There is an old instinct in marketplace law which sounds perfectly sensible.
If a shopkeeper sells you a defective kettle, pursue the shopkeeper.
If a counterfeiter sells you a fake handbag, pursue the counterfeiter.
If a trader sells dangerous cosmetics, pursue the trader.
The landlord who happens to own the building in which the transaction occurred is ordinarily not treated as though the landlord manufactured the kettle, forged the trademark or mixed the cosmetic.
For much of the early internet era, online marketplaces attempted to occupy something resembling that landlord’s position.
We provide the platform. Other people sell the products.
That proposition was always more complicated than it sounded.
An online marketplace does not simply provide four walls and a roof.
It may decide which products appear first.
It recommends alternatives.
It accepts advertising.
It verifies—or does not verify—sellers.
It provides ratings.
It processes complaints.
It analyses users.
It may facilitate payment.
It can suspend traders.
It designs the search interface.
It determines what information a seller must provide before listing a product.
It may know which sellers repeatedly generate complaints.
Its algorithms can promote a product to millions of people within hours.
And unlike the owner of a traditional market hall, it possesses extraordinary quantities of data about what is happening inside its marketplace.
On 20 July 2026, the European Commission imposed a €550 million fine on AliExpress for failures under the European Union’s Digital Services Act concerning the assessment and mitigation of risks associated with illegal, unsafe and counterfeit products available through its marketplace. The Commission said that AliExpress had fallen short of its obligation to assess diligently the risk of dissemination of such products and had failed to implement effective measures sufficiently reducing those risks.
That is an enormous penalty.
But the legal development is more important than the number.
Europe is not simply saying:
“If somebody sells an illegal product online, blame the website.”
The Digital Services Act is considerably more sophisticated than that.
It is saying something closer to:
“If you build an enormous digital marketplace, possess the capacity to understand the systemic dangers created by that marketplace, and design the systems through which traders reach consumers, you acquire legal responsibilities concerning how those risks are identified and managed.”
That is a fundamentally different conception of intermediary responsibility.
And it may eventually reshape e-commerce law well beyond Europe—including in Pakistan.
The €550 million fine did not appear from nowhere
AliExpress had already been under intensive European regulatory scrutiny for more than two years.
The European Commission designated AliExpress as a Very Large Online Platform, or VLOP, under the Digital Services Act in April 2023. The Commission currently records approximately 104.3 million average monthly active recipients in the European Union for the service.
That classification matters because the DSA imposes enhanced obligations on platforms operating at exceptional scale.
The basic idea is intuitive.
A neighbourhood noticeboard and a global marketplace capable of exposing more than one hundred million European users to products do not create equivalent systemic risks.
Scale changes responsibility.
The Commission opened formal proceedings concerning AliExpress in March 2024. By June 2025, the investigation had produced two distinct outcomes.
First, AliExpress offered commitments addressing a number of concerns involving matters including advertising transparency and recommender systems, and the Commission made those commitments legally binding.
Secondly—and importantly separately—the Commission reached preliminary findings that AliExpress had failed adequately to assess and mitigate risks relating to illegal products.
The €550 million decision in July 2026 represents the culmination of that latter strand.
This chronology matters because the case is not an example of Europe discovering an illegal listing one morning and issuing a half-billion-euro fine the following afternoon.
It represents systemic regulation.
What exactly was the legal problem?
The language used by the Commission is significant.
It did not merely say that illegal products had appeared on AliExpress.
It said the platform had failed properly to assess and mitigate the risk that illegal, unsafe or counterfeit products would be disseminated through its service.
Those concepts correspond with the central architecture applicable to very large platforms under Articles 34 and 35 of Regulation (EU) 2022/2065, the Digital Services Act.
Article 34 requires VLOPs and very large search engines systematically to identify, analyse and assess systemic risks resulting from the design, functioning and use of their services.
Article 35 then requires reasonable, proportionate and effective mitigation measures tailored to the risks identified. Those measures may extend to changes in platform design, terms and conditions, content-moderation systems, algorithms, advertising systems, internal resources, testing and supervision.
That distinction between the individual illegal item and the systemic risk of illegal items is the heart of this development.
A marketplace can remove one fake product and still have a systemic problem
Imagine a conventional market containing 10,000 traders.
A counterfeit handbag is discovered at Stall 45.
The market operator removes it.
Problem solved?
Perhaps not.
Suppose counterfeit handbags appear every day.
Suppose traders suspended for counterfeiting return under new identities.
Suppose obviously suspicious listings are repeatedly promoted.
Suppose the marketplace collects data indicating that a particular product category produces extraordinary complaint levels.
Suppose verification procedures are easily circumvented.
Suppose the recommender system continues amplifying questionable listings because they are cheap and generate high engagement.
At that point, removing individual products becomes analogous to mopping the floor while leaving the pipe broken.
The Digital Services Act asks the operator to examine the pipe.
That is the conceptual leap.
The DSA is not merely a giant takedown regime
This point deserves emphasis because the European legislation is sometimes caricatured as requiring platforms to police everything every user posts or sells.
It does not.
Article 8 expressly states that providers of intermediary services are not subject to a general obligation to monitor all information they transmit or store, nor a general duty actively to search for facts indicating illegal activity.
That principle matters profoundly.
A law imposing universal pre-publication surveillance would raise enormous practical and fundamental-rights concerns.
The DSA instead constructs something more nuanced.
Platforms retain important intermediary protections while simultaneously acquiring specific duties appropriate to their functions and scale.
For marketplaces, those duties can include knowing who their traders are, designing interfaces which permit legally required product information to be supplied, responding to illegal-content notices and, for the very largest platforms, understanding and mitigating systemic risk.
Europe is therefore moving away from two unsatisfactory extremes.
The first extreme says:
“Platforms are liable for everything users do.”
The second says:
“Platforms are merely neutral pipes and have almost no responsibility for what their systems facilitate.”
Neither proposition adequately describes the modern digital marketplace.
Article 30 introduces the marketplace equivalent of “know your customer”
One of the most interesting DSA provisions for commercial lawyers is Article 30.
It concerns traceability of traders.
An online marketplace facilitating contracts between traders and European consumers must obtain specified information before allowing the trader to offer products or services.
That information includes the trader’s name and contact details, identification information, payment-account details where applicable, trade-register information where relevant, and a self-certification committing the trader to offer only products or services compliant with applicable EU law.
This has sometimes been described as a form of:
“Know Your Business Customer” — KYBC.
The analogy with financial regulation is illuminating.
Banks learned decades ago that anonymity and scale create opportunities for abuse.
If an institution facilitates substantial financial activity, regulators increasingly expect it to know who is using the infrastructure.
Europe is beginning to apply something similar to marketplaces.
If a platform provides the infrastructure through which a merchant can sell thousands of products to European consumers, the identity of the merchant cannot simply be:
Seller_9384721.
There must be someone behind the listing whom law can locate.
Anonymous commerce creates asymmetric justice
Consider the consumer’s position.
You purchase an unsafe children’s toy through an online platform.
The product arrives.
It causes injury.
The seller disappears.
The business name is meaningless.
The contact address is false.
The company cannot be located.
The marketplace says:
“We only connected buyer and seller.”
That creates a peculiar legal asymmetry.
The marketplace knew how to locate the consumer well enough to process the transaction, recommend further products and deliver advertising.
The seller knew how to receive payment.
The logistics system knew how to move the product.
Yet when liability arises, suddenly nobody knows who sold it.
A regulatory regime which tolerates that structure effectively makes anonymity a commercial advantage for irresponsible traders.
Article 30 attempts to close that gap.
Europe has also created “compliance by design”
Article 31 may be even more consequential.
It requires online marketplaces to design and organise their interfaces in a way enabling traders to comply with pre-contractual information, compliance and product-safety obligations.
The platform must therefore provide the digital architecture through which legally required information can actually be supplied.
This is a remarkable development in regulatory philosophy.
Historically, law told the trader:
“Provide the required information.”
Digital regulation increasingly tells the platform:
“Build the interface so the trader can provide it.”
That is compliance by design.
Law moves upstream.
Interface design is becoming legal infrastructure
Think about an ordinary product listing.
Who decides whether there is a field for:
manufacturer identity;
product warnings;
age restrictions;
safety certifications;
responsible economic operator;
country of origin;
trader address;
return rights;
or regulatory information?
The marketplace does.
If the interface contains no meaningful place for legally required information, millions of individual sellers cannot easily solve the problem independently.
The platform architecture determines the regulatory architecture.
This is why modern technology regulation increasingly concerns design.
A dropdown menu can have legal consequences.
A compulsory field can prevent anonymity.
An algorithm can promote risk.
A warning can protect consumers.
A seller-verification workflow can determine whether an injured customer later has anyone to sue.
Law is increasingly embedded in software interfaces.
Counterfeiting illustrates the scale problem perfectly
Counterfeiting is not new.
Fake watches, handbags, medicines, automotive components and clothing long pre-date the internet.
What changed is distribution.
A counterfeiter once needed physical access to customers.
Online platforms can give a small seller immediate access to consumers across continents.
That dramatically reduces the cost of illicit distribution.
The same network effects which make e-commerce wonderful for legitimate entrepreneurs can make it extraordinarily efficient for dishonest ones.
This creates a difficult policy question.
Should society permit a platform to enjoy the commercial benefits of enormous scale while treating the corresponding risks as millions of unrelated acts committed solely by individual traders?
The DSA increasingly answers:
No—not where the scale itself generates identifiable systemic risk.
Counterfeit goods are not merely a luxury-brand problem
There is also a tendency to trivialise counterfeiting by imagining somebody receiving a fake designer handbag instead of a genuine one.
That is certainly an intellectual-property problem.
But unsafe and counterfeit e-commerce reaches far more serious territory.
A counterfeit electrical charger can cause fire.
A defective child’s toy can create choking or chemical hazards.
A falsified cosmetic can contain dangerous ingredients.
Counterfeit automotive components can fail.
Fake medical products can cause catastrophic harm.
A product may be cheap precisely because the seller avoided the testing, certification, labour, product-safety and intellectual-property costs borne by lawful competitors.
This is why platform regulation sits at the intersection of several bodies of law:
consumer protection;
product safety;
intellectual property;
competition;
contract;
advertising;
customs;
and increasingly digital-services regulation.
There is a competition issue hiding inside consumer protection
Consider two sellers.
Seller A manufactures legally.
It complies with product standards.
It purchases insurance.
It pays taxes.
It uses genuine trademarks.
It provides accurate safety information.
It observes recall obligations.
It employs identifiable staff.
Seller B does none of those things.
Seller B can therefore sell considerably more cheaply.
If the marketplace permits Seller B repeatedly to compete with Seller A while bearing none of the compliance costs imposed upon legitimate traders, the problem is not merely consumer safety.
It distorts competition.
Regulation protecting buyers can simultaneously protect honest businesses.
That is an important point for Pakistan.
Weak marketplace enforcement does not only hurt consumers.
It penalises legitimate Pakistani traders forced to compete against businesses which reduce prices by ignoring the law.
The marketplace is not necessarily the manufacturer
Europe has not erased distinctions between commercial actors.
An online marketplace does not automatically become the legal manufacturer of every product offered through it.
Nor does the mere presence of illegal goods necessarily establish that a platform has violated every applicable duty.
The DSA preserves intermediary-liability principles and expressly rejects general monitoring obligations.
The AliExpress case is therefore important precisely because the Commission’s theory is more sophisticated.
The alleged failure concerned the platform’s own obligations.
Risk assessment.
Risk mitigation.
Systems.
Governance.
This distinction should be preserved.
Good regulation should impose liability for what the relevant party can reasonably control.
But “we didn’t manufacture it” is becoming an incomplete answer
The marketplace may not manufacture the product.
It does, however, manufacture the marketplace.
That sentence captures the regulatory transition.
The platform creates:
the onboarding rules;
seller identity requirements;
search architecture;
recommendation algorithms;
reporting processes;
complaint mechanisms;
advertising systems;
ranking;
suspension procedures;
repeat-offender controls;
and much of the informational environment surrounding the purchase.
It therefore controls risks which the individual consumer cannot control.
Law increasingly follows control.
The recommendation algorithm creates a particularly interesting responsibility
Suppose a seller uploads an illegal product.
That is one thing.
Suppose the platform’s algorithm then actively recommends it to one million consumers because it is inexpensive and highly clicked.
The marketplace has not merely stored the listing.
Its system has amplified it.
That distinction becomes increasingly relevant as platforms personalise commerce.
The DSA specifically permits systemic-risk mitigation measures to include testing and adapting algorithmic systems, including recommender systems.
That tells us where European regulation is heading.
An algorithm cannot simply be treated as an invisible neutral intermediary.
Its design may form part of the regulatory enquiry.
“The algorithm did it” will become as weak as “the computer made an error”
Businesses once used phrases like:
“The computer automatically generated the charge.”
Law eventually learned that computerisation does not dissolve responsibility.
Somebody chose the software.
Somebody defined the rules.
Somebody benefits from the outcome.
Algorithmic marketplaces will experience the same evolution.
If a recommender system repeatedly promotes illegal products, the important question is not whether an employee manually selected every listing.
It is whether the platform has designed and governed its system responsibly.
Automation changes the mechanism.
It does not necessarily eliminate accountability.
The regulatory focus on internal resources is equally important
Article 35 permits consideration of whether a platform has adequately reinforced its internal processes, resources, testing, documentation and supervision when responding to systemic risks.
That makes compliance a governance question.
A platform cannot necessarily operate an enormous marketplace with a skeletal compliance function and then say that scale made effective enforcement impossible.
The European Commission’s July statement put the point quite directly: scale is not an excuse for failing systematically to identify and address illegal-product risks.
There is an important corporate-law lesson there.
A business model which creates regulatory risk must budget for regulatory control.
Compliance is part of the cost of operating at scale.
The DSA effectively asks management to understand the machine it built
This obligation reaches boardroom governance.
For very large platforms, the DSA requires a compliance function and imposes specific responsibilities upon management in relation to systemic-risk governance. Management must ensure that relevant risks are identified and mitigated, periodically review risk-management strategies and allocate adequate resources.
This destroys an increasingly untenable fiction in technology governance:
“The platform is too complicated for management to know what is happening.”
Complexity may explain a problem.
It cannot automatically excuse it.
If a commercial organisation becomes too complex for its governing body to understand its principal legal risks, complexity itself becomes a governance failure.
Europe is effectively regulating the business model
This is what makes the Digital Services Act distinctive.
Traditional enforcement often asks:
“Which specific item broke the law?”
Systemic platform regulation asks:
“What characteristics of this business model repeatedly create unlawful outcomes?”
That could involve:
seller anonymity;
financial incentives;
ranking algorithms;
weak verification;
inadequate moderation;
insufficient compliance staff;
repeat-offender loopholes;
poor reporting mechanisms;
or ineffective risk analysis.
The target shifts from the offending listing to the ecosystem.
That does not mean every risk must be eliminated
No marketplace of significant scale can guarantee perfection.
Illegal sellers adapt.
Counterfeiters deceive.
Fraudsters steal identities.
Products are misdescribed.
Human moderation fails.
Automated detection makes mistakes.
The DSA reflects this reality by requiring measures which are reasonable, proportionate and effective, not metaphysically perfect.
That wording is important.
The legal test is not:
“Did anything illegal ever appear?”
It is closer to:
“Did the platform properly understand the systemic risk and implement adequate measures proportionate to that risk?”
That gives platforms room to operate while preventing them from converting imperfection into immunity.
There is a danger of over-removal
Marketplace regulation also contains another side.
If penalties for illegal products become enormous, platforms may respond by removing anything remotely suspicious.
That can hurt lawful traders.
A legitimate small business may lose access to customers because an automated system incorrectly classifies its product as prohibited.
A trademark complaint may be abusive.
A competitor might submit false reports.
A seller’s account could be suspended without adequate review.
There is therefore a justice issue on both sides.
Consumers deserve protection from dangerous and counterfeit products.
Legitimate traders deserve protection from arbitrary exclusion.
Effective regulation must preserve both.
The platform is becoming a private regulator
This is an uncomfortable but unavoidable reality.
When a marketplace decides whether a trader may sell, it exercises economic power.
A suspension can destroy an online business.
An algorithmic demotion can make a seller effectively invisible.
A payment hold can cripple cash flow.
A counterfeit designation can damage reputation.
Platforms are therefore increasingly performing regulatory functions traditionally associated with public authorities.
They create rules.
Investigate complaints.
Adjudicate alleged violations.
Impose penalties.
Hear appeals.
Exclude offenders.
This private governance can be efficient.
But it also requires procedural fairness.
“Know your trader” should not become “believe every allegation”
Seller verification solves identity risk.
It does not solve evidential fairness.
A platform should know whom it is dealing with.
But when accusations arise, there should also be mechanisms proportionate to the seriousness of the decision.
Was the product actually counterfeit?
Was the trademark complaint valid?
Does the safety rule apply?
Was the seller given an opportunity to respond?
Is repeat infringement genuinely established?
Has automated enforcement produced false positives?
The future of marketplace regulation therefore requires both:
stronger responsibility; and
better due process.
The €550 million fine demonstrates that DSA sanctions are real
The financial exposure under the DSA is substantial.
Article 74 permits the European Commission, in relevant enforcement decisions against VLOPs and VLOSEs, to impose fines of up to 6 per cent of the provider’s total worldwide annual turnover in the preceding financial year for infringements of the Regulation or specified failures involving binding decisions or commitments.
Periodic penalty payments may also be available to compel compliance with regulatory requirements.
The July 2026 AliExpress penalty therefore belongs firmly within the category of board-level regulatory risk.
Digital marketplace compliance is not a website-terms-and-conditions exercise.
It is enterprise risk.
The case also demonstrates that cooperation does not necessarily end an investigation
This is another useful compliance lesson.
In June 2025, the Commission accepted and made legally binding several commitments offered by AliExpress concerning separate DSA issues including advertising and recommender-system transparency. At the same time, however, the Commission continued its illegal-products investigation and issued preliminary findings on risk assessment and mitigation.
A regulated company should therefore never assume that resolving one branch of an investigation automatically closes another.
Complex digital regulation creates multiple independent obligations.
A platform can improve advertising transparency and still face product-safety risk.
It can strengthen seller verification and still have algorithmic problems.
It can improve its complaint mechanism while leaving risk assessments deficient.
Compliance needs to be holistic.
The AliExpress decision belongs to a much broader European movement
AliExpress is not being singled out because Europe objects to one particular marketplace.
The DSA creates a general architecture applicable according to service type and scale, and the Commission maintains active supervision of numerous designated VLOPs and very large search engines.
The important commercial signal is therefore not:
“AliExpress has a problem.”
It is:
“Europe now expects enormous platforms to prove that they understand and manage the systemic risks created by their own architecture.”
Other marketplace operators should read the decision accordingly.
What would the same problem look like in Pakistan?
Pakistan’s e-commerce economy is developing under a very different legal architecture.
There is presently no direct Pakistani equivalent to the European Digital Services Act’s comprehensive VLOP systemic-risk regime.
Instead, online commerce in Pakistan sits across several overlapping bodies of law.
Electronic contracting has long had statutory recognition through the Electronic Transactions Ordinance 2002, which forms part of Pakistan’s federal legal framework for electronic transactions.
General contractual principles remain relevant.
Provincial and territorial consumer-protection regimes can become relevant depending upon location and circumstances.
Intellectual-property laws apply to counterfeit goods.
Product-specific regulation may govern medicines, food, cosmetics, electrical products or other regulated categories.
Cybercrime law may become relevant where dishonest online activity crosses into criminal conduct.
And the Competition Act 2010 separately prohibits deceptive marketing practices. The Competition Commission of Pakistan explains that section 10 encompasses false or misleading commercial representations concerning matters including a product’s price, character, production, properties, suitability and quality.
What Pakistan lacks is the same degree of integrated platform-system accountability.
That gap deserves serious discussion.
Pakistan should not simply copy the DSA
European regulation is not automatically good Pakistani regulation.
The European Union has a massive integrated market, specialised supranational institutions, mature product-safety structures and resources which Pakistan does not possess in equal measure.
Attempting to transplant the entire DSA mechanically would likely create complexity without equivalent enforcement capacity.
Pakistan should instead ask which underlying principles make sense locally.
Several do.
Pakistan needs a meaningful “know your seller” principle
This should be the starting point.
A consumer purchasing from a professional online trader should be able to identify whom they are dealing with.
That principle becomes especially important where a marketplace facilitates the transaction.
A serious platform should ordinarily know:
the seller’s legal identity;
contact details;
payment identity;
business registration where applicable;
tax or regulatory status where relevant;
and sufficient information to permit investigation where unlawful trading occurs.
The precise statutory design can be debated.
The principle should not be controversial.
Commercial anonymity should not become a shield against accountability.
Cash-on-delivery makes Pakistan’s marketplace ecosystem unusually interesting
Pakistan’s commercial habits also create local complications.
A substantial part of e-commerce historically developed around cash-on-delivery and courier-based fulfilment rather than purely card-based digital payment.
That creates a chain containing:
seller;
marketplace;
consumer;
courier;
payment collector;
and sometimes warehousing or fulfilment intermediaries.
Each actor possesses different information.
Who knows the seller?
Who receives the money?
Who holds the goods?
Who knows the consumer?
Who has the ability to suspend repeat offenders?
Liability should follow actual roles and control rather than simplistic labels.
A courier should not automatically become responsible for the legality of every sealed parcel it transports.
Equally, a platform which controls seller onboarding, advertising, ranking and payment should not necessarily be permitted to describe itself as though it were merely a passive noticeboard.
Functional analysis matters.
Pakistan’s 2026 e-commerce taxation changes make this even more relevant
Pakistan is already moving towards greater legal visibility of online commerce through taxation and reporting structures surrounding digitally ordered goods.
That policy direction creates a broader question.
If the State increasingly expects marketplaces, payment intermediaries and couriers to know enough about digital transactions to participate in tax compliance, it becomes harder conceptually to argue that the same ecosystem is incapable of providing meaningful seller traceability when consumers are harmed.
Tax law often discovers commercial reality before consumer law does.
The data already exists.
The more interesting question is what lawful accountability should follow from it.
Pakistani marketplaces should consider voluntary KYBC before legislation forces it
A sophisticated local marketplace does not need to wait for a statutory copy of Article 30.
There are commercial reasons to improve trader verification now.
Verified sellers create greater consumer trust.
Repeat fraud becomes easier to detect.
Law-enforcement enquiries become easier to answer.
Intellectual-property complaints can be investigated more efficiently.
Regulatory relationships improve.
Marketplace reputation improves.
And legitimate sellers gain protection from anonymous competitors.
Seller verification should therefore be understood as risk management rather than merely regulatory burden.
Counterfeit products present a major Pakistan-facing opportunity
Pakistan is both a consumer market and a manufacturing economy.
Counterfeiting therefore hurts Pakistan in several directions.
Consumers receive unsafe or inferior products.
Pakistani manufacturers lose sales.
International brands become cautious about local distribution.
Legitimate retailers face price competition from unlawful sellers.
Tax revenue is lost.
Trademark value is diluted.
And international confidence in Pakistani e-commerce suffers.
Platform accountability can therefore form part of a broader strategy for improving Pakistan’s commercial reputation.
A trustworthy digital marketplace is export infrastructure.
This matters particularly for Pakistani sellers going international
The DSA is not merely relevant to European platform operators.
Pakistani traders selling into Europe through online marketplaces increasingly enter an environment in which seller identity, product information and regulatory compliance are treated seriously.
A Pakistani manufacturer exporting products through a European-facing digital marketplace may therefore encounter demands concerning:
identity verification;
product safety;
manufacturer information;
economic-operator details;
intellectual-property rights;
warnings;
consumer information;
and regulatory documentation.
This should not be viewed merely as foreign bureaucracy.
For a compliant Pakistani exporter, robust standards can create competitive advantage.
Good Pakistani businesses should want dishonest sellers removed
There is sometimes a reflexive tendency to view all regulation as hostile to business.
That is mistaken.
Regulation which eliminates anonymous counterfeit sellers can benefit lawful businesses.
The trader who pays for certification should not have to compete indefinitely against someone selling an unsafe imitation.
The business that registers its trademark should not see counterfeit copies algorithmically recommended beside its genuine product.
The manufacturer complying with consumer-protection rules should not be undercut by traders who disappear whenever complaints arise.
Market integrity is commercially valuable.
Justice for consumers and fair competition for honest traders often point in the same direction.
Intellectual-property owners should also change strategy
Brand owners traditionally pursue individual counterfeiters.
That remains necessary.
But platform-scale commerce may require a broader litigation and enforcement strategy.
Rights holders should preserve evidence showing:
repeat listings;
seller identities;
re-emergence after suspension;
notice histories;
platform responses;
product recommendations;
advertising;
and the relationship between different seller accounts.
The question may eventually become not merely:
“Was this listing counterfeit?”
but:
“After repeated notice of the pattern, what did the marketplace reasonably do?”
That is a more powerful regulatory narrative.
Pakistani consumer litigation faces an identity problem
One of the mundane difficulties in online disputes is deceptively important:
Who exactly do you sue?
The customer knows the marketplace name.
The package bears a courier label.
The bank statement contains a payment reference.
The seller uses an informal shop name.
No corporate identity is obvious.
Contact details disappear.
This complicates legal notices, jurisdiction, service, enforcement and recovery.
Marketplace seller traceability could therefore improve access to justice in a very practical sense.
Rights are of limited use against defendants who cannot be found.
The law should distinguish three different marketplace roles
Future Pakistani regulation would benefit from separating at least three models.
First, the pure intermediary which genuinely performs little more than hosting information.
Secondly, the transactional marketplace which structures the transaction, identifies sellers, processes or facilitates payment, manages complaints and controls visibility.
Thirdly, the integrated marketplace or fulfilment model which may warehouse, package, promote, deliver, collect payment or otherwise participate much more deeply in the sale.
These businesses should not necessarily bear identical obligations.
Responsibility should rise with control and involvement.
That would be more principled than calling every digital service a “platform” and regulating them identically.
The label “marketplace” should not decide liability
Contractual drafting frequently contains language such as:
“We are not a party to the transaction.”
That provision may be relevant.
But legal characterisation cannot always be decided by a company drafting its own terms.
A court or regulator should be entitled to examine economic substance.
Who controls the payment?
Who controls the refund?
Who decides seller admission?
Who advertises the product?
Who presents the product as “recommended”?
Who controls delivery?
Who holds consumer funds?
Who profits from the transaction?
Who can prevent the seller returning?
Law should look at what the business does, not merely what its terms call it.
Consumer trust is itself an asset created by the marketplace
There is another argument for greater platform responsibility.
Why does a customer purchase from an unknown seller through a famous marketplace rather than transferring money directly to a stranger?
Because the marketplace lends the transaction credibility.
Its brand tells the consumer:
this transaction occurs inside an organised commercial environment.
The marketplace therefore monetises trust.
It receives commercial value from the perception that buying within its ecosystem is safer than buying from an unknown individual.
There is a principle of fairness here.
An enterprise which commercially benefits from creating trust should bear some responsibility for maintaining the systems upon which that trust reasonably depends.
But platform liability must not become strict insurance for every bad purchase
The other side remains important.
If every marketplace automatically became financially responsible whenever any seller committed wrongdoing, several consequences could follow.
Platforms could exclude small sellers.
Verification costs could become prohibitive.
Innovative marketplaces might never launch.
Platforms could demand excessive deposits.
Cross-border trade could shrink.
Small Pakistani exporters might face barriers designed primarily for giant manufacturers.
The correct legal goal should therefore not be absolute liability.
It should be proportionate responsibility.
What could the platform reasonably know?
What did it control?
What risks had become systemic?
What measures did it take?
Did it respond to repeated warnings?
Were verification systems credible?
Was its own algorithm amplifying the problem?
Those questions preserve both innovation and accountability.
The DSA’s greatest contribution may be the concept of systemic due diligence
This is the principle I believe other jurisdictions should study most carefully.
Large digital businesses create recurring patterns of risk.
Law should therefore sometimes ask them to perform a regulatory equivalent of corporate due diligence.
Identify the risk.
Measure it.
Document it.
Mitigate it.
Test the mitigation.
Allocate resources.
Review effectiveness.
Improve where necessary.
That is a much more mature form of regulation than simply imposing liability after thousands of consumers have already been harmed.
“Move fast and break things” does not work well when the thing being broken is consumer safety
Digital businesses have long celebrated rapid experimentation.
That culture generated extraordinary innovation.
But a marketplace facilitating millions of physical products cannot treat every legal obligation as an obstacle to experimentation.
The object arriving at the consumer’s home exists in the physical world.
It can burn.
Poison.
Break.
Explode.
Injure.
Or counterfeit somebody else’s intellectual property.
Digital interfaces do not repeal physical consequences.
This is where technology law reconnects with old-fashioned product law.
Artificial intelligence will make marketplace responsibility even harder
The next generation of e-commerce will increasingly use AI.
AI may:
generate product descriptions;
translate listings;
recommend products;
detect counterfeit imagery;
identify prohibited items;
automatically price products;
create advertisements;
rank sellers;
answer customer questions;
and decide which complaints require human review.
That will improve efficiency.
It will also complicate responsibility.
Suppose an AI system rewrites a seller’s product description in a way which creates a misleading safety claim.
Who made the representation?
Suppose a platform’s AI mistakenly identifies a lawful product as counterfeit.
Who compensates the seller?
Suppose AI moderation repeatedly fails to detect a dangerous product category.
At what point does inadequate model governance become inadequate marketplace governance?
The AliExpress case belongs to the beginning, not the end, of platform-liability evolution.
AI may also make counterfeiting cheaper
Generative technology can improve product photography.
Create convincing fake certificates.
Generate fictitious reviews.
Translate listings into dozens of languages.
Produce persuasive advertisements.
Create synthetic influencer endorsements.
Automate seller accounts.
And assist repeat offenders in changing identities and presentation.
Marketplace compliance must therefore become more technologically sophisticated at the same time that illicit selling becomes more technologically sophisticated.
The arms race has begun.
Reviews create another under-examined field of responsibility
Consumers frequently rely upon star ratings and reviews.
But what happens when those reviews are fabricated?
If a marketplace knows that coordinated fake reviews systematically increase sales of questionable products, the review architecture itself becomes part of consumer risk.
A platform cannot credibly market “trust signals” while refusing to examine whether those signals are manipulated.
The future of marketplace law will increasingly concern not merely products but the informational scaffolding surrounding products.
Ratings.
Badges.
“Best seller” labels.
Recommendations.
Sponsored placement.
Verified purchase designations.
All of these influence consumer choice.
All can potentially mislead.
Product ranking may eventually attract the same scrutiny as advertising
A consumer understands that a banner saying “Sponsored” has been paid for.
But what about:
“Top Pick”?
“Recommended for You”?
“Most Popular”?
“Customers Love This”?
“Trending”?
These apparently neutral labels can dramatically influence purchasing decisions.
What determines them?
Sales?
Advertising spend?
Commission rate?
Algorithmic engagement?
Return rates?
Product safety?
Customer complaints?
If ranking systems systematically promote risky goods, regulators may increasingly ask whether ranking itself forms part of platform responsibility.
The DSA already allows mitigation measures to include adapting recommender systems.
That principle will not remain confined to Europe.
The global regulatory contest is really about who bears the cost of trust
This is perhaps the deepest economic issue.
Trust costs money.
Verifying sellers costs money.
Testing products costs money.
Investigating complaints costs money.
Removing repeat offenders costs money.
Employing compliance staff costs money.
Building safer algorithms costs money.
If the marketplace bears none of those costs, somebody else does.
Consumers bear them through injury or fraud.
Legitimate businesses bear them through unfair competition.
Governments bear them through enforcement.
Trademark owners bear them through investigations.
Banks and payment processors bear them through disputes.
The DSA effectively says that very large platforms must internalise more of the trust costs generated by their own scale.
That is a significant economic choice.
It may ultimately create better marketplaces
Regulation is often presented as the enemy of growth.
But digital commerce cannot grow indefinitely without trust.
A customer who expects counterfeits stops buying.
A legitimate brand which cannot protect itself leaves the platform.
A regulator confronting repeated harm intervenes more aggressively.
A payment provider increases reserves.
An insurer increases premiums.
A market saturated with unreliable sellers eventually destroys its own value.
Compliance can therefore be understood as market infrastructure.
Trust is not merely an ethical virtue.
It is commercially productive.
What should international marketplace operators now do?
Companies operating online marketplaces with international exposure should examine the entire lifecycle through which traders enter and use their services.
That means asking:
Who is permitted to become a seller?
How is identity verified?
How easily can a suspended seller return?
What product information must be supplied?
Which product categories create heightened regulatory risk?
How are illegal-product notices processed?
Are intellectual-property complaints integrated with seller-risk analysis?
Do repeated complaints trigger enhanced scrutiny?
Do recommender systems take regulatory risk into account?
Can obviously anomalous seller behaviour be detected?
How are platform risk assessments documented?
Does senior management review systemic marketplace risks?
Are compliance resources proportional to platform scale?
What happens after a product recall?
How quickly can affected consumers be identified?
Can the business demonstrate the effectiveness of its controls?
Those are no longer merely operational questions.
For businesses falling within the DSA, they are potentially regulatory questions carrying enormous financial consequences.
What should Pakistani marketplaces do?
Pakistan’s domestic marketplaces should not wait for a €550 million equivalent before recognising the direction of travel.
A sensible voluntary framework would include robust seller identification; clear seller contact information; traceable payment relationships; procedures for high-risk product categories; clear intellectual-property complaint systems; controls against repeat offenders; transparent sponsored listings; escalation for serious safety complaints; record preservation; adequate complaint review; and documented policies regarding counterfeit, prohibited and unsafe products.
Larger marketplaces should additionally consider periodic systemic-risk reviews.
Not because Brussels requires Pakistani domestic commerce to imitate Europe.
Because it is sensible governance.
What should Pakistani exporters do?
Pakistani exporters using major international platforms should treat marketplace compliance as part of export readiness.
A company should have:
clean corporate documentation;
accurate manufacturer identity;
appropriate product labelling;
trademark rights where relevant;
clear product descriptions;
safety documents;
traceable invoices;
refund and complaint procedures;
and records capable of demonstrating product authenticity.
A seller who cannot document its legitimacy may increasingly find itself commercially indistinguishable from the illegitimate sellers platforms are being pressured to remove.
Documentation therefore becomes market access.
What should brands do?
Brand owners facing online counterfeiting should move beyond isolated takedown requests.
They should identify patterns.
Preserve evidence.
Document seller recurrence.
Record platform notifications.
Compare account details.
Analyse suspicious pricing.
Monitor re-listings.
Establish trademark and product-authentication evidence before complaints arise.
Where significant consumer safety issues are involved, enforcement strategy should consider product regulators as well as intellectual-property remedies.
The aim is to demonstrate not merely an isolated infringement but, where evidence permits, a systemic problem requiring systemic response.
What should regulators in Pakistan learn?
Pakistan does not need to build a European super-regulator tomorrow.
It does need to recognise that digital commerce has outgrown legal assumptions designed around bilateral transactions between one identifiable shop and one identifiable customer.
Marketplace law should eventually answer several basic questions clearly.
What information must a marketplace obtain about professional sellers?
When must that information be disclosed to consumers?
What must happen after authorities identify an unlawful product?
What obligations arise after repeated notices concerning the same trader?
When should marketplaces preserve transaction records?
What product-safety information must platforms enable sellers to display?
What safeguards protect legitimate sellers against wrongful suspension?
How should cross-border sellers be treated?
When does the platform’s own conduct amount to deceptive marketing?
Which regulator coordinates enforcement?
These questions will not disappear merely because legislation has not yet comprehensively answered them.
Frequently Asked Questions
Did the European Union fine AliExpress simply because illegal products appeared on the platform?
No. The Commission’s July 2026 decision concerned AliExpress’s own obligations under the Digital Services Act to assess diligently and mitigate systemic risks associated with illegal, unsafe and counterfeit products.
How large was the fine?
The European Commission imposed a €550 million fine on 20 July 2026.
Is AliExpress classed as a Very Large Online Platform?
Yes. The Commission designated AliExpress under the DSA’s VLOP framework and currently records approximately 104.3 million average monthly active recipients in the EU.
Does the DSA require marketplaces to monitor every single product continuously?
No. Article 8 expressly prohibits imposing a general obligation upon intermediary-service providers to monitor all transmitted or stored information or actively search generally for illegal activity.
What is the difference between that rule and the AliExpress fine?
The distinction is between general surveillance of everything and specific legal duties concerning systemic risk. Very large platforms must assess systemic risks and implement reasonable, proportionate and effective mitigation measures.
Does the DSA require marketplaces to identify sellers?
Article 30 requires marketplaces enabling consumers to conclude distance contracts with traders to obtain specified trader-identification information before those traders may offer products or services to EU consumers.
What does “compliance by design” mean?
Article 31 requires marketplace interfaces to be designed so that traders can supply information needed to comply with relevant pre-contractual, compliance and product-safety obligations.
Can DSA penalties exceed €550 million?
Potentially. Article 74 permits fines of up to 6 per cent of relevant worldwide annual turnover for specified infringements by VLOPs and VLOSEs.
Does Pakistan have an equivalent Digital Services Act?
Pakistan does not presently operate the same integrated EU-style VLOP systemic-risk regime. Online transactions instead interact with Pakistan’s contract law, the Electronic Transactions Ordinance 2002, consumer and product regulation, intellectual-property law, cybercrime provisions and competition law, depending upon the circumstances. The Electronic Transactions Ordinance remains part of Pakistan’s federal statutory framework for electronic transactions.
Can deceptive online advertising already create liability in Pakistan?
Yes. Section 10 of the Competition Act 2010 prohibits deceptive marketing practices, and the Competition Commission of Pakistan expressly treats false or misleading representations concerning qualities, price, character and other characteristics of goods or services as potentially actionable.
Should Pakistani marketplaces disclose every seller’s private identity documents publicly?
No. Seller verification and public disclosure are distinct questions. A sound regime should require the platform to possess sufficient verified identity information while protecting unnecessary personal data, with appropriate consumer-facing information and lawful disclosure to competent authorities where required.
Are marketplaces responsible for counterfeit goods under Pakistani law?
The answer depends heavily upon the factual role of the marketplace, applicable intellectual-property and consumer law, its own representations and conduct, knowledge, contractual arrangements, and the relief sought. It would be unsafe to assume either automatic platform liability or automatic platform immunity.
The larger jurisprudential question: who created the risk?
The AliExpress case forces us to reconsider an old legal instinct.
Law likes identifiable wrongdoers.
The manufacturer made the defective product.
The seller made the false representation.
The counterfeiter copied the trademark.
Digital systems distribute responsibility more diffusely.
A trader lists the product.
An algorithm recommends it.
A platform profits from the transaction.
A payment service transfers money.
A courier delivers it.
An advertising system retargets the buyer.
A review system creates confidence.
A seller-verification process determines whether anybody knows who the trader really is.
Which actor created the harm?
Sometimes the answer will still be the seller.
But when the same kind of harm occurs millions of times through a system consciously designed and commercially operated by another party, law inevitably begins examining the system itself.
A bazaar is more than the stalls inside it
That is the enduring lesson from the €550 million decision.
An online marketplace would like to be treated as infrastructure when liability arises and as an integrated commercial ecosystem when attracting customers and investors.
Those positions cannot always coexist.
If a platform says:
“Trust our marketplace.”
“Buy with confidence.”
“Recommended for you.”
“Verified seller.”
“Top product.”
“Best seller.”
then the platform is doing more than renting electronic floor space.
It is creating the architecture through which trust is manufactured.
With that power comes responsibility.
Not responsibility for every dishonest act committed by every trader.
Not universal surveillance.
Not absolute product liability.
But responsibility for the systems which only the marketplace itself can control.
That distinction is both fairer and more intellectually coherent.
Europe has moved liability upstream
The most significant thing about the AliExpress decision is therefore not the punishment.
It is the location at which the law intervenes.
Before the dangerous product reaches the child.
Before the counterfeit reaches the consumer.
Before thousands of individual complaints must be litigated.
Before the anonymous seller disappears.
The DSA asks the largest platforms:
What risks does your system predictably create, and what have you done about them?
That is preventative commercial law.
It is also a form of corporate responsibility perfectly suited to digital scale.
Pakistan should watch carefully
Pakistan’s e-commerce market does not need layers of regulation for their own sake.
Businesses already face enough bureaucracy.
What Pakistan does need is intelligent legal architecture capable of distinguishing legitimate innovation from commercial anonymity, and genuine intermediaries from platforms exercising extensive control over transactions while denying corresponding responsibility.
There is an enormous opportunity here.
Pakistan can learn from the European experiment without reproducing all of its complexity.
Seller traceability.
Clear platform roles.
Compliance-friendly interfaces.
Rapid action against dangerous goods.
Protection against counterfeiting.
Fair procedures for sellers.
Transparent advertising.
Preservation of evidence.
Proportionate duties increasing with platform size and control.
These are not hostile ideas.
They are the legal infrastructure of trustworthy digital commerce.
And Pakistan’s businesses should have an interest in that trust.
The question every marketplace should now ask
The useful question is no longer:
“Did we personally sell the illegal product?”
It is:
“What did the marketplace we designed make possible, what did our systems tell us about the resulting risks, and what did we reasonably do once those risks became foreseeable?”
For the largest online platforms operating in Europe, that is now a question with potentially hundreds of millions of euros attached to the answer.
For everyone else, it is a warning about where international digital-commerce regulation is going.
The traditional defence was:
“We are only the marketplace.”
After July 2026, that sentence requires a second question.
What kind of marketplace did you build?
That may ultimately be the more important enquiry.
About the Author
Barrister Aemen Zulfikar Maluka is the founder of Josh and Mak International, an Islamabad-based law practice providing Pakistani and international clients with commercial, regulatory, technology, public-law and cross-border legal advice.
Her international legal commentary focuses particularly upon regulatory developments which may initially appear geographically remote from Pakistan but which have consequences for Pakistani exporters, investors, technology companies, online businesses, foreign companies operating in Pakistan and international businesses dealing with Pakistani counterparties.
Digital marketplaces are a particularly good example of the modern cross-border regulatory problem. The seller may be in Pakistan, the platform headquartered elsewhere, the consumer in Europe, the payment service in another jurisdiction and the intellectual-property owner on another continent entirely. Effective legal advice increasingly requires the ability to see the entire commercial chain rather than treating each jurisdiction in isolation.
Barrister Aemen’s approach is therefore both comparative and practical: what has changed, why does it matter commercially, which liabilities are emerging, and what should businesses do before a regulatory problem becomes litigation?
For further insights, international regulatory commentary, e-commerce and marketplace advice, cross-border commercial strategy or assistance concerning the implications of foreign regulation for businesses connected with Pakistan, contact Barrister Aemen at Aemen@joshandmak.com.
Josh and Mak International
www.joshandmakinternational.com
This article is intended as general legal and regulatory commentary. It does not constitute legal advice concerning AliExpress, any particular marketplace, seller, product or transaction. Marketplace liability is highly dependent upon jurisdiction, contractual structure, factual involvement and the specific legal regime engaged.
Filed Under : AliExpress €550 million fine, AliExpress DSA fine 2026, AliExpress Digital Services Act, EU online marketplace liability, Digital Services Act marketplace rules, DSA illegal products, DSA counterfeit goods, DSA unsafe products, Article 34 DSA systemic risk, Article 35 DSA risk mitigation, Article 30 DSA trader traceability, Article 31 DSA compliance by design, know your business customer marketplace, KYBC online marketplace, online seller verification law, European e-commerce regulation 2026, marketplace counterfeit liability, platform liability counterfeit goods, online marketplace product safety, ecommerce platform legal responsibility, online intermediary liability Europe, VLOP regulation, very large online platform obligations, AliExpress European Commission fine, e-commerce seller verification EU, digital marketplace compliance, recommender systems illegal products, algorithm marketplace liability, algorithmic product recommendations law, marketplace systemic risk, digital platform risk assessment, online product safety regulation, counterfeit goods e-commerce law, fake products marketplace law, online marketplace legal advice, e-commerce lawyer Pakistan, online marketplace Pakistan law, digital marketplace liability Pakistan, counterfeit products Pakistan law, Competition Act 2010 deceptive marketing, section 10 Competition Act Pakistan, electronic transactions Pakistan, Electronic Transactions Ordinance 2002, e-commerce consumer protection Pakistan, online seller fraud Pakistan, Pakistani online marketplace regulation, Pakistan marketplace seller verification, Daraz seller legal issues Pakistan, social media seller legal liability Pakistan, Instagram sellers Pakistan law, Facebook marketplace Pakistan law, COD e-commerce Pakistan, courier e-commerce legal liability Pakistan, platform liability Pakistan, unsafe products online Pakistan, counterfeit products online Pakistan, trademark counterfeit Pakistan, intellectual property marketplace Pakistan, international e-commerce lawyer Pakistan, cross-border marketplace law, Pakistani exporters EU marketplace compliance, EU DSA Pakistan, Pakistani sellers European Union, product compliance European marketplace, international regulatory advisory Pakistan, online platform compliance Pakistan, digital commerce law Pakistan, ecommerce platform terms Pakistan, online consumer disputes Pakistan, marketplace fraud legal advice, product safety e-commerce, AI marketplace regulation, AI recommender legal liability, fake online reviews law, sponsored listing transparency, online marketplace due diligence, digital services regulation Pakistan, marketplace risk management, international technology law Pakistan.
