Skip to content

Regions and the privacy laws they cover

GDPR, UK GDPR, CCPA/CPRA and 19 other US state laws, PIPEDA and Quebec Law 25, LGPD and more — grouped into ready-made regions.

Updated

CookieType groups privacy laws into regions. Each region knows which laws apply there and whether visitors must opt in before tracking, can opt out, or only need to be told. You choose regions on the Regions tab of Cookie banner.

  • Europe (the 30 EEA countries) — GDPR and the ePrivacy Directive. Opt-in.
  • United Kingdom — UK GDPR and PECR. Opt-in.
  • United States (20 states) — CCPA/CPRA (California), VCDPA (Virginia), CPA (Colorado), CTDPA (Connecticut), UCPA (Utah) and the laws of Iowa, Indiana, Tennessee, Montana, Oregon, Texas, Delaware, Florida, New Jersey, New Hampshire, Kentucky, Nebraska, Maryland, Minnesota and Rhode Island. Opt-out, with a Do not sell or share option.
  • Canada — PIPEDA and Quebec Law 25. Opt-in, following the stricter of the two.
  • Brazil — LGPD. Opt-in.
  • Switzerland — nFADP (the revised Federal Act on Data Protection). Notice.
  • Japan — APPI. Opt-in.
  • South Korea — PIPA. Opt-in.
  • South Africa — POPIA. Opt-in.
  • Australia & New Zealand — the Privacy Acts of both countries. Notice.
  • Worldwide — a catch-all for everywhere else, using the strictest (opt-in) rules.

Global Privacy Control

Some browsers send a Global Privacy Control (GPC) signal meaning “don’t sell or share my data”. It is always honoured: in opt-out regions it counts as an opt-out automatically.

Keeping Shopify in step

CookieType keeps Shopify's own privacy settings matched to your regions and turns off Shopify's built-in cookie banner, so visitors never see two. See Shopify's privacy settings and the Customer Privacy API.

Note: Each region applies our reading of the laws in it. It is not legal advice — if you are unsure what your business needs, check with a privacy professional.

Still stuck?

Write to us — a real person answers, on every plan. Or email support@cookietype.com.

Contact support