Guide chapters
Seller Onboarding: Whom to Allow to Sell
Onboarding cannot be a single survey of 'company/private person'. It must establish roles, upon which consumer law, product safety, BDO, VAT, DAC7, and payouts depend.
Onboarding Scope - Do Not Duplicate Payment Provider Data#
The platform collects data directly only if it needs it for its own service and obligations. For a typical marketplace, these are:
- full name or company name, entrepreneur/private person/unregistered business status, address, and contact details;
- country of registered office and shipping countries;
- NIP/TIN, EU VAT number, KRS or relevant registry and number - if applicable;
- product roles: manufacturer, importer, distributor, brand owner, dropshipper;
- information on who warehouses, packs, and dispatches the shipment;
- categories and brands the seller wishes to offer;
- BDO/EPR and scope of registration, where applicable, or specific basis for exemption;
- identification data required for DAC7, if the operator is subject to reporting;
- acceptance of product compliance, recalls, complaints, and sanctions policies.
A payout account does not need to be copied to the marketplace database simply because Stripe or another PSP has it. In the Stripe Connect model, the platform may only store the account identifier with the PSP, verification and payout status, country/currency, and events necessary for transaction reconciliation. The full account number and KYC documents can remain solely with the PSP if the platform does not need them for its own obligations.
There are two exceptions:
- DAC7: the financial account identifier is reported only if it is available to the operator. It is not necessary to obtain the full account solely to make it 'available'. If Stripe provides the operator with the required identifier or reference data, it should be included in the report.
- Article 30 DSA: the obligation to obtain and securely store payment account data applies to marketplaces to which Section 4 of the DSA applies; micro and small operators are generally exempt from it. Upon losing exemption, the PSP may be a source of data, but the agreement and integration must ensure the operator fulfills the DSA obligation. The mere fact that Stripe has data to which the operator has no legal or technical access is not sufficient for a medium-sized operator covered by Article 30.
Additional package for non-EU sellers#
- the entity importing into the EU and its address;
- the responsible person in the EU, if required, with postal and electronic address;
- the direction of goods flow: warehouse in the EU or direct shipment from a third country;
- VAT/IOSS determination, customs duties, and the entity responsible for import charges;
- compliance documents and marking appropriate for the category;
- the entity responsible for EPR/BDO in Poland or another country of delivery;
- return and complaint procedure with an address in the EU or a viable logistical solution.
How to verify#
| Information | Minimum evidence | Response to discrepancy |
|---|---|---|
| Company and representation | current CEIDG/KRS entry or relevant foreign registry | Suspend onboarding; request clarification and proof of authorization. |
| NIP/VAT | relevant official database, including VIES for EU VAT | Do not use the 'active VAT' status based solely on a declaration. |
| Payout account | account status/identifier with PSP; full account only if the platform itself must obtain it | In the Stripe Connect model, do not copy IBAN. Suspend and change accounts through the PSP process. |
| Identity | document/eID, if required by DSA or risk process | Access only for authorized personnel; do not copy documents 'just in case' if the obligation does not apply. |
| BDO | BDO search engine/registry and relevant registration department | The number alone is insufficient if the scope does not cover the given role or product group. |
| Manufacturer/responsible person | manufacturer's document, contract/mandate, data on the product or documentation | Block offers until confirmation. |
| Regulated categories | documents specified in the category gateway | Allow only categories for which evidence is complete. |
Re-verification#
- upon changes in name, address, shipping country, owner, or representation, and in the PSP model, also upon changes in the payment account status/identifier visible to the operator;
- before entering a new category or commencing import;
- after a report of false data, a dangerous product, a large number of complaints, or fraud;
- cyclically at least once a year for key data; more frequently based on risk;
- before statutory DAC7 deadlines and upon expiration of a document.
Business or private individual#
If the platform allows private individuals, the interface must:
- collect their unambiguous declaration of status;
- react when the scale, regularity, or professional nature of sales contradicts the declaration;
- clearly indicate for each offer and before purchase that the seller is not a business entity;
- warn that the consumer right of withdrawal and the business entity's liability for product conformity do not apply to this contract;
- not mix private and business offers in a way that obscures the difference.
Basis and sources: DSA - Regulation (EU) 2022/2065, Articles 30–32; UOKiK - information obligations of platforms; VIES - VAT EU verification.
I design multi-vendor platforms with onboarding, payments, moderation, and operational workflows.
Explore marketplace development