Same practice, two verdicts: Make consumer protection have one meaning across Europe

A subscription button that is legal in one country can trigger enforcement in the next. European tech companies live with that reality every day, and the consumers they serve get different protection depending on where they live. Europe wrote a strong consumer rulebook, yet 27 national authorities read and apply it in 27 ways.

The European Commission can close that gap. In Q4 2026, it will propose a review of the Consumer Protection Cooperation (CPC) Regulation. A welcome development. The existing CPC Network already produces results, but it can do far more. We ask for two things together: improve the enforcement of rules Europe already has, and resist piling new rules on top. This will give consumers the same protection wherever they live, ensures competitiveness, and gives European tech companies legal certainty.

Make consumer protection have one meaning across Europe 

The Single Market still has no single approach to consumer protection. The same practice, like a new website layout, draws enforcement in one country and silence across the border. Think of the automatic renewal of a music or food-delivery subscription: one regulator calls it a dark pattern, the next understands the desire for consumers to have frictionless subscriptions. Companies cannot design once for 450 million people, and consumers cannot count on a common standard.

A revised CPC Regulation can turn the promise into daily reality. It needs clear responsibilities and procedures, reasonable deadlines for cross-border cases, and real cooperation between national and EU authorities. The Commission should pair it with overarching guidelines, binding on Member States, on how Europe’s online rules fit together. Consumers gain when the rulebook reads the same from Lisbon to Helsinki.

One procedure, one consumer protection, not a new EU layer

The review may give the Commission direct enforcement powers in major cross-border cases. This is a welcome development, on one condition. It must run through a single procedure, not create a parallel European track bolted onto the national and CPC ones.

EU action should, where relevant, replace national work, not duplicate or come on top of it. The Commission and national authorities need a clear remit of responsibility, otherwise companies may face the same case twice, in two forums, with two outcomes. Where other EU rules already apply (e.g. Digital Services Act, Digital Markets Act or the General Data Protection Regulation), it should be clear which enforcement system takes precedence. Authorities should coordinate so that the same facts are not investigated twice, avoiding a duplication of procedures.

As enforcement powers grow, safeguards must grow with them. Companies also need  the right to be heard, access to the file, workable deadlines and a real right of appeal. A cross-border whistleblower channel at CPC level, open to anonymous reports, would surface harm that national channels miss today.

Apply European rules consistently and focus our efforts where the greatest risks arise

The Commission should act based on risk, not on size. Turnover says nothing about the harm a company does to consumers. A risk-based trigger keeps enforcement where it matters and stops large firms being singled out simply for being large, while ensuring that risky, non-compliant smaller competitors don’t get a free pass.

Additionally, this approach will also contribute to ensuring a level playing field for all companies operating in Europe, regardless of where they are established.

The fragmented interpretation and enforcement of consumer protection rules has allowed some rogue actors to slip through the cracks and avoid sanctions for their conduct, while national authorities haven’t been able to apply the same rules consistently. 

The revised CPC Regulation should strengthen the enforcement toolbox for the most serious cross-border infringements that create the biggest risks for consumers, irrespective of the origin of the companies. European tech companies strongly support a review of the CPC Regulation that guarantees the ability and resources for authorities to apply the rules to all actors operating in Europe at the same pace.

It is only by interpreting and enforcing the rules consistently on all companies operating in the Single Market that the rulebook will deliver for European consumers, while ensuring fair competition.

Build digital fairness by enforcing what we have before writing more

The Digital Fairness Fitness Check points to the fastest win for consumers: better enforcement of the good rules Europe already has, not a new substantive layer of legal obligations. It should focus on making existing consumer protection work consistently across the Single Market. That means strengthening cross-border enforcement through a single, integrated Consumer Protection Cooperation (CPC) procedure, rather than introducing yet another set of design obligations for European companies.

European tech companies urge policymakers to seize this opportunity. By prioritising effective enforcement over additional new laws, the CPC review can ensure that consumer rights are applied consistently across Member States. Get this right, and  consumer protection will finally mean the same thing in every Member State, the Single Market that Europe promised.