eCommerce Laws in 2026: The 8 Rules Regulators Are Fining Stores Over

Most store owners find out an ecommerce law applied to them the day the fine arrives. A clothing brand in New York learned it in May 2025, when California fined it $345,178 over the tracking cookies on its checkout page. It had never set up shop in California. It just sold there.
eCommerce laws are the privacy, consumer, tax, and intellectual property rules that bind any business selling online, no matter where that business is based. This guide covers the eight that regulators are actively enforcing right now, with the exact statute behind each one, what it costs to get it wrong, and a real 2024 to 2026 case so you can see the rule in action. You will leave knowing which laws touch your store and where your biggest gaps sit. If you are still setting up your store, that is the cheapest time to build compliance in.
Key takeaways
eCommerce Laws at a Glance
| Law | What it governs | Maximum penalty | Recent enforcement |
|---|---|---|---|
| GDPR (EU/UK) | Consent, storage, and deletion of EU customer data | €20M or 4% of global turnover | LinkedIn, €310M (2024) |
| CCPA / CPRA (California) | California residents’ data and opt-out rights | $7,500 per intentional violation | Todd Snyder, $345,178 (2025) |
| FTC Act + Reviews Rule | Honest advertising, no fake reviews | $53,088 per violation | FTC warning letters (Dec 2025) |
| Sales tax (Wayfair nexus) | Collecting tax in states where you sell | Back taxes, interest, penalties | 16+ states dropped transaction thresholds (2026) |
| Business licensing | Registration and permits to operate | Local fines, forced shutdown | Varies by state and city |
| Lanham Act (trademarks) | Brand names, logos, counterfeits | Infringer’s profits plus damages | Abitron v. Hetronic (SCOTUS, 2023) |
| PCI DSS 4.0 | Security of stored card data | Card-network fines and liability | Mandatory since March 31, 2025 |
| COPPA | Data collected from children under 13 | $53,088 per violation | Disney, $10M (2025) |
What Counts as an eCommerce Law?
An eCommerce law is any regulation that applies the moment you sell, advertise, or collect data online. These rules come from different bodies: EU regulators, US federal agencies like the FTC, all 50 state governments, and the card networks. No single statute covers everything, which is exactly why stores miss things.
The eight areas below sort into four jobs. Privacy laws govern the data you hold. Consumer and advertising laws govern how you sell and promote. Tax and business laws govern registration and remittance. Intellectual property and security standards govern your brand and the payment data you store. Work through each one and you will know where your store stands.
None of this is legal advice. Details change by country and state, so treat a real gap as a reason to talk to a lawyer, not a reason to panic.
GDPR: The EU Privacy Law with Global Reach
The General Data Protection Regulation, formally Regulation (EU) 2016/679, governs how you collect, store, and delete the personal data of anyone in the EU, EEA, or UK. It applies to your store whether or not you have any European office, as long as you sell to or track European visitors. There is no revenue floor.
GDPR gives customers the right to see their data, correct it, delete it, take it elsewhere, and withdraw consent. As the business deciding why and how data is collected, you are the “controller,” and the legal duty stops with you, not with your plugins or payment processor. Marketing consent has to be a real opt-in, not a pre-ticked box, and you have to be able to prove when and how it was given.
The penalties are the reason to take it seriously. Serious violations can draw fines of up to €20 million, or 4% of worldwide annual turnover, whichever is higher (GDPR.eu). Enforcement is climbing: European regulators issued around €1.2 billion in GDPR fines in 2025 alone.
In October 2024, Ireland’s Data Protection Commission fined LinkedIn €310 million for analyzing user behavior and running targeted advertising without a valid legal basis for consent (Irish Data Protection Commission). The lesson for a store is direct: the tracking and ad pixels on your site are exactly the surface regulators are looking at.
What it means for your store: if any of your customers are European, you need lawful-basis records, a working consent banner, and a way to delete a person’s data on request. That last part is much easier when you own your customer data outright instead of renting access to it through a hosted platform.
CCPA and CPRA: California’s privacy law
The California Consumer Privacy Act, codified at California Civil Code § 1798.100 and amended by the California Privacy Rights Act, gives California residents control over their personal data. It applies to a for-profit business that handles Californians’ data and meets one of three tests: gross annual revenue over $25 million, buying or selling data on 100,000 or more California consumers, or earning half its revenue from selling data (California Attorney General).
Californians can ask you to disclose what you hold, delete it, correct it, and opt out of the sale or sharing of their data. Since 2024, enforcement has centered on one thing: whether stores actually honor opt-out signals, including the browser-level Global Privacy Control. Penalties run to $2,500 per violation, or $7,500 per intentional violation, and each affected consumer can count as a separate violation.
In May 2025, the retailer Todd Snyder agreed to pay $345,178 to settle claims that its cookie-consent tools failed to process opt-out requests and collected more data than needed (California Department of Justice). That is the case from the opening of this article. A clothing store with no California office paid six figures over the tracking scripts on its own checkout page.
What it means for your store: if you run ad or analytics trackers and sell to Californians, you need a real “Do Not Sell or Share” path that works when a customer or their browser asks for it. The step-by-step version of this sits in the checklist below.
Free download: The eCommerce GDPR & CCPA Compliance Checklist turns both laws into a plain-language audit, from consent banners to deletion requests, so you can tick what you already do and flag what you do not. It is the fastest way to close your two biggest privacy gaps this week.
FTC rules: Honest Advertising and the Fake-Review Ban
The Federal Trade Commission enforces truth in advertising under Section 5 of the FTC Act (15 U.S.C. § 45), which bans “unfair or deceptive acts or practices.” For an online store, that covers misleading claims, hidden fees, undisclosed paid endorsements, and, since 2024, fake reviews.
The Consumer Reviews and Testimonials Rule (16 CFR Part 465) took effect on October 21, 2024. It bans buying or selling fake reviews, writing reviews as an undisclosed insider, paying for reviews that express a specific sentiment, and suppressing honest negative reviews. Violations carry civil penalties of up to $53,088 per violation (Federal Trade Commission).
On December 22, 2025, the FTC took its first enforcement step under the rule, sending warning letters to ten companies over practices like paying employees to gather five-star reviews from friends and family, and soliciting reviews from people who never used the product (Federal Trade Commission). The agency signaled that penalties come next for repeat offenders.
What it means for your store: never seed your own product pages with insider or incentivized reviews, disclose any paid endorsement clearly, and keep honest negative reviews visible. The same honesty standard runs through your refund terms, which is why a clear return and refund policy is both a trust builder and a compliance safeguard.
Sales Tax: Economic Nexus after Wayfair
Sales tax is where stores get the most expensive surprise. For years you only owed tax in states where you had a physical presence. That ended in 2018 with the Supreme Court decision in South Dakota v. Wayfair, Inc. (585 U.S. 162), which let states tax remote sellers based on economic activity alone.
After Wayfair, most states set an economic nexus trigger of $100,000 in sales or 200 separate transactions into that state in a year (Sales Tax Institute). Cross the line and you must register, collect, and file there, even if you have never set foot in the state. The US has thousands of local tax jurisdictions, so a store selling nationwide can trip several thresholds at once.
Recent change: the rules are still moving. As of January 1, 2026, at least 16 states have removed the 200-transaction part of the test, because a store selling low-cost items could hit 200 orders with very little revenue and get pulled into full compliance. Utah dropped its transaction threshold in July 2025, Illinois in January 2026, and Kentucky follows in August 2026 (Avalara). The trend favors small sellers, but it also means the map you memorized last year is already out of date.
What it means for your store: track your sales by state so you see a threshold coming, and use a platform that calculates the right rate at checkout, including EU VAT if you sell into Europe. Doing it by hand across dozens of jurisdictions does not scale.
Business Structure, Licenses, and Permits
Business law covers how your company is registered and what permission it needs to operate. Forming a limited liability company (LLC) separates your personal assets from the business, so a company debt cannot reach your house. It is the cheapest protection you can set up, and most stores should do it before their first sale.
Beyond structure, many stores need a license or permit. A general business license is common, and regulated categories such as alcohol, food, cosmetics, supplements, and CBD carry extra state and federal requirements. Zoning rules can even limit running a large-inventory operation from home. Marketplace facilitator laws in most states now also decide who collects tax when you sell through a third-party marketplace versus your own site.
Enforcement here is usually local and administrative rather than a headline lawsuit: fines, back fees, or an order to stop operating until you register. It rarely makes the news, but a missing permit can freeze a growing store at the worst moment. Check your city and state rules before you scale, and keep proof of every registration.
Intellectual Property: Trademarks and Counterfeits
Intellectual property law protects your brand and your creative work, and keeps you from using someone else’s. The core statute for brand names and logos is the Lanham Act (15 U.S.C. § 1051), which lets you register a trademark and sue infringers. Copyright (17 U.S.C.) protects your photos and copy, and a patent protects an invention.
Registering a trademark with the US Patent and Trademark Office gives you enforceable rights against copycats and access to marketplace brand-protection programs. It also cuts both ways: every image and line of text on your store must be original or licensed, or you risk an infringement claim yourself.
In Abitron Austria GmbH v. Hetronic International, Inc. (2023), the Supreme Court vacated a roughly $90 million infringement award and held that the Lanham Act reaches only trademark uses that are domestic to the United States (Supreme Court of the United States). For online sellers, the practical fallout is a surge in “Schedule A” lawsuits, where brands sue dozens of foreign eCommerce stores at once for selling counterfeits. US trademark filings in district courts rose about 25% in 2025.
What it means for your store: register your brand early, license every asset you did not create, and watch marketplaces for sellers lifting your product photos or name. Keep your license records, because proof is what wins these disputes.
Payment security: PCI DSS 4.0
Payment security is governed by the Payment Card Industry Data Security Standard, or PCI DSS. It is not a government law; the card networks enforce it through your payment processor. A breach can bring network fines, higher processing costs, class-action lawsuits, and lost trust, so it functions like a law in practice.
The current version, PCI DSS 4.0, became fully mandatory on March 31, 2025, with no grace period. Two of its new requirements hit eCommerce checkouts directly: multi-factor authentication is now required for all access to systems that handle card data, and every third-party script on your payment page must be inventoried, justified, and monitored for tampering (PCI Security Standards Council). That second rule targets the exact skimming attacks that hit online stores.
In 2024 and 2025, retailer Stiiizy agreed to a $2.95 million settlement after a breach exposed customer data, one of many class actions following point-of-sale and checkout intrusions. The pattern is consistent: the breach itself is expensive, and the lawsuit that follows often costs more.
What it means for your store: never store raw card numbers. Route payments through Stripe, PayPal, or a similar gateway so they carry the heaviest PCI load, and keep the surrounding store hardened. Secure, well-maintained eCommerce hosting with SSL, a firewall, and current software is the base layer everything else sits on.
COPPA: Data from Children Under 13
The Children’s Online Privacy Protection Act (15 U.S.C. §§ 6501–6506) bans collecting personal data from a child under 13 without verifiable parental consent. The FTC updated the COPPA Rule in January 2025 to require opt-in consent before sharing children’s data with third parties for targeted advertising. Penalties reach $53,088 per violation.
This catches more stores than owners expect. If you sell toys, kids’ clothing, games, or educational products, some of your visitors are minors and their parents. Even a newsletter signup or an on-site quiz can cross the line if it gathers data from a child.
in 2025, Disney agreed to pay $10 million to settle FTC allegations that it let children’s data be collected from kid-directed videos without proper notice or parental consent (Federal Trade Commission). It follows the record $275 million Epic Games (Fortnite) penalty in 2023, which set the tone for aggressive COPPA enforcement.
What it means for your store: if children might be in your audience, add age gating and collect the minimum data the sale needs. When in doubt, collect less.
Why Owning your Data makes Compliance Provable
Look back across the eight sections and one thread connects most of them. GDPR deletion requests, CCPA opt-outs, COPPA data limits, and PCI script control all come down to the same question: when someone asks what data you hold and what you did with it, can you answer without asking a vendor first?
On a hosted SaaS platform, your customer records live on someone else’s server under someone else’s policy. When a deletion request lands, you depend on that vendor acting inside your legal window. On self-hosted WordPress, the records sit in a database you control, so access, correction, and deletion become queries you run and prove. Files can live in storage you own, and payments flow straight to your own gateway accounts, keeping the heaviest PCI load with the processor.
FluentCart is built on that model, with GDPR features on the free tier and a documented REST API for wiring up export and deletion flows. No plugin makes you compliant on its own. What self-hosting gives you is the thing compliance depends on: control of the data, and the ability to show your work.
Frequently asked questions
Do eCommerce laws apply if my business is not in the US or EU?
Yes. Privacy laws like GDPR and CCPA follow the customer, not the seller. If you sell to or track someone in the EU or California, their rules can reach you regardless of where you are based.
What is the most common eCommerce law violation?
Right now, privacy opt-out failures. A majority of California’s public CCPA settlements involve stores that did not honor opt-out or Global Privacy Control signals from their tracking tools.
Do I need an LLC to sell online?
No current law requires it, but an LLC separates your personal assets from business liabilities, which is why most store owners form one before scaling.
When do I have to collect sales tax in another state?
When you cross that state’s economic nexus threshold, commonly $100,000 in sales or, in states that still use it, 200 transactions in a year. Several states are now dropping the transaction test.
What happens if I use fake or incentivized reviews?
Under the FTC’s Consumer Reviews and Testimonials Rule, that can bring civil penalties of up to $53,088 per violation. The FTC began enforcing it with warning letters in December 2025.
Wrapping Up
You now have the map: eight active eCommerce laws, the statute behind each, what a violation costs, and a real case showing how enforcement actually lands. The stores that get fined are rarely bad actors. They are stores that never knew the rule applied until the letter arrived.
Start with the risk that moves fastest against you: data privacy. Download the eCommerce GDPR & CCPA Compliance Checklist, work through it this week, and close the obvious gaps first. Then look at how much easier all of this gets when you own your data outright. See how self-hosted, ownership-first commerce works with FluentCart, and build your store on a foundation you control instead of one you rent.
Rasel leads the marketing function at FluentCart, driving both high-level strategy and ground-level execution across the product’s growth engine. He plays a central role in defining how FluentCart is positioned, how it enters the market, and how it evolves based on user behavior and feedback. His responsibilities span go-to-market planning, funnel architecture, conversion strategy, and narrative development. He works across teams to ensure that product decisions, marketing efforts, and customer experience stay tightly aligned.

Subscribe now






Leave a Reply