EU e-commerce compliance audit

I audited a well-known EU fashion marketplace for the 2026 withdrawal-button rule. The gap was not hidden in legal copy.

The Directive 2023/2673 date has now passed: Member States had to transpose it by 19 December 2025, and the new rules apply from 19 June 2026. If you sell to EU consumers online and a statutory withdrawal right applies, the practical question is no longer “does our returns policy mention 14 days?” It is “can a consumer actually withdraw through the online interface?”

Real audit hook

One public-page scan scored 45/100.

I ran Retractly's live audit on a well-known German fashion marketplace and anonymized the store name because this was a public-page signal check, not a legal opinion. The scan found withdrawal wording, legal-footer signals, and cookie-consent signals. It did not find a visible withdrawal button/form signal or a common withdrawal/retractation page path.

Right-of-withdrawal wording found
Yes
Legal footer signal found
Yes
Cookie consent signal found
Yes
Visible withdrawal-button/form signal found
No
Common withdrawal/retractation page path found
No

Important caveat: an automated public-page audit can miss account-only or order-specific flows. That is exactly why merchants should test the consumer journey end-to-end before assuming they are ready.

What online sellers need to check now

Directive 2023/2673 amended the EU Consumer Rights Directive. For e-commerce teams, the operational checklist is concrete:

  1. 14-day withdrawal right wording: your pre-contract and post-purchase information should clearly tell consumers when they have a withdrawal right, how long the period lasts, where exceptions apply, and how to exercise the right. The classic EU baseline is 14 days for covered distance contracts.
  2. Model withdrawal form: if the withdrawal right applies, consumers should be able to use a clear model form or equivalent withdrawal statement. The form should collect enough information to identify the consumer and contract/order.
  3. Online withdrawal function: the online interface should offer an easy-to-find withdrawal function, using “withdraw from contract here” or an unambiguous equivalent. In practice, merchants should treat this as a prominent withdrawal entry point that leads to a confirmation step and sends an acknowledgement on a durable medium, such as email.
  4. Placement and availability: the function needs to be findable during the withdrawal period. A buried PDF, a support inbox, or a returns link that only appears after login may be risky if consumers cannot easily exercise the statutory right.

The real risk is not just a missing button

Non-compliance risk is cumulative: consumer-protection complaints, regulator remediation orders, national penalties, refund disputes, and evidence gaps when a customer says they tried to withdraw but could not. The audit example above is useful because it shows the common failure mode: a merchant can have policy language and still fail the user-interface test.

A practical internal test is simple: ask someone who did not build the site to find the withdrawal path from the homepage, from the order confirmation, and from the account/order page. If they cannot find it quickly, your legal copy is doing too much work and your interface is doing too little.

Paste your store URL for a free instant compliance audit.

Retractly checks withdrawal wording, model-form signals, withdrawal-button/page signals, cookie-consent signals, and legal-footer signals in under a minute.

Paste your store URL for a free instant compliance audit

This article is general information, not legal advice. Directive implementation and enforcement details vary by Member State, and some goods/services are exempt from withdrawal rights. The audit example was run on public pages on 11 August 2026 and should be treated as a signal for review, not as a final legal determination.