Last reviewed: June 2026. Regulatory dates below are flagged where they matter, confirm the current position for your country before you act on any single point.
This is general information, not legal advice. Compliance is the merchant's own responsibility, and no module makes a shop compliant on its own. The tools named here help you carry out a decision correctly once you've made it; they don't make the decision for you. Where a product or situation genuinely sits in a grey area, pay for an hour of a lawyer who does e-commerce.
Most "EU e-commerce law" guides bury you in directives and leave you no better off, you still don't know which rule applies to your store, where to configure it in PrestaShop, or what happens if you skip it. This is the opposite. Think of it as the map: a single page that names every legal obligation a PrestaShop store owner in the EU actually carries, sorts them by how much trouble ignoring them causes, and points you to the one deep guide that handles each in full. Read it once and you'll know exactly what you're responsible for, and what you can safely defer.
We run PrestaShop stores ourselves, so this isn't an abstract list. Where a rule has a real home in the PrestaShop back office, we tell you the path. Where it's deep enough to deserve its own treatment, we link the sibling guide rather than give you a rushed paragraph that gets the details wrong.
The seven obligations every EU store carries
Strip away the directive names and EU e-commerce law comes down to seven areas of responsibility. Every legitimate store touches all seven; the work is knowing which ones you've already satisfied and which are quietly exposed.
| Area | What it governs | Risk if ignored | Where it lives |
|---|---|---|---|
| Data protection (GDPR) | How you collect, store and use customer data | High, fines, complaints to authorities | PrestaShop GDPR module + privacy policy |
| Cookie consent | Tracking scripts before opt-in | Medium-high, the most-audited single item | Front office consent layer |
| Consumer info & withdrawal | Pre-contract disclosures, 14-day returns | Medium, order disputes, chargebacks | CMS pages, checkout button, emails |
| Terms & legal notice | T&Cs, imprint/Impressum | Medium, country-specific, easy to fix | CMS pages, checkout acceptance |
| VAT & invoicing | Correct tax, OSS/IOSS, compliant invoices | High, back-tax, audits | International → Taxes / Localization |
| Price display | Gross prices, unit prices, prior-price rules | Medium, consumer-protection fines | Tax rules + customer-group price display |
| Product safety & accessibility | CE marking, the European Accessibility Act | Varies, liability, EAA enforcement ramping | Product data, theme front office |
So what does this table actually do for you? It turns a vague "am I compliant?" worry into a seven-item audit you can run this afternoon. Go area by area, confirm you've handled it (or follow the linked guide), and the uncertainty is gone. The rest of this page walks each row in the order that matters: highest-risk first.
1. Data protection (GDPR), the highest-stakes obligation
The General Data Protection Regulation governs every piece of personal data your store touches: names, emails, shipping addresses, IP addresses, order history, and the browsing behaviour your analytics records. It carries the largest fines, which is why it sits at the top.
The headline duties: a plain-language privacy policy; the ability to honour access and deletion requests (install and configure the official psgdpr module from Modules → Module Manager; where enabled, customers access export and deletion tools from their own account); a 72-hour breach-notification reflex; and a data processing agreement with every third party that handles your customers' data (your email platform, analytics, payment provider).
Two things make GDPR confusing for store owners: people overestimate the parts that rarely bite small shops and underestimate the parts that do. We separated the genuinely mandatory from the over-cautious busywork in GDPR for online stores: what you must do and what you can skip, and covered the PrestaShop-specific setup, the GDPR module, data export, anonymisation, in GDPR and cookie compliance for PrestaShop. If you only fix one legal thing this quarter, fix this.
2. Cookie consent, the item auditors check first

Cookie consent is technically part of EU privacy law, but it earns its own row because it's the single most visible, and most frequently challenged, compliance item on any store. The rule is strict and specific: before you fire any non-essential script (analytics, marketing pixels, social trackers), the visitor must actively opt in. A banner reading "by continuing to browse you accept cookies" is not consent. The page must work normally if the visitor declines, and the trackers must stay dormant until they say yes.
That "stay dormant until consent" part is where most PrestaShop stores quietly fail: the banner appears, but Google Analytics and the Meta pixel have already loaded in the page head. A compliant setup actually blocks those scripts until the click. The full legal spec, what counts as consent, what you must log, how to handle withdrawal, is in cookie consent for PrestaShop: what the law actually requires.
This is the gap our Cookies Revolution module closes: it holds tracking scripts until the visitor consents, records each consent for your audit trail, and lets customers change their mind later from a preferences panel. The benefit in one line: the most-audited item on your store stops being the one you lose sleep over.
3. Consumer information and the right of withdrawal
EU consumer law overrides whatever your terms say: buyers get a 14-day right to return for any reason, and you owe specific disclosures before they pay, your full business identity, the total price including tax, shipping costs, accepted payment methods, delivery time, and how to exercise the withdrawal right.
One PrestaShop-specific detail trips up many stores: the order-confirmation button must make the payment obligation explicit. A button that just says "Order" or "Complete" can fall short in several jurisdictions (Germany is the strictest, expecting wording equivalent to "order with obligation to pay"). That's a theme/translation string, not a setting, and worth checking before it costs you a dispute.
The withdrawal mechanics (refund timing, who pays return shipping, the exemptions for personalised, hygiene-sealed, perishable and downloaded-digital goods) are detailed enough to live in their own guides: see distance selling regulations and the right of withdrawal for the legal floor, and returns policy: what the law requires and what smart stores offer extra for the part where a generous policy actually wins repeat customers. Selling across borders adds wrinkles to returns. Those are in cross-border returns.
4. Terms, conditions and the legal notice
Two CMS pages do most of the legal-text heavy lifting: your terms and conditions (which the customer should accept at checkout. PrestaShop has a built-in "terms of service" CMS page tied to a checkout checkbox) and your legal notice or imprint. The imprint is mandatory in most EU countries and unforgiving in Germany, where a missing or incomplete Impressum is a common target for competitor warnings; it must carry your company name, address, registration and VAT number.
What actually has to be inside the T&Cs, and what's just filler that lawyers copy-paste, is covered in terms and conditions for your store: what must be included.
5. VAT and invoicing. The costliest area to get wrong
Tax is where mistakes compound silently until an audit, which is why it ranks high. The essentials: if you're VAT-registered in the EU you charge your country's rate domestically, and B2C prices shown to consumers must include VAT. Net-only display to consumers is illegal in most member states. Once your cross-border B2C sales pass the €10,000/year EU-wide threshold, you either register in every destination country or use the One-Stop Shop to file a single return at home. OSS is the simpler path for almost everyone.
VAT is broad enough that we split it across focused guides rather than cram it here. Start with the framework in VAT in the EU: OSS, IOSS and what your PrestaShop store must handle, then the hands-on setup, tax rules, tax zones, the International → Taxes / Tax Rules screens, in tax configuration in PrestaShop. Selling B2B brings reverse charge and net pricing: see B2B e-commerce with PrestaShop for the VAT-number-validation and net-price handling. On the document side, e-invoicing in Europe covers the countries now mandating structured invoices, and invoice customization in PrestaShop plus invoice and order number customization cover making your PrestaShop PDFs legally complete and sequentially numbered the way tax authorities expect.
6. Price display rules
Beyond "include VAT for consumers," EU price-display law adds unit pricing for many product categories and, since the Omnibus Directive, rules about how you show the prior price next to a discount. PrestaShop handles the gross/net decision through your tax rules and the per-customer-group price-display method (set under Shop Parameters → Customer Settings → Groups, where each group is flagged tax-included or tax-excluded), but the legal nuance, when net is allowed, when unit prices are mandatory, how to present a "was/now" price honestly, is its own topic: price display rules in Europe.
7. Product safety, CE marking and accessibility
If you sell physical goods, EU product-safety rules apply, and some regulated product categories need CE marking. CE marking is required only for products covered by specific EU harmonisation legislation, not most consumer products, so verify whether each category is in scope. As the seller you carry a due-diligence duty: where CE marking applies, confirm the marking and safety documentation exist and keep that documentation, because selling non-compliant goods puts the liability on you. The full seller-side picture is in product safety and CE marking.
The newer obligation is the European Accessibility Act, whose requirements apply to in-scope e-commerce services and products from 28 June 2025, subject to exemptions (such as microenterprises providing services) and national transposition. Where it applies, it requires your storefront to be usable by people with disabilities, keyboard navigation, screen-reader compatibility, sufficient colour contrast, text alternatives, accessible forms. Enforcement is still ramping, and an accessible store reaches more buyers either way. What it means in practice for a PrestaShop theme is in accessibility for online stores.
A note on payment compliance
One area people lump under "EU law" is really a payments-industry standard rather than a directive: PCI DSS and strong customer authentication (the 3-D Secure prompt mandated by PSD2). It's mostly handled by your payment provider, but there are store-side responsibilities worth knowing, covered in payment security in PrestaShop.
Your one-afternoon compliance pass
Run these seven checks in order. Each either confirms you're covered or sends you to the guide that fixes it. No guesswork about what "compliant" means.
- Privacy policy & GDPR tooling, policy published in plain language; the official psgdpr module installed and configured from Modules → Module Manager so you can answer access and deletion requests (customers access export/deletion tools from their account where enabled). → GDPR: what to do and skip
- Cookie consent, real opt-in, scripts genuinely blocked until consent (check your page source, not just the banner). → cookie consent the law requires
- Pre-purchase disclosures & pay-obligation button, identity, total price, shipping, withdrawal right all shown before checkout; the order button states the payment obligation. → distance selling rules
- T&Cs and legal notice/imprint, both CMS pages present and complete; T&Cs accepted at checkout. → what must be in your T&Cs
- VAT & invoices, correct rates, OSS if you're over €10k cross-border, compliant invoice PDFs with sequential numbering. → EU VAT, OSS and IOSS
- Price display, gross prices to consumers, unit prices where required, honest prior-price on discounts. → price display rules
- Product safety & accessibility, CE documentation for product categories where it's required; storefront moving toward EAA accessibility. → product safety & CE
FAQ
Does installing the right PrestaShop modules make my store compliant?
No, and it's worth being blunt about it. A module can hold tracking scripts until consent, validate a VAT number, or print a sequentially numbered invoice, but compliance is a set of decisions and documents that remain your responsibility: what data you collect and why, what your terms actually say, whether your VAT registration matches where you sell. The tooling carries out those decisions cleanly; it can't make them for you. Treat any "GDPR module" or "cookie module" as the implementation of a policy you wrote, not a substitute for writing one.
I sell only within my own country. Do EU rules still apply?
Yes. The Consumer Rights Directive, GDPR, cookie-consent rules and price-display rules apply to domestic B2C sales inside any member state. They are not triggered only by crossing a border. What cross-border selling adds is extra layers: the OSS VAT threshold (€10,000/year EU-wide, as of 2026), language obligations for legal text and safety information, and country-specific wrinkles like the German imprint. Selling in one country doesn't exempt you; it just keeps the list shorter.
Which of these seven should a brand-new store fix first?
In risk order, as the page lays out: a published privacy policy plus working GDPR tooling, then genuine cookie consent (scripts blocked until opt-in, not just a banner), then your pre-purchase disclosures and the right of withdrawal. Those three are the most-audited and the most expensive to get wrong. The withdrawal-information failure alone can stretch your return window from 14 days to twelve months. VAT and product safety matter, but they tend to surface on a slower timeline.
Where in PrestaShop do most of these obligations actually live?
Four are CMS pages under Design → Pages (terms, legal notice, privacy, withdrawal/returns information). Tax and price display live under International → Taxes / Localization and Shop Parameters → Customer Settings → Groups. GDPR tooling is the official psgdpr module from Module Manager. Cookie consent and product-safety content are the two that core doesn't fully cover on its own, which is where the linked guides and the Cookies Revolution module come in.
How often should I re-check all this?
Treat the seven-row pass as an annual review, plus a trigger-based one whenever you change something material: start selling into a new country, add a digital or B2B line, cross the OSS threshold, or swap your analytics/marketing stack (which can quietly reintroduce a cookie problem). Regulation also moves, the European Accessibility Act's in-scope requirements applied from 28 June 2025, for instance, so a once-a-year read of the dated statements here, against your current setup, is the cheapest insurance you'll buy.
EU e-commerce law isn't built to punish honest stores, it's built to protect the same customers you're trying to keep. Treated as a checklist it's a long afternoon of work, most of it one-time. Treated as a footing for trust, it's an advantage: the store that's visibly straight on privacy, returns and pricing is the one a cautious European shopper buys from twice. Work down the seven rows, follow the links where you need depth, and the legal framework stops being a worry and becomes one of the quieter reasons your store is the dependable one.