Guide
The European Accessibility Act for online shops
The Act never mentions WCAG, never mentions WordPress, and does not give your website until 2030. Here is what it does say — article by article — and what a shop owner has to do about it.
By the end of this page you will be able to say, with the article numbers to hand, whether your shop is in scope, what date applied to you, whether the micro-enterprise exemption covers you, which standard your national authority is likely to measure you against, what the disproportionate-burden route actually costs you in paperwork, and what happens if someone complains. Everything below is drawn from the text of Directive (EU) 2019/882 as published in the Official Journal of 7 June 2019, and from the W3C specification the Directive’s language points at without naming.
What the Act actually says about an online shop
The Directive covers a fixed list of services. Article 2(2) opens by stating that it applies to the listed services provided to consumers after 28 June 2025, and point (f) of that list is, simply, e-commerce services.
Article 3(30) defines e-commerce services as services provided at a distance, through websites and mobile device-based services, by electronic means and at the individual request of a consumer, with a view to concluding a consumer contract. Read that definition slowly, because three things follow from it. Your website is the service — not a shop window in front of it. A mobile app that takes orders is in scope on the same footing. And the trigger is the intention to conclude a consumer contract, so a catalogue that quotes and takes payment counts, whether the basket is called a basket or an enquiry.
The obligations themselves sit in Annex I. Article 4(3) requires all services to meet the general requirements in Section III and the additional requirements in Section IV. For a shop, three provisions carry nearly all of the weight:
- Annex I, Section III(c) requires making websites, including related online applications, and mobile device-based services accessible in a consistent and adequate way by making them perceivable, operable, understandable and robust. Those four words are the four WCAG principles, verbatim.
- Annex I, Section III(b) requires information about the functioning of the service to be available via more than one sensory channel, presented in ways users can perceive, in text formats that can generate alternative formats, in fonts of adequate size with sufficient contrast and adjustable spacing, and with non-textual content supplemented by an alternative presentation.
- Annex I, Section IV(g) adds the e-commerce specifics: providing accessibility information about the products and services being sold where the responsible economic operator supplies it; ensuring that the functionality for identification, security and payment, where it is delivered as part of a service rather than as a product, is perceivable, operable, understandable and robust; and providing identification methods, electronic signatures, security and payment services that are perceivable, operable, understandable and robust.
That last point is the one that should make a merchant sit up. The Act singles out identification, security and payment — the exact three steps where an inaccessible field stops being an inconvenience and becomes a lost order. A product page that fails is a bad experience. A checkout that fails is a refusal to trade.
Who is in scope, including sellers outside the EU
Article 3(4) defines a service provider as any natural or legal person who provides a service on the Union market or makes offers to provide such a service to consumers in the Union. There is no establishment test, no turnover floor beyond the micro-enterprise definition, and no carve-out for marketplace sellers or drop-shippers.
The recitals reinforce the breadth: the e-commerce accessibility obligations are intended to apply to the online sale of any product or service, including the online sale of a product or service that is itself covered by the Directive in its own right. So a store selling e-readers online is in scope twice over — once for the site, once for the device.
Selling from outside the EU
A shop in Leeds, Sydney or Ohio that ships to Dublin and takes payment in euros is making offers to provide an e-commerce service to consumers in the Union. On the face of Article 3(4), that is a service provider. What the Directive does not do is explain how a Member State reaches an operator with no EU establishment; that is left to each country’s transposing law and to the authorities designated under Article 23(2). If you sell into the EU and you are not established there, the honest position is that you are within the definition and outside the easy enforcement path — which is a commercial risk assessment, not an exemption.
The dates, and the two transitions that are not extensions
Article 31 sets the timetable in two lines: Member States had to adopt and publish the transposing laws by 28 June 2022, and they apply those measures from 28 June 2025. Article 2(2) then attaches the obligation to services provided to consumers after that same date. There is no phase-in for websites.
Article 32 provides two transitional measures, and both are routinely misread as a reprieve for websites. They are not.
| Provision | What it actually covers | Latest date |
|---|---|---|
| Article 31(1) | Member States adopt and publish transposing measures | 28 June 2022 |
| Article 31(2) | Member States apply those measures; Article 2(2) obligations bite for services provided after this date | 28 June 2025 |
| Article 32(1), first subparagraph | Continuing to provide services using products lawfully used to provide similar services before the application date | 28 June 2030 |
| Article 32(1), second subparagraph | Service contracts agreed before the application date may continue unaltered until they expire | Five years from 28 June 2025 |
| Article 32(2) | Self-service terminals lawfully in use before the application date may run to the end of their economically useful life | Capped at 20 years from entry into use |
| Article 33(1) | Commission reports on the application of the Directive, then every five years | 28 June 2030 |
The load-bearing word in Article 32(1) is products. Article 3(2) defines a product as a substance, preparation or good produced through a manufacturing process. A website is not a good produced through a manufacturing process. The 2030 window exists so that a bank does not have to rip out working hardware and a transport operator does not have to scrap ticket machines; it does not license an inaccessible checkout for another five years. Article 13(3) points the same way, requiring service providers to have procedures in place so that provision of the service remains in conformity as the service, the requirements and the referenced standards change.
The micro-enterprise exemption, precisely
This is the single most consequential provision for small shops, and it is narrower and stranger than the summaries suggest.
Article 3(23) defines a micro-enterprise as an enterprise which employs fewer than ten persons and which has an annual turnover not exceeding EUR 2 million or an annual balance sheet total not exceeding EUR 2 million. The headcount is a hard gate; the money test is satisfied by either limb.
Article 4(5) then says that micro-enterprises providing services are exempt from complying with the accessibility requirements referred to in Article 4(3) and from any obligations relating to compliance with those requirements. Article 4(3) is the paragraph that pulls in both Annex I Section III and Section IV — so a genuine micro-enterprise service provider is out of the substantive requirements and out of the assessment and documentation machinery that surrounds them. The recitals are explicit about why: demanding a proportionality assessment from a micro-enterprise would itself be a disproportionate burden.
Article 4(6) obliges Member States to provide guidelines and tools to micro-enterprises to help them apply the national transposing measures, developed in consultation with stakeholders. The Directive encourages exempt micro-enterprises to comply anyway, and it is worth noticing why that is not merely pious: an inaccessible checkout excludes paying customers regardless of who is legally obliged to fix it.
Testing the threshold honestly
Three cautions, each traceable to a published text. First, the exemption is for services — Article 14(4) shows that micro-enterprises dealing with products have a different, lighter treatment, not an exemption. Second, the recitals require that micro-enterprises genuinely fulfil the criteria of Commission Recommendation 2003/361/EC and the relevant case law, aimed at preventing circumvention: a group structure split into nine-person entities is the circumvention that language anticipates.
Third, the exemption is a moving state — and the Directive alone will not tell you how fast it moves. Article 3(23) sets the gate at fewer than ten persons, and Article 4 writes no grace period for crossing it. But the recital that requires micro-enterprises to genuinely fulfil Commission Recommendation 2003/361/EC pulls that Recommendation’s own timing rule into the reading. Article 4(2) of its Annex provides that where an enterprise finds at the date of closure of the accounts that it has exceeded or fallen below the headcount or financial ceilings, that does not result in the loss or acquisition of micro-enterprise status unless the ceilings are exceeded over two consecutive accounting periods.
So a tenth employee in one good year is not, on that reading, the end of the exemption. For a shop owner that has two practical consequences. The status question is answered at your accounting year end, not on the day you sign a contract, which means the answer can change under you while nothing about the website has changed. And because the recital puts the burden on you to show you genuinely fulfil the criteria, the headcount and the turnover or balance sheet figure are worth recording deliberately at each year end, with the date, rather than reconstructing them the week an authority asks. That record costs nothing to keep and is the whole of your answer to the only question that decides whether any of the rest of this section applies to you.
What is out of scope even on an in-scope site
Article 2(4) lists content that the Directive does not apply to, and it is unusually practical:
- pre-recorded time-based media published before 28 June 2025;
- office file formats published before 28 June 2025;
- online maps and mapping services, provided essential information is given in an accessible digital manner for maps intended for navigational use;
- third-party content that is neither funded, developed by, nor under the control of the economic operator concerned;
- website and mobile application content qualifying as archives, meaning content not updated or edited after 28 June 2025.
Two of these get abused. The third-party exclusion requires all three of not funded, not developed by you, and not under your control — a review widget you pay for and configure fails that test. And the archive exclusion evaporates the moment you edit the page. A legacy product range you still sell is not an archive.
EN 301 549, WCAG, and how a standard becomes the yardstick
The Directive names no technical standard. Instead, Article 15(1) grants a presumption of conformity to products and services conforming to harmonised standards, or parts of them, the references of which have been published in the Official Journal of the European Union, in so far as those standards cover the requirements. Article 15(3) gives the Commission a fallback route to establish technical specifications by implementing act where a harmonised standard is missing or delayed.
So the practical question for any store is which standard the authority checking you is working from. In EU accessibility law the answer for ICT is EN 301 549. Commission Implementing Decision (EU) 2021/1339, published in the Official Journal of 12 August 2021, cites EN 301 549 V3.2.1 (2021-03), Accessibility requirements for ICT products and services, as the harmonised standard for Directive (EU) 2016/2102 — the parallel directive covering public sector websites and mobile applications. W3C/WAI records that EN 301 549 includes WCAG 2.1 Level AA verbatim without modifications for web content, and WCAG 2.0 Level AA as interpreted by WCAG2ICT for non-web documentation and software.
Follow the chain and you arrive where every serious practitioner already sits: WCAG 2.1 Level AA is the working technical target, because it is the thing the European standard restates word for word, and because “perceivable, operable, understandable and robust” in Annex I is the WCAG principle set. That is an inference from two published documents, not a sentence in the Act, and it deserves to be described as such.
WCAG 2.2, whose current W3C Recommendation is dated 12 December 2024, is additive: the specification states that content conforming to WCAG 2.2 also conforms to WCAG 2.0 and WCAG 2.1. Building to 2.2 therefore satisfies a 2.1 requirement and dates less quickly. It is the sensible target for new work.
Disproportionate burden is a file, not a feeling
Article 14 is the escape valve, and merchants consistently underestimate what using it costs.
The accessibility requirements apply only to the extent that compliance does not require a significant change resulting in the fundamental alteration of the basic nature of the service, and does not impose a disproportionate burden on the operator. Then the obligations start:
- Article 14(2): you must carry out an assessment of whether compliance would introduce a fundamental alteration or, based on the relevant criteria set out in Annex VI, impose a disproportionate burden. Note where Annex VI attaches: it supplies the criteria for the burden limb, not for the fundamental-alteration limb.
- Article 14(3): you must document it, keep all relevant results for five years from when the service was last provided, and hand a copy to the authority on request.
- Article 14(5): if you rely on disproportionate burden, you must renew the assessment for each category or type of service when the service is altered, when the authority asks, and in any event at least every five years.
- Article 14(6): if you have received funding from any source other than your own resources for the purpose of improving accessibility, you may not rely on disproportionate burden at all.
- Article 14(8): when you rely on Article 14(1) for a specific service, you must send information to that effect to the authority responsible for checking compliance of services in the Member State where the service is provided. That subparagraph does not apply to micro-enterprises.
Annex VI sets out what the assessment must weigh: the ratio of the net costs of compliance to the overall operating and capital costs of providing the service; the estimated costs and benefits for the operator in relation to the estimated benefit for persons with disabilities, taking into account the amount and frequency of use; and the ratio of the net costs of compliance to the operator’s net turnover. It then enumerates the cost elements you may count, from one-off costs of understanding the legislation and training staff through to the ongoing cost of testing and documentation.
Put plainly: claiming disproportionate burden for a WooCommerce store means building a costed file, notifying a regulator that you are relying on it, and rebuilding that file at least every five years. For most of the defects an automated scan finds — a missing language attribute, an unlabelled field, an alt text — assembling the file costs more than applying the fix.
What enforcement looks like
There is no EU-level fine schedule. Enforcement is national, and the Directive prescribes its shape in three articles.
Article 23 requires each Member State to establish, implement and periodically update procedures to check the compliance of services, to follow up complaints or reports of non-compliance, and to verify that the operator has taken the necessary corrective action. Member States designate the responsible authorities and must inform the public of their existence, responsibilities, identity, work and decisions, making that information available in accessible formats on request.
Article 29 requires adequate and effective means to ensure compliance, and specifies two of them: a consumer may take action under national law before the courts or the competent administrative bodies to enforce the transposing provisions; and public bodies, private associations, organisations or other legal entities with a legitimate interest may act before those courts or bodies on behalf of, or in support of, a complainant with their approval. That second limb is the one that changes the risk profile — it means a disability organisation can carry a case a lone consumer would never bring.
Article 30 requires Member States to lay down penalty rules for infringements of the transposing provisions. The penalties must be effective, proportionate and dissuasive, and must be accompanied by effective remedial action in the case of non-compliance. Article 30(4) says penalties shall take into account the extent of the non-compliance, including its seriousness, the number of units of non-complying products or services concerned, and the number of persons affected. Both Article 29 and Article 30 exclude procurement procedures governed by Directives 2014/24/EU and 2014/25/EU.
Two things follow. Because the penalty scales are national, the number a merchant needs is the one in their own transposing statute, not a figure quoted in a blog post. And because Article 30(4) counts the number of persons affected, a defect templated across every product page is treated as bigger than the same defect on one page — which is exactly how a WordPress theme distributes its mistakes.
The accessibility information you owe the public
This obligation is quietly separate from making the site work. Fixing the code goes to Article 13(1), which is about how you design and provide the service. It does not discharge Article 13(2), which asks for a written account of how the service meets the requirements — a different deliverable, with its own home and its own retention period.
Article 13(2) requires service providers to prepare the information set out in Annex V and to explain how the service meets the applicable accessibility requirements. The information must be made available to the public in written and oral format, including in a manner accessible to persons with disabilities, and kept for as long as the service is in operation.
Annex V says where it goes and what it contains: the assessment of how the service meets the Article 4 requirements belongs in the general terms and conditions, or an equivalent document, and must include a general description of the service in accessible formats, the descriptions and explanations needed to understand how the service operates, and a description of how the relevant Annex I requirements are met. Annex V point 3 adds that you must provide information demonstrating that the service delivery process and its monitoring ensure ongoing compliance.
Article 13(4) closes the loop: where the service is not compliant, you must take the corrective measures necessary and immediately inform the competent national authorities of the Member States where the service is provided, with details of the non-compliance and of the corrective measures taken.
What a store owner should actually do
Work in this order. It is the order that removes the most exclusion for the least money.
1. Establish whether you are exempt, in writing. Headcount and either turnover or balance sheet total, against Article 3(23), recorded with a date. If you are a micro-enterprise, everything below is commercial rather than legal — and still worth doing, because the checkout defects cost you orders.
2. Find out what is actually broken. Run a crawl that renders JavaScript, because a WooCommerce checkout assembled client-side is invisible to anything that only reads source HTML. Our free scan does this and returns evidence per issue, per page. The engine runs axe-core 4.12.0 with 100 rules in scope alongside vendored HTML_CodeSniffer and ACE checks, tracking 55 success criteria at Levels A and AA across WCAG 2.0, 2.1 and 2.2.
3. Fix the deterministic defects first. Three of them are mechanical fixes a developer can make with confidence, and all three touch checkout.
The page language, Success Criterion 3.1.1, is one attribute that governs how a screen reader pronounces every word on the page. The criterion itself asks only that the default human language of the page can be programmatically determined; technique H57 is the sufficient technique W3C documents for meeting it — a lang attribute on the html element carrying a valid language tag. In a WordPress theme, one function emits it correctly, including text direction:
<!doctype html>
<html <?php language_attributes(); ?>>
Fields need real labels and a stated purpose. A placeholder is not a label — it disappears the moment someone starts typing, and it satisfies neither the programmatic association behind SC 1.3.1 nor the labels-or-instructions requirement of SC 3.3.2. SC 1.3.5 then asks that the purpose of each field collecting information about the user can be programmatically determined, for the field purposes W3C enumerates — which is what an autocomplete token supplies, and what technique H98 documents as sufficient. Browsers and assistive software use it to pre-fill and re-describe the field:
<!-- Before: a placeholder standing in for a label, and no stated purpose -->
<input type="text" name="billing_first_name" placeholder="First name">
<!-- After: associated label, plus a machine-readable purpose -->
<label for="billing_first_name">First name</label>
<input type="text" id="billing_first_name" name="billing_first_name"
autocomplete="given-name">
Where a theme or plugin has stripped a WooCommerce checkout label, the documented woocommerce_checkout_fields filter puts it back without touching the template:
add_filter( 'woocommerce_checkout_fields', function ( $fields ) {
// A theme removed the visible label and left a placeholder in its place.
$fields['billing']['billing_first_name']['label'] = 'First name';
return $fields;
} );
The three fix pages behind those examples are document language, form labels and autocomplete on checkout fields.
4. Route the judgement calls to a person. Three of the ten families are never changed on software’s own authority. Colour contrast is a measurable failure with a brand-owned remedy, so a human approves the replacement value. Landmark structure depends on what the page is actually for. Ambiguous link text means rewriting copy, which is an editorial decision. Those three go to a review queue. Alt text runs the other way — it is generated, re-validated and then applied, and it stays reviewable afterwards, which matters most on a product catalogue where the wrong description is worse than none.
5. Write the Annex V information and put it in your terms. Not a badge. A description of how the service meets the requirements, in an accessible format, kept current for as long as the shop trades.
6. Get the rest audited by people. Sixteen of the 55 criteria we track cannot be judged by any scanner: focus order, error suggestion, consistent navigation, status messages, pointer gestures and the rest. No software certifies conformance, ours included — a human audit is what covers those sixteen, and a qualified human auditor is what issues a conformance certification, against a named standard, for a named scope, on a named date.
Where automation stops, and why we say so
Of the 55 criteria in our catalogue, 31 are Level A and 24 are Level AA. Thirty-nine have automated coverage; 16 are audit-only. And for all 39, the coverage is partial by definition — an automated check demonstrates that a specific element fails; passing is a different kind of claim, because most criteria turn on what the content means: whether that alt text describes the right thing, whether the focus order matches the visual order, whether the error message tells someone how to correct the mistake.
Our engine groups its remediation into ten fix families. Seven are applied automatically; three route to a human review queue rather than being changed silently.
| Fix family | Handling | Why |
|---|---|---|
| Document language | Automatic | Deterministic — one attribute, one correct value |
| Skip link | Automatic | Deterministic — insert and verify target |
| Autocomplete tokens | Automatic | Deterministic — field purpose maps to a published token |
| Image alt text | Automatic | Generated, then re-validated; catalogue text stays reviewable |
| Empty links, empty buttons, form labels | Automatic | Generated name, re-validated after applying |
| Colour contrast | Review queue | Measurable failure, brand-owned remedy |
| Landmark structure | Review queue | Correct structure depends on the page’s intent |
| Ambiguous link text | Review queue | Rewriting copy is an editorial decision |
Fixes are applied server-side in the page’s own markup — how the engine works sets out the mechanism. Nothing is layered over the top of a broken page at runtime, because an overlay leaves the underlying code exactly as non-compliant as it was and leaves nothing for an auditor to inspect.
The boundary is the honest part of the offer, and it maps cleanly onto the Directive. Software can find defects, apply the deterministic ones, evidence what changed and keep watching as the shop changes — which is precisely the standing obligation Article 13(3) imposes. What software cannot do is form the human judgement that Article 13(2) asks you to write down, or the assessment Article 14 asks you to defend. People do that part.
On this subject
The fixes this guide refers to:
- Missing document language
- Form fields with no label
- Checkout fields missing an autocomplete purpose
- Images without alternative text
- Text that fails colour contrast
- Landmark structure problems
- Ambiguous link text
The other guides
- WooCommerce accessibility, end to end
- WCAG 2.2 Level AA, for people who run shops
- The checkout, in detail
- Alt text for product images, done properly
- The accessibility statement, written so it survives scrutiny
- Every fix family, with what we do about it
- How the detect → fix → prove → keep loop works
- When a human audit is the honest answer
Sources
- Directive (EU) 2019/882 (European Accessibility Act), full text on EUR-Lex (2019-06-07)
- Directive (EU) 2019/882, Official Journal PDF — Articles 23 to 33 and Annexes I, V and VI (2019-06-07)
- EUR-Lex summary — accessibility requirements for products and services (2019-09-10)
- Commission Recommendation 2003/361/EC — SME definition; Annex Article 4(2), change of status over two consecutive accounting periods (2003-05-20)
- Commission Implementing Decision (EU) 2021/1339 — harmonised standard EN 301 549 V3.2.1 (2021-08-12)
- Web Content Accessibility Guidelines (WCAG) 2.2, W3C Recommendation (2024-12-12)
- W3C WAI — Web Accessibility Laws and Policies: European Union (2025-07-23)
- W3C technique H57: Using the language attribute on the html element (2026-01-12)
- W3C technique H98: Using HTML autocomplete attributes (2026-01-12)
Written by the Klarvo Access team. Published 2026-08-04.
FAQ
Questions this raises
Does the European Accessibility Act require WCAG 2.1 AA?
Not in those words. The Directive names no standard. Article 15 says products and services conforming to harmonised standards whose references have been published in the Official Journal are presumed to conform to its accessibility requirements, and Annex I requires websites to be perceivable, operable, understandable and robust — the four WCAG principles. EN 301 549 is the harmonised standard used in EU accessibility law for ICT, and W3C/WAI records that it includes WCAG 2.1 Level AA verbatim for web content. WCAG 2.1 AA is therefore the working technical target, not a literal quotation from the Act.
I am a small shop outside the EU. Am I really in scope?
Article 3(4) defines a service provider as any natural or legal person who provides a service on the Union market or makes offers to provide such a service to consumers in the Union. That definition is written to reach sellers established outside the EU who offer to sell to EU consumers. How any single Member State pursues an operator established elsewhere is a matter of that country's transposing law and its designated authority under Article 23, and the Directive does not answer that question.
My business has eight people. Am I exempt?
Possibly, and the test is precise. Article 3(23) defines a micro-enterprise as one employing fewer than ten persons and having either an annual turnover not exceeding EUR 2 million or an annual balance sheet total not exceeding EUR 2 million. Article 4(5) exempts micro-enterprises providing services from the accessibility requirements and from obligations relating to compliance with them. The exemption covers services; if you also manufacture, import or distribute products in scope, that is a separate regime with lighter but real obligations.
Can a scan tell me whether my shop complies?
No, and no honest tool claims otherwise. Our engine tracks 55 success criteria at Levels A and AA across WCAG 2.0, 2.1 and 2.2; 39 have automated coverage and 16 can only be judged by a person. Even for the 39, coverage is partial by nature — an automated check can prove a specific failure exists, never prove a criterion passes. No scan issues a conformance certification, ours included — that comes only from a qualified human auditor, against a named standard, for a named scope, on a named date. That is what the audit is for.
Does the transition to 2030 buy my website more time?
No. Article 32(1) provides a transitional period ending 28 June 2030 during which service providers may continue providing services using products lawfully used before the application date, and Article 3(2) defines a product as a substance, preparation or good produced through a manufacturing process. A website is not a product. The 2030 window covers hardware such as terminals, and Article 32(2) allows Member States to let self-service terminals run to the end of their economically useful life, capped at 20 years from entry into use.
Scan the store this applies to.
Three engines, nine probes, your real pages — home, product, populated basket, hydrated checkout. Free, no signup, and the findings are yours whether or not you buy anything.