What is the EU Geo-blocking Regulation?

The EU single market is built on the idea that businesses and customers should be able to trade freely across all member states. Geo-blocking - where a business restricts what a customer can buy, see, or pay for based on where they're located - works against that goal. The EU Geo-blocking Regulation was introduced to stop this kind of location-based discrimination.

Since 3 December 2018, businesses operating in the EU are not allowed to block or restrict a customer's access to goods, services, or payments purely because of their nationality, place of residence, or where their card was issued.

 

Who does this apply to?

If you sell goods or services to customers in the EU, this regulation likely applies to you. A few sectors are exempt, including audiovisual services, healthcare, and transport. If you are not sure whether your business qualifies for an exemption, we'd recommend checking with a legal advisor, since this depends on your specific circumstances.
 

What counts as geo-blocking?

Two things are specifically prohibited:

1. Blocking payments based on location: you can't refuse a payment method you'd normally accept just because the customer, their address, or their card issuer is based in a different EU country than you expected. 
For example: if you accept a certain card brand from customers in France, you can't block payments made with that same card brand from customers in Italy.

Please note: this only applies to payment methods the customer could actually use. It doesn't mean you have to offer every payment method to every customer regardless of relevance. Some methods are only usable in specific countries by design - for example, iDEAL only works with Dutch bank accounts. You're not geo-blocking by not showing iDEAL to a customer in France; it simply isn't a method they'd be able to complete a payment with. The regulation targets discrimination against customers who could pay with a given method but are blocked from doing so based on their location.

2. Blocking or redirecting website/app access: you can't block an EU customer from viewing your website or app based on their location or IP address, and you can't automatically redirect them to a different country version of your site without asking first. Even if a customer agrees to be redirected, the original site must still remain accessible to them.

 

Do I have to deliver anywhere in the EU?

No. You have to let any EU customer complete a purchase, but you don't have to physically deliver goods everywhere. You can still limit delivery to specific countries - you just need to say so clearly on your website, and let customers arrange their own onward delivery or collection if they're outside your delivery area.
 

Are there any exceptions?

Yes, two in particular:

  • Fraud prevention: if you have objective, well-founded reasons to suspect a transaction is fraudulent - based on more than just the customer's nationality or card origin - you're allowed to withhold delivery or the service.
  • Failed Strong Customer Authentication (SCA): if a payment doesn't meet SCA requirements under PSD2, you can decline it or apply different conditions.


What should I check to make sure I am compliant?

At Mollie we help people stay informed with these rules. Our Components and HPP interfaces respect this rule and help you stay compliant. But here are a few practical things worth reviewing:

  • Your website or checkout clearly states any delivery restrictions.
  • Your fraud prevention settings don't automatically decline cards from certain EU countries.
  • Your website or app doesn't automatically block or redirect visitors based on their location, unless the customer has explicitly agreed to it.

If you have questions about how this applies to your setup, get in touch with us - we're happy to help.