Consumer protection and the handling of personal data in the EU/EEA
The EU and EEA have only partially harmonised rules on distance selling and consumer protection. Consumer protection covers both consumers' rights when making purchases and data protection.
To operate an online business in the EU/EEA, you must comply with consumer protection rules. These cover the information you must provide on your website, delivery times, cancellation and returns policies, buyers' rights, the handling of personal data, and requirements for dispute resolution.
Consumer rights
Within the EU/EEA, e-commerce is governed by the Consumer Rights Directive, which sets minimum requirements for information and consumer rights. These include the seller's identity, the product's characteristics and price, delivery costs, how to exercise the right of withdrawal, and payment obligations. You must ensure that consumers receive clear and understandable information both before and after purchase, and that you clearly state any delivery restrictions and accepted payment methods.
Delivery time: The standard delivery period within the EU/EEA is 30 days from the date of order, although you may agree a different deadline. If the goods are not delivered, you have the right to cancel the purchase and receive a refund within 30 days.
Right of withdrawal and returns: Consumers have the right to withdraw from a purchase within 14 days of receiving it. Consumers must cover the return costs if this is specified in the terms and conditions. The seller must issue a refund within 14 days of receiving notice of withdrawal. Certain goods and services are exempt from the right of withdrawal, including perishable goods, customised products and services that have begun with the consumer's consent before the withdrawal period expires.
If the seller does not inform the consumer of their right to cancel, the cancellation period is extended to 12 months after the original cancellation period expires.
Right to complain: The seller must supply goods that are free from defects. Any defects discovered within six months are presumed to have existed at the time of delivery, unless the seller can prove otherwise. The consumer can complain about defects for up to two years after delivery, and this period may be longer in some countries. If the goods are defective, the consumer can request a replacement, repair, price reduction or cancellation of the purchase with a refund.
Guarantee: Sellers may offer voluntary guarantees, which must clearly state what they cover and must not affect the consumer's statutory rights. The guarantee must be binding under the terms set out, and the consumer must be informed that it does not replace their statutory right to make a claim.
It is important for e-commerce businesses to comply with these requirements to protect consumers' rights and avoid legal issues.
Handling personal data in the EU/EEA
To operate an online shop, sellers need buyers' personal data. The processing of this data is governed by the General Data Protection Regulation (GDPR), which strengthens citizens' rights and adapts the rules to a digital society.
Requirements for processing personal data:
GDPR: This regulation requires businesses to have procedures in place to comply with data protection legislation. Management is responsible for developing these procedures, but all employees must be familiar with them.
Data collection: When your business collects personal data, you have certain obligations, and the data subject has certain rights. If you use a third party (outsourcing), you must have clear agreements in place between the data processor and the data controller.
New regulations:
Changes to the GDPR: The new regulation, which came into force on 25 May 2018, imposes stricter requirements for information, consent and necessity when processing personal data. This includes the right of access, data portability and the erasure of digital traces.
Stricter requirements: Companies must have systems and internal controls in place for processing personal data and consider data protection at every stage when developing new products and services.
Cooperation between data protection authorities: Businesses and individuals only need to deal with one supervisory authority, making it easier and less costly to do business in the EU.
Higher fines: Companies that fail to comply with the GDPR risk fines of up to €20 million or 4% of their global annual turnover.
For more information about what the new data protection rules mean for your business in practice, we recommend that you visit the Norwegian Data Protection Authority's website.