RegTech Reviews

Retail and E-Commerce Compliance Obligations

Reporter · · 11 min read
Cover illustration for “Retail and E-Commerce Compliance Obligations”
Industry Regulations · August 1, 2026 · 11 min read · 2,445 words

Twenty states have enacted comprehensive consumer privacy laws. Eight of them activated in 2025 alone: Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, and Maryland. E-commerce operators trigger obligations in every state where their customers reside, regardless of whether they have a single employee or square foot of real estate there.

The differences between these laws are not cosmetic, and anyone who tells you otherwise hasn't read them closely. Delaware, effective January 1, 2025, applies to entities processing data for 35,000 or more consumers and requires formal data protection assessments. New Jersey, effective January 15, uses a broad definition of "sale" and mandates that businesses honor universal opt-out mechanisms, meaning a consumer's browser-level privacy signal must be respected without any additional friction. Tennessee, effective July 1, is one of the few laws that actually rewards good behavior: organizations operating under a recognized privacy framework get a genuine safe harbor, which creates a real incentive to pursue certifications like ISO 27001 rather than filing them away as optional credentials.

Maryland's Online Data Privacy Act, effective October 1, 2025, is the one that keeps catching people off guard. It significantly restricts collection and processing of sensitive data and data relating to minors, and it carries no monetary revenue threshold. Most state privacy laws exempt smaller businesses by design. Maryland does not. A boutique e-commerce operation with modest annual revenue but a broad customer base is fully in scope. That departure from the prevailing legislative pattern is exactly the kind of detail that gets missed in a surface-level compliance review.

State attorneys general are not auditing privacy policy language. They are examining rights-request processes, vendor oversight, and data governance controls. A polished privacy policy page sitting atop substantive gaps in the underlying infrastructure is precisely the profile that draws scrutiny.

The operational reality is that building separate compliance tracks for each state is unworkable for most retailers. Experienced compliance teams have largely converged on one approach: build toward the most stringent requirements, Maryland and California, and apply them as the universal baseline. You are not over-complying in Nebraska. You are building a system that does not collapse when you expand into the next restrictive jurisdiction.

Indiana, Kentucky, and Rhode Island laws take effect in 2026. California's Delete Act creates a centralized deletion system for data brokers beginning August 1, 2026. New CPPA regulations will require risk assessments and cybersecurity audits for certain businesses. Whatever compliance posture you build today needs to be designed for amendment, not just for the current statutory text.

Table: 2025 State Privacy Laws: Key Distinctions. Compares Effective Date, Notable Feature and Revenue/Size Threshold by Delaware, New Jersey, Tennessee and Maryland.

International Data Privacy Obligations That Reach U.S. Retailers Operating Across Borders

Venn diagram: U.S. vs. International Privacy Obligations. Compares U.S. State Laws and International Laws; overlap: Shared Obligations.

If you sell internationally, GDPR is not a European problem. It is your problem. Fines can reach €20 million or 4% of global annual revenue, whichever is higher, and the exposure concentrates not just in data collection practices but in how data moves across borders after it is collected. Meta's €1.2 billion fine in 2023 for improper EU-to-U.S. data transfers is instructive precisely because the underlying violation wasn't dramatic. It was structural. A routine transfer arrangement that hadn't kept pace with regulatory requirements.

The international landscape extends well beyond the EU. The UK maintains its own parallel GDPR regime post-Brexit, requiring a separate compliance track for UK customers. Canada's PIPEDA, Brazil's LGPD, India's Digital Personal Data Protection Act, and China's Personal Information Protection Law each impose distinct requirements. China's PIPL includes strict data localization requirements that are architecturally incompatible with how most U.S. retailers structure their data environments by default. That is a structural conflict requiring deliberate engineering decisions before you take a single Chinese customer's order, not something you patch later.

The 2025 TrustArc Global Privacy Benchmarks Survey found that retail lags behind other sectors in privacy maturity, with a majority of retailers citing technical complexity as the primary hurdle. Retail's tendency to perceive itself as lower-risk than financial services or healthcare is a false signal. GDPR enforcement has created no sector-specific exemptions, and being in retail means you haven't faced serious scrutiny yet, not that you're insulated from it.

Cross-border data transfers remain the single highest-risk point in this landscape. Standard Contractual Clauses and adequacy decisions require active legal maintenance. An SCC correctly executed two years ago is no longer sufficient if the underlying transfer arrangement or the vendor relationship has since changed. This is an ongoing operational function, not a one-time legal exercise, and most retail legal teams are not staffed to treat it that way.

Payment Security Requirements Under PCI DSS v4.0, Now Mandatory

PCI DSS v4.0 became mandatory by March 31, 2025. It is more prescriptive than its predecessors: passwords must be at least 12 characters, quarterly vulnerability scans are required, and authentication and logging standards are more exacting. These are the baseline for any entity that stores, processes, or transmits cardholder data.

That scope is broader than many retailers assume. The common misconception, especially among smaller operators, is that using a third-party payment processor transfers all PCI DSS responsibility. It reduces your scope. It does not eliminate your obligations. If your checkout flow touches cardholder data at any point, you carry compliance responsibility for that touchpoint.

The consequences of non-compliance are operationally severe in ways that aren't always obvious until they're immediate. Card brands can impose fines, increase per-transaction fees, or revoke the ability to process card payments entirely. Losing card processing is a business-stopping event for an e-commerce business, and it happens faster than most operators expect once a brand initiates that process.

There's also a meaningful intersection with state-level privacy obligations that gets overlooked. PCI DSS v4.0's authentication and logging requirements overlap with the data governance controls that state attorneys general are examining under their respective privacy laws. A retailer's security infrastructure has to satisfy both frameworks simultaneously, which means your security team and your privacy counsel need to be working from the same map, not optimizing separately for their respective audit cycles.

Sales Tax Nexus Obligations After Wayfair, and How 2025 Changed the Calculus Again

South Dakota v. Wayfair, decided in 2018, eliminated the physical presence requirement for sales tax nexus. States can now compel collection based on economic activity alone, typically $100,000 in sales to a state's residents.

As of January 1, 2025, fourteen states including California dropped the transaction-count threshold from their nexus rules, moving to a purely monetary measure. The effect cuts in both directions: a business that previously triggered nexus through a high volume of small transactions now falls below the threshold, while a business with fewer but higher-value transactions now crosses it. Any nexus analysis performed before January 2025 needs to be rerun. Not reviewed. Rerun.

The underlying complexity of U.S. sales tax hasn't changed. There are more than 13,000 distinct tax jurisdictions in the country, each with its own rates, rules, and product taxability definitions. A GAO study found that small remote sellers spend substantially more managing multistate sales tax obligations than their larger counterparts with in-house teams. That cost falls disproportionately on thin-margin e-commerce operators who can't absorb it the same way.

Marketplace facilitator laws complicate the picture further. All 45 sales tax states plus the District of Columbia now require platforms like Amazon, Walmart, and Etsy to collect and remit tax on behalf of sellers. But inventory stored in Amazon fulfillment warehouses creates physical nexus in those states, affecting your tax obligations on direct-channel sales that the marketplace facilitator arrangement does not cover. A seller operating across multiple channels cannot delegate their entire nexus analysis to the platforms they use. The facilitated portion is handled. The rest is yours.

Wayfair's logic has also spilled beyond sales tax. States are applying the economic nexus rationale to income tax nexus standards, extending its implications across a retailer's entire state tax exposure.

Federal Consumer Protection Obligations: FTC Enforcement, Dark Patterns, and Subscription Practices

Section 5 of the FTC Act prohibits unfair or deceptive business practices. That baseline applies to product descriptions, advertising claims, and pricing presentation, with no de minimis exception for smaller retailers. If your checkout flow conceals fees until the final confirmation screen, you are not in a gray area.

The FTC's September 2025 settlement against Amazon for dark patterns in its Prime subscription enrollment set the defining reference point for this enforcement cycle. The settlement reached $2.5 billion. The complaint detailed a cancellation process involving four pages, six clicks, and fifteen options. That specificity matters, because it documents exactly what regulators consider unacceptable subscription UX. It is not regulatory ambiguity. It is a published standard.

The FTC's Negative Option Rule was vacated by the Eighth Circuit on procedural grounds in July 2025, but the underlying obligations didn't disappear with it. ROSCA, FTC Act Section 5, state auto-renewal laws, and Visa and Mastercard's own subscription standards all remain in force. More than half of U.S. states have automatic renewal laws. California's amended auto-renewal law, effective July 1, 2025, is among the most aggressive in the country.

Drip pricing deserves equal attention. The obligation is to display complete pricing, including taxes, shipping, and fees, before a consumer commits to a purchase. Not at the final screen. Before.

COPPA updates effective in 2025 significantly increased requirements for platforms and retailers handling data from children under 13, with stricter parental consent rules for targeted advertising and for sharing children's data with third parties. If your product catalog has meaningful overlap with children's interests, COPPA compliance is not optional background noise.

Marketplace-Specific Obligations Under the INFORM Consumers Act

The INFORM Consumers Act, which took effect June 27, 2023, requires online marketplaces to collect, verify, and disclose identifying information for high-volume third-party sellers, defined as sellers completing 200 or more discrete sales and generating $5,000 or more in revenue over a 12-month period. The civil penalty for non-compliance is $53,088 per violation.

The first INFORM Act enforcement action came in September 2025, when the FTC filed suit against Whaleco, Inc., the operator of Temu, for failing to provide required information and tools to shoppers. The settlement included $2 million in civil penalties and mandatory compliance measures. Since the Act took effect, nearly 40,000 high-volume third-party seller accounts have been suspended for violations, approximately 20,000 of which were later reinstated after coming into compliance. Nearly 24 million product listings have been removed from online marketplaces as a result of enforcement activity under the Act.

What often gets missed is that the compliance responsibility doesn't rest solely with the marketplace. Sellers must maintain accurate, verifiable business information with every platform they use. Outdated tax IDs, mismatched contact information, unverified bank accounts: any of these gaps can result in account suspension regardless of sales volume or seller history. For a seller whose primary revenue channel runs through a major marketplace, that is an existential risk hiding inside what looks like routine administrative hygiene.

Product Safety Obligations for Online Sellers in the U.S. and EU

In January 2025, the CPSC issued a Decision and Order against Amazon covering more than 400,000 hazardous products, including carbon monoxide detectors, hairdryers lacking electrocution protection, and children's sleepwear failing flammability standards. By classifying Amazon as a "distributor" under the Consumer Product Safety Act, the CPSC established that marketplace operators bear recall responsibility for Fulfilled by Amazon products. That reclassification has real implications for how the entire marketplace ecosystem handles safety liability going forward.

What that ruling does not do is shield the original seller from CPSC action. If your product moves through a fulfillment program and a safety issue surfaces, the platform's distributor designation is a not a firewall.

On the EU side, the General Product Safety Regulation took full effect across all EU member states in December 2024. GPSR applies to manufacturers, importers, and retailers alike, and it requires safety evaluations before products enter the EU market. Where your business is incorporated is irrelevant. If you sell into the EU, GPSR compliance applies to you.

The EU's Digital Services Act adds another layer for marketplace participants. Platforms aware of an illegal product listing must inform consumers who purchased it within the last six months. If contact details are unavailable, the disclosure must be made publicly on the platform. Fines for non-compliance can reach 6% of annual global revenues.

A Senate bill introduced in October 2025 would give the CPSC enhanced mandatory recall authority for products where the manufacturer or retailer is located in China and has not adequately responded to CPSC information requests. If enacted, this would tighten the import supply chain compliance burden considerably for retailers whose sourcing relies on Chinese manufacturing.

How These Obligation Categories Interact and Where Retailers Most Commonly Underestimate Exposure

The most dangerous assumption in retail compliance is that these categories operate in separate lanes. They don't, and the interactions between them are where real exposure accumulates quietly.

Consider the data privacy and payment security intersection. PCI DSS v4.0's logging and authentication requirements and state-level data governance obligations aren't running parallel tracks that occasionally cross. A single breach event triggers both PCI penalties and state attorney general enforcement simultaneously, each with its own penalty structure and remediation requirements, each proceeding on its own timeline.

The tax and marketplace operations intersection is subtler but equally costly. A seller relying on Amazon for fulfillment unknowingly creates physical nexus in states where inventory is warehoused, generating sales tax obligations on direct-channel sales that the marketplace facilitator arrangement does not cover. The compliance benefit of the marketplace facilitator regime is real but partial, and treating it as complete is how nexus errors compound quietly until someone runs an audit.

The consumer protection and UX intersection is perhaps the most underappreciated. The Amazon dark patterns settlement, state auto-renewal laws, and the INFORM Act's disclosure requirements all converge on a single operational surface: how checkout flows and subscription terms are actually designed. A UX decision made in a product sprint is simultaneously a legal exposure decision. If your designers and lawyers are not in the same room for that conversation, someone is going to make an expensive assumption that nobody flagged in time.

The retail sector consistently reports feeling less compliance pressure than peers in financial services or healthcare. The CPSC Amazon order, the FTC dark patterns settlement, and the volume of listing removals under the INFORM Act collectively suggest enforcement is actively catching up to that perception. Feeling less scrutinized than a bank is not evidence of lower risk.

Eight state privacy laws activated in a single calendar year. PCI DSS v4.0 became mandatory. GPSR took full effect. The INFORM Act produced its first enforcement action. These are simultaneous activations across the full compliance stack, and the retailers navigating them are the ones who figured out that compliance is not a project with a completion date. It's an operating condition.

Sources

  1. framelegal.com
  2. pb-iplaw.com
  3. iclg.com

More in Industry Regulations