Skip to content
CIQRA
All legal documents

CIQRA Legal Set — Sources & Citations Appendix

Draft — not yet in force. These documents are shared for transparency and are pending legal review. They are not the final, binding terms until published at launch.


DRAFT support document. See 00-README. This appendix records the primary/authoritative sources the drafts were benchmarked and researched against (verified July 2026), and maps each risk area to its basis so counsel can verify efficiently. It is not itself a contract. Date/version-sensitive items must be re-checked at review time.

Version: 1.0-draft · Compiled: 2026-07-08


1. Data protection & privacy

TopicWhere usedPrimary source (verify at review)
GDPR (controller/processor, rights, 72h breach)03, 06, 07Regulation (EU) 2016/679 (EUR-Lex)
EU Standard Contractual Clauses06, 15Commission Implementing Decision (EU) 2021/914 (4 Jun 2021) — current; Modules 2 & 3
Transfer Impact Assessment06 §11.2EDPB Recommendations 01/2020 (post-Schrems II)
Art. 27 EU representative — not required (EU-established)03 headerGDPR Art. 27; EDPB Guidelines 3/2018 (territorial scope)
DPO likely required (Art. 37)03 headerGDPR Art. 37; EDPB DPO guidance
CCPA/CPRA — rights, Do-Not-Sell/Share, GPC, SPI, ADMT (2026)03 §12California CPPA regs (incl. §7025 GPC); OAG CCPA pages; CPPA 2026 rules (eff. 1 Jan 2026)
US state laws (VA/CO/CT/UT/TX/OR…)03 §13Respective state privacy statutes; universal opt-out (GPC)
UK GDPR + IDTA/Addendum + UK Art. 27 rep03 §14UK GDPR + DPA 2018; ICO IDTA/Addendum; DUAA 2025 (ICO updating transfer tools during 2026)
Estonia digital-consent age 1300, 01Estonian Personal Data Protection Act (IKS) §8

2. Payments & regulatory characterisation

TopicWhere usedPrimary source
PSD2 — PI trigger, technical-service-provider (Art. 3(j)) + no-possession framing10 §1Directive (EU) 2015/2366 Arts. 3(b), 3(j), 4, 11; Recitals 10–11 (EUR-Lex)
Commercial-agent exclusion is fragile for 2-sided platforms10 (avoid-list)EBA Q&A 2020_5355 (updated Aug 2025)
PSD3 / PSR status (monitor)10 §1.6Provisional agreement 27 Nov 2025; OJ ~mid-2026; PSD3 transposition ~2028 (NRF/DLA/MoFo commentary)
Stripe Connect flow-down (mandatory acceptance, roles, liability, reserves, KYC)02, 10Stripe Connected Account Agreement (last modified 18 Nov 2025) + Stripe Services Agreement + Connect docs
Direct-charge loss/liability config (losses_collector/losses.payments)02 §6.4, 10 §4.6Stripe Connect risk-management / account-balances docs
Reserves must be disclosed in platform ToS; 180-day max02 §5, 08 C, 10 §4.3Stripe connected-account reserves docs
Card-scheme dispute monitoring thresholds08 B.4Visa VDMP / Mastercard ECM program thresholds
PCI DSS v4.0.1 SAQ A (whole-site script protection)00 §5, 01 §4.5PCI SSC v4.0.1; SAQ A (updated Oct 2024)

3. Tax (VAT / DAC7)

TopicWhere usedPrimary source
SaaS + commission = electronically supplied service; B2B reverse charge, B2C OSS, non-EU out of scope01 §3.5(a), 02 §3.5VAT Directive 2006/112/EC Arts. 44, 58, 196, 226; Union OSS (EC taxation)
Deemed supplier (Art. 14a) — outside for EU-merchant flows; inside-risk for non-EU goods / ≤€150 imports02 §8.4VAT Directive Art. 14a; Implementing Reg. 282/2011 Art. 5b
DAC7 platform reporting (report merchants to EMTA by 31 Jan)02 §8.3Directive (EU) 2021/514 (DAC7); EC DAC7 guidance
Estonia VAT 24% (from 1 Jul 2025); OSS via e-MTA; B2B e-invoicing buyer-choice now, mandatory ~2027; 7-yr retention00, 02, 07EMTA; Estonian VAT Act §15; Accounting Act §12 (Riigi Teataja)

4. Platform, content & consumer law

TopicWhere usedPrimary source
DSA — notice-and-action, statement of reasons, trader traceability01 §4, 05 §4, 13Regulation (EU) 2022/2065 Arts. 16, 17, 30
P2B — ranking transparency, complaint handling01 §8.4Regulation (EU) 2019/1150
EU Consumer Rights Directive 14-day withdrawal + exceptions01 §4.6, 08 A, 11Directive 2011/83/EU (as amended by Omnibus 2019/2161)
Estonia VÕS distance-withdrawal + online withdrawal button (from 01.09.2026)01 §4.6, 08 A.2, 11Estonian Law of Obligations Act (VÕS) amendments
European Accessibility Act01 §8.3Directive (EU) 2019/882 (in force 28 Jun 2025)

5. AI

TopicWhere usedPrimary source
AI Act Art. 50 transparency (interaction disclosure + content marking) from 2 Aug 2026; marking-only grace to 2 Dec 2026 (Digital Omnibus, provisional)03 §4, 14 §3Regulation (EU) 2024/1689 Art. 50; EC Code of Practice; Digital Omnibus (provisional)
Provider no-training-on-customer-data14 §2, 15OpenAI enterprise/business terms (no training by default; ≤30-day abuse retention); Anthropic Commercial Terms (no training; customer owns outputs)

6. Benchmarked platform legal sets (clean-room; structure only, no copying)

  • Stripe — Connected Account Agreement, Services Agreement, Restricted Businesses, Connect docs.
  • Shopify — Terms of Service, DPA, AUP, Payments Terms, API Terms.
  • Paddle / Lemon Squeezy — merchant-of-record model (backstop refunds, MoR framing).
  • Vercel — Terms, Enterprise Terms, DPA, Privacy Notice, Subprocessors, Integrations Marketplace Agreement.
  • Automattic / WooCommerce — Privacy, DPA, WP Cloud DPA.
  • BigCommerce / Wix / Squarespace — SaaS e-commerce ToS (API/usage limits, SLA-credit).
  • İkas — TR competitor (TR-specific framing; deferred TR pack only).

7. Standing verification notes for counsel

  • Re-verify all date/version items (SCC version, PCI DSS version, AI Act/Digital Omnibus dates, PSD3/PSR text, Estonia VAT rate/e-invoicing, Stripe agreement version) against primary sources at review time.
  • Confirm the Stripe Connect losses/liability configuration actually deployed and align 02 §6.4 / 10 §4.6.
  • Obtain tax-counsel sign-off on VAT treatment, deemed-supplier characterisation, and DAC7 status ([TAX-COUNSEL]).
  • Obtain payments-counsel sign-off on the PSD2 characterisation ([PAY-COUNSEL]).
  • Obtain AI-counsel sign-off on Art. 50 implementation and executed provider ZDR/DPA terms ([AI-COUNSEL]).

End of Sources & Citations appendix (draft).