E-commerce deadlines 2026/27: What merchants need to implement now
Withdrawal function, PPWR, legal guarantee notice, CCD II, CRA and product passports: the next compliance deadlines from August 2026, ranked by urgency.

Online retail is not facing one isolated legal change, but a chain of deadlines. Two have already passed: since 19 June 2026, affected distance contracts need an online withdrawal function. The EU Packaging and Packaging Waste Regulation (PPWR) has applied since 12 August 2026. New duties on cyber incidents, legal guarantees, durability guarantees and environmental claims follow in September.
Not every merchant needs to implement every regulation at the same time. Five questions determine priority: Do you sell to consumers? Which countries do you supply? Which product groups do you carry? Are you only a distributor or also an importer or manufacturer? And do you offer private-label goods, connected products or consumer finance?
This article updates our whitepaper timeline as at 17 August 2026. One change is particularly important: the EUDR deadlines were postponed again after the whitepaper was published.
The next deadlines at a glance
Between June 2026 and December 2027, eleven compliance deadlines follow one another: from the already-applicable duties around the withdrawal function and PPWR, through CRA reporting, EmpCo guarantee notices and CCD II, to product liability, EUDR, the battery passport and full CRA application. The table orders them by date, applicability and status – each regulation links to its primary source.
| Deadline | Regulation | Who needs to check now | Status |
|---|---|---|---|
| 19 Jun 2026 | Online withdrawal function | B2C shops concluding eligible distance contracts online | already due |
| 12 Aug 2026 | Packaging and Packaging Waste Regulation (PPWR) | Merchants, manufacturers and importers placing packaging on the EU market | applies; individual duties are phased |
| 11 Sep 2026 | Cyber Resilience Act reporting | Manufacturers of connected products and software; importers and distributors in the escalation chain | next deadline |
| 12 Sep 2026 | Data Act: access by design | Manufacturers of connected products and providers of related services | product deadline |
| 27 Sep 2026 | EmpCo: legal guarantee, durability guarantee and green claims | Almost every B2C shop selling goods, digital content or using sustainability claims | urgent |
| 20 Nov 2026 | Consumer Credit Directive II | Shops offering instalments, deferred payment or BNPL | depends on payment model |
| 9 Dec 2026 | New Product Liability Directive | Especially manufacturers, importers, private labels and software providers | national transposition and new products |
| 30 Dec 2026 | EU Deforestation Regulation (EUDR) | First operators and exporters of relevant commodities and products | postponed deadline |
| 18 Feb 2027 | Battery passport and removability | Certain EV, industrial and LMT batteries plus products with portable batteries | assortment-specific |
| 30 Jun 2027 | EUDR for most micro and small undertakings | Affected small first operators and exporters | special deadline |
| 11 Dec 2027 | Cyber Resilience Act full application | Manufacturers, importers and distributors of products with digital elements | structural programme |
This table is a prioritisation aid, not a blanket assessment of applicability. An EU directive also needs national transposition, whereas an EU regulation is generally directly applicable. The business model, member state and national law therefore remain decisive.
Three existing obligations belong in every backlog audit
Three rulebooks have applied for some time and belong in every backlog audit: the General Product Safety Regulation GPSR (since December 2024), the European Accessibility Act with national laws such as Germany's BFSG (since June 2025) and the Data Act (since September 2025, with a product-specific follow-up date in September 2026). Businesses that treated them as completed legal projects should check whether they still work across the live assortment, new templates and the most recent relaunch.
GPSR: Mandatory information belongs on the specific offer
The General Product Safety Regulation has applied since 13 December 2024. For online retail, it changed which product and manufacturer details need to be visible in a distance-sales offer. Depending on the product, these include a unique identifier, contact details for the manufacturer and, where relevant, the responsible person in the EU, as well as warnings and safety information. Regulation (EU) 2023/988 expressly covers online offers and fulfilment actors.
A one-off data import is not enough. New suppliers, variants, bundles and marketplace feeds can introduce gaps at any time. A GPSR audit should sample product pages, mobile views, language versions and external sales channels. If the source data are absent from PIM or ERP, a manually maintained shop text field is rarely sustainable.
Accessibility remains an operational quality attribute
The European Accessibility Act has applied to covered e-commerce services since 28 June 2025 through national implementing laws. Germany's BFSG, for example, exempts microenterprises providing services, but that exemption does not automatically remove every product requirement. The exact scope depends on the relevant national law; Germany defines it in § 1 BFSG and the microenterprise rule in § 3 BFSG.
For a shop project, accessibility does not end with an automated Lighthouse score. Navigation, search, filters, variant selection, cart, checkout, payments, account and error handling need keyboard and assistive-technology testing. Theme updates, plugin replacements and new CMS elements can all require renewed functional checks.
Data Act: Access by design becomes concrete on 12 September 2026
The Data Act has generally applied since 12 September 2025. A further date is important for connected products and related services: the design obligation in Article 3(1) applies to products placed on the market after 12 September 2026. Users should be able to access the product and related-service data generated by use easily, securely and generally free of charge. The phased application is set out in Article 50 of Regulation (EU) 2023/2854.
For a pure reseller without access to the data platform, this is usually not an in-house development task. Private labels, IoT products, apps, customer portals and related services need to establish where users request data, in which format they receive it, and how contracts and privacy notices support the process. This overlaps with the CRA but is not the same programme: the Data Act regulates access to and use of data, while the CRA regulates product cybersecurity.
Already due: withdrawal function and PPWR
Two duties are already in force: since 19 June 2026, eligible online consumer contracts require an electronic withdrawal function – in Germany under section 356a BGB – and the EU Packaging and Packaging Waste Regulation PPWR has applied since 12 August 2026. A business that has not implemented either one is no longer preparing; it is catching up.
Online withdrawal function since 19 June 2026
Businesses offering consumers eligible distance contracts online must enable withdrawal through an easy-to-find online function. This involves more than a link: after entering the required information, the customer must be able to confirm the withdrawal explicitly and receive confirmation on a durable medium. The function must remain available throughout the withdrawal period. These rules come from Directive (EU) 2023/2673 and have applied since 19 June 2026.
For a detailed guide to when the function is actually required, what the workflow needs to cover and how to implement it natively or with a plugin in Shopware 6, see Withdrawal button 2026: requirement, implementation and Shopware 6 guide.
Three questions are enough for an initial shop audit:
- Is the function accessible without logging in or searching the footer?
- Do identification, confirmation and email evidence work end to end?
- Are withdrawals passed to customer service, ERP and returns processes in a structured format?
A contact form or email address alone does not cover this journey.
PPWR applies from 12 August 2026, but not every duty starts at once
The Packaging and Packaging Waste Regulation (EU) 2025/40 has applied since 12 August 2026. This does not mean that every labelling, recycled-content and reuse target became effective on the same day. Many requirements are phased or still require more detailed legal acts.
The groundwork is due now: map packaging types and countries, determine supply-chain roles, check registrations and extended producer responsibility schemes, and make material, weight and supplier data centrally available. Asking for that data only when the next labelling deadline arrives is too late.
11 September 2026: CRA reporting routes must work
The Cyber Resilience Act covers products with digital elements, including connected devices, IoT components and commercially supplied software. Regulation (EU) 2024/2847 applies in full from 11 December 2027, but reporting duties for actively exploited vulnerabilities and severe security incidents start on 11 September 2026, as also confirmed by the official EUR-Lex CRA summary.
Manufacturers bear the direct reporting duty. Distributors and importers still need a reliable escalation route: Who receives a security report? How is the manufacturer identified? Who stops sales if there is a serious risk? Can the business trace the affected batch, software version and customer group?
The manufacturer role deserves particular attention for private labels and custom-developed software. A plan for security updates, technical documentation and conformity assessment should already be on the roadmap to December 2027.
27 September 2026: Visible changes in B2C shops
The Empowering Consumers for the Green Transition Directive, or EmpCo, directly affects product communication and shop interfaces. National measures apply from 27 September 2026. Directive (EU) 2024/825 tightens the rules for environmental claims and introduces harmonised information on legal guarantees and commercial guarantees of durability.
Three workstreams matter for online merchants:
- Legal guarantee notice: The harmonised notice on the legal guarantee of conformity must be integrated prominently into the B2C experience.
- Durability guarantee: The harmonised label is shown on a particular product only where the producer provides a free durability guarantee of more than two years for the entire product and makes that information available. It is not a general quality badge.
- Green claims: Generic claims such as “environmentally friendly”, “climate neutral” or “green” need a robust basis or must be removed from product data, banners, filters and campaigns.
The design and content of both notice and label are prescribed by Implementing Regulation (EU) 2025/1960. Custom icons or freely worded substitutes are therefore not a safe shortcut.
20 November 2026: Reassess payment methods under CCD II
The new Consumer Credit Directive expands the European framework for consumer credit and deferred payment. National rules apply from 20 November 2026. Directive (EU) 2023/2225 contains exemptions, but “invoice purchase” or “Buy Now, Pay Later” are not outside its scope simply because of their labels.
Merchants should classify each payment method together with their payment service provider and legal counsel: Who is the creditor or intermediary? How long is payment deferred? Are there interest, fees or late charges? Who handles information duties, creditworthiness assessment and withdrawal? The answers must align across checkout, contracts and support processes before the deadline.
December 2026: Put product liability and EUDR in context
Two frameworks become relevant in December 2026: the new Product Liability Directive must be transposed by 9 December 2026 and expressly covers software for the first time, while the EU Deforestation Regulation EUDR – after its latest postponement – applies from 30 December 2026 for most affected businesses, and from 30 June 2027 for most micro and small undertakings.
New product liability from 9 December 2026
The new Product Liability Directive expressly includes software and digital components. Member states must transpose it by 9 December 2026, and it covers products placed on the market or put into service from that date. This follows from Directive (EU) 2024/2853.
This deadline does not require a new shop button. It is a trigger to review roles, supplier contracts, traceability, technical records and insurance, especially for imports, private labels, bundles and digitally enhanced products.
EUDR postponed to 30 December 2026 or 30 June 2027
The earlier timeline in the whitepaper is no longer current. Following the latest amendment, the EU Deforestation Regulation applies from 30 December 2026 for most affected businesses. Most micro and small undertakings have until 30 June 2027; certain small undertakings already covered by the EU Timber Regulation remain on the December 2026 date. The European Commission's current EUDR report summarises the change.
The rules do not apply to all merchants indiscriminately, but to relevant products derived from cattle, cocoa, coffee, oil palm, rubber, soya and wood. The revised model focuses the due diligence statement more closely on the first operator or exporter. Downstream merchants still need reliable product classification, supplier references and a process for authority requests.
Four merchant profiles and their likely priorities
A useful roadmap comes from the business's role, not from the number of legal acts. Four profiles cover most shops: the German B2C reseller, the cross-border EU merchant, the importer or private-label manufacturer, and the provider of digital or connected products. Each profile has a different set of likely priorities – the following cuts help with a first assessment.
1. German B2C reseller
A business selling standard products from EU suppliers only to German consumers should start with the withdrawal function, accessibility, GPSR display and September's EmpCo changes. PPWR and CCD II join the list where the merchant uses its own shipping packaging or offers finance and deferred payment. CRA, battery passports and EUDR remain assortment-dependent.
2. Cross-border EU merchant
Every destination country adds dependencies: language versions, country-specific registrations, extended producer responsibility schemes, take-back and packaging duties, and national transposition of directives. Shopware sales channels can separate countries, domains and languages, but do not replace a documented check that information and registrations are correct in each target market.
3. Importer, private label or manufacturer
This profile faces the highest regulatory density. Alongside GPSR and PPWR, product liability, CRA, Data Act, battery law and potentially EUDR become core programmes. The decisive question is not what appears in the footer, but whether technical files, risk assessment, conformity, vulnerability handling, traceability and supplier evidence exist. A merchant may become the legal manufacturer when marketing a product under its own name or brand.
4. Provider of digital or connected products
For software, IoT devices, apps and related services, several regulations touch the same data flow. Data Act, CRA, new product liability, EmpCo update information and data protection need one shared model. Solving each in isolation quickly produces four portals, four owners and conflicting claims about update and support periods.
18 February 2027: Not every battery needs a passport
From 18 February 2027, LMT batteries, electric vehicle batteries and industrial batteries above 2 kWh need an electronic battery passport. The Batteries Regulation (EU) 2023/1542 also starts applying removability and replaceability requirements for portable and LMT batteries on that date.
A merchant selling ordinary button cells therefore does not automatically have to create battery passports. Businesses selling affected batteries, e-bikes, storage systems or products with built-in batteries should clarify who provides the passport, how QR access reaches product and data flows, and which information needs to appear in the shop.
What belongs on the next 30-day roadmap
The sensible order follows risk and technical lead time: first the already-due withdrawal function and PPWR groundwork, by the end of August the CRA reporting and escalation process, by mid-September the visible EmpCo changes, in parallel the CCD II assessment of payment methods – and for Q4 and 2027, product liability, EUDR and battery data. In concrete terms:
- Today: Test the withdrawal function end to end and document PPWR roles and packaging data.
- By the end of August: Define CRA reporting and escalation for connected products; mark manufacturer and importer roles by assortment.
- By mid-September: Integrate the legal guarantee notice and conditional durability label; inventory environmental claims across shop, feeds and campaigns.
- In parallel: Assess BNPL, instalment and invoice payment against CCD II with payment providers.
- Plan for Q4: Review product-liability records and the EUDR assortment; assign owners and deadlines to supplier-data gaps.
- Prepare 2027: Treat battery data and CRA conformity as cross-functional programmes involving purchasing, product, IT and legal, not content tasks.
Where these requirements land in Shopware
Compliance is not one menu item in the Administration. Duties spread across five system areas: the product model and PIM as the data foundation for GPSR, PPWR, EUDR and battery passports; storefront and CMS for visible notices and labels; checkout and account for withdrawal and CCD II; Administration and Flow Builder for incident workflows; and monitoring and evidence. This system matrix helps estimate the real effort.
Product model, PIM and supplier data
This is the foundation for GPSR, PPWR, EUDR, battery passports and parts of EmpCo. More fields alone are not enough; ownership and validation matter. Which GTIN or model identifier is authoritative? Who supplies manufacturer address, responsible person, warnings, packaging material, guarantee period, update period and due diligence statement reference? Which data belong at variant level?
Required fields should depend on product group, brand, manufacturer role and country of sale. A battery-passport field across the entire catalogue creates as much confusion as one free-text field for every safety instruction.
Storefront and CMS
Product detail pages, listings, search and CMS expose the information. Notices must be visible, understandable, correctly translated and accessible. EmpCo labels, GPSR warnings and manufacturer details have different conditions and should not collapse into one static text block. AI and marketplace feeds need the same approved source data, or the shop can be correct while an external channel remains outdated.
Checkout, account and customer service
The withdrawal function and CCD II directly affect the purchase journey. A Shopware extension can implement input and confirmation, but the process does not end in the frontend. Status, timestamp, confirmation, order association and handover to service or ERP need to work as an auditable chain. Payment methods also require tests that notices, credit checks and contractual parties switch correctly across countries and breakpoints.
Administration, Flow Builder and integrations
CRA incidents, product recalls, EUDR requests and data-access requests need unambiguous workflows. Shopware rules, Flow Builder events and integrations can distribute work, but the business decision remains with a named owner. Useful designs define escalation levels, deadlines, deputies and evidence of which data were sent to whom and when.
Monitoring and evidence
Go-live is only a snapshot. Product data change, plugins are updated, and new countries or payment methods are added. Automated mandatory-field checks, accessibility tests, sampling plans and a regular compliance review therefore belong in operations. Good evidence answers not only “Is the information visible today?” but also “Which rule and source record caused this display?”
The most useful technical answer is rarely one separate compliance plugin per law. A shared data foundation for manufacturer role, material, packaging, guarantee, software version, risk and evidence works better. Shopware, PIM, ERP, feeds and documents can then consume the information that must be shown or transmitted at each deadline.
Conclusion: Assess applicability before implementing
The biggest risk is not failing to read a 200-page regulation in full. It is clarifying responsibility and data needs only weeks before the deadline. Businesses that map assortment, countries, customer groups and supply-chain roles once can work through the coming dates with much greater precision.
The exact position depends on the business model and national implementation. This article provides operational orientation and is not legal advice for an individual case.
Official sources
- Online withdrawal function – Directive (EU) 2023/2673
- General Product Safety Regulation – Regulation (EU) 2023/988
- German Accessibility Strengthening Act (BFSG)
- EU Data Act – Regulation (EU) 2023/2854
- PPWR – Regulation (EU) 2025/40
- Cyber Resilience Act – Regulation (EU) 2024/2847
- EmpCo – Directive (EU) 2024/825
- Consumer Credit Directive – Directive (EU) 2023/2225
- Product Liability Directive – Directive (EU) 2024/2853
- EUDR: current European Commission report
- Batteries Regulation – Regulation (EU) 2023/1542
Let's talk about your system.
No pitch deck. A conversation with the people who build.
