If people in the EU or UK visit your store: yes — and the banner must actually stop tracking until they agree. If people in California and several other US states visit: you need a working opt-out more than a banner. If neither is true, a banner is a choice, not an obligation.
It depends on your visitors, not on you
GDPR applies to anyone offering goods to people in the EU — a one-person Shopify store shipping to Berlin is in scope; there is no small-business exemption. US state laws work the other way: thresholds based on revenue and data volumes mean many small stores fall outside them, though honouring opt-outs anyway is cheap insurance. The full opt-in vs opt-out picture is in GDPR vs CCPA for Shopify merchants.
What each regime actually requires
- EEA / UK visitors: non-essential cookies held until consent, Reject as easy as Accept, no pre-ticked boxes, a way to withdraw later — and disclosure of what you set.
- California & co.: tracking may run by default, but a “Do Not Sell or Share My Personal Information” path must exist, work, and include honouring the automatic GPC signal.
- Everywhere: nobody, anywhere, requires consent for the cart, checkout and session cookies a store cannot function without.
The mistake that costs merchants: banner ≠ compliance
A banner that displays beautifully while trackers fire underneath is the most common failure in this category — and the specific pattern European regulators have fined. The compliance lives in the enforcement: trackers held before consent, choices written to Shopify's Customer Privacy API, rejects that actually remove identifiers, and records you could show an auditor. You can verify all of it on your own store with a five-minute devtools test.