Complete EU Compliance Checklist for Online Stores
A furniture retailer expanding from France into Germany, Poland, and the Netherlands asked me for "the one document" that would tell them everything they needed to be compliant before launch. There isn't one — and anyone who sells you one probably hasn't actually run a cross-border EU store. What exists instead is a stack of overlapping regulations, each with its own scope, deadline, and enforcement body, that together determine whether your store can legally operate across the bloc. This article is the closest thing to that one document: a working map of the full stack, with checklists you can act on, and links to the deep-dive on each piece.
Treat this as a living reference, not a one-time read. Several of these regulations are still being phased in through 2026 and beyond, and enforcement patterns are still settling. Bookmark it, and revisit the checklist each quarter.
Why this is harder than it should be
Each EU compliance regulation was written by a different committee, at a different time, targeting a different problem — data protection, consumer protection, product safety, accessibility, tax harmonisation, environmental policy, AI governance. None of them were designed with each other in mind, which is why a mid-sized store selling into six member states can genuinely need to track eight or nine separate compliance streams simultaneously, each with its own effective date and its own enforcement authority (data protection authorities, market surveillance bodies, national consumer protection agencies, and tax authorities all have a piece of this).
The good news: most of the actual work clusters around a handful of touchpoints — your checkout flow, your product listings, your cookie banner, your VAT registration, and your accessibility baseline. Fix those five areas properly and you've covered the large majority of cross-cutting obligations.
The full EU compliance stack
| Regulation | Instrument | What it governs | Applies to |
|---|---|---|---|
| GDPR | Regulation (EU) 2016/679 | Personal data collection, processing, storage, consumer rights over their data | Any store processing EU residents' personal data |
| Consumer Rights Directive + Omnibus | Directive 2011/83/EU, amended by (EU) 2019/2161 | Pre-contract information, withdrawal rights, price transparency, fake review rules | All B2C online stores selling to EU consumers |
| GPSR | Regulation (EU) 2023/988 | Product safety, traceability, EU Responsible Person, listing information | Physical consumer products |
| EAA | Directive (EU) 2019/882 | Digital accessibility for products and services, applies from 28 June 2025 | Stores meeting the EAA's size/scope thresholds |
| AI Act | Regulation (EU) 2024/1689 | AI system risk tiers, transparency, prohibited manipulative practices | Stores using AI for pricing, recommendations, chatbots, fraud scoring |
| VAT OSS/IOSS + ViDA | Council Directive 2006/112/EC and reforms | Cross-border VAT collection and reporting, e-invoicing direction | Any store selling cross-border within or into the EU |
| Cookie consent / ePrivacy | Directive 2002/58/EC (ePrivacy), read with GDPR | Consent for non-essential cookies and tracking technologies | Any store using analytics, marketing, or non-essential cookies |
| PPWR / EPR | Regulation (EU) 2025/40 (packaging) and national EPR schemes | Packaging design, recyclability, extended producer responsibility fees | Stores placing packaged goods on the EU market |
| DSA | Regulation (EU) 2022/2065 | Marketplace trader verification, illegal content handling, dark-pattern bans | Hosting services, online marketplaces |
That's nine separate legal instruments behind a single storefront. Nobody memorises all of this — the realistic goal is knowing which rows apply to your store and having a repeatable process for each.
1. GDPR — the data foundation
If you collect any EU resident's personal data (which includes an email address at checkout, a support ticket, or a browsing cookie tied to an identifier), GDPR applies regardless of where your company is based. The core mechanics for a PrestaShop store:
- A lawful basis for every processing activity — consent for marketing, contract necessity for order fulfilment, legitimate interest for basic fraud prevention
- A privacy notice describing what's collected, why, how long it's kept, and who it's shared with (payment processors, shipping carriers, marketing tools)
- Working data subject rights — access, rectification, erasure, portability — with a real process behind the "request my data" button, not just a page that says it exists
- A record of processing activities (Article 30) if you're not a micro-enterprise with only occasional, low-risk processing
- Breach notification readiness — a 72-hour clock starts the moment you become aware of a qualifying breach
Security practice and GDPR compliance overlap heavily but aren't identical — GDPR sets the legal floor, good security practice goes well beyond it. Our <a href="/blog/gdpr-security-best-practices-beyond-compliance/">GDPR security best practices guide</a> covers the operational side in more depth.
2. Consumer rights and the Omnibus Directive
The Consumer Rights Directive sets the baseline: pre-contract information (total price including taxes, delivery costs, right of withdrawal), a 14-day withdrawal right for most goods, and clear information about the trader's identity. The Omnibus Directive, (EU) 2019/2161, added several requirements that specifically target online retail practices:
- Price history transparency for discounts. When you advertise a price reduction, you must show the prior price used as a reference over the previous 30 days, not an inflated "was" price invented for the sale.
- Review authenticity. If you display customer reviews, you must take reasonable steps to verify they come from consumers who actually used or purchased the product, and disclose if you don't verify reviews at all.
- Personalised pricing disclosure. If a price was set using automated decision-making based on the individual consumer's data, that must be disclosed — a rule that increasingly matters as more stores adopt dynamic and AI-driven pricing.
- Ranking transparency. Where search results present ranked offers, the main parameters determining that ranking must be disclosed.
Our deep dive on <a href="/blog/omnibus-directive-compliance-guide/">Omnibus Directive compliance</a> walks through implementation specifics if this is a new area for your store.
3. GPSR — product safety and traceability
Since 13 December 2024, Regulation (EU) 2023/988 requires manufacturer identification, an EU Responsible Person for non-EU-manufactured goods, and pre-purchase safety information on product listings. This is one of the areas where PrestaShop store owners most commonly discover a gap only after a marketplace or authority notice, because the online-listing information requirement is new relative to the old directive. See our full <a href="/blog/understanding-gpsr-requirements/">GPSR requirements guide</a> for the product-by-product checklist.
4. European Accessibility Act
The EAA, Directive (EU) 2019/882, applies from 28 June 2025 and requires digital products and services — including eCommerce websites meeting the directive's scope thresholds — to meet accessibility standards broadly aligned with WCAG 2.1 AA: keyboard navigability, screen-reader compatibility, sufficient colour contrast, accessible forms and error messages, and captioned or described media where relevant. Micro-enterprises (fewer than 10 employees and under €2 million annual turnover) have a general exemption, but that exemption shrinks quickly as a store scales, and member states can interpret the boundary differently. See <a href="/blog/european-accessibility-act-prestashop-stores/">what the EAA means for PrestaShop stores</a> for template-level implementation guidance.
5. AI Act — where it touches everyday store operations
Regulation (EU) 2024/1689 is tiered by risk. Most eCommerce AI use — product recommendation engines, chatbots, dynamic pricing, fraud scoring — falls into "limited risk" or "minimal risk" categories rather than the "high-risk" tier aimed at things like credit scoring or biometric ID. Limited-risk obligations mainly mean transparency: telling users when they're interacting with a chatbot rather than a human, for instance. The Act separately and flatly prohibits manipulative AI practices that materially distort consumer decision-making and cause harm — a provision worth keeping in view for any AI-driven pricing or recommendation system, even where you're not in a formally regulated tier. Our <a href="/blog/eu-ai-act-online-stores-impact/">EU AI Act impact guide</a> covers the tiering in detail.
6. VAT OSS/IOSS and the shift toward ViDA
Selling across EU borders means navigating VAT obligations that changed substantially with the 2021 One Stop Shop (OSS) and Import One Stop Shop (IOSS) reforms, and are set to change further under the VAT in the Digital Age (ViDA) package, which phases in requirements including expanded digital/e-invoicing reporting through the later 2020s. Practically, for most PrestaShop merchants:
- OSS lets you report all EU cross-border B2C VAT through a single member-state return instead of registering in every country you ship to
- IOSS applies to imported goods valued under €150 sold to EU consumers, streamlining import VAT collection at the point of sale rather than at the border
- ViDA's e-invoicing direction is a longer runway, but it's worth architecting your invoicing system now with structured, machine-readable formats in mind rather than retrofitting later
Our <a href="/blog/future-vat-oss-changes-europe/">VAT and OSS changes guide</a> tracks the reform timeline in more detail.
7. Cookie consent and ePrivacy
This is the oldest item on this list in spirit but still one of the most commonly implemented incorrectly. Under the ePrivacy Directive, read alongside GDPR, non-essential cookies (analytics, marketing, personalisation) require prior, informed, freely given consent — which rules out pre-ticked consent boxes, cookie walls that block the site entirely until consent is given (in most interpretations), and "implied consent through continued browsing" banners that some stores still run.
Cookie consent checklist
- [ ] Non-essential cookies are blocked from firing until consent is explicitly given, not just visually hidden behind a banner
- [ ] Reject is exactly as easy as Accept — same number of clicks, same visual prominence
- [ ] Granular category choices (analytics, marketing, personalisation) rather than one all-or-nothing toggle
- [ ] Consent is logged with a timestamp and re-requested when your cookie usage changes materially
- [ ] A visible way to withdraw consent at any time, not just on first visit
8. Packaging and extended producer responsibility
The Packaging and Packaging Waste Regulation, (EU) 2025/40, sets recyclability and minimisation requirements for packaging placed on the EU market, layered on top of national Extended Producer Responsibility schemes that already require registration and fee payment in many member states based on packaging volume and material type. For a PrestaShop store shipping physical goods across borders, this means checking EPR registration requirements per destination country, not just your home market — a frequently missed detail for merchants who registered once at launch and never revisited it as they expanded.
The master compliance checklist
Work through this as a single quarterly audit rather than nine separate projects:
- [ ] GDPR: privacy notice current, data subject request process tested, lawful basis documented per processing activity
- [ ] Consumer rights/Omnibus: discount price history displayed correctly, reviews disclosed as verified or unverified, personalised pricing disclosed if used
- [ ] GPSR: manufacturer and Responsible Person details on physical product listings, safety warnings present pre-purchase
- [ ] EAA: site tested against WCAG 2.1 AA on core flows (browse, cart, checkout), accessibility statement published
- [ ] AI Act: any AI-driven feature (chatbot, recommendations, pricing) disclosed to users, manipulative-design audit done
- [ ] VAT OSS/IOSS: registration current for all destination markets, thresholds monitored as sales volume grows
- [ ] Cookie consent: banner meets equal-prominence and pre-consent-blocking standards, consent logs retained
- [ ] Packaging/EPR: registered in each destination country's EPR scheme where required, packaging materials reviewed against recyclability rules
- [ ] DSA (if marketplace or UGC-enabled): trader verification in place, notice-and-action mechanism live, dark-pattern audit done
How to actually manage this without a legal department
Most PrestaShop merchants running this checklist aren't going to hire in-house counsel for each regulation. What works in practice:
- Assign an owner per row, even if it's the same person for several — ambiguity is worse than an imperfect single owner.
- Calendar the recurring items (VAT threshold checks, cookie consent log audits, accessibility re-tests) rather than treating compliance as a one-time launch task.
- Use your platform's native tools first — PrestaShop's cookie consent modules, tax rule engines, and CMS pages for legal notices cover a meaningful share of this before you need custom development.
- Budget for a periodic external review, even a light one, on the higher-risk items (GDPR, GPSR) rather than only the areas that feel intuitive to a non-lawyer.
How to work through this checklist
Take the master checklist above and mark each line red, yellow, or green for your store today — not aspirationally, as it actually stands. Whatever's red gets addressed first, starting with GDPR and GPSR, since those two carry the most direct enforcement exposure. Then work through the deep-dive articles linked in each section for the specifics of your red and yellow items.
Frequently asked questions
Do all nine regulations apply to every online store?
No. GDPR, consumer rights law, and cookie consent apply almost universally to any store selling to EU consumers. GPSR applies to physical products specifically. EAA, DSA, and packaging/EPR obligations have scope thresholds (business size, marketplace model, packaging volume) that exempt some smaller or narrowly-scoped stores.
Which regulation carries the biggest compliance risk right now?
GDPR and GPSR see the most active enforcement against online retailers currently, GDPR through data protection authorities and GPSR through market surveillance and marketplace delisting. That said, "biggest risk" depends heavily on your specific business model — a marketplace should weight DSA more heavily, for instance.
How often should I re-audit compliance across this stack?
Quarterly for a working audit, with a deeper review whenever you expand into a new EU market, change your data processing (new marketing tool, new AI feature), or a regulation you track hits a new phase-in deadline, such as ViDA's e-invoicing rollout.
Is a EU-based company automatically exempt from any of this?
No. Every item on this stack applies based on the market you're selling into and the data or products involved, not your company's registration location. Non-EU companies face the same obligations when selling to EU consumers, sometimes with additional requirements like appointing an EU Responsible Person under GPSR.
What's the single highest-impact fix for a store just starting this audit?
Fixing the cookie consent banner and privacy notice tends to be the fastest, most universally applicable win, since nearly every store needs both and the common failure modes (pre-ticked boxes, vague privacy notices) are well documented and quick to correct.
Do micro and small merchants get any general exemptions?
Some regulations include size-based thresholds or exemptions — the EAA exempts qualifying micro-enterprises, for example, and some EPR schemes have minimum packaging-volume thresholds. GDPR, GPSR, and consumer rights law generally don't offer a small-business exemption, though obligations like Article 30 record-keeping scale down for lower-risk, occasional processing.
Related reading
- Understanding GPSR Requirements
- Digital Services Act Explained for Merchants
- What the European Accessibility Act Means for PrestaShop Stores
- How the EU AI Act Will Affect Online Stores
- Omnibus Directive Compliance Guide
