Accessibility laws · European Union
Web Accessibility Directive (EU) 2016/2102
Work for a European public body and this is the law you actually answer to, not the European Accessibility Act. Directive (EU) 2016/2102 covers the websites and mobile apps of public sector bodies, which means the State, regional and local authorities, and bodies governed by public law. It asks for content that is perceivable, operable, understandable and robust, and the practical target is EN 301 549 V3.2.1, which carries WCAG 2.1 Level AA. It also requires a published accessibility statement written to a template with seven mandatory parts. Every deadline in it has already passed, and somebody checks your site on a schedule without waiting for a complaint.
- Through EN 301 549 V3.2.1
- 2.1 AA
- Mandatory statement blocks
- 7
- Monitoring by your member state
- Annual
- Last application date, now passed
- 2021
What the law is
This directive and the European Accessibility Act are two different instruments that people merge into one, and the difference is who they follow. The EAA regulates a closed list of consumer products and services, and it follows the product wherever it is sold and whoever sells it. This directive regulates a category of organization, and it follows the body whatever the body publishes. So a private e-commerce company can owe the EAA and owe nothing here, and a city council can owe this and owe nothing under the EAA. Where they overlap is the standard. Both run through EN 301 549, which is why the two get confused in the first place.
Public sector body is a defined term and the definition is borrowed rather than written fresh. It means the State, regional or local authorities. It means bodies governed by public law, as that term is defined in the EU's public procurement directive. And it means associations formed by one or more of those, where the association exists to meet needs in the general interest and has no industrial or commercial character. That last clause is doing real work. A body set up by a council to run a commercial trading arm can fall outside it, and a charity delivering a service the State mandated can fall inside it. If the answer matters to your budget, it is a question for a lawyer rather than a website.
Two kinds of body are excluded outright. Public service broadcasters, their subsidiaries, and other bodies with a public service broadcasting remit are out, which was a press freedom decision rather than an accessibility one. So are non-governmental organizations that do not provide services essential to the public and do not provide services specifically addressed to the needs of people with disabilities. Member states may also exclude schools, kindergartens and nurseries, though not the content covering their essential online administrative functions. So the school itself may be out while its enrollment form stays in.
The directive names no WCAG version anywhere, and that is deliberate rather than an oversight. Article 4 asks only that public sector bodies make their sites and apps more accessible by making them perceivable, operable, understandable and robust. The version arrives through a separate route. Content that meets a harmonised standard whose reference the Commission has published in the Official Journal is presumed to conform. The reference published there is EN 301 549 V3.2.1 (2021-03). It has applied since February 12, 2022. Clause 9 of that standard is web content and it carries WCAG 2.1 Level AA. So the answer to what version do we need is two documents deep, and neither of them is the one with the word directive on the cover.
This applies to you if…
- You are the State, a regional authority, or a local authority anywhere in the European Union, or a body governed by public law under the definition in the EU procurement directive. The duty lands on the body, and it reaches your website and your mobile applications together.
- You are an association formed by public authorities or public law bodies to meet needs in the general interest, without an industrial or commercial character. Joint transport authorities, shared service organizations and public consortia commonly land here.
- You are a supplier building or running a public body's website, portal, or app. The obligation belongs to the body and it reaches you through the contract, along with the awkward question of who writes the accessibility statement and who owns the evidence behind it.
- You run an intranet or extranet for a public body, and this is the part most people miss. Intranet and extranet content is excluded only where it was published before September 23, 2019, and only until the site undergoes a substantial revision. Anything published since that date is inside the directive, so a staff portal built in the last few years carries the same standard as the public site.
- You are a private business selling to European consumers, in which case this is the wrong page. Read the European Accessibility Act instead, and note that a member state is free to go further than this directive if it wants to.
What it technically requires
- Your website and your mobile applications have to be perceivable, operable, understandable and robust. Meet EN 301 549 V3.2.1 and you get a presumption of conformity for whatever that standard covers. In practice that means two jobs. Test against WCAG 2.1 Level AA, then handle the parts of the European standard that WCAG never addresses at all.
- You have to publish an accessibility statement, keep it updated, put it in an accessible format, and write it using the Commission's model. It goes on the site itself. For a mobile app it goes on the website of the body that developed the app, or alongside the other information somebody sees before downloading.
- The model statement has seven mandatory blocks and it is a template rather than free prose, so a heartfelt paragraph about your commitment to inclusion satisfies none of it. The blocks are the commitment line naming your body and your national law, the scope of the statement, the compliance status, the non-accessible content, the preparation section, feedback and contact information, and the enforcement procedure. Leave one out and the statement is incomplete on its face, which is the first thing a monitoring body can see without testing a single page.
- Compliance status is one of exactly three answers and you have to pick one. Fully compliant is available only if every requirement of the standard is met without exceptions. Partially compliant means most requirements are met with some exceptions, and the template defines it as not yet fully compliant with the necessary measures still to be taken. Not compliant means most requirements are not met. There is no fourth option and no room to be vague about which one you are.
- Where content is not accessible, you list it under three headed reasons and the headings are fixed. Non-compliance with the national legislation, disproportionate burden, and content outside the scope of the applicable law. The template asks you to describe the failure in non-technical terms where you can. It even supplies the example it wants you to copy. The login form of the document sharing application is not fully usable by keyboard.
- The claims in your statement have to rest on something real. Member states have to make sure the declarations are accurate and based on an actual evaluation of compliance. That evaluation can be your own self-assessment or a third-party one such as a certification, or any other measure giving equal assurance. The statement has to say which method you used. So the statement is not the deliverable. It is the cover sheet on work you have to have actually done.
- Disproportionate burden is available and it is narrower than it sounds. You weigh the size, resources and nature of your body against the estimated costs and benefits, including the benefit to people with disabilities and how often and how long the site gets used. You perform the initial assessment yourself. And if you rely on it, you have to say so in your accessibility statement, name the parts of the requirements you could not meet, and provide accessible alternatives where appropriate. The directive's own reasoning rules out three excuses by name, and they are lack of priority, lack of time, and lack of knowledge.
All roads lead to WCAG. Start with Level AA, the legal standard or the full 55-rule library. Unfamiliar term along the way? The A to Z glossary decodes it.
This law expects a published accessibility statement, and regulators check for it first. Generate yours free →
How it is enforced
Somebody checks, on a schedule, whether or not anybody complains. That is the real difference between this directive and most of what else is on this site. Member states have to monitor compliance using a Commission methodology that combines an in-depth method to verify compliance with a simplified method to detect non-compliance. The first website monitoring period ran from January 1, 2020 to December 22, 2021, and monitoring has been annual since, running from January 1 to December 22 each year. Member states then report the outcome to the Commission, including the measurement data, every three years.
When deficiencies turn up, the member state has to hand them back to you in a usable form. The methodology requires the data and information on your deficiencies to reach you within a reasonable time, in a format that helps you correct them. That is a genuinely unusual design. Most regimes tell you that you failed. This one is built to tell you what to fix.
Each member state names its own enforcement body and its own procedure, and the directive suggests contacting an ombudsman as one shape it can take. The procedure has to cover the accessibility requirements, the disproportionate burden derogation, and the accessibility statement duty, and it has to handle the notifications and requests people send through your feedback mechanism. That means your statement is not just a disclosure. It is the on-ramp to the complaint that follows.
One thing this directive does not do is set penalties. There is no equivalent of the EAA's requirement that penalties be effective, proportionate and dissuasive, and no EU-wide fine schedule to look up. What a member state does about a public body that ignores this is a matter of national law, and it varies. If you need to know what happens in your country specifically, that is a question for a lawyer there.
Key dates
- Sep 23, 2018Transposition deadline: member states had to have the directive in national law, and had to name their monitoring and enforcement bodies
- Sep 23, 2019Applies to websites published on or after September 23, 2018. Intranet and extranet content published on or after September 23, 2019 is in scope too
- Sep 23, 2020Applies to every other public sector website
- Jun 23, 2021Applies to mobile applications. The last of the three application dates
- Feb 12, 2022EN 301 549 V3.2.1 becomes the harmonised standard behind the presumption of conformity, which puts WCAG 2.1 AA at the center of it
What to do about it
Every obligation on this page is measured against WCAG, so the first step is knowing where you actually stand. Run the free 10-page scan for the machine-checkable slice. For the rest, we review the key journeys with an expert and a real blind screen-reader user, then attach a screenshot and a fix to every finding. $499, 5 business days.
Primary sources
Other laws
- United StatesADAWCAG 2.1 AA (Title II rule, de facto standard in Title III cases)
- European UnionEAAAnnex I, EN 301 549 (includes WCAG 2.1 AA)
- United States (federal)Section 508WCAG 2.0 AA (incorporated by the 2017 refresh)
- United States (aviation)ACAAWCAG 2.0 AA, named in 14 CFR 382.43
- United States (telecoms)Section 255WCAG 2.0 A and AA, through the Revised 255 Guidelines
- California, USUnruh ActWCAG 2.1 AA (what courts and settlements expect)
- Manitoba, CanadaManitoba AMAWCAG 2.1 AA (Accessible Information and Communication Standard)
- ArgentinaArgentina Ley 26.653WCAG 2.0, referenced by the law
- ChinaChina PPD LawNo WCAG version named in the law itself
- ColombiaColombia guidelinesWCAG 2.1
- Hong KongHong Kong guidelinesWCAG 2.0
- TaiwanTaiwan 110.07WCAG 2.1 derivative
- Saudi ArabiaSaudi SWAWCAG 2.1 AA
- QatarQatar Law No. 2WCAG 2.1 AA
- United Arab EmiratesUAE requirementsWCAG 2.1 AA
- Ontario, CanadaAODAWCAG 2.0 AA (excl. 1.2.4 & 1.2.5)
- United KingdomUK Equality ActWCAG A and AA, named in PSBAR regulation 9 as amended from time to time
- United States (healthcare)HHS Section 504WCAG 2.1 AA (2024 final rule)
- New York, USNew York HRLWCAG 2.1 AA (what complaints and settlements cite)
- Colorado, USColorado HB21-1110WCAG 2.1 AA (written into state standards)
- Canada (federal)Accessible Canada ActCAN/ASC-EN 301 549 → WCAG 2.1 AA
- NorwayNorway (Universal Design)WCAG 2.0 AA private / 2.1 AA public
- IsraelIsrael IS 5568WCAG 2.0 AA (via IS 5568)
- AustraliaAustralia DDAWCAG 2.2 AA (AHRC 2025 guidance)
- GermanyGermany BFSGEN 301 549 → WCAG 2.1 AA
- FranceFrance RGAARGAA (WCAG-based) / EN 301 549
- ItalyItaly Stanca ActWCAG 2.1 AA (AgID guidelines)
- JapanJapan JIS X 8341-3JIS X 8341-3:2016 = WCAG 2.0 AA
- SpainSpain RD 1112/2018UNE-EN 301549, which incorporates WCAG 2.1 AA
- NetherlandsNetherlandsEN 301 549, which incorporates WCAG 2.1 AA
- IrelandIrelandEN 301 549, which incorporates WCAG 2.1 AA
- BrazilBrazil LBIeMAG, aligned with WCAG, plus ABNT NBR 17225 for web content
- IndiaIndia RPwDGIGW 3.0, which references WCAG 2.1
- New ZealandNew ZealandWCAG 2.2 Level AA
- South KoreaSouth KoreaKWCAG 2.2, a national standard aligned with WCAG
- SwitzerlandSwitzerland BehiGeCH-0059, which references WCAG 2.1 AA
- DenmarkDenmarkEN 301 549, which incorporates WCAG 2.1 AA
Related on this site
What to read next, and the terms this page uses.
Orientation only, current as of August 2026. Not legal advice, and no attorney-client relationship is created. For your specific situation, talk to your own lawyer.