forumNew topic

Selling online to EU countries: does GDPR directly apply to us?

DDamla Y***MemberCommunity member
Joined
Sep 2022
Message
131
#1

We produce custom handmade leather bags and desk accessories at our workshop based in Saint Petersburg. Through our own independent website, we sell both locally and to European Union countries like Germany, France, and the Netherlands. Our average order value for the EU is around 180 EUR, and we ship about 25-30 orders a month.

We accept payments in euros via international payment gateways. We store the customer's name, shipping address, phone number, and billing details on our system. We also run targeted ads directly aimed at audiences in these countries.

I read on a forum that even if you're outside the EU, you fall under GDPR simply by offering goods or services to individuals there. Does this regulation really bind us when we have no physical office or legal representative in the EU? What are the bare minimum requirements we must meet on our website and in our data flows?

İİlker G***Member
Job title
Board member
Sector
Livestock
Organization type
regional distributor
Joined
Apr 2026
Message
341
Most Helpful#2

Short answer: Yes, being located outside the EU does not exempt your business. Under GDPR Article 3(2), if you offer goods or services to individuals in the EU or monitor their behavior, you are directly obligated to comply with the regulation.

What determines applicability is whether your website actively targets the EU market. Offering prices in euros, listing EU countries in your shipping options, and running targeted ads to those regions are clear indicators that you fall within scope. The lack of a physical office in the EU does not eliminate your responsibility.

For minimum compliance, the first step is revising your cookie consent mechanism. The banner shown to EU visitors must not trigger marketing or tracking scripts before the user explicitly opts in. Second, you must have a clear English privacy policy detailing what data is collected, for what purpose, and which third parties (such as couriers or payment gateways) it is shared with.

Finally, you need a process for handling data subject rights. If a customer requests the deletion of their order history and address details (right to be forgotten), you must have an internal procedure and a dedicated contact email to purge non-mandatory marketing data within a reasonable timeframe, aside from legally required accounting records.

CCaner A***Member
Job title
Technical service technician
Sector
Agriculture
Organization type
sole proprietorship
Joined
Nov 2022
Message
157
#3

European data protection authorities aren't going to come after a small Russian workshop with millions of euros in fines let's be realistic. The real risk is international payment processors or integrations freezing your account over user complaints. Their own terms of service mandate GDPR compliance.

CCanerMember
Job title
Hosting provider
Joined
Nov 2023
Message
128
#4

If you use Google Analytics or ad pixels, turn on IP anonymization settings. Also, your cookie banner can't just be an "I Accept" button; users must be able to reject analytics and marketing cookies separately.

AAslıMember
Job title
Product photographer
Organization type
early-stage startup
Joined
Jul 2024
Message
76
#5

Add a clickable checkbox or note at checkout stating: "Your data is processed in accordance with our privacy policy for order fulfillment and delivery." Make sure your policy clearly lists a contact email for data deletion requests.

ÖÖmerMember
Job title
Financial Analyst
Joined
Dec 2023
Message
126
#6

Back when our EU sales were around 4,500 EUR a month, a customer from Germany sent a formal email asking which servers held their data and demanding its deletion. You are legally required to reply in writing within 30 days. We wiped the records from our database, confirmed it with them, and that was that.

LLale Y***Member
Job title
Social media manager
Sector
Software
Organization type
120-person company
Joined
Aug 2024
Message
377
#7

Is having an English version and showing prices in euros enough on its own or does an actual order have to be delivered there?

MMelis Ö***Expert
Job title
Social media manager
Sector
E-commerce
Organization type
120-person company
Joined
Feb 2022
Message
14

Doki · Log management setup · 2025

#8

It is worth noting that cross-border data processing exceeding certain volumes requires appointing an EU Representative. However, the principle of proportionality applies to micro-enterprises, making basic transparency and data security measures the primary focus of enforcement.

EElif E***Member
Job title
Sales Manager
Sector
Logistics
Organization type
medium-sized business
Joined
Feb 2024
Message
38
#9

dont panic at all. major lawsuits only target massive platforms. just dont collect anything beyond the name and address needed to ship the order post a clear policy, and if a customer asks for deletion do it without making a fuss. for an SME, thats basically it.

KKübra A***Member
Job title
Technical service technician
Sector
Automotive aftermarket
Organization type
120-person company
Joined
Aug 2025
Message
71

Doki · Phishing awareness training · 2026

#10

Saved.

OOkan E***Expert
Job title
QA Tester
Sector
Law
Organization type
early-stage startup
Joined
Feb 2022
Message
11
#11

Thanks for writing this that's the right way... An automated scan report is not the same as a penetration test.

EEsraMember
Job title
Python developer
Joined
Aug 2024
Message
134
#12

Let me share my experience. The answer varies greatly by industry; there is no one-size-fits-all rule.

This is my opinion, I'm not claiming it's absolute truth.

SSinan T***Member
Job title
Marketing director
Sector
Packaging
Organization type
sole proprietorship
Joined
Aug 2024
Message
27

Doki · Log management setup · 2024

#13

Good call starting this thread. Payment information changes are never verified through the channel they came from.

Good luck with that.

FFurkan B***Veteran
Job title
Store Manager
Sector
Machinery manufacturing
Organization type
two-branch business
Joined
Jan 2023
Message
126

Doki · Interface design · 2026

#14

Following.

YYiğit K***MemberCommunity member
Joined
Mar 2024
Message
226
#15

Thanks for posting. Just because everyone does it doesn't mean it's right.

Hope this helps.

MMert K***Expert
Job title
Data entry clerk
Sector
Leather
Organization type
40-person manufacturing company
Joined
Jun 2023
Message
18
#16

This is exactly what we experienced. Security isn't absolute; it's about making attacks not worth the effort.

That's all, sorry if I went on too long.

CCaner G***Expert
Job title
Store associate
Sector
Livestock
Organization type
chain store
Joined
Feb 2023
Message
105
#17

Let me write how it's done in practice. Any unwritten clause becomes a point of disagreement later, as both sides remember it differently.

If you post the result here, it will help others too.

FFerhat G***New memberCommunity member
Joined
May 2026
Message
180
#18

This approach has a cost, which isn't discussed. Any unwritten clause becomes a point of disagreement later, as both sides remember it differently.

This is my opinion, I'm not claiming it's absolute truth.

KKader T***Expert
Job title
Marketing director
Sector
Law
Organization type
boutique agency
Joined
Oct 2025
Message
3

Doki · Phishing awareness training · 2023

#19

I'll try it.

İİlker C***Member
Job title
Software developer
Sector
Machinery manufacturing
Organization type
sole proprietorship
Joined
Dec 2023
Message
52
#20

Let me summarize the topic, since several different answers were given. Mistakes made on the gdpr side are usually reversible but expensive.

If you scold false alarms, nobody will report again.

Reply