EU Geo-blocking Regulation and Shopify country redirects

Most articles about geolocation on Shopify treat the popup as a courtesy and the redirect as the efficient option. For visitors in the European Union the order is reversed, and not for reasons of taste. Since December 2018 a regulation has said, in so many words, that you may not send an EU customer to a different version of your store because of where they are unless they have explicitly agreed. It is the reason Shopify's own automatic redirection quietly stays off for EU country-code domains, and it should shape how any geolocation app is configured for a store with European customers.

This article reads the relevant part of the regulation plainly, explains how it maps onto the two things a geolocation app can do, and sets out a configuration that respects it without giving up the reason you installed the app. Our earlier post on cookie banners and the geolocation popup covered the privacy side; this one is about the consumer-protection side, which is a different law with a different point.

What Article 3 actually says

The law is Regulation (EU) 2018/302, usually called the Geo-blocking Regulation. It applies directly in every member state and does not need national implementation. Its Article 3 is about “access to online interfaces”, which in Shopify terms means your storefront, and it has two prohibitions.

Article 3(1): a trader shall not, “through the use of technological measures or otherwise, block or limit a customer's access” to the online interface for reasons related to the customer's nationality, place of residence or place of establishment. That is the geo-blocking part. Serving a “we do not serve your country” page to a visitor from Portugal is what it forbids.

Article 3(2) is the one for redirects. A trader shall not, for those same reasons, “redirect that customer to a version of the trader's online interface that is different from the online interface to which the customer initially sought access, by virtue of its layout, use of language or other characteristics that make it specific to customers with a particular nationality, place of residence or place of establishment, unless the customer has explicitly consented to such redirection.” And it adds that where the customer did consent, the version they originally asked for “shall remain easily accessible”.

Three things in that paragraph decide everything that follows. The trigger is a redirect because of where the customer is. The thing you may not redirect to is a different version, where language, layout or other characteristics mark it as being for a particular country. And the exception is explicit consent, with the original version still reachable afterwards.

Is a Shopify market a “different version”?

Yes, almost always. The regulation does not care whether the version lives on a separate domain, a subfolder or the same URL with a different context. A market with its own currency, its own prices, its own shipping rates and often its own language is a version of the store specific to customers in a place, which is exactly the description in Article 3(2). Switching a visitor from the French market view of a product to the German one is a redirect to a different version even if the path never changes.

Shopify's help centre reflects this directly. Its page on automatic storefront redirection says that “to comply with local legislation, customers from the EU who access a localized experience with an EU country code top-level domain name (ccTLD) aren't automatically redirected”, lists the 27 ccTLDs plus .eu, and suggests a third-party app “to provide EU customers with country or region recommendations, so that they can select the best experience”. The word is select. Shopify will still redirect EU visitors who land on a .com or .shop domain, which is Shopify's compliance judgement to make about its own feature; what matters for you is that the moment you reach for an app to do more than Shopify does, you are the trader making the redirect, and Article 3(2) is addressed to you.

Popup and redirect, read against the law

A geolocation app can do one of two things when a visitor from Austria lands on your German-market page. It can move them to the Austrian version immediately, or it can tell them an Austrian version exists and ask. The first is a redirect for reasons related to residence without consent. The second is an offer, and if the visitor accepts it, the redirect that follows is one they explicitly consented to.

BehaviourUnder Article 3(2)GeoBeacon setting
Silent redirect of an EU visitor to their country's market or domainProhibited unless they consented earlierRedirect mode; avoid for EU audiences
Popup offering the local version, with a “stay here” optionPermitted; accepting is explicit consentPopup mode (the default)
Remembering the accepted redirect on later visitsPermitted; recital 20 says consent carries overRemember for N days, 30 by default
Hiding the original version after the switchProhibited; it must remain easily accessibleKeep the theme's country selector visible
Blocking the site for visitors from an EU countryProhibited by Article 3(1), narrow legal exceptionNot a GeoBeacon feature; see below

The popup is therefore not a softer version of the redirect for EU traffic. It is the mechanism by which the redirect becomes lawful. That is why GeoBeacon ships with popup mode on by default and a decline button labelled “Stay here” that does nothing except close the dialog and remember that the shopper said no.

What “explicit” and “easily accessible” mean in practice

The regulation does not define a consent form, but the Commission's guidance and the recitals point the same way as the GDPR's vocabulary: an affirmative act, not silence. A popup that auto-redirects after five seconds unless the visitor finds the close button is not consent. A banner with a single “OK” that redirects, and no visible way to stay, is not consent either, because the version originally requested has to stay reachable. Two buttons, one that goes and one that stays, both equally prominent, is the honest shape, and the body text should say what will change: pricing, shipping, language.

“Easily accessible” after the switch is mostly a theme question. The country and language selector in your header or footer is what lets a shopper who accepted the Austrian version go back to the German one, and Shopify remembers a manual choice made there. Do not hide the selector on markets with a single country, and do not let the geolocation app re-prompt someone who has just used it; GeoBeacon treats a selector choice as a remembered decision and stays quiet.

Recital 20 also says the customer must be able to withdraw consent at any time. In a storefront that is the same selector, plus the fact that a remembered choice expires. Thirty days is a reasonable default; a year is defensible; “forever” is harder to square with the right to withdraw unless the selector is prominent.

Blocking is a separate, stricter rule

Merchants sometimes reach for a geolocation app to keep visitors from a country out entirely, for fraud or because they do not ship there. For EU customers, Article 3(1) is unambiguous: you may not block or limit access because of where they live, except where a legal requirement forces you to, and then you must tell them, in the language of the page they asked for, why. Not shipping somewhere is a different matter; the regulation lets you choose where you deliver, provided EU customers can still buy on the same terms as locals and arrange their own delivery where relevant. Say no at checkout, not at the door. Our post on why blocking a country does not stop fraud explains why blocking rarely achieves its stated goal anyway.

How seriously is this enforced?

Unevenly, and that is not a reason to ignore it. The European Court of Auditors published a special report in 2025 that found the regulation “provides a balanced framework” but that enforcement “remains a weak spot”, with delays and significant differences between member states in the measures taken against infringing traders. It recommended that the Commission strengthen enforcement and study whether to extend the regulation's scope, and the Commission's own evaluation of the regulation has been under way since. The direction is towards more enforcement, not less, and consumer bodies in Germany, Austria and the Netherlands have been the most active complainants. A store that depends on EU traffic is better off with a configuration it can defend than one that happens not to have been noticed.

Configuring GeoBeacon for a store with EU customers

  1. Leave the mode on popup. If your audience is entirely outside the EU, redirect mode is fine; if any meaningful share is European, the popup is the mode that keeps you inside Article 3(2), and it applies store-wide.
  2. Write the popup text to describe the change: “We have a store for Austria with prices in euros, local shipping and German-language pages.” Keep both buttons. The default decline text is “Stay here”; do not shorten it to an X.
  3. Set the remember period. The default of 30 days means an EU shopper who declined is not asked again for a month, and one who accepted is sent to their version on return without a prompt, which recital 20 permits.
  4. Check that your theme shows a country and language selector on every market, including the ones with a single country. That selector is your “easily accessible” original version and your withdrawal mechanism.
  5. If you run EU country-code domains, let Shopify's automatic redirection stay off for them as it already is, and let GeoBeacon make the offer. Add each of your own domains to the known-hosts list so a shopper who arrives from your .de domain onto your .at domain is not prompted again.
  6. Test it the way an EU visitor would: force a country with the testing parameter described in our no-VPN testing guide, land on a different market's page, and confirm you see a question, not a jump.

The short version

For EU customers, a geolocation app may suggest and must not decide. The popup is the lawful form of the redirect, remembering the answer is allowed, the way back must stay visible, and blocking is off the table. None of that costs a conversion that was worth having; a shopper who wanted the local store will click the button. GeoBeacon is built around that default, and the configuration above is the whole of what it takes to stay on the right side of a regulation most store owners have never read.

Frequently asked questions

Is it legal to automatically redirect EU visitors to their country's version of a Shopify store?

Not without their explicit consent. Article 3(2) of Regulation (EU) 2018/302 prohibits redirecting a customer, for reasons related to nationality or residence, to a version of your online interface that differs from the one they sought, unless they explicitly consented. A popup that asks and remembers the answer satisfies this; a silent redirect does not. Shopify's own automatic redirection is switched off for EU country-code domains for the same reason.

Does the Geo-blocking Regulation apply to a store based outside the EU?

Yes, when it sells to customers in the EU. The regulation is about where the customer is, not where the trader is established, so a US or UK store with a .de or .fr domain, or with EU markets on a .com, is covered for its EU customers.

Do I have to ask for consent on every visit?

No. Recital 20 of the regulation says that once a customer has explicitly consented, that consent is valid for subsequent visits to the same interface, and they must be able to withdraw it. Remembering the choice for a period and keeping a country selector visible does exactly that. GeoBeacon remembers the popup answer for a configurable number of days, 30 by default.

Can I block visitors from some EU countries instead of redirecting them?

Article 3(1) prohibits blocking or limiting access to your online interface for reasons related to an EU customer's nationality or residence, with a narrow exception where a legal requirement forces it, in which case you must explain why. Not shipping to a country is allowed; refusing to let its residents see the site is not. Keep the store reachable and let the shipping settings say no at checkout.