Helpful information ...
Legally compliant online store in Slovenia: what you need to arrange
A Legally Compliant Online Store in Slovenia: What You Need to Sort Out
A legally compliant online store in Slovenia means that all legally required information under the Consumer Protection Act (ZVPot-1), the Electronic Commerce Market Act (ZEPT), and GDPR/the Personal Data Protection Act (ZVOP-2) is clearly visible before an order is placed, and that processes such as checkout, order confirmation, and data processing agreements are technically implemented and provable. Compliance isn't a list of documents — it's a process built into the user journey. You need legal counsel when you sell abroad, process sensitive data, or build a loyalty club.
In short:
- If an online store doesn't meet every legal requirement, the withdrawal period can extend to as long as one year, increasing the risk of returns.
- Before an order is placed, the store needs to clearly display the final price including taxes and costs, and require explicit consent to pay.
- For personal data protection, cookie consent is mandatory, along with written agreements with external providers, and incidents must be reported within 72 hours.
- Legal requirements are best built into the planning phase, to avoid expensive fixes after launch.
- Compliance means processes built comprehensively into the whole system, not just a document checklist, and it's key to passing an inspection.
Table of Contents
- Which Laws Govern a Legally Compliant Store in Slovenia?
- What Needs to Be in Checkout Before an Order Is Placed?
- How to Protect Personal Data and Meet GDPR/ZVOP-2 Requirements?
- How to Implement Compliance Step by Step for a New or Redesigned Store?
- Why Compliance Built Into the Design Saves Time
- Build an Online Store That's Compliant From Day One
- Sources
- Frequently Asked Questions
Which Laws Govern a Legally Compliant Store in Slovenia?
Every online store in Slovenia touches on at least six legal frameworks, not just one. The Market Inspectorate's guide states that an online store needs to comply with ZVPot-1, ZEPT, GDPR/ZVOP-2, the Tax Procedure Act (ZDavPR), and the Public Use of the Slovenian Language Act (ZJRS) — together more than 8 related regulations. Each addresses a different issue, so it's worth looking at them individually.
- ZVPot-1 (the Consumer Protection Act) defines what information a consumer must receive before purchasing: price, characteristics of the goods, the right of withdrawal, and complaint procedures.
- ZEPT (the Electronic Commerce Market Act) requires easy, permanent access to information about the provider, clear price labeling, and technical procedures for concluding a contract electronically.
- GDPR and ZVOP-2 govern the processing of personal data, from cookies to incident reporting.
- ZDavPR sets the rules for tax verification of invoices, which also applies to invoices issued online.
- ZJRS (the Public Use of the Slovenian Language Act) requires that all sales to consumers in Slovenia be available in Slovenian, including terms of business and withdrawal notices.
- ZIsRPS governs out-of-court dispute resolution, which must be mentioned in the terms of business with a link to the dispute resolution platform.
Concretely, this means a store needs to display company information and price on the product page, a withdrawal notice and complaint procedure in the terms of business, a Slovenian-language version of every page a customer sees, and a link to the out-of-court dispute resolution body in the footer or in the terms. Each of these elements is checked separately, which is why superficially copying a foreign template almost always leaves a gap.
What Needs to Be in Checkout Before an Order Is Placed?
The order process is where compliance is actually tested — not in the terms of business, which hardly anyone reads. SPOT states that before placing an order, a consumer needs to be informed of the final price including taxes and delivery costs, the characteristics of the goods, and the right of withdrawal.
- Display the final price including VAT and delivery costs before the customer confirms their purchase, not only on the confirmation page.
- Include an explicit statement about the payment obligation, for example a button reading "order with obligation to pay," and send an order confirmation immediately after submission.
- Clearly state the right of withdrawal (14 days from receiving the goods) and who covers return shipping costs if the customer withdraws.
- Store the text of the contract and let the customer retrieve it again at any time, which ZEPT explicitly requires.
- Build in a technical way to correct errors before submitting the order — for example, the ability to edit the cart before the customer confirms payment.
If a store doesn't properly inform customers about the right of withdrawal, the deadline doesn't expire after 14 days — it extends to one year. This is one of the most costly mistakes we see in redesigns of existing stores.
Expert tip: Keep a provable version of your terms of business that was in effect on the day of purchase, not just the latest published version. In the event of a dispute, you'll need to prove what the customer actually saw.
How to Protect Personal Data and Meet GDPR/ZVOP-2 Requirements?
Data protection isn't just a legal matter — it's a security one too. When processing personal data, a merchant needs to follow GDPR and ZVOP-2, with a clear rule for response time.
- Cookies and analytics: prior consent is mandatory for all cookies except essential ones, along with a clear notice about the controller and the purpose of processing.
- Data processing agreements: you need a written agreement with external providers (hosting, payment system, email service) that defines the purpose, scope, and duration of processing.
- Breach reporting: an incident needs to be reported to the Information Commissioner within 72 hours, as required under Articles 33 and 34 of the GDPR.
- Technical measures: TLS/HTTPS across the entire site, regular backups, restricted access to the admin panel, and audit logs of access.
72 hours is the time you have to report a data breach, starting from when your business became aware of the incident, not from when the incident occurred. For more extensive processing, such as a loyalty club or customer profiling, it's also worth considering a data protection impact assessment and appointing a data protection officer. You can find a more detailed explanation of consent rules in this guide to GDPR in an online environment.
How to Implement Compliance Step by Step for a New or Redesigned Store?
Compliance is easiest to build in when you break it into phases, rather than treating it as one big project right before launch.
- Phase 0, preparation: check your registered business activities (online retail requires proper registration and technical conditions), define the language of the site and the scope of sales (Slovenia only, or the EU as well).
- Phase 1, content and documentation: prepare terms of business, a withdrawal notice, and a complaint procedure in Slovenian, with provable versions for each publication date.
- Phase 2, technical implementation: build checkout with explicit payment confirmation, storage of the contract text, cookie consent, and data processing agreements with hosting and payment providers.
- Phase 3, testing: walk through the entire order process as a customer, prepare internal staff instructions, and documentation you can present during a potential inspection.
For priorities, a rough timeline applies: in the first few weeks, sort out legal documentation and registrations, then implement the technical requirements for checkout and data protection within a reasonable timeframe, and later finish testing and train staff on handling complaints and withdrawals.
Expert tip: Don't wait until the site launches to check compliance. Include legal requirements in your project spec from the very first meeting with your developer, since fixing checkout later is more expensive than building it in from the start.
You can find a detailed technical checklist for a redesign in this guide to redesigning an online store, and for feature requirements, in this list of required online store features.
Why Compliance Built Into the Design Saves Time

The most common mistake we see during redesigns is copying terms of business from a competitor. The text almost never matches the business's actual offering, and checkout often lacks explicit payment confirmation or storage of the contract text. Compliance isn't a collection of documents — it's a process built into the user journey, and that's exactly what separates a store that passes an inspection from one that doesn't.
At Moxy-web, we build legal requirements into the site structure planning phase, not just before launch. That means checkout, cookie consent, and contract storage aren't after-the-fact fixes — they're part of the store's core architecture. What works best is collaboration between three roles on the same project: a lawyer who knows ZVPot-1 and GDPR, a developer who can technically implement the requirements, and a designer who makes sure the information is visible, not hidden in fine print.
— Ziga
Build an Online Store That's Compliant From Day One
During a redesign or a new store build, it's exactly the details an inspection checks first that are easiest to overlook: checkout, cookie consent, the language of the site. Moxy-web builds these requirements into the project at the design stage, so you're not paying for extra fixes after launch, as often happens with templates purchased without adapting them to Slovenian law. Our offering covers building online stores, hosting, GDPR preparation, and ongoing maintenance, all under one contract and one point of contact.

If you're considering a new store or redesigning an existing one, check out the offering at Moxy-web and request an initial conversation about your project. In that conversation, we review your scope of sales, the current state of your checkout, and what needs to be added before we put the site live.
Sources
- A Guide to Regulations for Online Stores | SPOT
- The Electronic Commerce Market Act (ZEPT) — summarized
Frequently Asked Questions
What does a legally compliant online store in Slovenia mean?
It means a store that shows consumers all legally required information under ZVPot-1, ZEPT, and GDPR/ZVOP-2 before an order is placed, and has technically provable processes, such as explicit payment confirmation.
What happens if a store doesn't inform customers about the right of withdrawal?
The withdrawal period extends from 14 days to one year, significantly increasing the business's exposure to potential returns.
How quickly does a data breach need to be reported?
An incident needs to be reported to the Information Commissioner within 72 hours from the moment the business becomes aware of it, as required under Articles 33 and 34 of the GDPR.
Does an online store in Slovenia need to be in Slovenian?
Yes, ZJRS requires that sales to consumers in Slovenia be available in Slovenian, including the terms of business, withdrawal notices, and checkout.
Who can help build legal requirements into an online store?
Moxy-web builds legal and technical requirements into the store planning phase, from checkout to cookie consent, reducing the risk of gaps that would otherwise need fixing later.
Recommended