Whether you run a shop, a blog or a company website – there are legal documents that must be in place. For a WooCommerce store, the list is slightly longer than for a simple website. And this is not about bureaucratic formalities – it is about real legal protection that kicks in when something goes wrong.
Contents
What documents are required in 2026 to launch an online store?
Show me your terms and conditions. That sentence – spoken by a customer, a regulator or a lawyer on the other side of a dispute – can cause panic for an unprepared store owner. If your terms are current and correct, you are protected. If you do not have them or they are outdated, the problems are just beginning.
1. Privacy Policy – mandatory for every website
A privacy policy explains to users what happens with their personal data. It is required for every website without exception. If you collect email addresses, use cookies, process contact form submissions or fulfil orders – you are processing personal data.
Your privacy policy must include: who is the data controller, what data you collect and why, how long you retain it, who you share it with and what rights the user has. A privacy policy copied from another website or generated by a generic tool without customisation is almost the same as having none at all. The document must reflect how you actually process data.
2. Terms and Conditions – mandatory for every online store
Terms and conditions are mandatory for every e-commerce operation. They cover purchase conditions: pricing, payment, delivery, the right to cancel and the complaints procedure.
Consumer law requires you to provide this information to the customer before the contract is concluded. If you do not, the customer may cancel the purchase within an extended window – up to 12 months from purchase in some jurisdictions. Terms and conditions protect you, not just the customer. They are your defensive document in every dispute.
Your terms must be permanently accessible on your site – meaning the customer can download and save them before placing an order. A link in the footer is the minimum. An increasingly common best practice is also to attach a PDF to the order confirmation email.
3. Review Policy – mandatory if you display reviews
A review policy explains where the reviews on your site come from, whether they are verified and what criteria determine which reviews are published. Since the Omnibus Directive came into force in 2023, displaying reviews without disclosing their source and verification method is non-compliant.
The Omnibus Directive requires that consumers know whether the reviews on a store site are authentic. If you have no verification system, you must say so. If you do have verification, you must describe how it works. A review policy applies to you if you collect reviews directly on your site, import them from Google or other platforms, or use a post-purchase review collection system.
What else should you have?
Beyond the three mandatory documents, you should also have a cookie policy and appropriate marketing consent mechanisms. The cookie policy is sometimes part of the privacy policy and sometimes a separate document – what matters is that it is current and reflects the tools you actually use.
How do you keep your documentation up to date?
E-commerce law changes regularly. The Omnibus Directive, Right to Repair, evolving GDPR interpretations – each change may require updates to your documents. A privacy policy written three years ago may no longer be compliant. A well-running WooCommerce store is not just correct technical configuration but also current legal documentation. Both layers need to be maintained continuously.
Something is coming – stay tuned
We are building a tool that takes care of your store's legal documentation automatically – tailored to your business, always up to date with the law. Stay tuned.

