Complete EU Compliance Checklist for Online Stores

PrestaInsights Team

A furniture retailer expanding from France into Germany, Poland, and the Netherlands asked me for "the one document" that would tell them everything they needed to be compliant before launch. There isn't one — and anyone who sells you one probably hasn't actually run a cross-border EU store. What exists instead is a stack of overlapping regulations, each with its own scope, deadline, and enforcement body, that together determine whether your store can legally operate across the bloc. This article is the closest thing to that one document: a working map of the full stack, with checklists you can act on, and links to the deep-dive on each piece.

Treat this as a living reference, not a one-time read. Several of these regulations are still being phased in through 2026 and beyond, and enforcement patterns are still settling. Bookmark it, and revisit the checklist each quarter.

Why this is harder than it should be

Each EU compliance regulation was written by a different committee, at a different time, targeting a different problem — data protection, consumer protection, product safety, accessibility, tax harmonisation, environmental policy, AI governance. None of them were designed with each other in mind, which is why a mid-sized store selling into six member states can genuinely need to track eight or nine separate compliance streams simultaneously, each with its own effective date and its own enforcement authority (data protection authorities, market surveillance bodies, national consumer protection agencies, and tax authorities all have a piece of this).

The good news: most of the actual work clusters around a handful of touchpoints — your checkout flow, your product listings, your cookie banner, your VAT registration, and your accessibility baseline. Fix those five areas properly and you've covered the large majority of cross-cutting obligations.

The full EU compliance stack

RegulationInstrumentWhat it governsApplies to
GDPRRegulation (EU) 2016/679Personal data collection, processing, storage, consumer rights over their dataAny store processing EU residents' personal data
Consumer Rights Directive + OmnibusDirective 2011/83/EU, amended by (EU) 2019/2161Pre-contract information, withdrawal rights, price transparency, fake review rulesAll B2C online stores selling to EU consumers
GPSRRegulation (EU) 2023/988Product safety, traceability, EU Responsible Person, listing informationPhysical consumer products
EAADirective (EU) 2019/882Digital accessibility for products and services, applies from 28 June 2025Stores meeting the EAA's size/scope thresholds
AI ActRegulation (EU) 2024/1689AI system risk tiers, transparency, prohibited manipulative practicesStores using AI for pricing, recommendations, chatbots, fraud scoring
VAT OSS/IOSS + ViDACouncil Directive 2006/112/EC and reformsCross-border VAT collection and reporting, e-invoicing directionAny store selling cross-border within or into the EU
Cookie consent / ePrivacyDirective 2002/58/EC (ePrivacy), read with GDPRConsent for non-essential cookies and tracking technologiesAny store using analytics, marketing, or non-essential cookies
PPWR / EPRRegulation (EU) 2025/40 (packaging) and national EPR schemesPackaging design, recyclability, extended producer responsibility feesStores placing packaged goods on the EU market
DSARegulation (EU) 2022/2065Marketplace trader verification, illegal content handling, dark-pattern bansHosting services, online marketplaces

That's nine separate legal instruments behind a single storefront. Nobody memorises all of this — the realistic goal is knowing which rows apply to your store and having a repeatable process for each.

1. GDPR — the data foundation

If you collect any EU resident's personal data (which includes an email address at checkout, a support ticket, or a browsing cookie tied to an identifier), GDPR applies regardless of where your company is based. The core mechanics for a PrestaShop store:

  • A lawful basis for every processing activity — consent for marketing, contract necessity for order fulfilment, legitimate interest for basic fraud prevention
  • A privacy notice describing what's collected, why, how long it's kept, and who it's shared with (payment processors, shipping carriers, marketing tools)
  • Working data subject rights — access, rectification, erasure, portability — with a real process behind the "request my data" button, not just a page that says it exists
  • A record of processing activities (Article 30) if you're not a micro-enterprise with only occasional, low-risk processing
  • Breach notification readiness — a 72-hour clock starts the moment you become aware of a qualifying breach

Security practice and GDPR compliance overlap heavily but aren't identical — GDPR sets the legal floor, good security practice goes well beyond it. Our <a href="/blog/gdpr-security-best-practices-beyond-compliance/">GDPR security best practices guide</a> covers the operational side in more depth.

2. Consumer rights and the Omnibus Directive

The Consumer Rights Directive sets the baseline: pre-contract information (total price including taxes, delivery costs, right of withdrawal), a 14-day withdrawal right for most goods, and clear information about the trader's identity. The Omnibus Directive, (EU) 2019/2161, added several requirements that specifically target online retail practices:

  • Price history transparency for discounts. When you advertise a price reduction, you must show the prior price used as a reference over the previous 30 days, not an inflated "was" price invented for the sale.
  • Review authenticity. If you display customer reviews, you must take reasonable steps to verify they come from consumers who actually used or purchased the product, and disclose if you don't verify reviews at all.
  • Personalised pricing disclosure. If a price was set using automated decision-making based on the individual consumer's data, that must be disclosed — a rule that increasingly matters as more stores adopt dynamic and AI-driven pricing.
  • Ranking transparency. Where search results present ranked offers, the main parameters determining that ranking must be disclosed.

Our deep dive on <a href="/blog/omnibus-directive-compliance-guide/">Omnibus Directive compliance</a> walks through implementation specifics if this is a new area for your store.

3. GPSR — product safety and traceability

Since 13 December 2024, Regulation (EU) 2023/988 requires manufacturer identification, an EU Responsible Person for non-EU-manufactured goods, and pre-purchase safety information on product listings. This is one of the areas where PrestaShop store owners most commonly discover a gap only after a marketplace or authority notice, because the online-listing information requirement is new relative to the old directive. See our full <a href="/blog/understanding-gpsr-requirements/">GPSR requirements guide</a> for the product-by-product checklist.

4. European Accessibility Act

The EAA, Directive (EU) 2019/882, applies from 28 June 2025 and requires digital products and services — including eCommerce websites meeting the directive's scope thresholds — to meet accessibility standards broadly aligned with WCAG 2.1 AA: keyboard navigability, screen-reader compatibility, sufficient colour contrast, accessible forms and error messages, and captioned or described media where relevant. Micro-enterprises (fewer than 10 employees and under €2 million annual turnover) have a general exemption, but that exemption shrinks quickly as a store scales, and member states can interpret the boundary differently. See <a href="/blog/european-accessibility-act-prestashop-stores/">what the EAA means for PrestaShop stores</a> for template-level implementation guidance.

5. AI Act — where it touches everyday store operations

Regulation (EU) 2024/1689 is tiered by risk. Most eCommerce AI use — product recommendation engines, chatbots, dynamic pricing, fraud scoring — falls into "limited risk" or "minimal risk" categories rather than the "high-risk" tier aimed at things like credit scoring or biometric ID. Limited-risk obligations mainly mean transparency: telling users when they're interacting with a chatbot rather than a human, for instance. The Act separately and flatly prohibits manipulative AI practices that materially distort consumer decision-making and cause harm — a provision worth keeping in view for any AI-driven pricing or recommendation system, even where you're not in a formally regulated tier. Our <a href="/blog/eu-ai-act-online-stores-impact/">EU AI Act impact guide</a> covers the tiering in detail.

6. VAT OSS/IOSS and the shift toward ViDA

Selling across EU borders means navigating VAT obligations that changed substantially with the 2021 One Stop Shop (OSS) and Import One Stop Shop (IOSS) reforms, and are set to change further under the VAT in the Digital Age (ViDA) package, which phases in requirements including expanded digital/e-invoicing reporting through the later 2020s. Practically, for most PrestaShop merchants:

  • OSS lets you report all EU cross-border B2C VAT through a single member-state return instead of registering in every country you ship to
  • IOSS applies to imported goods valued under €150 sold to EU consumers, streamlining import VAT collection at the point of sale rather than at the border
  • ViDA's e-invoicing direction is a longer runway, but it's worth architecting your invoicing system now with structured, machine-readable formats in mind rather than retrofitting later

Our <a href="/blog/future-vat-oss-changes-europe/">VAT and OSS changes guide</a> tracks the reform timeline in more detail.

7. Cookie consent and ePrivacy

This is the oldest item on this list in spirit but still one of the most commonly implemented incorrectly. Under the ePrivacy Directive, read alongside GDPR, non-essential cookies (analytics, marketing, personalisation) require prior, informed, freely given consent — which rules out pre-ticked consent boxes, cookie walls that block the site entirely until consent is given (in most interpretations), and "implied consent through continued browsing" banners that some stores still run.

Cookie consent checklist

  • [ ] Non-essential cookies are blocked from firing until consent is explicitly given, not just visually hidden behind a banner
  • [ ] Reject is exactly as easy as Accept — same number of clicks, same visual prominence
  • [ ] Granular category choices (analytics, marketing, personalisation) rather than one all-or-nothing toggle
  • [ ] Consent is logged with a timestamp and re-requested when your cookie usage changes materially
  • [ ] A visible way to withdraw consent at any time, not just on first visit

8. Packaging and extended producer responsibility

The Packaging and Packaging Waste Regulation, (EU) 2025/40, sets recyclability and minimisation requirements for packaging placed on the EU market, layered on top of national Extended Producer Responsibility schemes that already require registration and fee payment in many member states based on packaging volume and material type. For a PrestaShop store shipping physical goods across borders, this means checking EPR registration requirements per destination country, not just your home market — a frequently missed detail for merchants who registered once at launch and never revisited it as they expanded.

The master compliance checklist

Work through this as a single quarterly audit rather than nine separate projects:

  • [ ] GDPR: privacy notice current, data subject request process tested, lawful basis documented per processing activity
  • [ ] Consumer rights/Omnibus: discount price history displayed correctly, reviews disclosed as verified or unverified, personalised pricing disclosed if used
  • [ ] GPSR: manufacturer and Responsible Person details on physical product listings, safety warnings present pre-purchase
  • [ ] EAA: site tested against WCAG 2.1 AA on core flows (browse, cart, checkout), accessibility statement published
  • [ ] AI Act: any AI-driven feature (chatbot, recommendations, pricing) disclosed to users, manipulative-design audit done
  • [ ] VAT OSS/IOSS: registration current for all destination markets, thresholds monitored as sales volume grows
  • [ ] Cookie consent: banner meets equal-prominence and pre-consent-blocking standards, consent logs retained
  • [ ] Packaging/EPR: registered in each destination country's EPR scheme where required, packaging materials reviewed against recyclability rules
  • [ ] DSA (if marketplace or UGC-enabled): trader verification in place, notice-and-action mechanism live, dark-pattern audit done

How to actually manage this without a legal department

Most PrestaShop merchants running this checklist aren't going to hire in-house counsel for each regulation. What works in practice:

  1. Assign an owner per row, even if it's the same person for several — ambiguity is worse than an imperfect single owner.
  2. Calendar the recurring items (VAT threshold checks, cookie consent log audits, accessibility re-tests) rather than treating compliance as a one-time launch task.
  3. Use your platform's native tools first — PrestaShop's cookie consent modules, tax rule engines, and CMS pages for legal notices cover a meaningful share of this before you need custom development.
  4. Budget for a periodic external review, even a light one, on the higher-risk items (GDPR, GPSR) rather than only the areas that feel intuitive to a non-lawyer.

How to work through this checklist

Take the master checklist above and mark each line red, yellow, or green for your store today — not aspirationally, as it actually stands. Whatever's red gets addressed first, starting with GDPR and GPSR, since those two carry the most direct enforcement exposure. Then work through the deep-dive articles linked in each section for the specifics of your red and yellow items.

Frequently asked questions

Do all nine regulations apply to every online store?

No. GDPR, consumer rights law, and cookie consent apply almost universally to any store selling to EU consumers. GPSR applies to physical products specifically. EAA, DSA, and packaging/EPR obligations have scope thresholds (business size, marketplace model, packaging volume) that exempt some smaller or narrowly-scoped stores.

Which regulation carries the biggest compliance risk right now?

GDPR and GPSR see the most active enforcement against online retailers currently, GDPR through data protection authorities and GPSR through market surveillance and marketplace delisting. That said, "biggest risk" depends heavily on your specific business model — a marketplace should weight DSA more heavily, for instance.

How often should I re-audit compliance across this stack?

Quarterly for a working audit, with a deeper review whenever you expand into a new EU market, change your data processing (new marketing tool, new AI feature), or a regulation you track hits a new phase-in deadline, such as ViDA's e-invoicing rollout.

Is a EU-based company automatically exempt from any of this?

No. Every item on this stack applies based on the market you're selling into and the data or products involved, not your company's registration location. Non-EU companies face the same obligations when selling to EU consumers, sometimes with additional requirements like appointing an EU Responsible Person under GPSR.

What's the single highest-impact fix for a store just starting this audit?

Fixing the cookie consent banner and privacy notice tends to be the fastest, most universally applicable win, since nearly every store needs both and the common failure modes (pre-ticked boxes, vague privacy notices) are well documented and quick to correct.

Do micro and small merchants get any general exemptions?

Some regulations include size-based thresholds or exemptions — the EAA exempts qualifying micro-enterprises, for example, and some EPR schemes have minimum packaging-volume thresholds. GDPR, GPSR, and consumer rights law generally don't offer a small-business exemption, though obligations like Article 30 record-keeping scale down for lower-risk, occasional processing.

Related reading

Written by

PrestaInsights Team

At PrestaInsights, we specialize in everything PrestaShop, from hosting and performance optimization to module development and in-depth tutorials. Our goal is to help merchants, developers, and agencies succeed with up-to-date guides, practical insights, and proven best practices. Whether you're just getting started or scaling a high-traffic store, we're here to guide you.

Leave a comment

Your email address will not be published. Required fields are marked *