EU Withdrawal Button 2026
Disclaimer: This article is for informational purposes only and does not constitute legal advice. For jurisdiction-specific questions, consult an e-commerce lawyer familiar with EU consumer law.
From 19 June 2026, online shops selling to EU consumers need a withdrawal button.
What is the EU withdrawal button?
The EU withdrawal button is an electronic feature that online shops must provide so consumers can withdraw from a distance contract without friction.
Legally, it is called an electronic withdrawal function; in practice, retailers and developers call it the "withdrawal button". It has to be a:
- clearly labelled,
- prominently placed,
- always-available element
that makes a consumer right as easy to exercise as the action it reverses.
The principle is that the withdrawing from an online purchase should be no harder than concluding one.
A clear button, a two-step process, an automatic acknowledgement email - nothing more.
TL;DR
- Deadline: June 19, 2026. EU Directive 2023/2673 requires every online store selling to EU consumers to provide a clearly labeled, persistent electronic withdrawal function.
- This applies to you even if you're not EU-based. A store in the US, UK, or anywhere else shipping to EU consumers is in scope.
- Withdrawal ≠ return. These are two legally distinct things. Your existing returns flow does not automatically satisfy this requirement.
- The compliant flow is a two-step process: (1) identify the order + explicit withdrawal statement, (2) a second "Confirm withdrawal" button. A single-submit contact form doesn't cut it.
- You must send a timestamped email confirmation on a durable medium immediately after the consumer confirms.
- Non-compliance penalty: fines up to 4% of annual turnover in some member states, plus the consumer's withdrawal window extends from 14 days to 12 months and 14 days - for every affected shopper, individually.
- Reason fields are explicitly prohibited as mandatory. You cannot require a reason for withdrawal.
What's Changing - and What Isn't
EU consumers have had a 14-day cooling-off right for online purchases since the Consumer Rights Directive of 2011. Nothing about that underlying right is new.
What Directive (EU) 2023/2673 adds - by inserting Article 11a into the CRD - is a requirement around how that right must be made accessible. Instead of a clause buried in your T&Cs, consumers must be able to exercise their withdrawal right through a clearly visible, always-accessible digital function, in no more than two clicks, from the same interface where they bought.
The right existed. The UX around exercising it is now regulated.
Member states had until December 19, 2025 to transpose the directive into national law. Germany's implementation is §356a BGB (in force as of February 2026). Other member states have followed with similar transpositions. The EU-wide enforcement date is June 19, 2026.
Who Is in Scope
Three conditions must be met simultaneously:
- The contract is concluded through an online interface (website, web app, mobile app).
- The customer is a consumer (B2C - pure B2B operations are out of scope).
- At least one product or service in the catalog is subject to a right of withdrawal.
Crucially: your business location doesn't matter. Any non-EU store that directs commercial activity at EU consumers - EUR pricing, EU-language content, EU-targeting ads, EU shipping - is subject to this rule. A Shopify store in Ohio shipping to Germany is on the hook the same as a German store.
What's Exempt
Some product types are outside the right of withdrawal under Article 16 of the CRD, and therefore outside the button requirement for those specific items: custom-made goods, perishables, opened hygiene products, certain sealed digital products, and others. Exemptions are technical and can vary by member state - if a meaningful portion of your catalog might qualify, verify with legal counsel rather than guessing.
Withdrawal vs. Return: The Critical Distinction
This is the part most developers and platform setups get wrong, because returns infrastructure already exists and it's tempting to treat this as a minor label change.
It isn't. The directive explicitly requires that consumers can tell the two apart, and both must remain clearly identifiable.
| Right of Withdrawal | Commercial Return | |
|---|---|---|
| Legal basis | EU law (CRD / Directive 2023/2673) | Retailer's own policy |
| Who sets the rules | EU legislature | You |
| Time window | 14 days from delivery (day after) | Whatever your policy says |
| Reason required | No - explicitly forbidden as mandatory | Depends on your policy |
| Refund scope | Full price + standard delivery costs | Per your policy |
| Applies to | Any B2C distance contract (with exceptions) | Only what your policy covers |
A few practical consequences of this distinction:
- Labels matter. "Return", "Get a refund", "Cancel order" - none of these qualify on their own as the withdrawal entry point. The label must be unambiguous: "Withdraw from contract" or a direct national-language equivalent ("Vertrag widerrufen", "Résilier le contrat", etc.).
- Retention flows cannot obstruct withdrawal. You're allowed to make a retention offer, but only after withdrawal is complete and confirmed. "Are you sure?" screens, discount pop-ups in the withdrawal path, or any friction that steers users away from completing withdrawal is non-compliant.
- Reason fields must be optional. Requiring a reason explicitly hinders withdrawal and is prohibited.
You can combine withdrawal and return into a single flow - but only if withdrawal remains a clearly labeled, unobstructed step within it.
What a Compliant Flow Looks Like
Strip the directive down to its operational requirements and you get four mandatory pieces.
1. Persistent Entry Point
A button or link labeled "Withdraw from contract" (or an equivalent unambiguous label in the relevant language) that is:
- Accessible from the same online interface where the purchase was made
- Continuously available throughout the entire 14-day withdrawal window
- Reachable without requiring a customer account login
- Prominently placed - footer, main navigation, order confirmation email, or a dedicated withdrawal page linked from a visible position
2. Order Identification + Withdrawal Statement (Step 1)
After clicking the entry point, the consumer must be able to:
- Identify the contract or order being withdrawn (order number, auto-filled if possible)
- Provide their name and a contact email for the confirmation
- Submit an explicit withdrawal statement
The only fields that may be mandatory are: name, order/contract identifier, and contact email. Any additional mandatory field - especially a withdrawal reason - is non-compliant. Optional fields are fine.
3. Confirmation Button (Step 2)
A second button labeled "Confirm withdrawal" (or equivalent) that constitutes the legally valid submission. This two-step separation is one of the most commonly missed requirements in DIY implementations. A single-submit contact form does not satisfy Article 11a paragraphs 2 and 3.
4. Timestamped Acknowledgement on a Durable Medium
Immediately after the consumer activates the confirmation button, you must automatically send an email containing:
- The content of the withdrawal declaration (name, order reference, contact email)
- The date and time the declaration was received
The acknowledgement confirms receipt, not validity. Phrases like "Your withdrawal has been accepted" are legally problematic. The correct framing is closer to: "We received your withdrawal declaration on [date] at [time]."
Once the consumer activates the confirmation function before the deadline, the withdrawal is deemed timely - even if your system processes it later.
Conditions
The 14-Day Clock: When It Starts, When It Extends
For physical goods, the 14-day window starts the day after the consumer takes physical possession. For split deliveries within one order, the clock starts after the last item arrives.
Consumers can also withdraw before delivery - the right exists from the moment the contract is concluded. If they withdraw while the package is in transit, you're still obliged to process the withdrawal and refund. You're not legally required to intercept the shipment, but the refund obligation stands once goods are returned.
The 12-month extension: If your withdrawal function is missing, non-compliant, or hard to find, the 14-day window doesn't start for affected consumers. It extends to 12 months and 14 days from delivery - and this happens individually per shopper, not as a blanket policy. Each consumer's clock starts only when you provide a compliant function (or after 12 months, whichever comes first).
This is the most commercially damaging consequence of non-compliance, and it's not hypothetical. Consumer protection associations across the EU are expected to monitor rollout actively and pursue non-compliant stores through warnings, injunctions, and Representative Actions (Directive (EU) 2020/1828).
What Else Needs Updating
The button itself is not the only required change:
Withdrawal policy / pre-contractual information: Your existing withdrawal instructions must reference the new online withdrawal function and its location. Failure to update this is itself a compliance gap that can extend the withdrawal period.
Privacy policy: The withdrawal form processes personal data (name, email, order reference). Your privacy notice must cover this processing activity - purpose, legal basis (Art. 6(1)(c) GDPR: legal obligation), and retention period.
Checkout / pre-purchase information: Consumers must be informed about the existence and location of the withdrawal function before they complete a purchase - for example in the checkout flow or pre-contractual information screen.
Risks of Non-Compliance
Three stacked risks apply simultaneously:
- Warnings and injunctions from competitors, consumer associations, or national enforcement bodies - typically several hundred to several thousand euros per case plus mandatory cease-and-desist undertakings.
- Administrative fines - up to 50,000 EUR for smaller breaches; up to 4% of annual turnover for widespread infringements with an EU dimension. Calculated on turnover, not profit.
- Extended withdrawal window of up to 12 months and 14 days per affected consumer - commercially the most severe exposure, as every consumer affected during the non-compliant period individually retains this extended right.
Implementation on Vanilo Cloud
Vanilo provides built-in support for the EU withdrawal flow. Here's how to set it up:
Add this snippet to the resources/views/account/order.blade.php file:
@if(!$order->status->is_withdrawn && $order->ordered_at->diffInDays() < 14)
{!! Form::model($order, ['route' => ['shop.account.order.update', $order], 'method' => 'PATCH']) !!}
{{ Form::hidden('status', 'withdrawn') }}
@csrf
<button type="submit">{{ __('Withdraw') }}</button>
{!! Form::close() !!}
@endif
Checklist Before June 19
☐ Withdrawal entry point is present, labeled correctly, and accessible without login
☐ Consumers are informed about the withdrawal function before purchase (checkout / pre-contractual info)
☐ The flow uses two distinct steps with a separate "Confirm withdrawal" button
☐ No mandatory reason field in the withdrawal form
☐ Timestamped confirmation email sends automatically on submission
☐ Confirmation email wording confirms receipt, not acceptance
☐ Withdrawal function is distinct from (or clearly labeled within) your returns flow
☐ No retention pop-ups or friction in the withdrawal path
☐ Withdrawal policy updated to reference the online function
☐ Privacy policy updated to cover withdrawal form data processing
☐ Exempt products verified with legal counsel if applicable