Back to Blog
    Legal Guides

    E-commerce Legal Requirements: Complete Compliance Checklist

    Master e-commerce compliance with this complete 12-section checklist covering privacy, payments, returns, accessibility, sales tax, and more. Avoid costly legal violations and chargebacks.

    E-commerce Legal Requirements: Complete Compliance Checklist
    October 15, 2025
    5 min read
    e-commerce-compliance-checklist
    e-commerce-legal-requirements
    sales-tax-compliance
    wcag-accessibility
    ecommerce-privacy-policy
    pci-dss-compliance
    return-refund-policy
    business-registration
    ftc-advertising-compliance
    chargeback-prevention
    Share:

    Introduction

    Running an e-commerce store means more than just building a website and processing payments. You're subject to a complex web of federal, state, and international laws that regulate how you collect data, describe products, handle returns, charge customers, and protect information.

    According to the FTC, e-commerce businesses face an average of 8-12 compliance violations per business model—many of which are avoidable with proper documentation and procedures.

    The stakes are high: A single compliance violation can result in fines ranging from $100-$10,000+ per offense, not to mention chargebacks, refunds, and reputational damage.

    This guide walks you through every legal requirement for running a compliant e-commerce business, organized by category with actionable steps for each.


    Quick Compliance Checklist (At a Glance)

    Data & Privacy

    • [ ] Privacy policy explaining data collection and use

    • [ ] Cookie consent banner (GDPR/CCPA compliant)

    • [ ] Secure SSL/HTTPS certificate on checkout

    • [ ] Data breach notification plan

    • [ ] CCPA "Do Not Sell" link (if serving California residents)

    Consumer Protection

    • [ ] Clear, accurate product descriptions

    • [ ] Visible pricing (no hidden fees until checkout)

    • [ ] Return and refund policy posted

    • [ ] Shipping and delivery timeframes disclosed

    • [ ] Contact information (address, phone, email)

    • [ ] Terms of service governing purchases

    Payments & Billing

    • [ ] PCI DSS compliance for payment processing

    • [ ] Clear billing authorization before charging

    • [ ] Cancellation options for recurring charges

    • [ ] Receipt emails with order details

    • [ ] Chargeback documentation procedures

    Accessibility

    • [ ] WCAG 2.1 Level AA compliance (at minimum)

    • [ ] Alt text for product images

    • [ ] Accessible checkout process

    • [ ] Screen reader compatibility

    • [ ] Keyboard navigation throughout site

    Tax Compliance

    • [ ] Collect sales tax where required (nexus analysis)

    • [ ] State registration certificates

    • [ ] Sales tax audit documentation

    • [ ] Tax return filing deadlines tracked

    Legal Structure

    • [ ] Business registration (LLC, Corporation, etc.)

    • [ ] EIN (Employer Identification Number)

    • [ ] Business insurance (general liability, cyber liability)

    • [ ] Terms of service for purchases

    • [ ] Age verification (if selling age-restricted items)


    1. Privacy and Data Protection

    Privacy Policy Requirements

    Your privacy policy must be specific to e-commerce and address:

    Data Collection Disclose exactly what information you collect:

    • Contact information (name, email, phone, shipping address)

    • Payment information (processed through third-party, you don't store full card numbers)

    • Behavioral data (browsing history, purchase history)

    • Device information (IP address, device type, browser)

    • Cookies and tracking technologies (analytics, ads, recommendations)

    Data Use Explain each purpose:

    • Fulfilling orders and delivering products

    • Processing payments and fraud prevention

    • Sending transactional emails (order confirmation, shipping)

    • Marketing and promotional emails (requires separate opt-in under CAN-SPAM)

    • Personalizing recommendations and user experience

    • Analytics and business improvement

    Third-Party Sharing List every service that receives customer data:

    • Payment processors (Stripe, PayPal, Square)

    • Shipping partners (FedEx, UPS, USPS)

    • Email marketing platforms (Mailchimp, ConvertKit)

    • Analytics providers (Google Analytics)

    • Advertising networks (Facebook Ads, Google Ads)

    • Customer service tools (Zendesk, Intercom)

    Data Security Describe your security measures:

    • SSL/HTTPS encryption for data transmission

    • Secure password storage

    • Access controls (who can view customer data)

    • Regular security audits and monitoring

    • Incident response plan (what happens if breached)

    User Rights Under GDPR, CCPA, and similar laws, customers have the right to:

    • Access their personal data

    • Request correction of inaccurate data

    • Request deletion (right to be forgotten)

    • Data portability (receive data in portable format)

    • Opt-out of marketing communications

    Include instructions for each right:

    "To access your data, email privacy@yourstore.com with 'Data Access Request' in the subject line. We'll respond within 30 days."

    Data Retention Specify how long you keep customer data:

    • Order records: 3-7 years (for tax and dispute purposes)

    • Payment information: Not stored (processed by payment provider)

    • Marketing list data: Until user unsubscribes

    • Analytics data: Typically 26 months (Google Analytics default)

    CCPA and California Privacy Rights

    If you serve California residents, your privacy policy must explicitly state:

    "California Consumer Privacy Rights California residents have the right to:

    1. Know what personal information you collect, use, and share

    2. Delete personal information you've collected

    3. Opt-out of data sales or sharing

    4. Not be discriminated against for exercising these rights

    To exercise these rights, email [privacy contact] or call [phone]. We'll verify your identity and respond within 45 days."

    Add a prominent link: "Do Not Sell or Share My Personal Information"

    CCPA Penalties: $2,500 per violation, $7,500 per intentional violation. This adds up fast.

    GDPR Compliance (EU Customers)

    If you ship to Europe, GDPR applies. Requirements:

    • Privacy policy in simple, clear language

    • Explicit opt-in for marketing emails (double opt-in best practice)

    • Data Processing Agreement with any vendors handling data

    • Lawful basis for processing (consent, contract, legitimate interest)

    • Documentation that user consented to terms

    GDPR Penalties: Up to €20 million or 4% of annual revenue—take this seriously.

    Cookies and Tracking

    E-commerce sites typically use:

    • Necessary: Session cookies, fraud prevention, authentication

    • Analytics: Google Analytics, understanding customer behavior

    • Marketing: Facebook Pixel, retargeting ads

    Your cookie policy must disclose:

    • What cookies you set and why

    • How long cookies persist

    • Third-party cookies (any external script that sets cookies)

    • How users can opt-out or delete cookies

    Requirement: Cookie consent banner must display before loading non-essential tracking scripts.


    2. Product Descriptions and Advertising

    FTC Guidelines for Accuracy

    The FTC requires that product descriptions:

    Be Truthful

    • Accurately describe product materials, size, color, functionality

    • No misleading comparisons to competitors

    • No exaggerating benefits or effectiveness

    Be Substantiated

    • Have evidence supporting health/performance claims

    • "Doctor-recommended" only if actually recommended

    • "Best-selling" or "#1" only if true and verifiable

    Disclose Material Facts

    • Refurbished, used, or reconditioned items must be clearly labeled

    • Third-party certifications (organic, fair-trade) must be verified

    • If a product is restricted or requires licensing, disclose it

    FTC Fine Example: A vitamin company claiming to "boost immunity" without evidence paid $12 million in settlements. Be specific about product claims.

    Product Images and Content

    Best Practices:

    • Show accurate colors (account for monitor differences)

    • Include multiple angles and zoom views

    • Use images that represent the actual product

    • No photoshopped or misleading images

    • Include dimensions or size comparison photos

    Legal Risk: If customers receive products that don't match images, you face chargebacks, returns, negative reviews, and potential fraud claims.

    Age-Restricted Products

    If selling alcohol, tobacco, supplements, or age-restricted items:

    • Verify age before checkout (require date of birth)

    • Use third-party age verification services

    • Document compliance procedures

    • Refuse sales to ineligible customers

    • Keep records for audits

    Penalties: Up to $43,792 per violation (COPPA for children's products).


    3. Pricing and Payment Disclosure

    Clear Pricing Requirements

    FTC Pricing Rule: Price must be:

    • Clearly visible before checkout begins

    • The lowest price available in recent time

    • Accurate at time of sale

    • Include all mandatory fees in displayed price

    What You MUST Disclose BEFORE Checkout:

    • Product price

    • Shipping cost (or "Free Shipping" if applicable)

    • Tax (if collected)

    • Any subscription or recurring charges

    • Cancellation terms for subscriptions

    What You CAN Disclose AT CHECKOUT:

    • Promo codes or discounts

    • Gift messages or personalization

    • Delivery address verification

    Example of Compliant Pricing:

    Product Price:              $49.99
    Shipping:                   $9.99
    Tax (estimated):           $4.65
    ─────────────────────────────────
    Total:                     $64.63
    

    Hidden Fees Violations

    The FTC's "Negative Option Rule" specifically prohibits:

    • Pre-checking boxes for additional charges (must be active opt-in)

    • Hiding cancellation processes (must be as easy as signup)

    • Charging without clear, affirmative consent

    • Not honoring cancellation requests immediately

    Red Flag Examples (Don't do these):

    • Charging for a free trial without explicit authorization

    • Making cancellation available only by phone (must allow email/web)

    • Charging monthly without reminding customers


    4. Return and Refund Policies

    The FTC does not require you to accept returns, BUT if you do:

    Policy Must Be Clear About:

    • Time frame for returns (30 days, 60 days, etc.)

    • Condition requirements (new, unused, resellable)

    • Restocking fees (if applicable)

    • Who pays shipping (customer or business)

    • Refund timeline (when money goes back to customer)

    • Items that cannot be returned (final sale items, custom orders)

    • How to initiate a return

    Example Policy:

    "We accept returns within 30 days of purchase. Items must be unused and in original packaging. Customer pays return shipping. Refunds are issued to the original payment method within 5-7 business days of receiving returned items."

    State-Specific Requirements

    Some states have stricter return requirements:

    California

    • Must accept returns if item is defective or misrepresented

    • 30-day minimum return window recommended

    • Cannot charge restocking fee for defects

    New York

    • All sales final policies must be disclosed at point of sale

    • Defective goods must be replaceable or refundable

    Best Practice: Adopt California's standards (most consumer-friendly). If you comply with California, you'll likely comply elsewhere.

    Digital Products

    Digital products (e-books, software, courses) have different rules:

    FTC Allows No Return for Digital if:

    • Clearly labeled "Digital - Non-Returnable" before purchase

    • Customer has immediate access to product

    • No technical issue prevents use

    But If Customer Can't Access:

    • You must provide a refund (technical failures aren't customer's problem)

    Subscription Services

    For recurring charges, your policy must state:

    • Billing frequency and amount

    • How to cancel (make it easy; same way they signed up)

    • When cancellation takes effect

    • No automatic renewal without affirmative consent

    Legal Requirement (ROSCA - Restore Online Shoppers Confidence Act):

    • Negative option (recurring charge) requires express informed consent

    • Clear, conspicuous terms and conditions

    • Simple mechanism to cancel

    • Acknowledging consent before charging


    5. Shipping and Delivery

    Required Disclosures

    Before Checkout:

    • Estimated delivery dates

    • Shipping method options (standard, express, overnight)

    • Cost for each shipping method

    • Any regional restrictions

    Example:

    Standard Shipping (5-7 business days):  $9.99
    Express Shipping (2-3 business days): $24.99
    Next Day (1 business day):            $49.99
    * Orders placed on weekends ship Monday morning
    

    FTC Mail or Telephone Order Rule

    If you ship products:

    Must Ship Within:

    • Stated timeframe, OR

    • 30 days if no timeframe stated

    If You Can't Ship:

    • Notify customer and offer:

      • A firm revised shipping date, OR

      • Full refund (and process refund within 7 business days)

    • Get new consent for delayed shipment

    Exceptions: Backorders are okay IF customer agrees upfront.

    International Shipping

    If shipping internationally:

    • Disclose customs fees (if applicable)

    • Disclose import restrictions by country

    • Provide tracking information

    • Comply with destination country's import laws

    • Clearly state you're not responsible for customs delays


    6. Business Information and Contact Details

    Required Business Information

    By law, your website must display:

    Physical Address

    • Your actual business address (or registered agent address)

    • Cannot use P.O. Box alone

    Contact Method

    • Email address and/or phone number

    • Response time (within 24-48 hours recommended)

    • Live chat optional but recommended for customer service

    Company Information

    • Business name (DBA if different from legal name)

    • Business registration number (if applicable)

    • Tax ID or EIN (for B2B)

    Where to Display

    • Footer of every page

    • Contact or "About Us" page

    • Checkout page (builds trust)

    Legal Requirement: These must be easily findable; burying contact info violates FTC unfair practice rules.

    Terms of Service

    Your terms must cover:

    • Who can use your store (age restrictions if applicable)

    • Acceptable use (no harassment, fraud, illegal activity)

    • Your liability limitations

    • Dispute resolution (arbitration clause optional)

    • Intellectual property (product images, reviews)

    • Termination rights (you can refuse service to bad actors)

    • Governing law and jurisdiction


    7. Payment Processing and Security

    PCI DSS Compliance

    If you accept credit cards, you must comply with PCI DSS (Payment Card Industry Data Security Standard):

    Level 1 (Highest): >6 million transactions/year Level 2: 1-6 million transactions/year Level 3: 20,000-1 million transactions/year Level 4 (Lowest): <20,000 transactions/year

    Minimum Requirements for All Levels:

    • Use HTTPS/SSL for all transactions

    • Never store full credit card numbers on your server

    • Use tokenization (payment processor stores card data)

    • Regular security assessments

    • Firewall protection

    • Strong access controls

    Easiest Approach: Use a payment processor (Stripe, Square, PayPal) that handles PCI compliance for you. They assume responsibility for security.

    Cost: PCI compliance fines start at $5,000/month for violations.

    Data Breach Notification

    If customer data is breached:

    Within 30-60 Days:

    • Notify affected customers

    • Notify credit card companies

    • Notify state attorney general (many states require this)

    Content of Notification:

    • What data was compromised

    • When the breach occurred

    • What you're doing to prevent future breaches

    • What customers should do (monitor accounts, credit freeze, etc.)

    • Your contact information

    Have a Plan: Document your breach notification procedure now before it's needed.

    Fraud Prevention

    E-commerce businesses are high-risk for fraud:

    • Credit card fraud

    • Friendly fraud (chargebacks)

    • Account takeover

    Prevention Steps:

    • Use address verification (AVS)

    • Require CVV codes

    • Monitor for unusual purchase patterns

    • Use fraud detection tools (Stripe Radar, MaxMind)

    • Require customer verification for high-value orders

    • Keep detailed transaction records


    8. Accessibility Compliance (ADA/WCAG)

    U.S. businesses must make websites accessible under the ADA (Americans with Disabilities Act). International businesses should follow WCAG 2.1 standards.

    Minimum Standard: WCAG 2.1 Level AA

    E-commerce sites are particularly targeted in accessibility lawsuits because checkout is critical—if a disabled customer can't purchase, you're violating ADA.

    What You Must Provide

    For Product Images:

    • Alt text describing the product

    • Example: alt="Red leather iPhone case with card slots"

    For Navigation:

    • Keyboard navigation (Tab through all elements)

    • Skip navigation links (bypass repetitive content)

    • Clear focus indicators

    For Checkout:

    • Accessible form labels

    • Clear error messages

    • No time-based session expirations (or warn users)

    • Option to complete purchase by phone/email if needed

    For Content:

    • Sufficient color contrast (4.5:1 for normal text)

    • No information conveyed by color alone

    • Captions for videos

    • Transcripts for audio

    Testing and Compliance

    Test Your Site:

    • Use free tools: WAVE, Axe DevTools, Lighthouse

    • Use screen readers: NVDA (Windows), VoiceOver (Mac)

    • Get accessibility audit from professional if budget allows

    Lawsuit Risk: Average ADA settlement is $5,000-$50,000. Prevention is much cheaper than litigation.


    9. Email Marketing and CAN-SPAM Compliance

    CAN-SPAM Requirements

    If you send promotional emails:

    Every Email Must Include:

    • Accurate "From" name (not misleading)

    • Clear subject line (not deceptive)

    • Physical mailing address of your business

    • Clear identification that message is an advertisement

    • Easy unsubscribe link (must work within 10 days)

    • Honor unsubscribe requests within 10 business days

    Cannot:

    • Purchase email lists from questionable sources

    • Send emails to addresses on National Do Not Call Registry

    • Use false headers or routing information

    • Send unsolicited emails (spam)

    Can Send Without Consent:

    • Transactional emails (order confirmation, shipping updates, receipts)

    • Response to customer inquiry

    • Account notifications

    Require Express Consent Before Sending:

    • Marketing emails

    • Newsletters

    • Product recommendations

    • Promotional offers

    Best Practice: Use double opt-in (customer confirms signup via email before being added to list).

    Penalties: Up to $43,792 per email violation for intentional violations.


    10. Sales Tax Compliance

    Nexus Analysis: When You Must Collect Sales Tax

    Economic Nexus (Most Common):

    • If you have sales over a threshold in a state, you must collect sales tax

    • Thresholds: $100,000 to $1 million depending on state

    • MANY states now have sales tax requirements for online sales

    Determine Your Nexus:

    1. Where is your business located? (Collect sales tax there)

    2. Where do you have employees or offices? (Collect sales tax there)

    3. What are your sales in other states? (Check each state's threshold)

    Current State Requirements

    States Requiring Online Sales Tax:

    • Most states now require it (34+ states)

    • California, Texas, New York, Florida, Illinois all require it

    • Check TaxJar or each state's Department of Revenue website

    States Without Sales Tax:

    • Alaska, Delaware, Montana, New Hampshire, Oregon

    Collection and Remittance

    You Must:

    1. Register with each state's Department of Revenue (free)

    2. Collect sales tax at checkout (vary rate by customer's address)

    3. File sales tax returns (monthly, quarterly, or annually depending on state)

    4. Remit taxes to the state

    Resources:

    • TaxJar: Automates sales tax calculation and filing ($20-$100/month)

    • Avalara: Enterprise solution for complex businesses

    • Most e-commerce platforms (Shopify, WooCommerce) have integrations

    Penalties for Non-Compliance

    • Back taxes owed

    • Interest charges

    • Penalties (5-25% of owed amount)

    • Audit costs

    • Potential criminal charges if willful evasion


    11. Business Registration and Insurance

    Choose one:

    Sole Proprietorship

    • Simplest, no separate business entity

    • You're personally liable for all debts and lawsuits

    • Not recommended for e-commerce (too much personal risk)

    LLC (Limited Liability Company)

    • Personal liability protection (lawsuits limited to business assets)

    • Pass-through taxation (business income on personal tax return)

    • Requires annual filing and fees ($50-$500 depending on state)

    • Recommended for most e-commerce

    Corporation (C-Corp or S-Corp)

    • Separate business entity with more formal requirements

    • More liability protection

    • More complex tax situation

    • Better for larger businesses with employees

    Partnership

    • Multiple owners share liability

    • More complex than LLC

    • Not common for e-commerce

    Action: Register your business with your state. Cost: $0-$500.

    Employer Identification Number (EIN)

    Get a free EIN from the IRS even if you're a sole proprietor:

    • Required for hiring employees

    • Required for opening business bank account

    • Protects your personal Social Security number

    • Apply at: IRS.gov (takes 15 minutes)

    Business Insurance

    Highly recommended:

    General Liability Insurance

    • Covers injuries, accidents, property damage

    • Cost: $500-$1,500/year

    • Example: Customer injured receiving package

    Cyber Liability Insurance

    • Covers data breaches, ransomware, business interruption

    • Cost: $1,000-$5,000/year

    • Essential for e-commerce (you hold customer data)

    E&O (Errors & Omissions)

    • Covers mistakes, negligence, misrepresentation

    • Cost: $1,000-$2,500/year

    • Optional but recommended

    Product Liability (If selling physical products)

    • Covers harm from defective products

    • Cost: $1,000-$10,000+/year depending on product risk

    • Critical for anything that could harm someone


    12. Accessibility to Dispute Resolution

    Clear Return/Refund Process

    Customers Need to Know:

    • How to initiate a return (online form, email, phone?)

    • Where to send returns (return address clearly posted)

    • What happens next (how long for refund?)

    • Who to contact if issues arise (email, phone, support portal?)

    Chargeback Management

    If a customer disputes a charge through their bank:

    Provide Documentation:

    • Order confirmation

    • Shipping tracking (proof of delivery)

    • Delivery signature

    • Communication with customer

    • Return authorization if return requested

    Process:

    1. Customer initiates dispute with bank

    2. Bank gives you 5-10 days to respond with evidence

    3. Bank decides based on evidence provided

    4. You either win back funds or lose them

    Best Practices:

    • Keep detailed records of all transactions

    • Use tracked shipping (you need proof of delivery)

    • Communicate with customers to resolve issues before chargebacks

    • Use fraud prevention to avoid disputes


    Checklist by Platform

    Shopify

    Built-in features that help with compliance:

    • SSL/HTTPS automatic

    • PCI compliance handled

    • Sales tax automation available

    • Privacy policy generator

    • Cookie consent options

    • GDPR consent checkboxes

    Still Required:

    • Customize privacy policy for your business

    • Create accurate product descriptions

    • Disclose return policy clearly

    • Set up email opt-in (Shopify doesn't auto-opt)

    • Verify you have sales tax collection set up

    WooCommerce

    More manual setup required:

    • Install SSL certificate (usually free with hosting)

    • Install privacy policy plugin

    • Set return/refund policy in product settings

    • Use tax extension for sales tax

    • Install GDPR compliance plugin (WP GDPR Compliance)

    • Add cookie consent banner (plugin: Cookie Notice)

    BigCommerce

    Good compliance features:

    • Built-in privacy policy generator

    • GDPR tools included

    • Sales tax integration

    • Abandoned cart recovery (must have consent)

    Still Required:

    • Customize generated documents

    • Ensure product descriptions are accurate

    • Set clear shipping and return policies


    Compliance Audit Timeline

    Monthly:

    • Review chargeback documentation

    • Monitor product reviews for accuracy issues

    • Verify email list opt-in compliance

    • Check for new regulatory updates

    Quarterly:

    • Review return/refund requests for patterns

    • Audit accessibility compliance (test checkout)

    • Review data security procedures

    • Check sales tax collection accuracy

    Annually:

    • Full privacy policy review and update

    • Accessibility audit (professional if possible)

    • Sales tax nexus analysis (thresholds may have changed)

    • Business insurance renewal and adequacy check

    • Legal document review (ToS, return policy, etc.)


    Common E-commerce Compliance Mistakes

    Mistake 1: Generic Privacy Policy Using a template for a different industry. E-commerce requires specific disclosures about payment processing, shipping partners, third-party integrations.

    Mistake 2: Hidden Shipping Costs Showing product price, then surprising customer with high shipping at checkout. Must show total cost before payment.

    Mistake 3: Pre-checked Email Opt-in Automatically subscribing customers to marketing emails. Must be explicit, unchecked opt-in.

    Mistake 4: No Clear Return Policy Ambiguous language about returns. "Reasonable return time" is too vague. Must be specific: "30 days from purchase date."

    Mistake 5: Inaccessible Checkout Building a beautiful checkout that screen readers can't navigate. Roughly 15% of population has disabilities; they can't buy from your store.

    Mistake 6: Not Collecting Sales Tax Selling to California from another state and not collecting sales tax. You're personally liable for back taxes, interest, and penalties.

    Mistake 7: Storing Credit Card Data Never store full credit card numbers. Use payment processor (Stripe, etc.) that handles this securely.

    Mistake 8: Slow Chargeback Response Not responding to chargeback disputes because you assume you'll win. You lose by default if you don't respond in time.


    Compliance Tools and Resources

    Free Tools:

    • WAVE (accessibility testing)

    • Google Lighthouse (accessibility & performance)

    • IRS.gov (EIN application)

    • Each state's Department of Revenue (sales tax rates)

    • TaxJar free tier (sales tax rates)

    Affordable Tools ($10-50/month):

    • TaxJar (sales tax automation)

    • WP GDPR Compliance (WordPress privacy)

    • Cookiebot (GDPR cookie consent)

    • Stripe (payment processing, fraud detection)

    Professional Services ($500-2,000+):

    • E-commerce lawyer (comprehensive review)

    • Accessibility consultant (WCAG audit)

    • Accountant (tax strategy and compliance)

    • Insurance broker (business insurance review)


    Final Checklist: E-commerce Compliance

    Before Launching:

    • [ ] Privacy policy specific to e-commerce operations

    • [ ] Terms of service for purchases

    • [ ] Clear, accurate product descriptions

    • [ ] Return and refund policy disclosed

    • [ ] Shipping costs and timeline transparent

    • [ ] Business registration completed (LLC, Corp, etc.)

    • [ ] EIN obtained

    • [ ] SSL/HTTPS certificate installed

    • [ ] Payment processor integrated (Stripe, PayPal, etc.)

    • [ ] Accessibility audit completed (at least self-audit with WAVE)

    • [ ] Contact information (address, email, phone) on site

    • [ ] Email opt-in is opt-in, not pre-checked

    Before First Sale:

    • [ ] Sales tax nexus analysis completed

    • [ ] Sales tax collection configured in cart

    • [ ] Business insurance obtained (at least liability)

    • [ ] Chargeback documentation procedures established

    • [ ] Fraud detection tools configured

    • [ ] Customer service response process documented

    • [ ] Return shipping address identified

    • [ ] Breach notification plan written

    • [ ] CAN-SPAM compliance reviewed (email marketing)

    • [ ] GDPR/CCPA privacy rights implemented in account settings

    Ongoing Compliance (Quarterly):

    • [ ] Review chargeback/return patterns

    • [ ] Update inventory and product descriptions

    • [ ] Check for new regulatory updates

    • [ ] Test website accessibility

    • [ ] Review email list opt-in practices


    FAQ: E-commerce Compliance

    Q: Do I need a lawyer to set up my store? A: Not necessarily. Many tools automate compliance (privacy policy generators, tax software). A lawyer is valuable if handling sensitive products, selling B2B, or operating in regulated industries (healthcare, supplements).

    Q: What if I only ship within one state? A: You still need a privacy policy, terms of service, and return policy. Sales tax is only needed in your home state (already collected by you).

    Q: Can I use the same privacy policy for my website and mobile app? A: Mostly, but review for app-specific data (location, device ID, push notifications). Update your policy to reflect all data practices.

    Q: What's the difference between a charge-off and a chargeback? A: Charge-off = customer stops paying (recurring billing). Chargeback = customer disputes charge with bank (fraud). Handle chargebacks with documentation; handle charge-offs with collection attempts.

    Q: Do I need accessibility compliance if I'm a small business? A: Yes. ADA applies to all businesses serving the public. "Small" is not an exception. However, you may have a reasonable amount of time to achieve compliance (typically 30 days notice from lawsuit).

    Q: What's the easiest way to stay compliant with sales tax? A: Use TaxJar or Avalara. They integrate with your store, auto-calculate rates, and file for you. Cost ($20-100/month) is worth the peace of mind.

    Q: Can I refuse to do business with a customer? A: Generally yes, except on discriminatory grounds. You can refuse service for legitimate reasons (policy violations, fraud risk, unprofitable customer).


    Next Steps

    1. Audit Your Current State: Go through the checklist above. Note what you already have and what's missing.

    2. Prioritize High-Risk Items: Privacy policy, secure payment processing, and sales tax are the most common violations.

    3. Implement Missing Items: Use templates and tools to fill gaps quickly.

    4. Get Professional Review: For high-value businesses, have a lawyer review terms and privacy policy.

    5. Set Compliance Calendar: Block recurring time each quarter to review and update.

    E-commerce compliance seems overwhelming, but it's mostly about documentation and transparency. Get the fundamentals right now, and you'll avoid costly violations later.

    Legal compliance expert contributing to PolicyForge insights.

    Legal Compliance

    Related Posts

    Legal Guides

    Return & Refund Policy Template + Legal Requirements

    Complete return and refund policy template with legal requirements. Copy-paste templates for physical products, digital goods, subscriptions, and fashion. Reduce chargebacks and returns fraud.

    10/15/20255 min read
    Legal Guides

    Does My Business Actually Need a Privacy Policy? (And What to Include)

    Stop wondering if your business needs a privacy policy. Learn the real requirements, consequences of not having one, and what must be included to stay compliant.

    9/4/20255 min read
    Legal Guides

    How to Write a Privacy Policy in 2025: Step-by-Step Guide

    Learn how to write a comprehensive privacy policy from scratch. Our step-by-step guide covers legal requirements, essential sections, and best practices.

    7/12/202510 min read

    Ready to generate your legal policies?

    Create compliant privacy policies, terms of service, and more with AI assistance.