
REP27 · Ecommerce
Article 27 GDPR · Article 16 GPSR · Ecommerce
An online shop selling physical goods into the Union usually has two separate obligations, governed by two regulations, answering to two sets of authorities. Most sellers discover the second one only when a marketplace hides their listings, and the first one only when a European buyer asks. Both are contact-point obligations, and both are satisfied the same way: by naming someone established in the Union.

| What you handle | Article 27 GDPR | Article 16 GPSR |
|---|---|---|
| Customer names and delivery addresses | Yes | No |
| Newsletter subscribers and analytics | Yes | No |
| Physical consumer products | No | Yes |
| Product labels and safety warnings | No | Yes |
| Recall or corrective action | No | Yes |
| A data subject asking for their order history | Yes | No |

Both obligations, always. Customer data on one side, product labelling on the other.
The platform forces the GPSR side and never mentions the GDPR side. Both still apply to you, not to the platform.
You are the controller of customer data and usually the operator placing the goods on the market. The supplier's compliance does not transfer to you.
No GPSR obligation, because there is no physical product. The GDPR side applies exactly as before.
GDPR and GPSR came from different places, a decade apart, and were written by different people for different purposes. To an online shop they arrive as the same thing: a European rule requiring a name and an address on the site and on the parcel.
The convergence is real, and it is why we sell them together. Both require an operator established in the Union. Both require that operator to be reachable by an authority. Both require documentation to be held and produced on request. Both are checked by third parties — a supervisory authority on one side, a marketplace or a market surveillance authority on the other — from information you publish rather than from an audit.
The differences that matter are practical. The GDPR contact point deals with individuals asking about their own data, in whatever language they choose. The GPSR contact point deals with authorities asking about a product, usually with a deadline attached and often about a batch shipped two years earlier. The first needs languages; the second needs records.
A shop that has solved one has usually built half of what the other needs, which is the argument for not buying them from two suppliers on two renewal dates.
If you sell physical consumer products to people in the Union, usually yes. Article 27 GDPR covers the personal data of your customers; Article 16 of the GPSR covers the safety of the goods. They are different regulations with different authorities and different contact points.
Yes, and it is simpler that way: one onboarding, one renewal date, one invoice. We provide both, which is what the Multi plan covers.
It usually makes it worse. You hold customer data as controller, and you are typically the economic operator placing the product on the EU market, so both obligations land on you rather than on the supplier.
The marketplace enforces the GPSR side and ignores the GDPR side. Neither obligation belongs to the marketplace: they belong to the seller.
Almost certainly not. A warehouse operated by a logistics provider is not your establishment; Recital 22 asks for effective and real activity through stable arrangements of your own.
There is no threshold. A customer list, an order history and a newsletter are continuous processing, which fails the occasional-processing exemption in Article 27(2)(a) immediately.
The Multi plan covers Article 27 and the GPSR responsible person together from €890 a year, against buying them from two providers separately.
One form, one renewal date, two designations issued together and both verifiable.
See the plans