Etsy GDPR Compliance: What EU Sellers Need to Know (2026)
If you sell on Etsy and have even one customer in the European Union, GDPR applies to you — regardless of where your shop is based. This guide breaks down your obligations as a data controller, what Etsy handles for you, and the practical steps every seller should take to stay compliant in 2026.

What GDPR Means for Etsy Sellers
The General Data Protection Regulation (GDPR) is the EU's data privacy law that governs how businesses collect, store, and use personal data belonging to EU residents. It went into effect in May 2018 and remains the most far-reaching data protection law in the world.
Here's the part that trips up most Etsy sellers: GDPR applies based on where your customers are, not where you are. If you're a seller in Texas and someone in Berlin buys your handmade candles, you're processing EU personal data. GDPR applies to you.
This isn't theoretical. EU data protection authorities have been increasing enforcement actions against e-commerce businesses of all sizes since 2023, and online marketplace sellers are squarely in scope. The 2026 Etsy policy changes have also emphasized seller compliance with international regulations, making this more urgent than ever.
What Data Etsy Collects on Your Behalf
Every time someone places an order in your Etsy shop, personal data flows through the transaction. Understanding exactly what data is involved is the first step toward compliance.
Personal Data You Receive Through Etsy Orders
- •Full name — as provided by the buyer at checkout
- •Shipping address — street, city, postcode, country
- •Email address — for order communications
- •Payment info — Etsy Payments handles this, but transaction records are accessible to you
- •Custom order details — personalization requests may contain additional personal information
- •Message conversations — anything shared through Etsy Messages
If you export this data to spreadsheets, CRM tools, shipping label software, or email marketing platforms, you're extending the data processing chain — and your GDPR obligations extend with it.
Your Responsibilities as a Data Controller
Under GDPR, there's a critical distinction between data controllers (who decide why and how data is processed) and data processors (who process data on behalf of someone else).
As an Etsy seller, you are an independent data controller. Etsy is a separate data controller for its own platform operations. This means you can't rely on Etsy's privacy policy to cover your obligations — you have your own.
What This Means in Practice
- •You must have a lawful basis for processing customer data (contract fulfillment for orders, legitimate interest for fraud prevention, consent for marketing)
- •You must inform customers about how you use their data
- •You must honor data subject requests (access, correction, deletion)
- •You must secure the data you hold — no unencrypted spreadsheets sitting in shared Google Drives
Think of it this way: Etsy handles the platform, but your shop, your data, your responsibility. If you export customer emails into a Mailchimp list without consent, that's on you — not Etsy. Learn more about protecting your Etsy shop from compliance risks.
Privacy Policy Requirements
GDPR requires you to provide clear, accessible information about your data practices. On Etsy, the best place for this is your Shop Policies section, specifically in the Privacy Policy field.
Your Etsy Privacy Policy Should Include
- •What data you collect — names, addresses, emails, order details
- •Why you collect it — order fulfillment, shipping, customer support
- •How long you keep it — specify retention periods (e.g., “order data retained for 7 years for tax purposes”)
- •Who you share it with — shipping carriers, payment processors, email marketing tools
- •Customer rights — right to access, correct, delete, or port their data
- •How to contact you — provide a way for customers to make data requests
Keep the language simple and direct. GDPR explicitly requires that privacy notices be written in “clear and plain language”. Legalese-heavy policies can actually be considered non-compliant. Your Etsy return policy and privacy policy should both prioritize clarity.
GPSR Compliance: The New EU Product Safety Rule
The General Product Safety Regulation (GPSR) took effect on December 13, 2024, and it introduces requirements that overlap with GDPR in important ways. While GPSR is primarily about product safety, it also requires sellers to provide personal contact information that must be handled in a GDPR-compliant manner.
GPSR Requirements for Etsy Sellers
- •Responsible person in the EU — non-EU sellers must designate an EU-based representative with a physical address
- •Product identification — clear labeling with manufacturer details, batch numbers where applicable
- •Safety documentation — warnings, instructions, and compliance declarations must accompany products
- •Etsy enforcement — Etsy has begun removing listings that lack GPSR compliance fields for EU-targeted sales
The GPSR and GDPR intersection matters because the “responsible person” details you provide become publicly accessible data. If you use a personal home address, that's personal data you're exposing. Many sellers use a registered agent or virtual office address to maintain compliance with both regulations. For more on shipping and logistics compliance, see our dedicated guide.
Handling Right to Deletion Requests
Under GDPR Article 17, EU customers have the “right to erasure”. If a customer contacts you and asks you to delete their personal data, you must respond within 30 days.
How to Handle a Deletion Request
- Acknowledge the request — reply confirming you received it and will process it within 30 days
- Identify all data you hold — check spreadsheets, email lists, shipping software, CRM tools, and any backups
- Delete the data — remove it from every system you control
- Note the exceptions — you may retain data required by law (tax records, legal disputes). Inform the customer of any data you can't delete and why
- Confirm completion — send a confirmation that their data has been erased
Important: you cannot delete data from Etsy's systems on behalf of a customer. If they want Etsy to delete their platform data, they need to contact Etsy directly. Your responsibility covers only the data you hold outside of Etsy's platform.
Marketing and Email Compliance
This is where most Etsy sellers unknowingly violate GDPR. Collecting customer emails from Etsy orders and adding them to marketing lists without explicit consent is illegal under GDPR.
Email Marketing Rules Under GDPR
- •Consent must be explicit — pre-checked boxes don't count. The customer must actively opt in
- •No purchased email lists — buying or scraping email lists of EU residents is a clear GDPR violation
- •Easy unsubscribe — every marketing email must include a one-click unsubscribe option
- •Record consent — keep a log of when and how each subscriber gave consent
- •Transactional emails are fine — order confirmations, shipping updates, and review requests related to a purchase don't require separate marketing consent
If you use Etsy's built-in “Send a coupon” feature to reach past buyers, Etsy handles the compliance aspects of that communication. But if you export emails to Mailchimp, Klaviyo, or any external tool for marketing, the GDPR responsibility shifts entirely to you.
Fines and Penalties
GDPR penalties are designed to be deterrents, and they scale based on severity:
GDPR Penalty Tiers
Lower tier — up to €10M or 2% of global annual revenue
For violations related to record-keeping failures, inadequate security measures, or failure to appoint a data protection officer when required.
Upper tier — up to €20M or 4% of global annual revenue
For violations related to data processing without lawful basis, failure to honor data subject rights, or unauthorized international data transfers.
Will a small Etsy seller realistically get fined €20 million? No. But data protection authorities across Europe have been issuing fines to small businesses and sole traders since 2022. In 2025, a German sole proprietor was fined €5,000 for sending marketing emails without consent. The amounts are smaller, but they're real.
Beyond fines, a GDPR complaint from a customer can trigger an investigation that consumes significant time and legal resources — something most Etsy sellers aren't prepared for.
Practical Steps for US Sellers Targeting the EU Market
If you're a US-based seller with EU customers, here's a concrete checklist to get compliant:
- Add a privacy policy to your Etsy shop — go to Shop Manager → Settings → Shop Policies → Privacy Policy
- Audit your data storage — identify every place you store customer data outside Etsy (spreadsheets, email tools, shipping apps, CRM)
- Stop adding order emails to marketing lists — unless customers explicitly opted in via a separate consent mechanism
- Set up a data deletion process — create a simple workflow for when deletion requests arrive
- Review third-party tools — ensure any tool processing customer data (Mailchimp, ShipStation, etc.) has GDPR-compliant data processing agreements
- Add GPSR information — if selling to the EU, add responsible person details to your listings
- Document everything — keep records of your data processing activities, consent logs, and any deletion requests handled
- Consider geo-blocking — if compliance feels overwhelming, you can restrict your Etsy shop from selling to EU countries via shipping profile settings
Most of these steps take less than an hour to implement. The hardest part is the ongoing discipline of not using customer data for marketing without consent — a habit many sellers have built over years of US-centric selling.
Stay Compliant Without the Guesswork
Unflagged scans your Etsy listings for policy violations, GPSR gaps, and compliance risks — so you can fix problems before they cost you your shop.
Start Your Free Compliance ScanFrequently Asked Questions
Does GDPR apply to Etsy sellers outside the EU?
Yes. GDPR applies to any business that processes personal data of EU residents, regardless of where the business is located. If you sell to customers in the EU, EEA, or UK, you must comply.
Is an Etsy seller a data controller or data processor?
Etsy sellers are independent data controllers for customer data they collect through their shops. Etsy acts as a separate data controller for its own platform-level processing. This means you have your own GDPR obligations independent of Etsy's.
Do I need a privacy policy for my Etsy shop?
Yes. Under GDPR, you must inform customers about what personal data you collect, why you collect it, how long you retain it, and their rights. Add a privacy notice in your Etsy Shop Policies section.
What is GPSR and does it affect Etsy sellers?
GPSR (General Product Safety Regulation) took effect December 2024. It requires products sold to EU consumers to have a responsible person in the EU, proper labeling, and safety documentation. Etsy has begun enforcing this by removing non-compliant listings.
How do I handle a GDPR deletion request?
Respond within 30 days. Delete customer data from all your personal records, spreadsheets, email lists, and external tools. The customer must contact Etsy separately for platform-level data. You may retain data required for legal obligations like tax records.
What are the penalties for GDPR non-compliance?
Fines can reach up to €20 million or 4% of annual global revenue, whichever is higher. While massive fines against small sellers are rare, data protection authorities have been issuing smaller fines to sole traders and small businesses for marketing violations and failure to honor deletion requests.