Focus Area

One legal framework from cart to customs in cross-border e-commerce.

For stores selling to the EU and Türkiye: marketplace, consumer, data, tax and product compliance — from spotting externally visible gaps to a lasting compliance framework, all in a single team.

Overview

An integrated legal framework for International E-Commerce

In an e-commerce operation selling abroad, law is not a single heading: every order is at once a consumer contract, a data-processing activity, a tax event, and a logistics commitment. The rules also vary from country to country — distance selling and İYS in Türkiye, and consumer directives, GDPR, the DSA, and the VAT e-commerce package in the EU, all meet in the same basket.

What is more, the target keeps moving: the responsible-person requirement in the EU under the GPSR (December 2024), 1% withholding on marketplace payments (January 2025), the accessibility obligation for web stores (June 2025), the closure of the EU ODR platform (July 2025), the distance-selling amendments in Türkiye placing the return-shipping cost on the seller (January 2026), and the authorised-representative requirement of the EU packaging regulation (August 2026) have come into force one after another. A set of texts that was compliant last year may today carry the risk of warning notices and penalties.

From marketplace contracts to multilingual sales texts, from OSS/IOSS registrations to return logistics and combating counterfeiting, we manage every legal layer of cross-border selling in a single work plan together with our tax and accounting team, and track regulatory changes with the Legislation Radar.

Compliance Gaps

The 17 most common compliance gaps in e-commerce

The gaps we encounter most often in practice at stores selling to the EU and Türkiye markets. Most are the kind that competitors and supervisory authorities notice at first glance — and all of them can be closed in a planned way when addressed in the right order.

01

No privacy policy, or a copied one

A text copied from a template that does not reflect your actual processing purposes is riskier than having none at all: it commits you to what someone else does, not to what you do.

GDPR Arts. 13–14 · KVKK Art. 10KVKK/GDPR Compliance Programme →
02

No cookie banner, or tracking before consent

Loading analytics and marketing cookies before consent is among the most frequently reported violations in the EU, and it is easily detected technically.

ePrivacy · TDDDG §25 · KVKK Cookie GuideCookie & consent layer →
03

KVKK information notice missing

The information-notice obligation applies to every store that receives Turkish traffic; if there is no notice beside the forms, the gap is visible at first glance.

KVKK Art. 10 · Information Notice CommuniquéInformation notice set →
04

VERBİS registration not completed

VERBİS registration is mandatory for data controllers that exceed the employee-count or balance-sheet threshold, or that process special-category data as their main activity — and the registry is public: non-registration is visible with a single query.

KVKK Art. 16 · VERBİSVERBİS & inventory setup →
05

No KVKK cross-border transfer safeguard

Every store using Google Analytics, Meta and foreign hosting transfers data. The 2024 regime requires signing a standard contract and notifying the Authority within 5 business days; on most sites this layer has never been set up.

KVKK Art. 9 (7499) · Transfer RegulationTransfer & standard contract →
06

Commercial e-message approvals and İYS setup missing

Newsletter and campaign messages require prior approval; approvals are managed through İYS. A newsletter form without an approval checkbox leaves every send open to complaints and to an administrative fine per message.

6563 · Commercial Communication Reg. · İYSPermission-based marketing setup →
07

No GDPR EU representative named

Most stores that sell to the EU without being established there have never heard of the Art. 27 representative requirement; the absence of a representative block in the privacy policy is proof of this.

GDPR Art. 27Representative & transfer setup →
08

Distance selling contract out of date

In Türkiye, since 1 January 2026 the return-shipping cost lies with the seller; sites carrying the old text display a clause that cannot be applied on any return.

Distance Contracts Reg. (2026 amendments)Distance selling set →
09

Right-of-withdrawal text and model form missing

In the EU, the 14-day withdrawal must be provided together with its model form; if it is missing, the period extends to up to 12 months and every order turns into a potential return.

2011/83/EU · Turkish Consumer Protection LawWithdrawal & return setup →
10

ETBİS registration not visible

Registration with ETBİS is mandatory for service providers selling through their own site, and the registration can be verified publicly. A missing registration is among the first items asked about in an inspection.

6563 · ETBİS CommuniquéE-commerce registration setup →
11

No Impressum / imprint

If you sell to Germany, provider identification is mandatory, and its absence is the number-one target of the Abmahnung industry — a single missing page means a costly warning notice.

§5 DDG · 2000/31/ECGerman market compliance →
12

Dead ODR link still in place

The EU ODR platform was shut down on 20 July 2025; sites still linking to it both provide misleading information and announce that their texts have not been updated for years.

(EU) 2024/3228Ongoing legislation maintenance →
13

No accessibility statement

Since June 2025, web stores selling to consumers in the EU are under an accessibility obligation; in Germany there is a risk of penalties of up to €100,000 and of warning notices.

EAA 2019/882 · BFSGAccessibility compliance →
14

GPSR responsible-person information missing from listings

Since December 2024, the name and address of an EU-established responsible person must appear in the listing for products sold from outside the EU; marketplaces remove incomplete listings.

GPSR (EU) 2023/988 Art. 16GPSR setups →
15

No IOSS/OSS trace, customs falls to the buyer

The statement “Customs charges are the buyer's responsibility” is an announcement that IOSS is not used for orders up to €150; it directly hurts the delivery experience and conversion.

EU VAT e-commerce packageOSS/IOSS registration →
16

Packaging registration (LUCID) not visible

LUCID registration is mandatory for every seller shipping to Germany and the registry is public; in August 2026 the PPWR adds an authorised-representative requirement for non-EU sellers.

VerpackG · PPWR (EU) 2025/40Packaging & EPR registration setup →
17

No previous price on discount labels

Both the EU (Omnibus) and Türkiye require displaying the lowest price of the last 30 days during a discount; if a “-70%” label stands alone, the gap is visible from the outside.

Omnibus 2019/2161 · Price Labelling Reg.Pricing & promotion compliance →
Self-Assessment

Your e-commerce compliance scorecard in a few minutes

First, tell us about your operation so we ask only the questions relevant to you. For any question you are unsure about, use the guidance opened with “?”.

Profile
Which markets do you sell to?

Select the markets where you actively receive orders or that you target through advertising/marketplaces — we will narrow the question set accordingly.

Which are your sales channels?

You can select more than one. If you hold stock within the EU (e.g. FBA), tick "Warehouse / fulfilment within the EU" — the tax and registration questions change.

This result is an indicative preliminary assessment; the definitive position can be determined only after reviewing your terms and processes.

Preliminary Legal Assessment

Request a legal pre-assessment

Tell us briefly about your operation. We assess your sales texts, your order flow and any contracts or internal documents you wish to share against our 17-point framework; we share the findings in a short summary arranged in order of priority.

  • Your self-assessment result is automatically attached to your request — the meeting starts ready
  • A response within one business day, itemised and prioritised
  • Dual-legislation practice on the Türkiye–EU axis; Berlin office and Germany Desk
  • The findings are yours; whether to proceed is entirely your decision
Step 1/2
01

Services We Offer in This Focus Area

In the International E-Commerce focus area, we combine the relevant legal disciplines into a single work plan.

Marketplace & Platform Compliance

Seller agreements on Amazon, eBay, Etsy and local marketplaces, account-suspension appeals, and the operation of P2B/DSA transparency rules.

Explore →

Distance Selling & Consumer Rules

Setting up pre-contractual disclosure, the right of withdrawal, and return processes as multilingual text sets compliant with Turkish legislation and EU consumer rules.

Explore →

KVKK/GDPR Dual Compliance & Cookie Setup

A single compliance programme for Turkish and EU traffic: information-notice set, cookie/consent layer, GDPR EU-representative requirement and data-breach response plan.

Explore →

VAT, OSS/IOSS & Customs

Registration and reporting setup under the EU e-commerce VAT package, distance-selling thresholds, the allocation of liability in sales through platforms, and customs/origin planning.

Explore →

Logistics & Fulfilment Contracts

Structuring warehousing, 3PL/fulfilment, drop-shipping, and return-logistics contracts together with the Incoterms and CMR liability regime.

Explore →

Trademark & Content Protection

Trademark registration in target markets; customs detention, platform complaints, and unfair-competition proceedings in combating counterfeit products.

Explore →

VERBİS & Data Inventory

Preparing the personal-data processing inventory, VERBİS registration and updates, the retention-and-destruction policy, and defence in Data Protection Board reviews.

Explore →

İYS & Commercial Message Setup

İYS registration and integration, setting up approval/rejection flows, and structuring newsletter and campaign messages in compliance with Law No. 6563 (Turkish Electronic Commerce Law) and the Commercial Communication Regulation.

Explore →

ETBİS & 6563 Registration Obligations

ETBİS registrations and notifications, service-provider information-disclosure and imprint requirements, and a compliance review of the mandatory disclosures on the sales site.

Explore →

Advertising, Pricing & Campaign Compliance

The lowest-price-in-the-last-30-days rule for discounts, review of misleading advertising and influencer collaborations, and defence in Advertising Board proceedings.

Explore →

GPSR & EU Responsible Person

Analysis of product-safety obligations, appointment of an EU-established responsible person, and setting up listing and label information and recall processes.

Explore →

Packaging, EPR & authorised representative

Country-by-country extended producer responsibility registrations, primarily VerpackG/LUCID, and preparation for the PPWR's 2026 authorised-representative requirement.

Explore →
Why Köksal?

A single work plan from cart to customs

In cross-border e-commerce, problems arrive not one by one but in a chain: a suspended account halts collections, a missing VAT registration halts delivery, a faulty data flow halts marketing. We combine the consumer, data, tax and logistics layers in a single team and apply them on the ground with our Germany and UK desks.

  • Dual-legislation practice on the Türkiye–EU axis (KVKK/GDPR, TKHK/EU consumer rules)
  • Hands-on experience in marketplace suspension and appeal processes
  • VAT/OSS-IOSS and 1% withholding advice integrated with our tax and accounting team
  • Multilingual (TR/DE/EN) contract and sales-text sets
  • Preventive setup against the Abmahnung, GPSR, accessibility and PPWR wave
  • Local execution power through our Germany, United Kingdom and Gulf desks
International E-Commerce multi-disciplinary team
Why Köksal?

A team field-tested in cross-border work

39Years of accumulated experience
3Offices — İstanbul · Berlin · Kyrenia
17Assessment-framework topics
TR·DE·ENMultilingual sales-text sets
03

Related Services

Our services most often engaged in this focus area — together with their scope.

Contract Management

Contract management covers the drafting, negotiation and full-lifecycle tracking of your commercial contracts. Weighing Turkish law together with DACH-region practice, we structure balanced and enforceable texts.

Explore

Compliance

Compliance advisory: we build programmes that bring your company into line with KVKK/GDPR, anti-corruption rules, and sectoral regulations. Through internal audit, policy, and training, we turn compliance into a lasting corporate culture.

Explore

Tax Compliance

From tax return processes to tax planning, from double taxation treaties to audit support, we manage tax compliance end to end. We bring clarity to cross-border taxation along the TR–DACH corridor.

Explore

Data & Document Management

Data and document management brings secure storage, KVKK/GDPR compliance, and the access and authorisation framework together under one roof. We manage your information without losing any of it, while protecting confidentiality and keeping it audit-ready.

Explore

Contract Digitalisation

Contract digitalisation brings your CLM process into a single order with a template library, electronic signatures, and renewal tracking. We turn scattered documents into traceable, analysable contract management.

Explore

Ongoing Legal Counsel

Ongoing legal counsel provides retainer-based legal support for your company's day-to-day operations — readily accessible and with predictable costs. As your external legal counsel, we stand by you at every stage of your decisions.

Explore
View all

Clarify your compliance status

Let us prepare a prioritised findings summary for your sales terms, ordering flow and contract framework—without obligation.

Request a preliminary assessment
09

Related Legislation

International E-Commerce — the legislation that directly affects this focus area, tracked in plain language on our Legislation Radar.

ABAvrupa B.EU Directive & RegulationIn forceEU General Data Protection Regulation (GDPR)Source · ABl. L 119, 4.5.2016In force · 25.05.2018Last amended · Nov 2025 (Digital Omnibus proposal — Regulation text unchanged)

The framework of the EU data protection regime: it also directly covers Turkish companies that offer goods and services to persons in the EU or monitor their behaviour.

RelatedPersonal Data ProtectionCommercial LawLaw of Obligations & Contracts
TRTürkiyeLawIn forcePersonal Data Protection Law (KVKK, 6698)Source · RG 29677, 07.04.2016In force · 07.04.2016Last amended · Mar 2024 (Law No. 7499) · Jan 2025 (cross-border transfer guide)

Türkiye’s data protection framework: the 2024 amendments re-established the regime for special-category data and cross-border transfers; the standard contract and notification to the Board are at the centre of practice.

RelatedPersonal Data ProtectionEmployment LawCommercial Law
ABAvrupa B.EU Directive & RegulationRecently amendedEU Data ActSource · ABl. L, 22.12.2023In force · 12.09.2025 (application)Last amended · Sep 2025 (application) · next 12.09.2026 (design obligation); Digital Omnibus proposal under negotiation

Rules on access to, sharing of, and cloud switching for connected-product and related-service data: the regulation that re-establishes the contractual order of the data economy has been in application since September 2025.

RelatedPersonal Data ProtectionLaw of Obligations & ContractsCommercial Law
ABAvrupa B.EU Directive & RegulationIn forceEU Digital Services Act (DSA)Source · ABl. L 277, 27.10.2022In force · 17.02.2024 (full application)Last amended · First fines: X €120M (Dec 2025) · Temu €200M (2026)

Transparency, content-moderation and seller-traceability rules for online platforms and marketplaces: it directly shapes the platform relationships of Turkish sellers selling online into the EU.

RelatedCommercial LawIntellectual Property LawPersonal Data Protection
Open the Legislation Radar
Practical Resource

A 17-point legal compliance checklist for selling to the EU & Türkiye

Leave your email to unlock the full list immediately. You can print it and share it with your team.

  1. Privacy policy (TR + target-market language) — With actual processing purposes, recipient groups and retention periods; do not use copied text.
  2. KVKK information notice + explicit-consent setup — Beside the form and membership flows; with processing that requires consent separated out.
  3. Cookie banner: blocking before consent — Non-essential cookies must not load before consent; rejecting must be as easy as accepting.
  4. GDPR Art. 27 EU representative — If you are not established in the EU, appoint a representative and show it in the privacy policy.
  5. KVKK cross-border transfer safeguard — When using foreign tools, a standard contract + notification to the Authority within 5 business days.
  6. VERBİS and ETBİS registrations — VERBİS if you are above the threshold; ETBİS if you sell from your own site — both registries are public, keep them up to date.
  7. Commercial e-message approvals + İYS — Prior approval for newsletter/campaign messages; approval and rejection management through İYS, retaining the records.
  8. Distance selling contract + pre-contractual disclosure (2026-compliant) — Including the return-shipping arrangement, contracted-carrier information and mediation disclosure.
  9. Right-of-withdrawal text + model form — 14 days; exceptions correctly defined on a category basis; tied to the approval flow.
  10. Impressum / imprint (for DE sales) — Company name, address, email, register and VAT number; in German.
  11. Remove the old ODR link — The platform closed on 20.07.2025; the link has become misleading. Update the ADR disclosure.
  12. Accessibility (EAA/BFSG) baseline — Keyboard navigation, contrast, form labels; publish an accessibility statement.
  13. GPSR: EU responsible person + listing information — The manufacturer and responsible-person name/address/email must be visible on the product pages.
  14. OSS/IOSS registration and VAT setup — Monitor the EU-wide €10,000 threshold; for shipments below €150, customs-free delivery via IOSS.
  15. Packaging registrations (LUCID) + PPWR preparation — LUCID + license for Germany; prepare for the August 2026 PPWR authorised-representative requirement.
  16. Price and campaign display — The lowest price of the last 30 days during a discount; in DE, the unit-price (Grundpreis) requirement.
  17. Marketplace seller-profile consistency — Merchant details consistent with DSA seller verification and the 1% withholding regime, not contradicting your site.

Seller-verification documents, target-country VAT registrations or OSS/IOSS, GDPR compliance, and packaging/recycling registrations (e.g., Germany's LUCID) are the minimum set. With our market-entry checklist, we close the gaps in a single pass.

Under EU rules, the consumer may, as a rule, withdraw within 14 days without giving a reason; who bears the return-shipping cost depends on the prior disclosure. We set up your multilingual return policy in compliance with both Turkish and EU rules.

Towards the consumer, you are liable in your capacity as seller; supplier delay or a defective product is your risk. We make the model sustainable by tightening the recourse, stock, and delivery undertakings in the supplier contract.

We proceed first through the platform’s internal appeal mechanism and, where necessary, under the P2B rules, with structured grounds and evidence; EU rules oblige platforms to state reasons and to offer an appeal route. In parallel, we put an interim plan in place to manage inventory and revenue risk, and document the correspondence with potential litigation in mind.

OSS applies once the EU-wide annual threshold for distance sales to consumers within the EU is exceeded; IOSS comes into play for low-value orders (up to €150) shipped from outside the EU. For sales through marketplaces, the platform often takes on the VAT. We set up the correct registration and filing arrangements together with our tax team.

As a rule, yes; however, for data collected from the EU, the GDPR’s transfer safeguards (such as standard contractual clauses) and the KVKK’s cross-border transfer regime must be satisfied together. We build your data architecture with a single contract set compliant with both bodies of legislation.

Several layers at once: EU distance selling and consumer rules, the GDPR (with an EU representative where required), the VAT e-commerce package and Germany-specific obligations (e.g. packaging registration). We draw up a country-by-country inventory of obligations for your operation and close the gaps in order of priority.

Yes; many models work without setting up a company. However, thresholds such as VAT registrations (OSS/IOSS), a GDPR representative and marketplace conditions must be met. Beyond a certain scale, a warehouse or a company structure becomes advantageous in tax and commercial terms — we plan this transition together with our regional desks.

Focus Area

Let us build a legal strategy in the International E-Commerce focus area.

Let us assess your needs together with the relevant practice areas, sectors and regional desks.