---
title: "E-commerce deadlines 2026/27: What merchants need to implement now"
description: "Withdrawal function, PPWR, legal guarantee notice, CCD II, CRA and product passports: the next compliance deadlines from August 2026, ranked by urgency."
canonical_url: "https://nuonic.de/en/insights/e-commerce-deadlines-2026-27"
last_updated: "2026-08-18"
---

Online retail is not facing one isolated legal change, but a chain of
deadlines. Two have already passed: since 19 June 2026, affected distance
contracts need an online withdrawal function. The EU Packaging and Packaging
Waste Regulation (PPWR) has applied since 12 August 2026. New duties on cyber
incidents, legal guarantees, durability guarantees and environmental claims
follow in September.

Not every merchant needs to implement every regulation at the same time. Five
questions determine priority: Do you sell to consumers? Which countries do
you supply? Which product groups do you carry? Are you only a distributor or
also an importer or manufacturer? And do you offer private-label goods,
connected products or consumer finance?

This article updates our whitepaper timeline as at 17 August 2026. One change
is particularly important: the EUDR deadlines were postponed again after the
whitepaper was published.

<whitepaper-teaser slug="e-commerce-compliance-2026-27">



</whitepaper-teaser>

## The next deadlines at a glance

Between June 2026 and December 2027, eleven compliance deadlines follow one
another: from the already-applicable duties around the withdrawal function and
PPWR, through CRA reporting, EmpCo guarantee notices and CCD II, to product
liability, EUDR, the battery passport and full CRA application. The table
orders them by date, applicability and status – each regulation links to its
primary source.

<table>
<thead>
  <tr>
    <th>
      Deadline
    </th>
    
    <th>
      Regulation
    </th>
    
    <th>
      Who needs to check now
    </th>
    
    <th>
      Status
    </th>
  </tr>
</thead>

<tbody>
  <tr>
    <td>
      19 Jun 2026
    </td>
    
    <td>
      <a href="https://www.gesetze-im-internet.de/bgb/__356a.html" rel="nofollow">
        Online withdrawal function
      </a>
    </td>
    
    <td>
      B2C shops concluding eligible distance contracts online
    </td>
    
    <td>
      already due
    </td>
  </tr>
  
  <tr>
    <td>
      12 Aug 2026
    </td>
    
    <td>
      <a href="https://eur-lex.europa.eu/eli/reg/2025/40/oj/eng" rel="nofollow">
        Packaging and Packaging Waste Regulation (PPWR)
      </a>
    </td>
    
    <td>
      Merchants, manufacturers and importers placing packaging on the EU market
    </td>
    
    <td>
      applies; individual duties are phased
    </td>
  </tr>
  
  <tr>
    <td>
      11 Sep 2026
    </td>
    
    <td>
      <a href="https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng" rel="nofollow">
        Cyber Resilience Act reporting
      </a>
    </td>
    
    <td>
      Manufacturers of connected products and software; importers and distributors in the escalation chain
    </td>
    
    <td>
      next deadline
    </td>
  </tr>
  
  <tr>
    <td>
      12 Sep 2026
    </td>
    
    <td>
      <a href="https://eur-lex.europa.eu/eli/reg/2023/2854/oj/eng" rel="nofollow">
        Data Act: access by design
      </a>
    </td>
    
    <td>
      Manufacturers of connected products and providers of related services
    </td>
    
    <td>
      product deadline
    </td>
  </tr>
  
  <tr>
    <td>
      27 Sep 2026
    </td>
    
    <td>
      <a href="https://eur-lex.europa.eu/eli/dir/2024/825/oj/eng" rel="nofollow">
        EmpCo: legal guarantee, durability guarantee and green claims
      </a>
    </td>
    
    <td>
      Almost every B2C shop selling goods, digital content or using sustainability claims
    </td>
    
    <td>
      urgent
    </td>
  </tr>
  
  <tr>
    <td>
      20 Nov 2026
    </td>
    
    <td>
      <a href="https://eur-lex.europa.eu/eli/dir/2023/2225/oj/eng" rel="nofollow">
        Consumer Credit Directive II
      </a>
    </td>
    
    <td>
      Shops offering instalments, deferred payment or BNPL
    </td>
    
    <td>
      depends on payment model
    </td>
  </tr>
  
  <tr>
    <td>
      9 Dec 2026
    </td>
    
    <td>
      <a href="https://eur-lex.europa.eu/eli/dir/2024/2853/oj/eng" rel="nofollow">
        New Product Liability Directive
      </a>
    </td>
    
    <td>
      Especially manufacturers, importers, private labels and software providers
    </td>
    
    <td>
      national transposition and new products
    </td>
  </tr>
  
  <tr>
    <td>
      30 Dec 2026
    </td>
    
    <td>
      <a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A52026DC0191" rel="nofollow">
        EU Deforestation Regulation (EUDR)
      </a>
    </td>
    
    <td>
      First operators and exporters of relevant commodities and products
    </td>
    
    <td>
      postponed deadline
    </td>
  </tr>
  
  <tr>
    <td>
      18 Feb 2027
    </td>
    
    <td>
      <a href="https://eur-lex.europa.eu/eli/reg/2023/1542/oj/eng" rel="nofollow">
        Battery passport and removability
      </a>
    </td>
    
    <td>
      Certain EV, industrial and LMT batteries plus products with portable batteries
    </td>
    
    <td>
      assortment-specific
    </td>
  </tr>
  
  <tr>
    <td>
      30 Jun 2027
    </td>
    
    <td>
      <a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A52026DC0191" rel="nofollow">
        EUDR for most micro and small undertakings
      </a>
    </td>
    
    <td>
      Affected small first operators and exporters
    </td>
    
    <td>
      special deadline
    </td>
  </tr>
  
  <tr>
    <td>
      11 Dec 2027
    </td>
    
    <td>
      <a href="https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng" rel="nofollow">
        Cyber Resilience Act full application
      </a>
    </td>
    
    <td>
      Manufacturers, importers and distributors of products with digital elements
    </td>
    
    <td>
      structural programme
    </td>
  </tr>
</tbody>
</table>

This table is a prioritisation aid, not a blanket assessment of applicability.
An EU directive also needs national transposition, whereas an EU regulation
is generally directly applicable. The business model, member state and
national law therefore remain decisive.

## Three existing obligations belong in every backlog audit

Three rulebooks have applied for some time and belong in every backlog audit:
the General Product Safety Regulation GPSR (since December 2024), the European
Accessibility Act with national laws such as Germany's BFSG (since June 2025)
and the Data Act (since September 2025, with a product-specific follow-up date
in September 2026). Businesses that treated them as completed legal projects
should check whether they still work across the live assortment, new templates
and the most recent relaunch.

### GPSR: Mandatory information belongs on the specific offer

The General Product Safety Regulation has applied since 13 December 2024. For
online retail, it changed which product and manufacturer details need to be
visible in a distance-sales offer. Depending on the product, these include a
unique identifier, contact details for the manufacturer and, where relevant,
the responsible person in the EU, as well as warnings and safety information.
[Regulation (EU) 2023/988](https://eur-lex.europa.eu/eli/reg/2023/988/oj/eng)
expressly covers online offers and fulfilment actors.

A one-off data import is not enough. New suppliers, variants, bundles and
marketplace feeds can introduce gaps at any time. A GPSR audit should sample
product pages, mobile views, language versions and external sales channels.
If the source data are absent from PIM or ERP, a manually maintained shop text
field is rarely sustainable.

### Accessibility remains an operational quality attribute

The European Accessibility Act has applied to covered e-commerce services
since 28 June 2025 through national implementing laws. Germany's BFSG, for
example, exempts microenterprises providing services, but that exemption does
not automatically remove every product requirement. The exact scope depends
on the relevant national law; Germany defines it in
[§ 1 BFSG](https://www.gesetze-im-internet.de/bfsg/__1.html) and the
[microenterprise rule in § 3 BFSG](https://www.gesetze-im-internet.de/bfsg/__3.html).

For a shop project, accessibility does not end with an automated Lighthouse
score. Navigation, search, filters, variant selection, cart, checkout,
payments, account and error handling need keyboard and assistive-technology
testing. Theme updates, plugin replacements and new CMS elements can all
require renewed functional checks.

### Data Act: Access by design becomes concrete on 12 September 2026

The Data Act has generally applied since 12 September 2025. A further date is
important for connected products and related services: the design obligation
in Article 3(1) applies to products placed on the market after 12 September
2026. Users should be able to access the product and related-service data
generated by use easily, securely and generally free of charge. The phased
application is set out in Article 50 of
[Regulation (EU) 2023/2854](https://eur-lex.europa.eu/eli/reg/2023/2854/oj/eng).

For a pure reseller without access to the data platform, this is usually not
an in-house development task. Private labels, IoT products, apps, customer
portals and related services need to establish where users request data, in
which format they receive it, and how contracts and privacy notices support
the process. This overlaps with the CRA but is not the same programme: the
Data Act regulates access to and use of data, while the CRA regulates product
cybersecurity.

## Already due: withdrawal function and PPWR

Two duties are already in force: since 19 June 2026, eligible online consumer
contracts require an electronic withdrawal function – in Germany under
[section 356a BGB](https://www.gesetze-im-internet.de/bgb/__356a.html) – and
the EU Packaging and Packaging Waste Regulation PPWR has applied since 12
August 2026. A business that has not implemented either one is no longer
preparing; it is catching up.

### Online withdrawal function since 19 June 2026

Businesses offering consumers eligible distance contracts online must enable
withdrawal through an easy-to-find online function. This involves more than a
link: after entering the required information, the customer must be able to
confirm the withdrawal explicitly and receive confirmation on a durable
medium. The function must remain available throughout the withdrawal period.
These rules come from
[Directive (EU) 2023/2673](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32023L2673)
and have applied since 19 June 2026.

For a detailed guide to when the function is actually required, what the
workflow needs to cover and how to implement it natively or with a plugin in
Shopware 6, see [Withdrawal button 2026: requirement, implementation and
Shopware 6 guide](/en/insights/withdrawal-button-shopware-6).

Three questions are enough for an initial shop audit:

1. Is the function accessible without logging in or searching the footer?
2. Do identification, confirmation and email evidence work end to end?
3. Are withdrawals passed to customer service, ERP and returns processes in a
structured format?

A contact form or email address alone does not cover this journey.

### PPWR applies from 12 August 2026, but not every duty starts at once

The [Packaging and Packaging Waste Regulation (EU) 2025/40](https://eur-lex.europa.eu/eli/reg/2025/40/oj/eng)
has applied since 12 August 2026. This does not mean that every labelling,
recycled-content and reuse target became effective on the same day. Many
requirements are phased or still require more detailed legal acts.

The groundwork is due now: map packaging types and countries, determine
supply-chain roles, check registrations and extended producer responsibility
schemes, and make material, weight and supplier data centrally available.
Asking for that data only when the next labelling deadline arrives is too
late.

## 11 September 2026: CRA reporting routes must work

The Cyber Resilience Act covers products with digital elements, including
connected devices, IoT components and commercially supplied software.
[Regulation (EU) 2024/2847](https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng)
applies in full from 11 December 2027, but reporting duties for actively
exploited vulnerabilities and severe security incidents start on 11 September
2026, as also confirmed by the
[official EUR-Lex CRA summary](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=legissum%3A4797302).

Manufacturers bear the direct reporting duty. Distributors and importers
still need a reliable escalation route: Who receives a security report? How
is the manufacturer identified? Who stops sales if there is a serious risk?
Can the business trace the affected batch, software version and customer
group?

The manufacturer role deserves particular attention for private labels and
custom-developed software. A plan for security updates, technical
documentation and conformity assessment should already be on the roadmap to
December 2027.

## 27 September 2026: Visible changes in B2C shops

The Empowering Consumers for the Green Transition Directive, or EmpCo,
directly affects product communication and shop interfaces. National measures
apply from 27 September 2026.
[Directive (EU) 2024/825](https://eur-lex.europa.eu/eli/dir/2024/825/oj/eng)
tightens the rules for environmental claims and introduces harmonised
information on legal guarantees and commercial guarantees of durability.

Three workstreams matter for online merchants:

- **Legal guarantee notice:** The harmonised notice on the legal guarantee of
conformity must be integrated prominently into the B2C experience.
- **Durability guarantee:** The harmonised label is shown on a particular
product only where the producer provides a free durability guarantee of
more than two years for the entire product and makes that information
available. It is not a general quality badge.
- **Green claims:** Generic claims such as “environmentally friendly”,
“climate neutral” or “green” need a robust basis or must be removed from
product data, banners, filters and campaigns.

The design and content of both notice and label are prescribed by
[Implementing Regulation (EU) 2025/1960](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32025R1960).
Custom icons or freely worded substitutes are therefore not a safe shortcut.

## 20 November 2026: Reassess payment methods under CCD II

The new Consumer Credit Directive expands the European framework for
consumer credit and deferred payment. National rules apply from 20 November
2026. [Directive (EU) 2023/2225](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32023L2225)
contains exemptions, but “invoice purchase” or “Buy Now, Pay Later” are not
outside its scope simply because of their labels.

Merchants should classify each payment method together with their payment
service provider and legal counsel: Who is the creditor or intermediary? How
long is payment deferred? Are there interest, fees or late charges? Who
handles information duties, creditworthiness assessment and withdrawal? The
answers must align across checkout, contracts and support processes before the
deadline.

## December 2026: Put product liability and EUDR in context

Two frameworks become relevant in December 2026: the new Product Liability
Directive must be transposed by 9 December 2026 and expressly covers software
for the first time, while the EU Deforestation Regulation EUDR – after its
latest postponement – applies from 30 December 2026 for most affected
businesses, and from 30 June 2027 for most micro and small undertakings.

### New product liability from 9 December 2026

The new Product Liability Directive expressly includes software and digital
components. Member states must transpose it by 9 December 2026, and it covers
products placed on the market or put into service from that date. This follows
from [Directive (EU) 2024/2853](https://eur-lex.europa.eu/eli/dir/2024/2853/oj/eng).

This deadline does not require a new shop button. It is a trigger to review
roles, supplier contracts, traceability, technical records and insurance,
especially for imports, private labels, bundles and digitally enhanced
products.

### EUDR postponed to 30 December 2026 or 30 June 2027

The earlier timeline in the whitepaper is no longer current. Following the
latest amendment, the EU Deforestation Regulation applies from 30 December
2026 for most affected businesses. Most micro and small undertakings have
until 30 June 2027; certain small undertakings already covered by the EU
Timber Regulation remain on the December 2026 date. The
[European Commission's current EUDR report](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A52026DC0191)
summarises the change.

The rules do not apply to all merchants indiscriminately, but to relevant
products derived from cattle, cocoa, coffee, oil palm, rubber, soya and wood.
The revised model focuses the due diligence statement more closely on the
first operator or exporter. Downstream merchants still need reliable product
classification, supplier references and a process for authority requests.

## Four merchant profiles and their likely priorities

A useful roadmap comes from the business's role, not from the number of legal
acts. Four profiles cover most shops: the German B2C reseller, the
cross-border EU merchant, the importer or private-label manufacturer, and the
provider of digital or connected products. Each profile has a different set of
likely priorities – the following cuts help with a first assessment.

### 1. German B2C reseller

A business selling standard products from EU suppliers only to German
consumers should start with the withdrawal function, accessibility, GPSR
display and September's EmpCo changes. PPWR and CCD II join the list where the
merchant uses its own shipping packaging or offers finance and deferred
payment. CRA, battery passports and EUDR remain assortment-dependent.

### 2. Cross-border EU merchant

Every destination country adds dependencies: language versions,
country-specific registrations, extended producer responsibility schemes,
take-back and packaging duties, and national transposition of directives.
[Shopware sales channels](https://docs.shopware.com/en/shopware-6-en/settings/saleschannel)
can separate countries, domains and languages, but do
not replace a documented check that information and registrations are correct
in each target market.

### 3. Importer, private label or manufacturer

This profile faces the highest regulatory density. Alongside GPSR and PPWR,
product liability, CRA, Data Act, battery law and potentially EUDR become core
programmes. The decisive question is not what appears in the footer, but
whether technical files, risk assessment, conformity, vulnerability handling,
traceability and supplier evidence exist. A merchant may become the legal
manufacturer when marketing a product under its own name or brand.

### 4. Provider of digital or connected products

For software, IoT devices, apps and related services, several regulations
touch the same data flow. Data Act, CRA, new product liability, EmpCo update
information and data protection need one shared model. Solving each in
isolation quickly produces four portals, four owners and conflicting claims
about update and support periods.

## 18 February 2027: Not every battery needs a passport

From 18 February 2027, LMT batteries, electric vehicle batteries and
industrial batteries above 2 kWh need an electronic battery passport. The
[Batteries Regulation (EU) 2023/1542](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32023R1542)
also starts applying removability and replaceability requirements for portable
and LMT batteries on that date.

A merchant selling ordinary button cells therefore does not automatically
have to create battery passports. Businesses selling affected batteries,
e-bikes, storage systems or products with built-in batteries should clarify
who provides the passport, how QR access reaches product and data flows, and
which information needs to appear in the shop.

## What belongs on the next 30-day roadmap

The sensible order follows risk and technical lead time: first the
already-due withdrawal function and PPWR groundwork, by the end of August the
CRA reporting and escalation process, by mid-September the visible EmpCo
changes, in parallel the CCD II assessment of payment methods – and for Q4
and 2027, product liability, EUDR and battery data. In concrete terms:

1. **Today:** Test the withdrawal function end to end and document PPWR roles
and packaging data.
2. **By the end of August:** Define CRA reporting and escalation for connected
products; mark manufacturer and importer roles by assortment.
3. **By mid-September:** Integrate the legal guarantee notice and conditional
durability label; inventory environmental claims across shop, feeds and
campaigns.
4. **In parallel:** Assess BNPL, instalment and invoice payment against CCD II
with payment providers.
5. **Plan for Q4:** Review product-liability records and the EUDR assortment;
assign owners and deadlines to supplier-data gaps.
6. **Prepare 2027:** Treat battery data and CRA conformity as cross-functional
programmes involving purchasing, product, IT and legal, not content tasks.

## Where these requirements land in Shopware

Compliance is not one menu item in the Administration. Duties spread across
five system areas: the product model and PIM as the data foundation for GPSR,
PPWR, EUDR and battery passports; storefront and CMS for visible notices and
labels; checkout and account for withdrawal and CCD II; Administration and
Flow Builder for incident workflows; and monitoring and evidence. This system
matrix helps estimate the real effort.

### Product model, PIM and supplier data

This is the foundation for GPSR, PPWR, EUDR, battery passports and parts of
EmpCo. More fields alone are not enough; ownership and validation matter.
Which GTIN or model identifier is authoritative? Who supplies manufacturer
address, responsible person, warnings, packaging material, guarantee period,
update period and due diligence statement reference? Which data belong at
variant level?

Required fields should depend on product group, brand, manufacturer role and
country of sale. A battery-passport field across the entire catalogue creates
as much confusion as one free-text field for every safety instruction.

### Storefront and CMS

Product detail pages, listings, search and CMS expose the information. Notices
must be visible, understandable, correctly translated and accessible. EmpCo
labels, GPSR warnings and manufacturer details have different conditions and
should not collapse into one static text block. AI and marketplace feeds need
the same approved source data, or the shop can be correct while an external
channel remains outdated.

### Checkout, account and customer service

The withdrawal function and CCD II directly affect the purchase journey. A
Shopware extension can implement input and confirmation, but the process does
not end in the frontend. Status, timestamp, confirmation, order association
and handover to service or ERP need to work as an auditable chain. Payment
methods also require tests that notices, credit checks and contractual parties
switch correctly across countries and breakpoints.

### Administration, Flow Builder and integrations

CRA incidents, product recalls, EUDR requests and data-access requests need
unambiguous workflows. Shopware rules,
[Flow Builder events](https://docs.shopware.com/en/shopware-6-en/settings/flow-builder)
and integrations
can distribute work, but the business decision remains with a named owner.
Useful designs define escalation levels, deadlines, deputies and evidence of
which data were sent to whom and when.

### Monitoring and evidence

Go-live is only a snapshot. Product data change, plugins are updated, and new
countries or payment methods are added. Automated mandatory-field checks,
accessibility tests, sampling plans and a regular compliance review therefore
belong in operations. Good evidence answers not only “Is the information
visible today?” but also “Which rule and source record caused this display?”

The most useful technical answer is rarely one separate compliance plugin per
law. A shared data foundation for manufacturer role, material, packaging,
guarantee, software version, risk and evidence works better. Shopware, PIM,
ERP, feeds and documents can then consume the information that must be shown
or transmitted at each deadline.

## Conclusion: Assess applicability before implementing

The biggest risk is not failing to read a 200-page regulation in full. It is
clarifying responsibility and data needs only weeks before the deadline.
Businesses that map assortment, countries, customer groups and supply-chain
roles once can work through the coming dates with much greater precision.

The exact position depends on the business model and national implementation.
This article provides operational orientation and is not legal advice for an
individual case.

### Official sources

- [Online withdrawal function – Directive (EU) 2023/2673](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32023L2673)
- [General Product Safety Regulation – Regulation (EU) 2023/988](https://eur-lex.europa.eu/eli/reg/2023/988/oj/eng)
- [German Accessibility Strengthening Act (BFSG)](https://www.gesetze-im-internet.de/bfsg/)
- [EU Data Act – Regulation (EU) 2023/2854](https://eur-lex.europa.eu/eli/reg/2023/2854/oj/eng)
- [PPWR – Regulation (EU) 2025/40](https://eur-lex.europa.eu/eli/reg/2025/40/oj/eng)
- [Cyber Resilience Act – Regulation (EU) 2024/2847](https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng)
- [EmpCo – Directive (EU) 2024/825](https://eur-lex.europa.eu/eli/dir/2024/825/oj/eng)
- [Consumer Credit Directive – Directive (EU) 2023/2225](https://eur-lex.europa.eu/eli/dir/2023/2225/oj/eng)
- [Product Liability Directive – Directive (EU) 2024/2853](https://eur-lex.europa.eu/eli/dir/2024/2853/oj/eng)
- [EUDR: current European Commission report](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A52026DC0191)
- [Batteries Regulation – Regulation (EU) 2023/1542](https://eur-lex.europa.eu/eli/reg/2023/1542/oj/eng)
