Guide chapters
00 - How to use the guide01 - First choose the business and responsibility model, then build the marketplace02 - Construction plan: what must exist and when03 - Responsibility Matrix: Operator, Seller, and Suppliers04 - Seller Onboarding: Whom to Allow to Sell05 - Product card: information without which an offer cannot be published06 - GPSR: Product Safety in Practice07 - Product Category Gates08 - BDO, packaging, and EPR: who is actually responsible09 - Consumer Law: Sale, Withdrawal, and Complaint10 - Prices, Promotions, Ranking, Advertising, and Reviews11 - Payments, Payouts, VAT, and Sales Documents12 - GDPR without myths: what to record, where, and on what basis13 - DSA: reporting, moderation, and seller traceability14 - P2B: fair rules for business users15 - DAC7: seller data and annual reporting16 - E-commerce accessibility from June 28, 202517 - Cybersecurity and KSC/NIS218 - Retention: How long to store data and evidence19 - Post-launch operations: calendar and owners20 - Four business models - specific decisions21 - Document and Procedure Package to Prepare22 - GO / NO-GO Checklist Before Launch23 - Most Common Misconceptions24 - Sources and Update Principle§ - Important Disclaimer Regarding the Nature of the Material
Chapter 23
Most Common Misconceptions
| Myth | Correct Rule |
|---|---|
| "We will write in the terms and conditions that the seller is responsible for everything." | The agreement divides responsibility between parties but does not exclude the operator's statutory obligations. |
| "The law requires a separate acceptance table." | The law requires proof of provision and the ability to reproduce the applicable version, not a specific table. A consistent link between an account/order event and an immutable document version is sufficient. |
| "A locked button and checkbox are always sufficient as proof." | There must be a persistent event that allows identification of the person or context, time, and version. This can be stored in an existing log, not necessarily in a separate table. |
| "Accepting the terms and conditions constitutes GDPR consent." | This is a contractual statement. Order fulfillment is usually not based on consent. |
| "Handmade items are not subject to GPSR." | A craftsperson operating commercially is a producer; scale does not remove the safety obligation. Occasional private sales are a separate case. |
| "Every product requires a form with weight, dimensions, and a hundred fields." | The common minimum is short, and industry-specific fields are activated only for the relevant category. A clear photo of the label can convey some information, but key data and warnings must be visible and accessible. |
| "Below 1 ton, there is no BDO." | A threshold may grant exemption from certain obligations upon meeting conditions, but it does not automatically remove the registration and reporting requirement. |
| "Every seller must have a BDO." | No. First, a distinction is made between private sales/unregistered activity and entrepreneurs, and only then between packaging role, import, and product group. |
| "Dropshipping means the wholesaler is responsible." | Dropshipping is a logistics method. The seller and the platform still need to determine the importer, the EU-based representative, VAT/customs, returns, and BDO. |
| "Since Stripe has an account, the platform must copy the IBAN." | No. For DAC7, the account identifier is reported when available to the operator; for an exempted micro/small marketplace under Article 30 of the DSA, it generally does not apply. Once Article 30 is applicable, the integration with the PSP must already allow the obligation to be fulfilled. |
| "A GPSR contact point means a separate form for authorities." | No. It can be a public email/alias or a shared form with a clear category and appropriate routing. Authorities and consumers can be directed to the same backend. |
| "A UUID from a regular request is not a case number." | It is a sufficient operational identifier if it is persistent, unique, and searchable. GPSR does not mandate a specific format for the number. |
| "We are small, so DSA does not apply to us." | The exemption for micro/small platforms covers only certain obligations, not the entirety of the DSA. |
| "Account deletion means deletion of all orders." | Data required for legal, tax, DAC7, dispute resolution, and safety purposes will be retained with restricted use until the relevant deadline. |
| "One product card can serve every seller." | Only if the product, manufacturer, variant, responsible entity, and warnings are indeed identical. |
| "Compliance is a launch project." | It is an ongoing operation: deadlines, re-verifications, audits, incidents, reports, and legal changes. |
Need to implement these processes in a real marketplace?
I design multi-vendor platforms with onboarding, payments, moderation, and operational workflows.
Explore marketplace development