I Got Frustrated.
A few days ago I came across an online store built by an outside agency. At first glance it looked like hundreds of other small WooCommerce-based shops. Products were listed, the cart worked, you could go through checkout and place an order.
But after a few minutes it was clear this store had the feel of a minimum-effort implementation. It was noticeably slow, relied almost entirely on default WooCommerce components, and the product pages were missing information you'd expect from a professional online store.
Then things got more serious: a hidden privacy policy, terms and conditions that were practically invisible, a broken cookie banner, and doubts about whether basic consumer information obligations were even being met.
And this wasn't some hobby project built after hours. It was a real, operating store selling to consumers, built by an external agency! A store someone paid for. A store that — from the owner's point of view — "works." The problem is that "working" and "being legally compliant" are two completely different things.
This article probably wouldn't exist if the store's footer didn't include a link to the agency that built it. Because if you publicly put your name on an e-commerce build, you also take on the risk that someone will take a closer look at the quality of that work.
The Problem Starts Before GDPR
Before I even got into the privacy policy and cookies, I already had doubts. The store was slow, the product page was very sparse, and some of the information you'd expect from a modern professional store simply wasn't shown.
That's an important lesson for business owners. Compliance is rarely the only problem. If a store looks like it was built with minimum effort and leans almost entirely on the platform's default components, it usually turns out that the same minimal-effort approach was applied to legal matters and information obligations too.

The Market Problem: You Can Build a Store for a Few Hundred Bucks
I get it — e-commerce is a competitive market. I get that small store owners have limited budgets; I've been there myself. I also get that agencies often have to compete on price. But there's something that genuinely bothers me.
The problem isn't that cheap solutions are bad — something I've said many times on this blog. The problem shows up at a very specific moment: when a "professional online store" is sold to a client, the client assumes everything is legally compliant. In reality, they get a site that appears to work on the surface... except the store owner usually has no idea what they should even expect from a professional e-commerce build. They see a working cart and working payments, but have no awareness that a store also needs to meet a range of legal and informational obligations — and they have no way to verify the technical side either. That is legal risk being quietly shifted onto the client, without their knowledge or consent.
A false belief has taken root in the industry: that e-commerce equals WordPress + a theme + a payment plugin, or Shopify, or PrestaShop. That if the cart works and the payment gateway accepts transactions, the store is "done." In reality, an online store is far more than that. It also includes:
- consumer protection law and the information obligations arising from consumer rights legislation
- GDPR and the information clauses covering personal data processing
- the ePrivacy Directive and a properly implemented cookie banner
- the law on providing services electronically, and the seller's contact details
- data security and the documentation required under GDPR
- terms and conditions compliant with the Civil Code and consumer protection law
The owner who commissioned the agency's work often has no idea these elements even exist. They assume that since they paid for "a store," they got everything they need. That's exactly the moment legal risk gets quietly transferred to the business owner — without them even knowing it.
Does a Small Store Also Have to Comply with GDPR?
Yes. No exceptions. GDPR doesn't include any revenue threshold, order-volume limit, or carve-out for small businesses. If your online store collects a name, a delivery address, an email address, and a phone number — you're processing personal data and you're subject to GDPR, regardless of how small your operation is.
What's more, an online store by definition processes personal data in an automated way — which makes GDPR obligations especially relevant. Poland's data protection authority (UODO) doesn't go easy on small businesses. Administrative fines can be severe, but more importantly, violating consumers' data protection rights can expose a business to civil claims from customers.
The core obligation under GDPR's information-duty provisions is informing the person whose data you collect about: who the data controller is, what the purpose and legal basis for processing is, how long the data will be retained, what rights the person has, and whether the data will be transferred outside the European Economic Area. That is exactly what your store's privacy policy should cover.
What Documents Should an Online Store Have?
Every online store selling to consumers in Poland should have at least three key documents. Their absence, or improper implementation, is the most common problem I find during audits.
Store Terms and Conditions
The store's terms and conditions are a document required under consumer protection law and the law on providing services electronically. Proper terms and conditions should include:
- the business's full details (name, address, tax ID, registration number, email, phone)
- how orders are placed and how the contract is formed
- available payment methods and fulfillment timelines
- shipping costs and delivery methods
- the complaint and warranty procedure
- the 14-day right of withdrawal, without needing to give a reason
- exceptions to the right of withdrawal (e.g. personalized products, digital content)
- the moment the sales contract is considered formed
Just as important as the content is its accessibility. The terms and conditions should be: easily accessible from every subpage of the store, available before a purchase is made, linked in the site footer, and linked directly within the checkout flow — so the customer can review it before clicking "Buy and Pay."
Privacy Policy
The privacy policy fulfills the information obligation required under GDPR. It should contain all the information a data controller is required to disclose to the person whose data is being processed. A proper privacy policy for an online store should cover:
- the data controller's identity and contact details
- the purposes of data processing and the legal basis for each purpose
- categories of data recipients (e.g. courier companies, payment processors, hosting providers)
- retention periods for each purpose
- the user's rights: access, correction, deletion, restriction, portability, objection
- information about any data transfers outside the European Economic Area
- information about cookies and the analytics tools in use
The privacy policy should be permanently accessible — a footer link is the absolute minimum. Hiding it, or only surfacing it next to a contact form, is a practice that raises serious doubts about whether the information obligation is actually being met.
Cookie Policy
The cookie policy is a separate document (or section of the privacy policy) describing which cookies are used on the site, who sets them, for what purpose, and how the user can manage them. This document needs to be consistent with how the cookie banner and analytics tools actually behave on the site.
What About Product Information?
Since December 2024, businesses selling products to consumers are also subject to requirements under the General Product Safety Regulation (GPSR).
Depending on the type of product, the consumer should be able to access information such as:
- manufacturer details
- importer or responsible party details
- information identifying the product
- safety warnings and information, where relevant to the nature of the product
In the store I analyzed, the product pages were very sparse, and I wasn't able to find some of the information you'd expect from a modern, professional online store. Without a full audit of the entire product catalog, though, it's not possible to say definitively which GPSR obligations were violated.
What Should a Cookie Banner Look Like?
The cookie banner is one of the most commonly mis-implemented elements of online stores. The requirements come from the ePrivacy Directive and GDPR, and they're fairly precise — even though many stores still ignore them.
A proper cookie banner must:
- include an option to accept both essential and optional cookies — an "Accept" button
- include an equally accessible option to reject non-essential cookies — a "Reject" or "Essential only" button
- allow granular consent management — a "Settings" or "Manage preferences" button
- present the accept and reject options with equal visibility and accessibility — the reject button can't be hidden away
A cookie banner must NOT:
- have only an "OK" button with no reject option — that is not valid consent
- use phrasing like "continuing to use this site means you consent" — that is not consent under GDPR
- have pre-checked checkboxes for analytics or marketing cookies
- load analytics tools (Google Analytics, Meta Pixel) before consent has been given
What Should Checkout Look Like?
The checkout process is a critical point from a consumer law perspective. Consumer protection law places a number of information obligations on the seller that must be fulfilled before the consumer clicks the final purchase button.
Before clicking "Buy and Pay" (or an equivalent button), the consumer must have:
- access to the store's terms and conditions — the link must be visible and clickable
- access to the privacy policy — the link must be visible and clickable
- information about how personal data is processed in connection with fulfilling the order
- a clear statement of the 14-day right of withdrawal
- information about any exceptions to the right of withdrawal (if relevant to the products ordered)
- the ability to review these documents before completing the purchase — not after
All of this information must be in Polish if the store targets Polish consumers. Fragments in English appearing at key points in checkout aren't just a cosmetic issue — they're a potential problem for fulfilling information obligations. In the store that "inspired" this post, both the terms and conditions and the privacy policy were only accessible at the very last step of checkout, and the way they were presented raised a number of doubts about whether the information obligations were properly met.
A Special Case: Personalized Products
Many online stores sell made-to-order products, handmade goods, or personalized items — with a name, a dedication, a custom design. This is an important category from a consumer law perspective, because consumer protection law provides exceptions to the 14-day right of withdrawal.
But — and this is the key part — that exception doesn't apply automatically. To effectively exclude the right of withdrawal for personalized products, the seller must:
- properly inform the consumer about this exception before the purchase is made
- include the relevant clause in the store's terms and conditions
- clearly inform the consumer about the exception before the purchase. An additional confirmation step during the purchase flow can be good evidentiary practice.
A store that sells personalized products without properly informing the consumer about the withdrawal exception may be exposed to claims from customers — even if the product was made exactly as ordered.
What Did This Case Teach Us?
The store I analyzed is a great illustration of a pattern I see regularly in Polish e-commerce. A store can simultaneously:
✅ function — products, cart, payments, shipping
✅ look professional and visually inspire trust
✅ accept orders and process sales
❌ fail to meet basic GDPR compliance standards
❌ fail to properly fulfill information obligations toward consumers
❌ use a cookie banner that doesn't meet ePrivacy and GDPR requirements
That's exactly the heart of the problem.
The most frustrating part of all this isn't that the store had bugs. Bugs happen to everyone.
What's frustrating is that the business owner often doesn't even know they bought an incomplete product.
They bought "an online store" and got a website with a shopping cart bolted on.
And it's only when a customer complaint comes in, or a return is requested, or a cookie issue surfaces, or there's an inspection, that it becomes clear: professional e-commerce is far more than a WordPress theme, a few product photos, and working payments.
And most importantly — it won't be the agency explaining itself to the customer, the data protection authority, or the consumer protection office. Responsibility falls first and foremost on the business owner, who was often never even aware that their store had been implemented incompletely.
List of Problems Found in the Analyzed Store
Below is a detailed list of the problems I identified during the analysis. Each one is described from the perspective of potential legal risk.

1. ⚠️ Hidden privacy policy
The privacy policy isn't linked in the site footer or the main menu. The link only appears next to the contact form and at the very end of the checkout flow. This is a very weak practice from the perspective of fulfilling the GDPR information obligation. A user who doesn't fill out the contact form and doesn't go through checkout has essentially no way to access the privacy policy. This raises serious doubts about whether the information obligation is being properly fulfilled.
2. ⚠️ Terms and conditions practically hidden
The terms and conditions aren't accessible from the site footer or the main navigation. A user browsing the store and considering a purchase has no way to review the terms before making a buying decision. This is a potential violation of the consumer information obligations under consumer protection law. A proper implementation requires linking the terms in the footer, in the menu, and directly within the checkout flow.
3. ⚠️ Cookie banner that doesn't meet requirements
The cookie banner only has an "OK" button, with no equivalent option to reject non-essential cookies. There's no "Reject" or "Essential only" button. On top of that, the banner suggests that continuing to use the site implies consent to cookies — which directly contradicts GDPR's requirements for valid consent (consent must be freely given, specific, informed, and unambiguous). This is likely the biggest legal problem in the entire store, and an area of very high risk of non-compliance with ePrivacy and GDPR.
4. ❓ Possible loading of analytics tools before consent
The site has analytics and marketing tools installed (Google Analytics, possibly Meta Pixel and other trackers). It's not possible to determine from the outside, with certainty, whether these tools only load after the user gives consent or whether they run immediately on page load. Confirming this would require a full technical audit including network traffic analysis. If analytics tools load before consent is given, that's a serious violation of GDPR and the ePrivacy Directive.
5. ⚠️ Incomplete localization in checkout
The store targets Polish consumers and is run in Polish. However, fragments of English appear in the checkout flow — including key information about personal data processing. This isn't just a cosmetic or branding issue. Information about data processing, the right of withdrawal, and purchase terms needs to be understandable to the consumer — and fragments in a foreign language reduce clarity and may raise doubts about whether information obligations are being properly fulfilled.
6. ⚠️ Contact form with a likely unnecessary consent checkbox
The contact form includes a checkbox stating "I consent to the processing of my personal data." In many cases, this kind of consent isn't actually needed — processing data to respond to an inquiry can rely on a different legal basis (e.g. the controller's legitimate interest, or necessity for pre-contractual steps). Collecting consent where it isn't required can create consent-management problems down the line, and is more likely an implementation mistake than a deliberate decision.
7. ⚠️ Likely lack of deliberate compliance architecture
Looking at the whole picture — documents scattered with no consistency, a mismatch between the privacy policy and the cookie banner's actual behavior, default WooCommerce components left unadapted to Polish law, no holistic approach to compliance — it's fair to say this store wasn't built with compliance in mind. This is a systemic issue, not a collection of isolated mistakes. Compliance in e-commerce requires deliberate architecture from day one, not documents bolted on at the end of a project.
What We Can't Honestly Claim Without a Full Audit
Being fair means clearly marking the line of what can and can't be assessed from the outside. Based on an analysis of the store's visible elements, it would not be accurate to definitively claim that the store:
❌ violates GDPR as a whole — that would require a full audit of internal documentation
❌ lacks valid legal bases for data processing — that's not visible from the outside
❌ hasn't signed data processing agreements with its service providers — that's not visible from the outside
❌ doesn't maintain the documentation GDPR requires (a record of processing activities, risk assessments) — that's simply not visible from the outside
What can be said with full confidence: the store shows a number of shortcomings and implementation patterns that raise serious doubts about its level of compliance with information obligations, cookie requirements, and its overall approach to legal compliance. The visible elements — the cookie banner, document accessibility, checkout localization — point to a lack of any systemic approach to legal compliance. Realistic costs were broken down by me in “How Much Does an Online Store Cost in 2026? Honest Breakdown: Shopify, WooCommerce & Headless Commerce”
This isn't about calling out one specific store. It's about illustrating a mechanism that repeats itself across Polish e-commerce: a business owner buys a "finished store" that works, sells, and accepts payments — but has been left in a precarious legal position. No terms and conditions compliant with consumer law. No proper privacy policy. No working cookie banner. No deliberate compliance architecture.
If you run an online store, or you're planning to launch one — get a compliance audit done. Don't assume the agency took care of everything. Ask directly: Do the terms and conditions comply with consumer protection law? Does the privacy policy meet GDPR's information requirements? Does the cookie banner comply with the ePrivacy Directive? Does checkout include all the required information? The answers to these questions could save you from serious legal consequences.


