Free guide
A plain-English guide to website accessibility and data privacy basics
What the European Accessibility Act, WCAG, and UK/US/India data privacy rules actually require of a small business website, without the jargon or the sales pitch.
If you run a small business website, you've probably seen the warnings: accessibility lawsuits, GDPR fines, the European Accessibility Act. Most of what's written about them is either a sales pitch dressed as an explainer, or dense enough that you need a lawyer to read the explainer. This is neither. It's what we've actually found doing this work, written the way we'd explain it to a friend who runs a shop.
What this is not: legal advice, a compliance checklist, or a promise that following it satisfies any law. Laws differ by country and by your specific business, and only a lawyer who knows your situation can tell you what you're required to do. What we can tell you is what the rules actually say, in the languages we work in every day — the code, and the standards it's tested against.
Part 1: Accessibility
The short version
Some of your visitors use a keyboard instead of a mouse, a screen reader instead of their eyes, or a switch device instead of either. If your site's menus, forms, and pop-ups don't work for them, they can't buy from you — and increasingly, in some places, that's also a legal problem, not just a lost sale.
What actually applies to you
- The European Accessibility Act (EAA) has applied since June 2025 and includes accessibility requirements for certain e-commerce services. Whether your specific business is in scope depends on your circumstances and the rules of the country involved — enforcement is done member-state by member-state, not centrally. If you sell into the EU, this is worth a real answer from a lawyer, not a guess from a blog post.
- The ADA (US) doesn't name websites explicitly, but US courts have increasingly applied it to them, and demand letters and lawsuits over inaccessible websites are a real, ongoing pattern — not a hypothetical.
- The technical yardstick, in both cases, tends to be WCAG (the Web Content Accessibility Guidelines), currently at version 2.2, level AA. The EU's regulatory reference standard is EN 301 549, which currently incorporates WCAG 2.1 AA (version 3.2.1); a newer version (4.1.1) that adopts WCAG 2.2 was reported as published on 2 September 2026 and is expected to be formally cited around November 2026.
What we actually see go wrong (from real complaints, not a generic checklist)
Most accessibility advice is a long list of abstract rules. In our own review of real, recent accessibility complaints and lawsuits, three specific patterns come up again and again on e-commerce sites:
- Drop-down menus that only work with a mouse. A sighted mouse user hovers and a menu appears. A keyboard user tabs to the menu item, presses Enter, and — nothing happens, or the menu opens but they can't reach the items inside it. This is one of the single most common accessibility complaints against online stores.
- Pop-ups that trap or lose keyboard focus. A newsletter sign-up or cookie banner appears, but the keyboard cursor stays "behind" it, or gets stuck inside it with no way to close it without a mouse. Either way, a keyboard-only visitor is stuck.
- The shopping cart itself. When the cart opens as a slide-out panel or a pop-up dialog, can a keyboard-only visitor actually see what's in it, change the quantity, and reach the checkout button — or does the same focus problem happen right at the point of sale?
None of these are exotic. They're the kind of thing that takes a developer minutes to fix once it's found — the hard part is finding it, because standard automated scanners often can't (a hover menu that never gets triggered by a scan looks "fine" to a tool that never actually pressed Tab). This is also, not coincidentally, exactly the kind of thing an honest audit should be testing for by hand, not just running a scanner and calling it done.
What automated tools can and can't tell you
An automated accessibility scan is a genuinely useful starting point — free, fast, and it catches a real category of problems (missing image descriptions, broken form labels, insufficient color contrast, missing headings). But by our own count, running the current WCAG 2.2 standard's 55 success criteria against what an automated tool can actually check: roughly two out of three still require a person — someone using a keyboard, a screen reader, or a real assistive-technology setup to find out whether it actually works. A report that says "zero issues found" from an automated scan alone is telling you something real, but it isn't telling you the site is accessible. It's telling you the easy third passed.
What a real check looks like
At minimum: an automated scan, plus a keyboard-only walkthrough of your main paths (browsing, adding to cart, checking out), plus a check of what happens when things zoom or resize, plus color contrast in every state (not just the default one). Screen-reader testing with real assistive technology goes further still, and is worth asking for explicitly if a report doesn't mention it — a report that doesn't say what wasn't tested is easy to over-trust.
Part 2: Data privacy basics (for the emails and forms your own site sends)
The short version
If your website collects any information from a visitor — a contact form, a newsletter sign-up, an email address — or if you send business emails to other companies, a handful of rules apply depending on where you and your recipients are. They're less about grand principle and more about specific, checkable things.
What actually applies, by place (not exhaustive — a lawyer confirms your specific case)
- UK: Electronic marketing to individual people generally needs their prior consent. Business-to-business marketing to a corporate subscriber (a limited company or LLP, not a sole trader) is treated differently — the consent rule for unsolicited email is generally understood not to apply the same way, but you still need to identify yourself clearly and give a working opt-out, and the UK GDPR still applies to any personal data involved.
- US: The CAN-SPAM Act applies to commercial email, business-to-business included — there's no exemption for B2B. It requires accurate sender information, a subject line that isn't deceptive, clear identification that the message is an advertisement, a valid physical postal address, and a working opt-out that you honor promptly.
- EU (various countries): Several EU countries require prior consent for unsolicited commercial email even between businesses — this varies enough by country that a blanket "EU is fine" or "EU is not fine" answer is usually wrong. Check country by country.
- India: The Digital Personal Data Protection Act, 2023 is being brought into force in stages, and not all of its provisions (including some rights and complaint routes) are operational yet. If you handle personal data of people in India, worth a specific, current check rather than relying on a summary written on any given date — including this one.
The practical checklist that actually matters
Whatever the legal basis, these are the concrete things that keep a small business's outreach and data handling defensible:
- Only write to business role addresses (info@, hello@, sales@) that the company itself publishes, not scraped personal addresses.
- Say plainly who you are, where you're based, and why the recipient is hearing from you.
- Give a real, working way to opt out — and honor it the same day, not "eventually."
- Keep a record of where you got each contact, and delete data you no longer need.
- If you didn't collect the data directly from someone (for example, you found their business email on their own website), tell them so, and tell them the same day they first hear from you — not buried three clicks deep.
Where to go from here
This guide doesn't make your site or your outreach lawful on its own — nothing free does, and we wouldn't tell you it does. What it should do is give you the actual shape of the two problems, so a conversation with a lawyer (for the legal side) or a developer (for the technical side) starts from real footing instead of a vague worry.
If the accessibility side is what brought you here: we run fixed-price WCAG 2.2 AA readiness audits, engineering-led, with findings your developer can act on directly. See what's included or get a free automated snapshot first — no certificate claims, no pressure, just what we actually found on your pages.
This guide reflects our understanding as engineers, not lawyers, as of 22 September 2026. It is not legal advice. Laws and their commencement dates change; verify anything time-sensitive independently.
See what your store looks like to a stranger
Send us your store address. We send a one-page snapshot within one working day. No call needed.
We only look at public pages, and only once. See how we handle your details.