
- The same judgment cuts the other way on names: the Court indicated that personalising commercial communication "puisse se limiter au traitement des noms et prénoms des clients" — could be limited to surnames and first names. Requiring a name is not what that ruling condemns.
- Article 25(2) requires measures ensuring that "by default, only personal data which are necessary for each specific purpose of the processing are processed" — the provision a shipped-by-default field configuration has to answer to.
Introduction
Open Checkout settings in your Shopify admin this week and you may find something new waiting: a set of personalised recommendations for what to ask your customers for. Shopify shipped them on 13 August 2026, and the pitch is refreshingly candid — they help you "collect more complete customer details at checkout so you can reconnect with past shoppers more effectively and personalize your marketing."
That sentence contains the entire problem in miniature. It names a marketing purpose for data collected in a fulfilment moment, and under the GDPR those two things answer to different rules and often different lawful bases. Applying the recommendations takes one click. Working out whether you may is the job this article does, field by field.
This is informational content, not legal advice.
What Shopify Actually Changed on 13 August 2026
Shopify's changelog entry is short, and each sentence carries a different consequence. "Eligible stores can now get personalized recommendations for customer information settings from the Checkout settings page in Shopify admin," it begins, and the recommendations "help you collect more complete customer details at checkout so you can reconnect with past shoppers more effectively and personalize your marketing."
Then the line that matters most to anyone who opened a store recently: "New stores already use these recommended settings by default." Existing merchants get a reassurance instead — "Existing store settings won't change unless you apply the recommendations."
Two populations, two different problems. With an established store, nothing has moved underneath you; you face a prompt and a decision. If you opened recently, the settings arrived switched on and the decision was taken for you.
The content of the recommendations is specified too: "setting customer contact method to email-only, requiring first and last name, or optionally collecting shipping address phone number." Those map onto controls Shopify's Help Center documents — contact method as "Phone number or email" or "Email only", the name field as "Only require last name" or "Require first and last name", and the shipping address phone as "Don't include", "Optional" or "Required".
One of the three is a data-protection improvement, and it deserves saying before any criticism: email-only collects less, not more. Take that one. The other two ask for more, for a stated reason that is about marketing — and that is where the analysis has to get specific.
Which Checkout Fields Can You Require Under GDPR?
You may require a field when the purchase genuinely cannot be completed without it, and only then. Anything you collect because it is useful — for marketing, personalisation, or reconnecting with past shoppers — has to be optional, with its own lawful basis. The test is necessity for the contract, not benefit to the business.
That distinction is not PrivacyForge's invention. It is the settled reading of Article 6(1)(b), and the regulators have been unusually blunt about it.
The test is "objectively indispensable", not "useful"
The EDPB set the standard in Guidelines 2/2019 on Article 6(1)(b) in online services, adopted 8 October 2019. Paragraph 25 is the sentence to keep next to your admin screen:
"Article 6(1)(b) will not cover processing which is useful but not objectively necessary for performing the contractual service or for taking relevant pre-contractual steps at the request of the data subject, even if it is necessary for the controller's other business purposes."
The same paragraph adds the practical corollary: "If there are realistic, less intrusive alternatives, the processing is not 'necessary'."
The Guidelines also anticipated the exact dynamic Shopify's feature creates. At paragraph 16 the EDPB warns that "there is an acute risk that data controllers may seek to include general processing terms in contracts in order to maximise the possible collection and uses of data, without adequately specifying those purposes or considering data minimisation obligations." Written in 2019, describing a button shipped in 2026.
Nor can your terms of service fix it. Paragraph 27 is explicit that "merely referencing or mentioning data processing in a contract is not enough to bring the processing in question within the scope of Article 6(1)(b)."
What the Court of Justice decided about a mandatory checkout field
The case is more useful to merchants than its subject matter suggests.
In Case C-394/23, Mousse v CNIL and SNCF Connect, decided 9 January 2025, the Court of Justice examined a rail operator that required online customers to select a title — "Monsieur" or "Madame" — when buying a ticket. This was not a fringe position: France's data protection authority had already rejected a complaint about the field, by a decision of 23 March 2021, treating the collection as necessary to perform the transport contract.
The Court disagreed. Processing customers' title data "ayant pour finalité une personnalisation de la communication commerciale fondée sur leur identité de genre" — for the purpose of personalising commercial communication based on their gender identity — "ne paraît ni objectivement indispensable ni essentiel afin de permettre l'exécution correcte d'un contrat", and so cannot be regarded as necessary for performing it.
Two details make this transferable to a checkout page. The test, at paragraph 33: processing must be "objectivement indispensable" to a purpose forming an integral part of the contractual service, and the controller "doit ainsi être en mesure de démontrer" why the contract's main object could not be achieved without it. The burden sits with you, and it is a demonstration rather than an assertion. Then, at paragraph 40, the Court found "une solution praticable et moins intrusive semble exister" — the company could simply use generic, inclusive forms of address. Where a less intrusive route exists, the necessity argument collapses.
Now the part that stops this article from overreaching. At paragraph 55 the Court indicated that personalising commercial communication "puisse se limiter au traitement des noms et prénoms des clients" — could be limited to processing customers' surnames and first names — with title and gender identity being what "ne paraît pas strictement nécessaire" in that context. The Court pointed at names as the acceptable, less intrusive alternative.
Our read: that materially weakens any argument that requiring a first and last name is unlawful in itself, and merchants should not be told otherwise. What the judgment does establish is the method — purpose first, then necessity, then whether something less intrusive would do — and that method is what Shopify's recommendation prompt does not supply.
Field by field: the verdict table
Here is the analysis applied to the controls Shopify actually gives you. The verdict column is our recommendation for a store selling physical goods into the EU or UK; a genuinely different service changes the answer, and the fourth row shows how.
| Shopify control | Purpose it actually serves | Basis that fits | Our verdict |
|---|---|---|---|
| Contact method: Email only | Order confirmation, delivery updates, statutory receipts | Art. 6(1)(b) — contract | Apply it. Collects less than the alternative and still performs the contract |
| Require first and last name | Addressing the parcel; personalising later communication | Art. 6(1)(b) for delivery; the personalisation use needs its own basis | Defensible as required for shipped goods — but record delivery, not marketing, as the reason |
| Shipping address phone: Required | Carrier contact for a failed or scheduled delivery | Art. 6(1)(b) only where your carrier genuinely uses it | Set to Optional unless your carrier requires it. Ask the carrier before deciding |
| Shipping address phone: Required, service delivered by phone | Actually performing the purchased service | Art. 6(1)(b) — contract | Required is fine. Here the phone call is the product |
| Marketing consent checkbox, preselected | Email marketing | Art. 6(1)(a) — consent, which must be an active choice | Never preselect. See the section below |
The fourth row is not a hypothetical. On the Shopify Community forum in April 2023, a merchant asked how to make the billing phone number mandatory, explaining: "As we only sell only Services / Digital products and need to phone clients to provide the service they bought." That store has a necessity argument a physical-goods retailer does not have, because without the call there is no service. Same field, same platform, opposite verdict — which is precisely why a platform-wide recommendation cannot answer the question for you.
Why "Personalise Your Marketing" Cannot Make a Field Mandatory
Because marketing is a separate purpose from fulfilment, and Article 5(1)(b) requires data to be "collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes." A purpose that needs consent cannot borrow the necessity of one that does not.
Article 5(1)(c) then limits collection to what is "adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed", and Article 5(2) makes it your problem to prove: "The controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1."
The EDPB has applied this to exactly the kind of profiling that "reconnect with past shoppers" describes. Guidelines 2/2019 endorse the Article 29 Working Party's position that contractual necessity "is not a suitable legal ground for building a profile of the user's tastes and lifestyle choices based on his clickstream on a website and the items purchased. This is because the data controller has not been contracted to carry out profiling, but rather to deliver particular goods and services."
Then there is the default itself. For new stores the recommended settings arrived switched on, and Article 25(2) speaks to that directly: controllers must ensure that "by default, only personal data which are necessary for each specific purpose of the processing are processed." A default collecting more than fulfilment requires is what that provision exists to prevent — and the controller answering for it is the merchant, not the platform.
Shopify says as much itself. Its documentation for these settings carries the line: "These automatic recommendations don't constitute legal advice, and you're responsible for complying with your local laws and regulations." A fair position for a platform to take — and a transfer of the decision to you, in writing.
The Setting Most Merchants Will Miss
While you are in Checkout settings, there is a second control worth more attention than the field toggles: which customer regions have the email marketing consent checkbox preselected.
Shopify documents two ways to set this. In the automated mode, "Customer regions with the email marketing consent checkbox preselected are chosen based on the latest recommendations from Shopify." In the manual mode, "You can manually choose the customer regions where the email marketing consent checkbox is preselected. You can leave no regions selected so that all customers in all regions must manually opt in to email marketing."
Here is the honest limit of what we can tell you: Shopify does not publish which regions its automated recommendation preselects. We looked; the Help Center names the mechanism, not the list. So this article does not claim that Shopify pre-ticks marketing consent for EU or UK shoppers, and you should be sceptical of anyone who tells you it does without showing you the list.
What we can say is what the standard requires, and why an unpublished list is the wrong thing to rely on. EDPB Guidelines 05/2020 on consent, adopted 4 May 2020, are categorical at paragraph 79: "The use of pre-ticked opt-in boxes is invalid under the GDPR. Silence or inactivity on the part of the data subject, as well as merely proceeding with a service cannot be regarded as an active indication of choice." Paragraph 81 closes the workaround: "The GDPR does not allow controllers to offer pre-ticked boxes or opt-out constructions that require an intervention from the data subject to prevent agreement."
Our recommendation is unqualified for EU and UK sellers: switch that setting to manual and leave no regions selected, so every customer opts in actively. The reason is Article 5(2) rather than suspicion of Shopify — you have to be able to demonstrate how consent was obtained, and "an automated regional recommendation whose contents I could not see" is not a demonstration. The trade-off is real and you should price it in: unticked boxes produce fewer subscribers than ticked ones. They also produce a list you can defend, which is the only kind worth having.
How to Audit Your Checkout Settings: Six Steps
Do this before you click apply, not after. It takes under an hour for most stores.
- Screenshot your current Checkout settings. Article 5(2) puts the burden of demonstrating compliance on you, and a dated before-and-after is the cheapest evidence you will ever produce.
- Write the purpose next to each field before you touch a toggle. Not "customer data" — the operational use: "the carrier calls when the buzzer fails". If you cannot finish that sentence without the word "marketing", the field cannot be mandatory.
- Ask your carrier whether they actually use the phone number. This single question decides the phone field, and most merchants have never asked it. If the carrier does not use it, your necessity argument for requiring it does not exist.
- Apply the email-only contact method. It is the one recommendation in the set that reduces collection.
- Set marketing consent preselection to manual with no regions selected, then place a test order from an EU address and confirm the checkbox arrives unticked. Test the refusal path — an acceptance test passes in almost any configuration.
- Record each field, purpose and lawful basis in your records of processing. That pairing is what a supervisory authority asks for under Article 30, and reconstructing it in eighteen months is far harder than writing it down today.
If you only have time for two, do steps 2 and 3. The purpose statement tells you what you may require; the carrier answer settles the field merchants get wrong most often.
Common Mistakes
Treating a platform recommendation as a compliance opinion. The costly one, and easy to fall into because the prompt arrives inside the tool that runs your store. It is a marketing suggestion, from a company whose same documentation says it is not legal advice. The controller is you.
Requiring a phone number nobody uses. Baymard Institute's checkout research found that 14% of online shoppers are reluctant to provide their phone number, and that 39% of sites in its benchmark require one without any explanation. In testing, Baymard observed "several participants enter a false phone number to proceed with their purchase" — one had "learned to type '9999'". Consider what that does to a mandatory field: you take on a data-protection justification you may not have, in exchange for a column of numbers that do not ring. Article 5(1)(d) expects personal data to be accurate, so a required field that teaches customers to lie fails on two principles at once.
Assuming "optional" is a cop-out. An optional field with a one-line explanation of why you are asking is the minimisation-compliant route and the higher-converting one. Baymard's finding is about missing explanations, not missing fields.
Applying the recommendation set as a bundle. Three recommendations, three different answers: email-only is good, the name field is defensible for shipped goods, and the phone field turns on a fact about your carrier. One click, three separate decisions.
Forgetting that new stores started here. If you opened recently you did not choose these settings, you inherited them — and Article 25(2) applies to what you inherited. Go and look at what your checkout asks for today; you may be requiring a field you have never once used.
How PrivacyForge Helps
The hard part of this exercise is not the toggling. It is that six months from now nobody will remember why the phone field was set to required, and the person who rang the carrier will have left.
PrivacyForge's data mapping module holds the artefact this decision produces: each field, the purpose it serves, and the lawful basis you settled on, in the structure Article 30 expects. That turns a Thursday-afternoon judgement call into a record you can hand to a supervisory authority, or to whoever inherits your checkout. Consent management covers the marketing opt-in — what each customer was asked and what they answered — which is the evidence Article 5(2) wants, and the thing an unticked-box policy is worth nothing without.
For the wider checkout picture, our guide to guest checkout and forced account creation covers whether you may require an account at all, and building a record of processing activities covers where these entries live. Shopify merchants should also note the separate web pixel consent deadline of 26 August 2026, which lands in the same admin area on a much tighter clock.
Frequently Asked Questions
Is requiring a phone number at checkout GDPR compliant?
Only where the phone number is genuinely needed to perform the order. Under EDPB Guidelines 2/2019, Article 6(1)(b) does not cover processing that is "useful but not objectively necessary" for the contract. If your carrier uses the number for delivery, requiring it is defensible; if it exists for marketing or fraud screening, make it optional and rely on a separate lawful basis.
Can I use checkout data for marketing under GDPR?
Not automatically. Article 5(1)(b) requires data to be "collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes". Fulfilment and marketing are separate purposes, so marketing needs its own lawful basis — usually consent for email marketing. Collecting a field for delivery does not license using it to promote.
Does Shopify's recommendation mean these checkout settings are GDPR compliant?
No. Shopify's own documentation states that "these automatic recommendations don't constitute legal advice, and you're responsible for complying with your local laws and regulations." The recommendations optimise for marketing reach and order completeness. Under the GDPR the merchant is the controller and carries the accountability obligation in Article 5(2), regardless of what the platform suggests.
Is requiring a first and last name at checkout allowed?
Generally yes for shipped goods, because the name is needed to address the parcel. In Case C-394/23 the Court of Justice indicated that personalising commercial communication could be limited to processing customers' surnames and first names, treating title and gender identity as the data that was not strictly necessary. Record delivery as your reason rather than marketing.
Should the email marketing checkbox be preselected at checkout?
No, not for EU or UK customers. EDPB Guidelines 05/2020 state at paragraph 79 that "the use of pre-ticked opt-in boxes is invalid under the GDPR". Shopify lets you set preselection manually and leave no regions selected, so every shopper opts in actively. Shopify does not publish which regions its automated recommendation preselects.
Conclusion
The 13 August change is not an attack on your compliance posture. It is a marketing feature doing what a marketing feature should, in a place where marketing and data protection collide — and Shopify has been straightforward that the legal call is yours.
Make it deliberately. Take the email-only recommendation, keep the name field with delivery written next to it, ring your carrier before requiring a phone number, and leave the marketing checkbox unticked everywhere. Then write down why, while you still remember.
The compliant configuration also happens to be the one that asks your customers for less, which tends to be the one they finish. Map your checkout fields to their purposes in PrivacyForge and have the answer ready before anyone asks.
Sources
- Shopify Changelog: Recommended changes to checkout field settings are now available — the 13 August 2026 announcement, the marketing rationale, and the new-store default
- Shopify Help Center: Checkout form options — contact method, name and shipping-phone controls, marketing consent preselection, and the not-legal-advice disclaimer
- CJEU, Case C-394/23, Mousse v CNIL and SNCF Connect (9 January 2025) — a mandatory title field held neither objectively indispensable nor essential to the contract, and names identified as the less intrusive alternative
- EDPB Guidelines 2/2019 on Article 6(1)(b) GDPR in the context of online services — paragraphs 16, 25 and 27 on necessity, less intrusive alternatives, and contractual wording
- EDPB Guidelines 05/2020 on consent under Regulation 2016/679 — paragraphs 79 and 81 on pre-ticked opt-in boxes
- GDPR Article 5: Principles relating to processing of personal data — purpose limitation, data minimisation and accountability
- GDPR Article 25: Data protection by design and by default — the by-default requirement in Article 25(2)
- Baymard Institute: Explain Why You Need the User's Phone Number — 14% reluctance, 39% of sites requiring it unexplained, and observed false entries