EU withdrawal button for guest orders: what the law actually requires
What Directive (EU) 2023/2673 and § 356a BGB require for an EU withdrawal button, and why that means guest checkout too, checked against the primary legal text.
Also available in Deutsch
Coming soon to the Shopify App Store
Short answer: since 19 June 2026, Directive (EU) 2023/2673 requires EU member states to make online sellers who sell to EU consumers add a "withdrawal function" to their site itself — a labelled button, a separate confirmation step, and an acknowledgement of receipt. What actually binds a given shop is that country's own transposing law, not the directive text directly; see "Scope" below for what we could verify country by country. The statute doesn't mention customer accounts anywhere. If the only way to cancel an order is a feature that requires signing in first, a guest buyer — someone who checked out without creating an account — has no way to reach it.
This is general information, not legal advice, and it isn't a substitute for advice from a lawyer qualified in your market.
If you're only finding out about this now, or you're new to selling into the EU, this is what to check and what the text actually says, not a countdown to panic about. The application date (19 June 2026) has already passed; this is about closing a real gap, not beating a deadline.
What Article 11a actually requires
Article 11a was inserted into Directive 2011/83/EU (the Consumer Rights Directive) by Directive (EU) 2023/2673, as a general provision — Article 11a(1) itself applies to "distance contracts concluded by the means of an online interface," with no financial-services qualifier. Recital 37 makes the scope explicit: "Therefore, this obligation should be laid down not only for distance contracts for financial services, but also for distance contracts for other goods and services where Union law provides for a right of withdrawal" — ordinary goods and services sold online, not just financial products. We fetched and read the article and recital text directly on EUR-Lex (CELEX:32023L2673, checked 2026-09-25). In summary, the operative article requires:
- A withdrawal function, labelled "withdraw from contract here" or "an unambiguous corresponding formulation," continuously available for the whole withdrawal period, prominently displayed and easily accessible.
- Three pieces of information the buyer can provide or confirm: their name, details identifying the contract they're withdrawing from, and where to send the acknowledgement. (Recital 37 separately notes a trader can let a buyer withdraw from only part of a multi-item order rather than all of it; Germany's § 356a BGB makes that explicit as part of this same requirement — see below.)
- A separate confirmation step, labelled only "confirm withdrawal" or an unambiguous equivalent — our reading of "only with the words" is that this rules out combining it with other text or swapping it for an icon.
- An acknowledgement of receipt, on a durable medium (an email, for instance), without undue delay, including the content of the declaration and, in the directive's own English wording, "the date and time of its submission."
Germany transposed this as § 356a of the Civil Code (BGB), in force from the same date, 19 June 2026 (Noerr, "Umsetzungsgesetz zum Widerrufsbutton veröffentlicht", checked 2026-09-25). We fetched and quoted § 356a verbatim from gesetze-im-internet.de (legal/withdrawal_texts.md §1, checked 2026-09-24). Both buttons are worded to match the directive exactly: "Vertrag widerrufen" ("withdraw from contract") and "Widerruf bestätigen" ("confirm withdrawal"), and § 356a Abs. 2 Nr. 2 BGB adds "or the part of it" explicitly, for a multi-item order. One genuine wrinkle worth knowing if you're implementing this yourself: the directive's own English text says the acknowledgement must show "the date and time of its submission" (quoted above) — but the directive's own German text, and § 356a BGB which follows it, both say "Eingang": receipt, not submission. That's a difference between the directive's own language versions, not an extra requirement Germany invented. If you're building this for Germany, the receipt timestamp is the one that matters.
Why "sign in first" doesn't clear the bar for guest orders
Article 11a's own text doesn't require or even mention customer accounts, logins or registration anywhere. Recital 37 goes further and describes logging in as just one optional way a buyer might already be identified, not a requirement: "a consumer who has already identified himself or herself, for example by logging in, should be able to withdraw from the contract without the necessity of providing once more their identification." What the operative article requires is that the function be "continuously available" and "easily accessible to the consumer" for the whole withdrawal period.
Shopify's own help center sets out how to enable self-serve returns — the closest native mechanism to a withdrawal function — and its requirements section instructs merchants to "Give customers access to sign in to customer accounts" (Shopify Help: Setting up self-serve returns and cancellations, checked 2026-09-25). No separate no-login path is described for that feature. A buyer who checked out as a guest has no account to sign in to, so a function gated behind sign-in isn't "easily accessible" to that buyer, under a plain reading of the recital and the statute together with the help page. This is our reading, not a quote from a regulator or a court, and it isn't legal advice.
What "guest-compatible" means in practice
In practice, it means the form asks for what the statute actually requires and nothing that depends on being signed in:
- Full name
- Order number
- Email address (where the acknowledgement gets sent)
- Which items the buyer is withdrawing from (all pre-selected, in our reading, is a reasonable default; the statute doesn't ask for a reason)
No password, no account creation, no sign-in wall. Name, order number and email cover Article 11a(2)'s own three items; item selection covers what § 356a Abs. 2 Nr. 2 BGB spells out explicitly (identifying "the contract or the part of it") and what Recital 37 describes as an option the trader can offer. Asking for less — say, skipping which items are involved — wouldn't identify what's being withdrawn from, under either reading.
A withdrawal isn't the same thing as a return or an exchange
These get talked about together because they usually land in the same inbox, but they're legally different things:
- A withdrawal is a cancellation right created by consumer-protection law. The buyer is undoing the contract itself, within a statutory window, no reason required.
- A return or exchange request is commercial policy the merchant sets: a window, conditions, and whether store credit or a different size is offered instead of a refund.
Where national law requires a withdrawal function, that requirement exists regardless of what a store's return policy says. A return policy can be more generous than the legal minimum, but it isn't a substitute for the withdrawal function itself, in a market where the function is required.
What this article isn't claiming
Several Shopify apps already offer some form of withdrawal button, and a few returns apps bundle one into a paid tier. This isn't a "we're the only one" pitch, and it isn't a claim that installing any app makes a store compliant — no software can make that promise on its own. A store's own return and withdrawal policies, how its checkout is actually configured, and whether the rest of the store matches what it tells buyers all still matter, and none of that is something an app does automatically. Nothing on this page is legal advice; talk to a lawyer qualified in your market before relying on it.
Where Comeback fits
Comeback, an app we're building for Shopify stores, is designed to include a no-login withdrawal form free on every plan, unlimited, because, where the rule applies, it's a legal obligation, not a premium feature. It isn't available yet: Comeback is still in development. For the detail on how that specific form is designed to work once it ships, see the EU withdrawal explainer.
Scope: which countries, as of the check date
A directive binds EU member states to legislate; it doesn't bind a shop directly. What applies to a given shop is that country's own transposing law, once it's actually enacted. The 19 June 2026 application date has passed EU-wide, but we've only checked national transposition status for six of the 27 member states so far: Germany (§ 356a BGB, quoted throughout this article, verified in full) plus a spot-check of France, Italy, Spain, Poland and the Netherlands, and that spot-check (against EUR-Lex's list of notified national measures, checked 2026-09-25) found real gaps — no measure notified for Spain or Poland as of that date, and for France, Italy and the Netherlands a notified measure exists but we couldn't confirm it covers the general, non-financial-services withdrawal-button rule specifically rather than only the directive's financial-services provisions (see legal/withdrawal_labels_eu.md §6 for the detail). Austria has its own transposition of the same directive, which we haven't independently verified here, and we haven't checked the remaining 20 member states at all. If you sell into other EU countries, check that country's own current law rather than assuming this article covers it.
As of our check of EFTA's EEA-Lex tracker (2026-09-25), the directive had not yet been incorporated into the EEA Agreement for Norway, Iceland or Liechtenstein, so nothing in EU or EEA law currently requires this specific function there.
Sources checked
- Directive (EU) 2023/2673, Article 11a and Recital 37, full text, EUR-Lex, checked 2026-09-25.
- § 356a BGB, verbatim,
gesetze-im-internet.de, checked 2026-09-24 (seelegal/withdrawal_texts.md). - Shopify Help, "Setting up self-serve returns and cancellations," checked 2026-09-25.
- EFTA EEA-Lex, Directive (EU) 2023/2673 incorporation status, checked 2026-09-25.
- EUR-Lex, National Implementing Measures for Directive (EU) 2023/2673, checked 2026-09-25 (see
legal/withdrawal_labels_eu.md§6). - Noerr, "Umsetzungsgesetz zum Widerrufsbutton veröffentlicht," checked 2026-09-25.