Image description: A round black sign with an illuminated border displays neon-style icons and text reading "EAA" with an accessibility symbol—highlighting European Accessibility Act compliance—and "GDPR" with a padlock, set against red curtains.
Why the EAA is the new GDPR
Reading Time: 4 minutes
The European Union’s General Data Protection Regulation (GDPR) revolutionized data privacy when it came into force in 2018. Suddenly, organizations had to rethink how they collected, stored, and shared personal data. Those who prepared early by rewriting policies, training staff, and redesigning systems weathered the change well, while late adopters scrambled to avoid penalties.
Today, a similar compliance wave is here – the European Accessibility Act (EAA). The Act came into force on 28 June 2025, and enforcement is already underway across EU member states. Companies that treat accessibility as an afterthought face both reputational damage and legal liability. In contrast, those that apply the lessons of GDPR and act now will be in a stronger position as enforcement accelerates.
The new era of European Accessibility Act compliance
GDPR enforcement proved that regulators are willing to impose substantial penalties on companies that ignore user rights. In May 2023 the European Data Protection Board fined Meta Platforms Ireland €1.2 billion – the largest GDPR penalty to date – for repeatedly transferring EU-resident Facebook data to U.S. servers in violation of EU law.
The Hamburg Data Protection Commissioner fined clothing retailer H&M €35.3 million in 2020 after managers secretly recorded employees’ personal circumstances and used that information for employment decisions. In July 2021 Luxembourg’s data regulator hit Amazon with a €746 million fine for processing users’ data without valid consent.
Companies that failed to implement adequate security measures also faced punishment. British Airways was fined £20 million for a 2018 data breach that exposed the personal and financial details of more than 400 000 customers. The UK Information Commissioner’s Office determined that the airline neglected basic security practices such as multi-factor authentication and network monitoring.
These cases show that GDPR is not a paper tiger – regulators can and will enforce the law. The reputational damage and compliance costs often far exceeded the fines themselves. The same pattern is now emerging with EAA compliance. Unlike GDPR, where most violations happened behind the scenes in how data was stored or transferred, accessibility gaps are visible to anyone. A missing alt text, a form that can’t be completed without a mouse, or a checkout button that screen readers can’t reach – all of these failures are instantly obvious to users and advocacy groups. This visibility makes EAA breaches harder to conceal and easier to report, which in turn drives stronger and faster enforcement compared to GDPR.
What is the European Accessibility Act?
The European Accessibility Act (Directive 2019/882) is the EU’s answer to digital inclusion. It harmonises accessibility requirements across member states for many everyday products and services, including ATMs, ticketing and check-in machines, consumer computers, smartphones, e-readers, payment terminals, telephony services, audiovisual media, bank services, e-books, e-commerce websites, and emergency communications.
Products and services placed on the EU market after 28 June 2025 must meet these requirements, though there is a transition period until 28 June 2030 and self-service terminals installed before the deadline may remain until the end of their economic life. Microenterprises are generally exempt, but any organisation selling covered products or services to EU consumers needs to understand the Act’s scope.
Much like the GDPR, the EAA is not a single law but a directive implemented through national legislation. This means each country defines its own enforcement mechanisms and penalties, and early cases already show regulators are prepared to act.
Concrete cases of EAA enforcement
The impact of European Accessibility Act compliance is already visible. In May 2024, the Administrative Court of Paris issued a key ruling on Pronote, a school management platform widely used across France. The case, brought by the association apiDV, confirmed that public schools using Pronote must comply with accessibility obligations under French law. The court annulled the State’s refusal to act and instructed the regulator ARCOM to investigate compliance. Importantly, the ruling reaffirmed that non-compliant digital services can face administrative fines of up to €25 000 per year, per service, until accessibility requirements are met. In this case, the State was ordered to pay €1 500 to the claimant association.
A few months later, in July 2025, four of France’s largest grocery retailers – Auchan, Carrefour, E. Leclerc, and Picard – received formal notices demanding that their websites and mobile apps meet accessibility standards by September 1, 2025. The complaints highlighted that the platforms failed to support screen readers, blocked keyboard navigation, and excluded blind users from “click & collect” services. If corrective action is not taken, these companies risk escalating sanctions, public scrutiny, and fines similar to those already seen in other sectors.
Together, these cases signal that accessibility barriers are no longer regarded as minor technical oversights but as acts of discrimination under EU law. They also highlight that EAA compliance is not optional – it is being actively monitored and enforced.
The reality of ignoring accessibility in the EU
All EU countries have taken equally firm stances. Italy’s accessibility legislation – the Stanca Act and its subsequent amendments – requires businesses covered by the law to comply within 90 days of receiving a notice. Companies previously subject to the Stanca Act face fines up to 5 % of their annual turnover if they fail to meet accessibility requirements; other companies may be fined up to €40 000.
France’s transposition law treats non-compliance as a Class 5 offence and can impose €50 000 fines plus €25 000 for failing to publish accessibility statements. Germany’s Accessibility Strengthening Act imposes fines up to €100 000 for selling non-compliant products and €10 000 for providing incorrect information about the accessibility of products and services.
These national penalties may seem modest compared with GDPR’s billion-euro fines, but they illustrate that EU regulators will not hesitate to penalize non-compliant organizations. Companies that ignore EAA compliance are likely to face both legal action and negative publicity.
Applying GDPR lessons to accessibility
The parallels between GDPR and the EAA are striking. Both require organizations to embed compliance into their processes rather than bolting it on at the last minute. GDPR taught that:
- Compliance is continuous. Data protection compliance involves ongoing monitoring, risk assessments, and documentation. Similarly, accessibility compliance requires regular audits, user testing, and updates as products evolve.
- Design matters. Under GDPR, privacy by design and by default became standard practice. For the EAA, accessibility by design means integrating the Web Content Accessibility Guidelines (WCAG 2.2 and beyond) and the harmonized standard EN 301 549 into product development from concept to launch.
- Transparency builds trust. Clear privacy notices and consent practices helped organisations avoid fines. For accessibility, transparency involves publishing accessibility statements, providing feedback mechanisms for users with disabilities, and documenting efforts to improve.
- Training and culture are essential. GDPR showed that staff at all levels needed training on data protection. Similarly, accessibility requires training for designers, developers, product managers, and procurement teams so that inclusive design becomes part of the company culture.
- Documentation matters. Privacy programs rely on records of processing activities. For the EAA, organizations should document accessibility audits, remediation plans, and evidence of fixes. This documentation can demonstrate good faith if regulators investigate.
By viewing accessibility as a fundamental user right, organizations can avoid the last-minute panic that plagued many GDPR projects. Those who built strong privacy cultures gained reputational benefits and customer trust. Similarly, acting early on EAA compliance positions companies ahead of enforcement.
The future of European Accessibility Act compliance
Just as GDPR transformed the way organizations approach data protection, the European Accessibility Act is reshaping how digital products and services are designed and delivered. Enforcement has already begun, and companies that delay will face not only financial penalties but also lasting reputational harm.
By embedding accessibility into strategy and culture now, businesses can avoid last-minute compliance scrambles, reach millions of new customers, and demonstrate genuine respect for user rights. EAA compliance is not only a legal requirement – it is a core driver of trust, inclusion, and long-term competitiveness in the EU market.
Read more about the accessibility services that we offer.
EAA has been effective since June 28, 2025.
