What Is the European Accessibility Act?
The European Accessibility Act (EAA), formally Directive (EU) 2019/882, requires a broad range of products and services to be accessible to people with disabilities. Its obligations have applied to consumer services since 28 June 2025, and it reaches deep into the digital economy. E-commerce, banking, e-books, transport booking, and electronic communications all fall under it. For website and app operators, that changes things: accessibility is no longer just good practice, it's a condition for reaching the market, and national authorities across the EU enforce it.
Who Must Comply and What Is Required
The rules bind manufacturers, importers, and service providers that offer in-scope products or services to consumers in the EU. That includes companies based outside the Union, since what counts is the market you serve. Microenterprises that provide services are exempt, but only just: the exemption covers companies with fewer than ten employees and limited turnover. The EAA doesn't invent its own technical rules. Conformity is measured against harmonized standards, chiefly EN 301 549, which for web content builds on WCAG 2.1 Level AA. Each member state writes the directive into national law. Germany, for example, did so through the Barrierefreiheitsstärkungsgesetz (BFSG). Member states also name the authorities that investigate complaints, order fixes, and impose penalties.
Where Verification Flows Come In
The EAA covers a service from end to end, and that includes its security gates. Picture an online shop with fully accessible product pages but a checkout that throws up an inaccessible verification puzzle. The barrier sits at the exact point a customer needs to finish the purchase, which is precisely what the directive set out to remove. Identification, login, and payment are all part of the accessible experience the law expects. That turns third-party verification widgets into a compliance dependency: you chose the component, so you answer for the barrier it creates, and the accessibility of your bot-detection provider becomes part of your own conformity.
Meeting the Requirement in Practice
For the verification step, the practical answer is invisible-first protection. Risk checks run in the background, so most customers pass without doing anything. Any challenge that remains has to work with a keyboard, work with screen readers, and never depend on solving a visual puzzle. That's the approach CaptchaFox takes, built to meet WCAG requirements so the verification gate doesn't undermine an otherwise accessible service. When you run an EAA audit, include the whole journey: login, forms, checkout, and every security check along the way. Our article on CAPTCHAs and accessibility digs into this intersection in more depth.
About CaptchaFox
CaptchaFox is a GDPR-compliant solution based in Germany that protects websites and applications from automated abuse, such as bots and spam. Its distinctive, multi-layered approach utilises risk signals and cryptographic challenges to facilitate a robust verification process. CaptchaFox enables customers to be onboarded in a matter of minutes, requires no ongoing management and provides enterprises with long-lasting protection.
To learn more about CaptchaFox, talk to us or start integrating our solution with a free trial.