← All posts Insights 10 min read

EU GPSR Enforcement in 2026: What WooCommerce and Shopify Exporters Must Add to Every Product Page

EU GPSR has been enforceable since December 2024. What WooCommerce and Shopify exporters must add to every product page in 2026 — and the NetSuite mapping.

EU GPSR product page requirements for WooCommerce and Shopify sellers
Quick Summary

EU GPSR Compliance for WooCommerce and Shopify Exporters

  • GPSR (Regulation (EU) 2023/988) became mandatory 13 December 2024 and applies to every product sold to an EU consumer, regardless of where the seller is based.
  • Two different articles apply, and most guides only cover one: Article 9 governs what the manufacturer puts on the physical product; Article 19 separately requires the online listing itself to show manufacturer, identification, and warning information before the customer can buy.
  • The Commission’s own interpretive Guidelines — mandated by Article 17(2), published 19 November 2025 — clarify what counts as an “electronic address” and narrow the Article 20 accident-reporting duty to death or serious harm.
  • WooCommerce has no native GPSR field; Shopify ships one, a “Disclosures” product metafield built for exactly this. Neither platform provides an EU Responsible Person for you — that is a role you appoint separately.
Dec 13, 2024
GPSR became directly applicable EU-wide — a Regulation, not a Directive, so no national transposition step
Art. 19
The GPSR article governing what an online listing must show before purchase — distinct from Article 9’s physical-product duties
Nov 19, 2025
Date the Commission published its Article 17(2) Guidelines (C(2025) 7699 final), clarifying scope for online sellers
2 portals
Safety Gate (public recall alerts) and the Safety Business Gateway (mandatory Article 20 notifications) are separate EU systems

The EU General Product Safety Regulation (GPSR — Regulation (EU) 2023/988) replaced the General Product Safety Directive and became mandatory on 13 December 2024. It applies to every product sold to an EU consumer, whether the seller is based in the EU or not. Most compliance write-ups stop at “add manufacturer and safety info to the page” and treat WooCommerce and Shopify as interchangeable. They are not: WooCommerce has no native compliance field at all, and Shopify ships one — a metafield built for exactly this purpose — that most guides never mention. This piece specifies the two GPSR articles actually in play, what the Commission’s November 2025 guidelines changed in practice, and the concrete implementation for both platforms.

GPSR splits into two duties, and most guides only cover one

Article 9 covers the manufacturer’s own duties: identify the product with a type, batch, or serial number, put your name and contact address on the product or its packaging, and keep technical documentation on file. That duty attaches to the physical product. Article 19 is separate and attaches to the listing: it introduces additional information obligations that apply to every individual product offer made in distance selling, and it requires that information to appear on the online interface itself, before the sale — not only in an accompanying document or on packaging the buyer sees after the parcel arrives.

The practical consequence: a product can satisfy Article 9 — batch number printed on the box — and the same listing can still fail Article 19 if the manufacturer, identification, and warning information is not also rendered on the product page the shopper sees before checkout. A store that only labels its packaging is compliant with the manufacturer’s physical-product duty and non-compliant with the distance-selling duty at the same time. Every WooCommerce and Shopify implementation below is built to satisfy Article 19 specifically, because that is the article a hosted online store actually controls.

GPSR is not the only EU compliance deadline WooCommerce and Shopify stores are tracking this year — see the three PCI DSS 4.0.1 audit findings hitting stores in 2026 and the EU AI Act documents small businesses needed for the others on the list. The full compliance picture for store operators is covered in the WooCommerce store operations guide.

Required information per product page

Required field What it must contain Where to display
Responsible person (EU) Name and postal address of an entity established in the EU who can be contacted about the product Product page, visible before purchase
Manufacturer information Manufacturer’s name, registered trade name, and postal address Product page (Art. 19) — packaging alone is not sufficient
Product identification Type, batch number, serial number, or model number — anything that uniquely identifies the specific product, plus a picture On the product page listing
Safety warnings Any warnings required for safe use — especially for products aimed at children or with hazard components Clearly visible on the product page
Electronic address An email address, or a specific, easy-to-find section of the seller’s own website that lets a consumer make direct contact Product page or a linked contact page that meets that bar

The November 2025 Commission Guidelines changed three practical answers

GPSR’s Article 17(2) obliged the Commission to issue interpretive guidance for businesses, particularly small and micro-enterprises. It did, on 19 November 2025, as Commission Notice C(2025) 7699 final — nearly a year after the regulation itself took effect, and after most of the existing GPSR compliance content on the web was written. Three clarifications matter directly to a WooCommerce or Shopify store:

1
“Electronic address” is broader than an inbox

The Guidelines define it as an email address or a specific section of the company’s website that lets a consumer contact it directly and easily. A properly scoped contact page can satisfy this field — it does not have to be a dedicated compliance mailbox.

2
Accident reporting has a severity floor

Article 20 requires manufacturers to report accidents through the Safety Business Gateway. The Guidelines clarify that only accidents causing death or serious adverse health effects trigger the duty — a minor, temporary issue does not.

3
Old conformity work still counts

Products that already met harmonised standards carried over from the previous Directive (GPSD) keep a presumption of conformity under GPSR. Sellers do not need to re-run a conformity assessment from zero for unchanged products.

None of this changes what has to appear on the product page — Article 19 is unchanged. It changes how strictly two adjacent duties (the contact channel, and accident reporting) are read, which matters when deciding how much engineering effort a small catalog needs to spend beyond the product page itself.

Implementation for WooCommerce

1
Add GPSR custom fields to products

Use WooCommerce custom product fields, ACF, or one of the compliance plugins available on WordPress.org to add: gpsr_responsible_person, gpsr_manufacturer, gpsr_product_id, gpsr_safety_warnings, gpsr_safety_url. For large catalogs, add the same fields to the NetSuite item record and sync them to WooCommerce so the ERP stays the single source of truth — the same pattern that keeps NetSuite tax compliance from drifting out of sync with the storefront.

2
Display conditionally for EU customers

Detect EU shipping addresses at checkout. If the ship-to country is an EU member state, render the GPSR fields in the product description or a dedicated tab. Non-EU customers do not require these fields, though rendering them for everyone is the simpler build if your catalog is EU-only anyway.

3
Appoint an EU Responsible Person if needed

If you have no entity in the EU, GPSR requires a third-party EU Authorised Representative. Several firms across the EU offer this as a paid annual service; pricing varies by SKU count and product risk category, so get quotes rather than budgeting a placeholder figure. Their contact details go in the gpsr_responsible_person field.

4
Update product export feeds

If you also list on EU marketplaces (Amazon.de, Otto, Bol.com), their product feeds now require GPSR fields independently of your own store. Make sure your WooCommerce-to-marketplace sync carries these fields, not just price and stock.

Implementation for Shopify

Shopify’s own help documentation is explicit that it does not offer EU Responsible Person designation as a built-in service — merchants are pointed to the App Store for that. But for the safety and warning text itself, Shopify ships a purpose-built mechanism that most GPSR guides skip entirely: the Disclosures product metafield and metaobject.

1
Use the Disclosures metafield for warnings

Shopify recommends the Disclosures product metafield and metaobject entries specifically for legally required product warnings — it exists for this. Populate it per product rather than pasting warning text into the description field.

2
Cover manufacturer and identification data separately

Disclosures is scoped to warnings. Manufacturer name/address, the responsible person, and product identification need their own metafields or a structured block in the product description — Shopify does not restrict where the rest of the Article 19 information lives, only recommends the one purpose-built field for warnings.

3
Scope display to EU buyers with Markets

Stores running Shopify Markets can localize product-page content by market, which is the native way to show GPSR fields only to EU-bound orders. Stores on a single default market have no built-in per-region product-page conditional — the honest option there is to show the fields to everyone, the same trade-off WooCommerce stores face without checkout-based detection.

4
Appoint the EU Responsible Person the same way

Since Shopify has no native field for this role, the WooCommerce approach applies unchanged: appoint a third-party EU Authorised Representative and place their contact details in the metafield built in step 2.

Enforcement runs through three separate channels

GPSR non-compliance does not surface through one mechanism. Three run independently, and a store can trip any of them without the others noticing.

RiskMarketplace delisting:

Amazon EU began requiring GPSR information in product listings from December 2024. Non-compliant listings are suppressed in search and can be delisted — immediate revenue impact, not a theoretical future risk.

RiskCustoms, at the border:

GPSR applies specific provisions of Regulation (EU) 2019/1020 on market surveillance — including its external-border-controls article — to GPSR-covered products. Customs authorities inspect shipments alongside market surveillance bodies, and goods missing traceability information or a responsible person can be stopped before they clear the EU border, independently of whatever your product page says.

The third channel is the one most WooCommerce and Shopify guides conflate: the Safety Gate and the Safety Business Gateway are different systems with different audiences.

Safety Gate Safety Business Gateway
Audience The public — consumers, press, market surveillance authorities Businesses — manufacturers, importers, distributors, online marketplaces
Purpose Publishes rapid alerts about dangerous products already found on the market Mandatory channel for the notifications Articles 9, 10, 11, 12, 20, and 22 require from economic operators
What triggers it A product a national authority has assessed as dangerous An accident causing death or serious harm (Art. 20), or a business’s own discovery that a product it sold is dangerous

A store that only monitors the public Safety Gate for its own products is watching the wrong system for its own reporting duty — that duty runs through the Business Gateway, and it is the seller’s to initiate, not something that happens automatically once a product ships.

Syncing GPSR fields from NetSuite to your storefront?

An ecommerce sync audit checks whether the fields your product pages need — GPSR, tax, compliance — are actually propagating from the ERP record, not just price and stock.

See what an ecommerce sync audit covers →

Get the working checklists

The runbooks and decision checklists from these guides, as printable PDFs — free in the SoftXone guide library.

Browse the guide library →

Sources & Further Reading

References

  1. EU GPSR — Regulation (EU) 2023/988EUR-Lex — full text of the General Product Safety Regulation, the primary legal source.
  2. Commission Notice C(2025) 7699 final — GPSR GuidelinesEUR-Lex — Official Journal publication of the Commission’s Article 17(2) interpretive guidelines, 19 November 2025.
  3. European Commission — GPSR FactsheetEuropean Commission, Justice and Consumers — official summary of scope and obligations.
  4. Shopify Help Center: Understanding GPSRShopify — official guidance, including the Disclosures metafield mechanism.
  5. Amazon Seller Central: GPSR RequirementsAmazon — marketplace-specific GPSR implementation requirements for EU listings.

Frequently asked questions

What must appear on every EU product page?

Manufacturer identity and contact details, product identification, safety warnings, and an electronic address for contact — all on the listing itself, under Article 19, before the customer buys. Packaging alone does not satisfy this.

Does GPSR apply if I only ship occasionally to the EU?

Selling into the EU market triggers it, not order volume. A single sale to an EU consumer brings the same product-page obligations as a store shipping thousands of units.

How do I implement this in WooCommerce?

Through structured product fields — custom fields, ACF, or a compliance plugin — rendered consistently on every product template, rather than free text added per product. Large catalogs sync the same fields from the NetSuite item record.

How is this different for Shopify vs WooCommerce?

Shopify ships a purpose-built Disclosures product metafield for the warning and safety text; WooCommerce has no native equivalent, so stores add custom fields themselves. Neither platform provides the EU Responsible Person role — that is a service appointed separately on both.

Do the November 2025 Commission guidelines change what I need to display?

No — the Article 19 disclosure duty is unchanged. The guidelines clarify definitions, including that an electronic address can be a website contact section rather than only an email inbox, and they narrow the Article 20 accident-reporting duty to incidents causing death or serious harm.

Related guides

Discussion

Leave a Reply

Your email address will not be published. Required fields are marked *


Ship it

Need this in your stack?

We build, integrate, and ship — no calls, just delivery.

Start a project →