Selling cosmetics in the EU: what compliance means for your storefront, not just your formula

By Robin Laseur

The CPNP confirmation reads like a finish line. Your Responsible Person has filed the notification, the safety report is signed, the product information file is sitting where it should be, and the product is now legal to place on the EU market. It is a real milestone. It is also the point where a second body of work quietly begins, and that work happens on your storefront rather than in a regulatory portal.
Most guides to selling cosmetics in the EU stop at that confirmation. They walk you through appointing a Responsible Person, preparing the Cosmetic Product Safety Report, and notifying the product, then treat the job as finished. What they rarely cover is what your Shopify catalog and product pages have to carry once the product is live, in which languages, and how to keep all of it correct as the rules shift. That is the half this article is about.
Start here: what notification settles, and what it hands to your storefront
Notifying through the Cosmetic Products Notification Portal, appointing an EU-established Responsible Person, and holding a signed safety report make a product legal to place on the EU market. They do not govern what your online store displays, in which language, or how your claims are worded. That second layer lives on your product pages.
The regulatory foundation is set by Regulation (EC) No 1223/2009. Before a cosmetic is placed on the EU market, a Responsible Person established in the EU must be in place, a Cosmetic Product Safety Report must exist for the product as part of a product information file that is kept for ten years after the last batch, and the product must be notified through the CPNP. A product that has not been notified cannot be legally marketed. This is well covered by the compliance consultancies who dominate the search results, and the European Commission’s own summary of the obligations lays it out clearly.
The notification establishes legality at the moment of market placement. It says almost nothing about the storefront. The storefront is governed by two other parts of the same regulation: the labeling rules in Article 19 and the claims rules in Article 20, both of which apply to how a product is made available on the market, including online. That is the handoff. The portal closes one task and opens another.
Settled by notification | Your storefront’s ongoing job |
Responsible Person appointed and registered | Display the RP and economic-operator details on listings |
Safety report and product information file complete | Surface mandatory on-pack information on every product page |
Product notified before market placement | Keep claims wording defensible wherever it appears |
Legal to place on the EU market | Render mandatory information per market language, kept current |

What your product pages must actually carry
An EU cosmetics product page has to surface the information a buyer would otherwise read on the pack: the full ingredient list in INCI form, the product function, any warnings or precautions, the nominal content, and the name and address of the Responsible Person. For online listings, the General Product Safety Regulation adds identification of the economic operator and a route to contact them.
Article 19 sets out the mandatory information that must appear on the container and packaging in indelible, legible, visible form. For distance selling, that information also has to be available to the buyer before they purchase, which in practice means it belongs on the product page itself rather than only on the carton that arrives later. The Responsible Person details can be presented in a shortened form online, typically the name, postcode, and country code, with the electronic contact often satisfied by the RP’s website.
Selling direct from your own store rather than through a marketplace does not reduce any of this. If anything it concentrates the responsibility, because you own the entire display. A marketplace will impose its own listing fields and may surface some of this information for you, but the legal obligation still rests with the brand. On your own Shopify store, every required field is yours to render and yours to keep accurate.
In practice the product page needs to carry:
The full INCI ingredient list. The same list that appears on the pack, in the standardized ingredient nomenclature, complete rather than summarized.
The product function. What the product is for, where that is not obvious from its name.
Warnings, precautions, and period after opening. Any cautionary text and the durability or post-opening guidance that applies to the formulation.
Nominal content. The quantity, presented as it is on the pack.
Responsible Person details. Name and address, in the shortened online form where appropriate, plus a contact route.
Economic-operator identification. Required for online listings under the General Product Safety Regulation, so a buyer and an authority can identify who is accountable.
The principle underneath the list is parity. Whatever a regulator expects a customer to be able to read on the pack, the online buyer should be able to read before they buy. A page that looks complete to a marketer can still be missing the fields a market-surveillance authority looks for first.

Claims: where the storefront, not the lab, creates the exposure
Article 20 of the Cosmetics Regulation prohibits claims that suggest a product has characteristics or functions it does not have, and the EU common criteria require every claim to be truthful, evidence-based, honest, and fair. On a storefront that obligation reaches well beyond the label. It governs product-page copy, collection descriptions, homepage banners, email content, and even meta descriptions and structured data.
This is where a brand with a flawless safety file can still drift out of compliance. Efficacy claims such as reducing the appearance of wrinkles or supporting the skin barrier, qualifiers like clinically proven or dermatologically tested, and the increasingly scrutinized free-from and natural claims all need substantiation that holds up to the common criteria. The substantiation has to support the claim in the specific way it is worded, for the specific product it is attached to.
The structural problem is duplication. A single claim rarely lives in one place. It appears on the product page, in the collection description that lists the product, in a campaign banner, in a paid ad, in the meta description, and inside the JSON-LD that feeds search engines. Each of those is a separate instance of the same claim, and each one has to be defensible on its own.
A claim is only as compliant as its least-governed copy.
That is why claims compliance on a storefront is a content-governance problem rather than a one-time wording exercise. When a substantiation lapses, or the common criteria tighten around a particular type of claim, the work is not editing one sentence. It is finding every copy of that sentence across a catalog that was never built to track where its claims live.
Selling across several EU markets: the language layer that multiplies
Mandatory cosmetics information must appear in the official language, or languages, of every member state where the product is sold. A single CPNP notification covers the whole EU under the free movement of goods, but the language obligation applies per destination market. The storefront, not the notification, is where multi-market selling gets heavier.
This distinction catches brands that assume one compliant English page covers the bloc. It does not. A store selling into France, Germany, and the Netherlands needs the ingredient list, the warnings, and the Responsible Person information rendered in each market’s official language, not only the marketing copy translated for conversion. The mandatory information is part of what has to be localized, and it carries the same legal weight in Dutch or German as it does in English.
The scope is wider than the EU itself. The European Economic Area extends the same framework to Norway, Iceland, and Liechtenstein, so a brand selling there inherits the obligation too. The United Kingdom, by contrast, now runs a separate regime with its own notification route and its own UK-based Responsible Person, which is a parallel project rather than a translation of the EU one. For an EU-focused launch the practical takeaway is simpler: one notification, but a language matrix that grows with every market you open.
How to model this in a Shopify catalog so it stays correct
The durable way to carry compliance on Shopify is to store the mandatory data as structured product metafields, the INCI list, warnings, Responsible Person details, and period after opening, rendered the same way on every product page, then use Shopify Markets and Translate and Adapt to serve each market its required language. That turns compliance from copy scattered across pages into a data model the catalog enforces.
The mechanics are straightforward once the shape is right. Define metafields for each piece of mandatory information, then render those fields in the product template so that every product, including ones added later, shows them by construction rather than by a writer remembering to paste them in. Shopify Markets handles the per-market structure, and Translate and Adapt, or an equivalent translation layer, holds the localized version of each mandatory field for the markets you sell into. The claims that need substantiation live in governed fields too, so there is a single source for each rather than a dozen hand-typed copies.
The payoff is in maintenance, which is where the real work sits. EU cosmetics compliance is not a launch event. The annexes that restrict ingredients are updated on a rolling basis, several times a year, and a Responsible Person can change, and a claim that was fine last year can fall foul of tightened criteria. When the mandatory information is a field rendered everywhere, an update is a single edit to the source. When it is free text pasted across hundreds of pages, the same update becomes a catalog-wide search for every place the old wording survives. Across the Shopify Plus catalogs Flatline has worked on, the brands that treated compliance data as structured fields were the ones who could absorb an annex change without a manual audit.
Requirement | Shopify mechanism |
INCI list, warnings, PAO, RP details | Product metafields rendered in the PDP template |
Per-market language of mandatory info | Shopify Markets plus Translate and Adapt or a translation layer |
Claim substantiation kept consistent | Single governed source per claim, referenced not retyped |
Economic-operator identification | Store-level setting plus a metafield surfaced on listings |
If you are unsure where to start: the safe default
If the sequence is unclear, work in this order, and a single-market launch can stop after the first three steps while multi-market selling needs all five:
Confirm the product is legally notified. Responsible Person in place, safety report complete, CPNP notification filed. Nothing on the storefront matters until this is true.
Make every product page carry the on-pack mandatory information. INCI list, function, warnings, nominal content, and Responsible Person details, present by construction rather than by memory.
Audit your claims against their substantiation. Every efficacy, clinical, and free-from claim, in every place it appears, traced back to evidence that supports the exact wording.
Localize the mandatory information for each market. Not just the marketing copy, but the required fields, in each destination’s official language.
Move that information into structured fields. So that the next annex update, RP change, or claim revision is one edit rather than a hunt.
The order matters because each step depends on the one before it. Localizing claims you have not yet substantiated only multiplies the exposure, and modeling fields before you know what they must contain builds the wrong structure faster.
Frequently asked questions
Can I sell cosmetics online in the EU without a CPNP notification?
No. Every cosmetic product must be notified through the CPNP before it is placed on the market, whether it is sold in a shop, on a marketplace, or direct from your own store. Selling online does not create an exception.
Do I need a separate safety report for each variant or scent?
Yes. Each distinct formulation, including a different fragrance of the same product, needs its own Cosmetic Product Safety Report as part of the product information file. A variant is a new formulation, not a label change.
Can my product pages and labels be in English only?
No. Mandatory information must appear in the official language of each member state where the product is sold, so an English-only page is not sufficient for the French or German market. The marketing copy and the mandatory fields are both in scope.
Who can act as my Responsible Person?
An RP must be a legal or natural person established in the EU. It can be the manufacturer, the importer, a distributor, or a third party appointed in writing, and it carries the legal responsibility for the product’s compliance and for holding the product information file.
Does selling direct rather than through a marketplace reduce my obligations?
No. The same obligations apply to direct-to-consumer sales. On your own store you also own the entire display, so the responsibility for getting the mandatory information and the claims right sits squarely with the brand.
Key takeaways
Notification makes a product legal to place on the market. The storefront is governed separately, by the labeling and claims rules, and that is where ongoing compliance actually lives.
Product pages must carry the same mandatory information a buyer would read on the pack: INCI list, function, warnings, nominal content, and Responsible Person details, plus economic-operator identification for online listings.
Claims are a content-governance problem on a storefront, because the same claim is duplicated across pages, ads, and structured data, and each copy has to be defensible on its own.
A single notification covers the EU, but the language obligation multiplies by market. The storefront, not the portal, is where multi-market selling gets heavier.
Modeling the mandatory data as structured Shopify metafields rendered on every page, with Shopify Markets handling per-market language, keeps compliance current from one edit instead of a catalog-wide hunt.
EU cosmetics compliance is less a launch checklist than a catalog you keep current. It is also the kind of structured Shopify build our ecommerce agency runs for regulated categories, where the catalog has to stay correct long after launch. The product page is where that maintenance succeeds or quietly lapses, which is why it is worth saving this and walking your team through your own product pages before the next market opens.
Related articles



