Build a Shopify store in 2 minutes.→
Back to Blog
By Clyro·Guides·September 28, 2026·16 min read

EU Checkout Rules for Online Stores (2026): 11 Requirements, Ranked by Risk

If you sell to consumers in the EU, your checkout has to do eleven things. The two that cost the most when they go wrong: the final button must say the customer is paying ("Pay now", not "Complete order"), and you must tell buyers about their 14-day right of withdrawal before they commit - skip that and their window to cancel stretches by twelve months. And since 19 June 2026 you also need an online withdrawal button, the newest rule and the one most stores have not caught up with yet.

A lot of the checklists that rank for this topic are out of date or loose with the details. Several still tell you to link to an EU complaints platform that shut down in 2025; others overstate what happens when you get the button wrong. So every rule below is checked against the legislation itself or a court ruling, and the sources are linked at the end.

The rules are ranked from the ones that can undo a sale or reopen it for a year, down to the operational ones. None of it is legal advice: these are EU directives, each country writes them into its own law, and the details differ between member states. If you sell heavily into one country, have a local lawyer look at it.

1. The final button must say the customer is paying

This is the rule with the sharpest edge.

The Consumer Rights Directive requires the button that places the order to be labelled "only with the words 'order with obligation to pay' or a corresponding unambiguous formulation" (Article 8(2)). The European Commission's guidance treats "Buy now", "Pay now" and "Confirm purchase" as acceptable, and "Register", "Confirm" and "Order now" as unlikely to be.

Two rulings made this strict in practice. In Fuhrmann-2 (C-249/21, 2022), the EU Court of Justice held that only the words on the button count - text elsewhere on the page explaining that payment is due cannot rescue a vague button. Then in October 2024 the Dutch Supreme Court ruled that buttons reading "place order", "order" and "complete order" do not comply, because in everyday language ordering is not necessarily tied to paying.

The consequence written into the directive is that "the consumer shall not be bound by the contract or order". That is often retold as "the customer keeps the goods for free", which overstates it. What happens next is a matter of national law. In the Dutch cases the contract became voidable at the consumer's choice; where the consumer did not turn up to defend the claim, the court partly voided it and cut the price by a third.

On Shopify: the checkout's final button reads "Pay now", which is fine. Shopify changed it from "Complete Order" - and there are merchants asking how to change it back. Don't. If you have customised your checkout text, or you run a custom checkout or funnel, check the final button says you're paying.

2. Tell buyers about the 14-day right of withdrawal

EU consumers can withdraw from an online purchase within 14 days, without giving a reason (Article 9). For goods, the clock starts when they take physical possession.

You must tell them this before they are bound: the conditions, the deadline, how to withdraw, and the standard model withdrawal form. If you don't, the period does not simply extend to a year - it "shall expire 12 months from the end of the initial withdrawal period" (Article 10). So twelve months on top of the original 14 days. There is a way back: provide the information late, within those twelve months, and the period ends 14 days after the customer receives it.

Three details worth building into your policy:

  • Return shipping. The customer pays the direct cost of sending goods back only if you told them they would. Say nothing and it is yours to pay (Article 14).
  • Refunds. You have 14 days from the withdrawal notice to refund, including the original standard delivery charge. You can hold the refund until the goods are back or the customer shows proof they sent them, whichever comes first (Article 13).
  • Exceptions. The right does not apply to goods made to the customer's specifications or clearly personalised, goods that deteriorate quickly, and sealed goods unsealed after delivery that can't be returned for health or hygiene reasons (Article 16). If an exception applies to what you sell, say so up front.

On Shopify: write this into your refund policy, and make sure it covers the 14 days, how to withdraw, who pays return shipping, and the model form. A generic "returns accepted within 30 days" line does not cover it.

3. Give buyers a withdrawal button (in force since 19 June 2026)

This is the newest rule, and the one most checklists are missing.

A 2023 amendment added Article 11a to the Consumer Rights Directive. It came in through a directive about financial services, but it applies to any distance contract concluded online - physical products included. If a customer can buy through your website or app, they must be able to withdraw through it too.

What it requires:

  • A withdrawal function labelled "withdraw from contract here" or an equally unambiguous formulation, easy to find, and available for the whole withdrawal period.
  • Two steps. First the customer gives their name, details identifying the contract, and how they want the confirmation sent. Then they confirm through a function labelled "confirm withdrawal" or something equally clear.
  • An acknowledgement on a durable medium without undue delay, showing what they submitted and the date and time.

On Shopify: Shopify says its return and cancellation rules can help you meet this requirement - but you have to configure them. Nothing turns on by default, and Shopify is clear that compliance is still your responsibility.

4. The price before the button is the price they pay - and nothing pre-ticked

Before the customer commits, you must show the total price including taxes, plus delivery charges (Article 6(1)(e)). No fees appearing after the click.

Any extra payment beyond the main purchase needs the customer's express consent (Article 22). If you infer consent through "default options which the consumer is required to reject" - a pre-ticked box - the customer is entitled to their money back for it.

And payment fees: you cannot charge more than your actual cost for a payment method (Article 19), and for the most common consumer cards, EU payments law bans surcharges outright.

On Shopify: the checkout shows tax and shipping before payment. Two things to check yourself. First, that your EU prices display with VAT included - Shopify supports this, but confirm it is on for your EU markets. Second, your apps: shipping-protection, insurance and donation add-ons that switch themselves on by default are exactly the pre-ticked box this rule targets.

5. Sale prices must be measured against the 30-day low

If you announce a price reduction, you must show the prior price: the lowest price you charged in the 30 days before the reduction (Price Indication Directive, Article 6a, added by the 2019 Omnibus Directive). It exists to stop a familiar trick - raise the price for a few days, then "slash" it.

The EU Court of Justice sharpened this in Aldi Süd (C-330/23, September 2024): the reduction you advertise has to be calculated from that 30-day low. A "-50%" badge worked out from an inflated list price is non-compliant even if the 30-day price appears somewhere on the page.

Member states can make exceptions - for perishable goods, products on the market less than 30 days, and progressive reductions during one campaign - so check the country you sell into.

On Shopify: Shopify's own guidance is to use the compare-at price, entering the lowest price from the last 30 days - but it is not automatic. The common mistake is putting the original price or RRP in that field. And because most themes calculate their "-X%" sale badge from the compare-at price, a wrong compare-at price makes the badge wrong too, which is exactly the Aldi Süd problem. If your prices change often, a price-history app or a theme change to show "Lowest price in the last 30 days" is safer than updating it by hand.

6. Put product safety details on the listing itself

Since 13 December 2024, the General Product Safety Regulation (GPSR) requires every online offer to show, clearly and visibly (Article 19):

  • the manufacturer's name or trade mark, and a postal and electronic address;
  • if the manufacturer is not in the EU, the name and address of the responsible person in the EU;
  • information identifying the product - a picture, its type, and any other identifier;
  • any warnings or safety information, in a language easily understood by consumers where you are selling.

This belongs on the product listing. A link to a separate page is generally not considered enough.

On Shopify: this is product-page content, so it lives in your theme - usually a block fed by product metafields, so each product carries its own manufacturer and safety details.

7. Make the checkout accessible (European Accessibility Act)

Since 28 June 2025, the European Accessibility Act has covered e-commerce services sold to EU consumers. In practice that means meeting the harmonised standard EN 301 549, which is aligned with WCAG 2.1 AA: text with enough contrast, buttons and form fields that screen readers can name, everything usable with a keyboard, images with alternative text.

There is one exemption for services, and it is narrow: micro-enterprises with fewer than 10 employees and annual turnover or balance sheet of €2 million or less. Both conditions have to be true.

On Shopify: Shopify builds and maintains the checkout itself. Your theme - navigation, product pages, cart, pop-ups - is yours. Pop-ups that trap keyboard focus and low-contrast sale badges are among the most common failures.

8. Don't block or force-redirect foreign customers

Under the Geo-blocking Regulation (2018/302), you cannot block a customer from another EU country from your store, or automatically redirect them to a different country version without their consent. You can't apply different general conditions because of their nationality or where they live, and you can't refuse a card because it was issued in another member state.

What the rule does not do is force you to ship everywhere. You choose where you deliver. A customer from another country can "shop like a local" - buy on your normal terms and collect, or arrange delivery to an address you already ship to.

On Shopify: if you use geolocation to point visitors toward a country store, make it a suggestion they can decline rather than an automatic redirect.

9. Let buyers see the steps and fix mistakes before paying

The E-Commerce Directive requires you to explain the technical steps to complete the purchase, whether the contract will be stored and accessible, how to correct input errors, and which languages are available (Article 10). You must provide "appropriate, effective and accessible technical means" to spot and correct mistakes before the order is placed (Article 11).

On Shopify: the standard checkout's review step and editable fields cover this. It becomes your problem when you build a custom funnel or one-click flow that skips the review.

10. Say who you are, where people can find it

Customers must be able to find out who they are buying from. The E-Commerce Directive (Article 5) and the Consumer Rights Directive (Article 6) together require your business name, geographic address, telephone number and email address, trade register number, and VAT number if you are VAT-registered. The phone number is not optional: until 2022 the rule said "where available", but the Omnibus Directive removed that qualifier. Some countries, Germany most famously with its Impressum, enforce this rigorously.

On Shopify: put these details on a contact or legal-notice page and link it from your footer, so it is one click from every page including checkout.

11. Confirm the order in writing

This is two duties that one email usually covers:

  • Acknowledge the order "without undue delay and by electronic means" (E-Commerce Directive, Article 11).
  • Confirm the contract on a durable medium "within a reasonable time after the conclusion of the distance contract, and at the latest at the time of the delivery of the goods" (Consumer Rights Directive, Article 8(7)). This confirmation must include your pre-contract information - withdrawal rights included - unless you have already given it on a durable medium.

So despite what some checklists say, it does not legally have to arrive the instant they pay - but in practice your order confirmation email is where it belongs.

On Shopify: the order confirmation is sent automatically. Add your withdrawal information, or a link to it and the model form, to that email template so the one email does both jobs.

For years, EU traders had to link to the European Online Dispute Resolution platform. That platform closed on 20 July 2025 (Regulation (EU) 2024/3228), and the duty to link to it ended with it. A link to a complaints service that no longer exists can itself mislead consumers, so take it out of your footer, terms and emails.

What's coming: the Digital Fairness Act

The European Commission is expected to propose a Digital Fairness Act in late 2026, aimed at manipulative design: dark patterns, pressure tactics, subscriptions that are easy to start and hard to cancel. It is not law yet, and would take years to apply.

But some of it is already illegal. Falsely claiming something is available only for a very limited time, to push an immediate decision, is on the EU's blacklist of unfair commercial practices (Unfair Commercial Practices Directive, Annex I). A countdown timer that resets on every page load is not a future risk.

What Shopify handles, and what's on you

Rule Shopify handles Your job
1. "Pay now" button Yes, by default Don't change it back to "Complete order"
2. 14-day withdrawal notice Policy pages Write a policy that actually covers it
3. Withdrawal button Return and cancellation rules Configure them - not on by default
4. Total price, no pre-ticked boxes Shows tax and shipping at checkout VAT-inclusive EU prices; audit add-on apps
5. 30-day prior price The compare-at price field Enter the 30-day low, not the RRP
6. GPSR product details - Theme block and product data
7. Accessibility The checkout Your theme
8. No geo-blocking - No forced redirects
9. Review and correct The checkout Custom funnels
10. Business identity - Contact page, linked in the footer
11. Order confirmation Sends it automatically Add withdrawal info to the template

What most checklists get wrong

  • "Buy now" is risky. The Commission lists it as acceptable. The wording to avoid is "Order", "Place order" or "Complete order".
  • "If the button is wrong, customers keep the goods for free." The directive says the consumer is not bound. What happens to goods already delivered depends on national law, and courts have ordered price reductions rather than free goods.
  • "Miss the withdrawal notice and it becomes a year." It becomes twelve months on top of the 14 days - and giving the information late shortens it again.
  • "Link to the ODR platform." It closed in July 2025. Remove the link.
  • "Send the receipt immediately." The confirmation is due within a reasonable time, at the latest at delivery. Sending it immediately is simply the easiest way to comply.

The parts that live in your theme

Look back down the table and a pattern shows: Shopify's checkout covers most of the transaction itself, and much of what is left is on your storefront. The product-page safety block, how your sale prices and badges are calculated, keyboard-friendly pop-ups, contrast that passes - these are theme changes, and they are the ones most stores never get to because theme work means a developer or a weekend in the code.

That is what Clyro does. Describe the change - "add a product safety section under the description using the manufacturer metafields", "show the lowest price from the last 30 days under the sale price" - and it edits your Shopify theme to match.

FAQ

Do these rules apply if my business is outside the EU? Generally, yes. If you sell to consumers in the EU and direct your store at them, EU consumer rules apply wherever your business is based.

Do they apply to B2B sales? Most of this is consumer protection, so it applies when you sell to consumers. Business customers can agree to different terms on several points, such as the error-correction and order-acknowledgement rules.

What are the fines? Each country sets its own, but for widespread infringements across several member states, the Omnibus Directive requires maximum fines of at least 4% of the trader's annual turnover in the countries concerned. The button and withdrawal rules carry their own consequences on top: a customer who isn't bound, or a cancellation window reopened for a year.

Is Shopify's checkout compliant out of the box? It covers a lot - the button wording, showing total price and delivery, the review step, the confirmation email. It does not cover the parts only you can decide: your policies, your prices, your product information, your apps and your theme. Shopify's own compliance pages say the same: the responsibility stays with the merchant.

Sources

This article is general information, not legal advice. EU directives are written into each member state's own law, and the details vary between countries.

Share: