E-commerce compliance: the full map of what regulates your store
Five regimes govern a typical online store. Most owners only know about one of them.
Ask a store owner about compliance and you will usually hear about cookies. Cookies are one slice of one regime. A store selling internationally sits inside at least five separate frameworks, each with its own enforcement body and its own idea of what a violation looks like. Here is the whole map, and the specific thing on your site that each one judges.
1. Privacy and data protection
GDPR in the EU and UK, CCPA/CPRA in California, and a growing list of US state laws with near-identical requirements. What they judge: whether trackers wait for consent, whether your policy is accurate and specific, whether people can get their data out or deleted, and whether you can prove any of it.
2. Advertising and marketing claims
The FTC in the US and equivalent consumer authorities elsewhere. What they judge: whether affiliate and sponsorship relationships are disclosed clearly and near the claim, whether health, income or performance claims are substantiated, whether reviews are genuine, and whether 'free trials' convert into charges without clear notice.
- Affiliate links carry a visible disclosure above the fold, not in a footer.
- Testimonials that describe atypical results say so.
- Countdown timers and 'only 3 left' claims are real, not decorative.
- Negative-option and subscription offers disclose the recurring charge before payment.
3. Consumer rights and contract terms
| Requirement | Typical gap |
|---|---|
| Terms of service | No terms page at all, or a template naming another company |
| Refund and return policy | Present but not linked from checkout |
| EU right of withdrawal | 14-day cooling-off period never mentioned |
| Delivery timeframes | Vague 'ships soon' with no stated window |
| Total price disclosure | Shipping and tax revealed only on the final step |
| Trader identity | No legal entity name or contact address anywhere on the site |
4. Accessibility
The ADA in the US, the European Accessibility Act since June 2025, and WCAG 2.2 AA as the shared technical standard. E-commerce is the single most litigated category in the US for web accessibility, and the claims are almost always machine-detectable issues: unlabelled buttons, images without alternative text, insufficient colour contrast, form inputs with no associated label, and keyboard traps in modals.
That is good news. A large share of accessibility exposure can be found automatically and fixed in theme code.
5. Payments and security
- PCI DSS — largely handled by your gateway if you never touch card data, but self-hosted checkouts change that.
- Strong Customer Authentication for European card payments.
- HTTPS everywhere, valid certificates, no mixed content.
- Clear currency, tax and duty disclosure for cross-border sales.
How to keep it manageable
- 1Fix the machine-detectable things first — trackers, missing pages, broken disclosures, accessibility violations. They are the cheapest to fix and the easiest to be caught on.
- 2Get your document set complete and accurate: privacy, cookies, terms, refunds, shipping, contact.
- 3Put the remaining judgement calls — lawful bases, retention periods, claim substantiation — in front of a professional once, then leave them alone.
- 4Monitor continuously. Compliance decays with every app install and theme edit.
Step one and step four are the ones that repeat, and they are the ones worth automating.
See where your own store stands in 60 seconds.
mir-n loads your storefront in a real browser, records every tracker and cookie fired before consent, checks your required documents and runs WCAG tests — then hands you the fix for each finding.
Run a free auditFrequently asked
What is e-commerce compliance?
It is the set of legal obligations that apply to selling online: data protection, advertising standards, consumer contract rights, web accessibility and payment security. Each is enforced by a different authority and judged against different parts of your site.
Which compliance issue gets stores in trouble most often?
In the US, web accessibility lawsuits and FTC disclosure actions. In the EU and UK, cookie and consent complaints. Both categories are dominated by issues that are detectable from the public site.
Do small stores really get enforced against?
Direct regulator action against very small stores is rare. The realistic costs are private accessibility demand letters, payment processor reviews, ad account rejections and lost B2B deals that require a vendor security review.