Skip to content
For Gulf brands launching in the EU or UK

Launching in Europe?
Consent is on the critical path.

Most of a European launch is logistics, tax and translation. The part that quietly slips is consent — because the requirements come from two different laws, one of them needs a person appointed in another country, and none of it is visible until the site is live. Here is the whole list, and a scan that tells you where your store stands today.

Selling on two domains — say .sa and .com? The scan detects both and prices them.

What the law requires — cited, so your counsel can check it

Art. 27
You must appoint an EU representative

A controller or processor not established in the Union must designate a representative in writing, inside the EU, unless a narrow exemption applies. It is a named point of contact for regulators and data subjects — not your law firm, and not optional.

Source: GDPR, Article 27
+1
The UK needs a separate one

Post-Brexit, an EU representative does not cover the United Kingdom. Selling to both means two appointments under two regimes. This is the requirement most often discovered after the launch date is already fixed.

Source: UK GDPR — ICO guidance
4%
of worldwide annual turnover

The upper tier of GDPR fines is €20 million or 4% of total global turnover for the preceding financial year — whichever is higher. Turnover, not European revenue.

Source: GDPR, Article 83(5)

What your current setup probably does not cover

None of this is a criticism of how the store was built. These requirements simply were not enforced in the market it was built for.

Consent in Europe has a definition, and silence is not it

GDPR requires consent to be freely given, specific, informed and unambiguous, by a clear affirmative act. The Court of Justice settled the rest in Planet49 (C-673/17): a pre-ticked box is not consent. A banner that loads trackers first and asks afterwards is the single most common finding on stores arriving from markets where that was never enforced.

The banner is required by a different law than the one you read

GDPR governs the personal data. The requirement to ask BEFORE storing or reading anything on a visitor's device comes from the ePrivacy Directive (2002/58/EC). That is why analytics and advertising tags must wait for a decision even where you believe you have a lawful basis — and why "we updated our privacy policy" does not resolve it.

An Arabic-first banner is not a European one

Consent must be informed, which means presented in a language your visitor actually reads, with cookie purposes described rather than listed. A storefront serving Riyadh and Rotterdam needs both — correct RTL for one, correct LTR for the other, and the same consent record behind both. Arqam360 was built bilingual rather than translated.

Without Consent Mode v2, your European ad spend goes half-blind

Google requires Consent Mode v2 for advertisers using its audience and measurement features with EEA users. Without it, conversions from consenting visitors stop being attributed and remarketing audiences stop filling — so the campaign funding the expansion is the first thing to break. This is the part that costs money every day rather than once.

Start with what your store does right now

The scan reads your live site: which trackers fire before anyone consents, whether Consent Mode v2 is actually emitting, whether a banner is detected at all, and which other domains your brand runs. It takes under a minute, needs no signup, and you can hand the result to whoever is running the launch.

Scan your store free

Arqam360 is a consent management platform, not a law firm. This page cites the instruments so you can verify them; it is not legal advice, and whether an exemption applies to your business is a question for your counsel.