# EU Website Compliance Checklist (EAA + GDPR)

A practical, one-afternoon checklist across the four areas small businesses get fined, ordered or sued over: accessibility, legal pages, cookie consent and basic security. Written by Nikola Lalovic (belikenikola.com). General information, not legal advice.

Score it if you like: tick what passes, count the gaps, fix the ones marked **critical** first.

---

## 1. Accessibility (WCAG 2.1 AA, as required by the European Accessibility Act)

Applies to e-commerce and other consumer services sold in the EU since 28 June 2025. Microenterprises (fewer than 10 employees AND up to €2M turnover) providing services are exempt; everyone else is not.

### Page basics
- [ ] **critical** Every page declares its language: `<html lang="sv">` / `lang="en"` (WCAG 3.1.1)
- [ ] Every page has a unique, descriptive `<title>` (2.4.2)
- [ ] Viewport meta does not block zoom: no `user-scalable=no`, no `maximum-scale` below 5 (1.4.4)
- [ ] One `<h1>` per page; heading levels do not skip (1.3.1)
- [ ] A "skip to main content" link is the first focusable element (2.4.1)

### Images and media
- [ ] **critical** Every `<img>` has an `alt` attribute; meaningful images are described, decorative ones use `alt=""` (1.1.1)
- [ ] Product images describe the product (colour, type, view), not "product image"
- [ ] Icon-only links and buttons have an accessible name (`aria-label` or visually hidden text) (2.4.4, 4.1.2)
- [ ] Videos have captions; audio has a transcript (1.2.2)
- [ ] Nothing auto-plays sound for more than 3 seconds without a pause/stop control (1.4.2)
- [ ] Every `<iframe>` has a `title` (4.1.2)

### Text and colour
- [ ] **critical** Normal text has at least 4.5:1 contrast; large text at least 3:1 (1.4.3)
- [ ] Colour is never the only way information is conveyed (error states, required fields, charts) (1.4.1)
- [ ] Text can be resized to 200% without loss of content or function (1.4.4)
- [ ] Content reflows at 320px width without horizontal scrolling (1.4.10)

### Forms
- [ ] **critical** Every input has a visible `<label for="…">` or an `aria-label`; placeholders are not labels (1.3.1, 4.1.2)
- [ ] Required fields are marked in text, not only with colour or an asterisk alone (3.3.2)
- [ ] Error messages say what is wrong and how to fix it, and are announced (3.3.1, 3.3.3)
- [ ] `autocomplete` attributes are set on name, email, address and payment fields (1.3.5)

### Keyboard and focus
- [ ] **critical** Every interactive element is reachable and operable with Tab, Enter and Space (2.1.1)
- [ ] Focus is visible on every element; no `outline: none` without a replacement (2.4.7)
- [ ] Modals, menus and carousels do not trap focus and return focus when closed (2.1.2)
- [ ] No `tabindex` greater than 0 (2.4.3)
- [ ] Focus order matches the visual order (2.4.3)

### Checkout flow (EAA covers the whole flow, not only the home page)
- [ ] Search, product page, cart, checkout, confirmation and account pages all pass the items above
- [ ] Payment provider's embedded forms are keyboard-operable and labelled
- [ ] Time limits (session timeouts, reservation timers) can be extended or turned off (2.2.1)

### Process
- [ ] **critical** An automated WCAG 2.1 AA audit has been run on the main templates and the checkout in the last 90 days (Alfa Audit: audit.alfasystem.se)
- [ ] Critical and high findings are fixed; the dated report is kept
- [ ] A manual screen-reader and keyboard-only walkthrough of the purchase flow has been done at least once
- [ ] **critical** An accessibility statement is published: standard aimed for, known gaps, contact address, date
- [ ] No accessibility "overlay" widget is relied on as the compliance solution

---

## 2. Legal pages (GDPR, consumer law, EAA)

### Privacy policy (GDPR Art. 13–14)
- [ ] **critical** A privacy policy exists and is linked from every page (footer)
- [ ] Names the controller (your company) and contact details
- [ ] Lists every purpose and its legal basis (consent, contract, legitimate interest, legal obligation)
- [ ] Names the actual processors and third parties (email provider, analytics, payment, hosting, chat, CRM)
- [ ] States transfers outside the EU/EEA and the safeguard used (SCCs, adequacy, DPF)
- [ ] States retention periods per data category
- [ ] Lists the data subject rights and how to exercise them
- [ ] Names the supervisory authority (Sweden: IMY) and the right to complain
- [ ] Last-updated date is present and less than 12 months old

### Terms and conditions (if you sell anything)
- [ ] **critical** Terms exist and are presented before purchase
- [ ] Identify the seller, total price, delivery, payment and complaint route
- [ ] Describe what you actually sell today (subscription vs one-off, digital vs physical)
- [ ] Governed by the law of an EU country; no US-only arbitration clauses applied to EU consumers
- [ ] The 14-day right of withdrawal is explained (or the lawful exception stated)

### Return and refund policy (e-commerce)
- [ ] Separate, findable page stating the 14-day withdrawal right and how to use it
- [ ] Refund timing (14 days from notice) and who pays return shipping

### Accessibility statement (EAA; DOS-lagen for public sector)
- [ ] **critical** Published and linked from the footer
- [ ] Names the standard (WCAG 2.1 AA / EN 301 549), known non-conformances, contact address, date
- [ ] Links to or references the latest audit

### Housekeeping
- [ ] Company registration number, VAT number and physical address appear on the site (e-commerce information duty)
- [ ] All legal pages were generated or reviewed for your jurisdictions, not copied from another site (Legal Craft: legalcraft.alfasystem.se)

---

## 3. Cookie consent (ePrivacy / LEK; supervised in Sweden by PTS, with IMY for the data side)

- [ ] **critical** No non-essential cookies or trackers (analytics, ads, pixels, heatmaps, chat) load before the user consents
- [ ] **critical** "Reject all" is as visible and as easy as "Accept all" on the first layer
- [ ] No pre-ticked boxes; closing the banner is not treated as consent
- [ ] Users can change or withdraw consent later (a persistent link or icon)
- [ ] A cookie policy lists each cookie: name, provider, purpose, duration, category
- [ ] Consent is re-asked when the cookie set changes and expires after a defined period
- [ ] Consent records are stored (your CMP does this) in case you have to prove it
- [ ] Strictly necessary cookies (cart, session, consent choice itself) are the only ones set by default

Quick test: open the site in a private window, open DevTools → Network, do not touch the banner. If you see requests to google-analytics, facebook, hotjar, doubleclick or similar, you fail the first item.

---

## 4. Security basics (GDPR Art. 32 "appropriate security")

- [ ] **critical** The whole site is served over HTTPS; HTTP redirects to HTTPS
- [ ] `Strict-Transport-Security` header is set
- [ ] `X-Content-Type-Options: nosniff` header is set
- [ ] A `Content-Security-Policy` exists (even a permissive one is better than none)
- [ ] Admin and account logins use MFA where the platform supports it
- [ ] Forms have rate limiting or a bot check (contact, newsletter, login)
- [ ] Backups exist, are tested, and the restore procedure is written down
- [ ] A data-breach response note exists: who to call, the 72-hour IMY notification deadline
- [ ] Data processing agreements (DPAs) are in place with every processor named in the privacy policy

---

## Scoring

Count unticked **critical** items:

- **0** — You are in better shape than 90% of the web. Keep the audit cadence.
- **1–3** — Fixable in a week. Do them in the order listed.
- **4+** — Start with accessibility statement + privacy policy + cookie blocking; those are the three a regulator sees first.

Need a second opinion? Sign in at belikenikola.com/login and request a free compliance consultation.

Last updated: October 2026.
