--- id: RISK-POL-0011 type: legal-policy title: "Accessibility of digital services" regime: "BFSG (European Accessibility Act, Directive 2019/882), EN 301 549 / WCAG" status: dormant activates_when: "a consumer-facing digital service or product is offered in Germany — e-commerce, banking, e-books, ticketing, or a consumer app" owner: risk-nexus written: "2026-08-20" cadence: 1h clean_streak: 1 last_checked: "2026-09-22T06:26:29Z" next_check: "2026-09-22T07:26:29Z" checked_by: "worsch" --- # RISK-POL-0011 — accessibility **Dormant, and the most likely of the dormant set to activate.** The estate has a consumer domain and design work in it; the day any of that is offered to consumers in Germany, this applies in full and without a grace period for new services. ## Why it is written before it is needed Accessibility cannot be retrofitted cheaply. It constrains component choice, colour, focus handling, form semantics and content structure — decisions taken early and expensively reversed. A policy retrieved at launch is a rebuild; a policy read at design time is a constraint like any other. That is the whole argument for this catalogue existing, and this is the entry that demonstrates it. ## What it requires, in outline - Conformance to the harmonised standard (EN 301 549, which carries WCAG at level AA) for the service's interface, and for its documentation and support. - An **accessibility statement**, published, saying what conforms and what does not. - Accessibility considered in the product's own conformity assessment, with records kept. Micro-enterprises providing services are outside scope, which is a real exemption and also a fragile one to build on — it disappears with headcount or turnover, and the product does not become accessible by growing. ## What it requires of systems Design-time, not launch-time: semantic markup, keyboard operability, contrast and focus visibility, form labelling and error identification, no information-by-colour-alone, captions and alternatives for media. Plus a way to **test** these that runs before release rather than at it. ## Evidence that would show this is met A conformance assessment against EN 301 549; a published accessibility statement; automated and manual test results in the release path. Nothing here binds any repo today. `whynot-design` and the consumer-domain repos are where it will land, and naming the owner is theirs, not the register's. **2026-09-22 review.** The policy stays dormant. No consumer-facing digital service offered in Germany is on record. The micro-enterprise exemption for services is still the fragile basis described above. ## Reviews - **2026-09-22** — clean check: Dormant: no consumer-facing service on record. Cadence instant → 1h (1 clean in a row); next check 2026-09-22 07:26Z.