- Regulation (EU) 2016/679 — GDPR, Article 27
- Directive 2002/58/EC — ePrivacy
- Directive 2011/83/EU — Consumer rights
- Directive 2005/29/EC — Unfair commercial practices
- Regulation (EU) 2023/988 — GPSR Article 19 for the listings
Who has to appoint one
Any retailer established outside the Union running its own store and selling to consumers in the EU. Two distinct obligations arise: the data side, because you process customer and visitor data and almost certainly run analytics and advertising pixels, and the product side, because every physical item you ship needs an EU economic operator.
Thresholds and exemptions
No threshold on either side. The narrow Article 27(2) exemption does not cover a shop with a customer database, and GPSR applies from the first item shipped.
What must appear on the label
On the site: the representative's identity and contact details in the privacy notice, the trader identification required by consumer law, the right of withdrawal information with the model form, delivery and payment terms, and under GPSR Article 19 the manufacturer and responsible person details and warnings for each product before purchase.
Marketplace fields
Payment providers and platforms increasingly verify trader identity and the presence of a lawful cookie banner. Consumer authorities run coordinated sweeps on withdrawal rights, countdown timers and fake scarcity, and cross-border cases are pursued through the CPC network.
Documentation you must hold
Article 30 records listing every processing activity and every processor, from the shop platform to the email tool and the ad pixels. The Article 27 designation. A consent management platform with per-user consent logs. Data processing agreements with each processor. Standard contractual clauses and transfer impact assessments for non-EU transfers. Product technical documentation for the goods themselves.
Standards and testing
Not applicable, except that the cookie banner is effectively tested by regulators: whether non-essential tags fire before consent, whether refusing is as easy as accepting, and whether consent is recorded. Automated sweeps are common.
Language requirements
Privacy notice, cookie banner and consumer information in the language of each market you target. A localised shop with an English-only legal layer is a transparency failure.
When it applies
The representative before processing begins. Consent before any non-essential cookie or pixel fires, which means before the first analytics call, not after the page loads. Withdrawal rights information before the order is placed.
How long records are kept
Processing records for the life of the processing. Consent logs for as long as the processing continues. Order and tax records per national law, typically six to ten years, which is a separate and longer retention than marketing data.
What happens if you do not comply
Up to €20 million or 4% of turnover for unlawful processing, €10 million or 2% for a missing representative, separate national fines for cookie infringements, and consumer law penalties up to 4% of turnover under the Omnibus rules for widespread infringements. GPSR failures suppress nothing on your own site but bring product withdrawal orders.
Who enforces it
Data protection authorities in any member state where customers are, consumer protection authorities through the CPC network, and market surveillance authorities for the products.
Where the boundary lies
Running your own shop removes the marketplace's compliance filter, which sellers often experience as freedom and authorities experience as an unmonitored channel. Nobody suppresses your listing, so the first signal is usually a complaint or a sweep, and by then the exposure covers the whole trading period.
Questions we are asked
- We use Shopify — does that cover us?
- Shopify is a processor for the shop and a controller for its own purposes. Your obligations as controller, including the Article 27 representative, are unaffected by the platform you chose.
- Do we need consent for analytics?
- For storing or reading anything on the user's device that is not strictly necessary, yes, before it happens. That covers analytics and advertising cookies and most pixel-based tracking.
- Is a US privacy policy enough?
- No. It must state the EU representative, the lawful bases, the retention periods, the transfer mechanism and the rights under Articles 15 to 22, in the language of the users.
Who signs for you
EU representative Europe Services, SE — Na Čečeličce 425/4, Smíchov, 150 00 Praha 5, Czech Republic
UK representative REP27 LTD — Unit 82a James Carter Road, Mildenhall, Suffolk IP28 7DE, United Kingdom